<?xml version="1.0"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>openSUSE News</title>
    <link>https://news.opensuse.org</link>
    <description>Latest news from the openSUSE Project</description>
    <atom:link href="https://news.opensuse.org/feed.xml" rel="self" type="application/rss+xml"/>

    <item>
      <guid>https://news.opensuse.org/2026/06/03/tsp-open-for-asia-summit/</guid>
      <title>TSP Open for Asia Summit</title>
      <pubDate>Wed, 03 Jun 2026 11:00:00 +0000</pubDate>
      <link>https://news.opensuse.org/2026/06/03/tsp-open-for-asia-summit/</link>
      <author>admin@opensuse.org (Douglas DeMaio)</author>
      <enclosure url="https://news.opensuse.org/wp-content/uploads/2025/12/yogyakarta.png" length="286780" type="image/png" />
      <description>The Travel Support Program (TSP), which is aided through donations to the Geeko Foundation, is now accepting applications for the openSUSE.Asia Summit 2026. Funds are allocated by the foundation specifically for travel assistance for speakers attending the event. Applications for the TSP are open now and will run until July...</description>
      <content:encoded>&lt;p&gt;The &lt;a href=&quot;https://en.opensuse.org/openSUSE:Travel_Support_Program&quot;&gt;Travel Support Program (TSP)&lt;/a&gt;, which is aided through donations to the &lt;a href=&quot;https://geekos.org/&quot;&gt;Geeko Foundation&lt;/a&gt;, is now accepting applications for the &lt;a href=&quot;https://events.opensuse.org/conferences/oSAS26&quot;&gt;openSUSE.Asia Summit 2026&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Funds are allocated by the foundation specifically for travel assistance for speakers attending the event.&lt;/p&gt;

&lt;p&gt;Applications for the TSP are open now and will run until July 31, which will follow an announcement related the Call for Papers.&lt;/p&gt;

&lt;p&gt;People whose talks are accepted can submit a request at &lt;a href=&quot;https://tsp.opensuse.org/events&quot;&gt;tsp.opensuse.org&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;The TSP exists to ensure financial constraints don’t prevent passionate contributors and community members from participating.&lt;/p&gt;

&lt;p&gt;The openSUSE.Asia Summit 2026 organizers of the summit encourage you to apply early.&lt;/p&gt;

&lt;p&gt;For questions about the TSP process, visit the &lt;a href=&quot;https://en.opensuse.org/openSUSE:Travel_Support_Program&quot;&gt;wiki for more information&lt;/a&gt; and read the &lt;a href=&quot;https://en.opensuse.org/images/4/4c/Geeko_Foundation_Travel_Policy.pdf&quot;&gt;Geeko Foundation’s travel policy&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Further details will be shared later about the event planning, so please pay attention to announcements for the summit.&lt;/p&gt;

&lt;p&gt;We look forward to seeing you there!&lt;/p&gt;

&lt;p&gt;For more details on openSUSE.Asia Summit 2026, visit &lt;a href=&quot;https://events.opensuse.org/&quot;&gt;events.opensuse.org&lt;/a&gt;.&lt;/p&gt;

&lt;meta name=&quot;openSUSE, community, project, conference, open source, tsp, Geeko, cfp&quot; content=&quot;HTML,CSS,XML,JavaScript&quot; /&gt;

</content:encoded>
    </item>

    <item>
      <guid>https://news.opensuse.org/2026/06/01/tw-monthly-update-may/</guid>
      <title>Tumbleweed Monthly Update - May 2026</title>
      <pubDate>Mon, 01 Jun 2026 11:00:00 +0000</pubDate>
      <link>https://news.opensuse.org/2026/06/01/tw-monthly-update-may/</link>
      <author>admin@opensuse.org (Douglas DeMaio)</author>
      <enclosure url="https://news.opensuse.org/wp-content/uploads/2025/05/tw.png" length="209112" type="image/png" />
      <description>May delivered a steady cadence of openSUSE Tumbleweed snapshots across the major desktop stacks with KDE Gear 26.04.1, KDE Frameworks 6.26.0, Plasma 6.6.5 and GNOME 50 minor releases. Mesa made a couple leaps with the 26.1 series with the new Vulkan 1.4 Application Programming Interfaces, and the Linux kernel progressed...</description>
      <content:encoded>&lt;p&gt;May delivered a steady cadence of &lt;a href=&quot;https://get.opensuse.org/tumbleweed/&quot;&gt;openSUSE Tumbleweed&lt;/a&gt; snapshots across the major desktop stacks with &lt;a href=&quot;https://kde.org/announcements/gear/26.04.1/&quot;&gt;KDE Gear 26.04.1&lt;/a&gt;, &lt;a href=&quot;https://kde.org/announcements/frameworks/6/6.26.0&quot;&gt;KDE Frameworks 6.26.0&lt;/a&gt;, &lt;a href=&quot;https://kde.org/announcements/plasma/6/6.6.5&quot;&gt;Plasma 6.6.5&lt;/a&gt; and &lt;a href=&quot;https://release.gnome.org/50/&quot;&gt;GNOME 50&lt;/a&gt; minor releases. &lt;a href=&quot;https://www.mesa3d.org/&quot;&gt;Mesa&lt;/a&gt; made a couple leaps with the 26.1 series with the new &lt;a href=&quot;https://www.vulkan.org/&quot;&gt;Vulkan&lt;/a&gt; 1.4 &lt;a href=&quot;https://en.wikipedia.org/wiki/API&quot;&gt;Application Programming Interfaces&lt;/a&gt;, and the &lt;a href=&quot;https://www.kernel.org/&quot;&gt;Linux kernel&lt;/a&gt; progressed from 7.0.5 through 7.0.9 with significant security and driver fixes. Sysadmins received a major &lt;a href=&quot;https://gitlab.com/apparmor/apparmor&quot;&gt;AppArmor&lt;/a&gt; 5.0 release and a fresh &lt;a href=&quot;https://httpd.apache.org/&quot;&gt;Apache HTTP Server&lt;/a&gt; 2.4.67 carrying many &lt;a href=&quot;https://en.wikipedia.org/wiki/Common_Vulnerabilities_and_Exposures&quot;&gt;Common Vulnerability and Exposure&lt;/a&gt; fixes.&lt;/p&gt;

&lt;p&gt;Other notable bumps include &lt;a href=&quot;https://libusb.info/&quot;&gt;libusb&lt;/a&gt; 1.0.30, &lt;a href=&quot;https://gnupg.org/&quot;&gt;GnuPG&lt;/a&gt; 2.5.20, &lt;a href=&quot;https://www.libreoffice.org/&quot;&gt;LibreOffice&lt;/a&gt; 26.2.3.2, &lt;a href=&quot;https://www.postgresql.org/&quot;&gt;PostgreSQL&lt;/a&gt; 18.4, &lt;a href=&quot;https://rsync.samba.org/&quot;&gt;rsync&lt;/a&gt; 3.4.3, &lt;a href=&quot;https://poppler.freedesktop.org/&quot;&gt;poppler&lt;/a&gt; 26.05.0, and &lt;a href=&quot;https://libexpat.github.io/&quot;&gt;Expat&lt;/a&gt; 2.8.1.&lt;/p&gt;

&lt;p&gt;Security received heavy attention with &lt;a href=&quot;https://httpd.apache.org/&quot;&gt;Apache HTTP Server&lt;/a&gt;, &lt;a href=&quot;https://www.postgresql.org/&quot;&gt;PostgreSQL&lt;/a&gt;, &lt;a href=&quot;https://rsync.samba.org/&quot;&gt;rsync&lt;/a&gt;, &lt;a href=&quot;https://www.thekelnetworks.org/projects/dnsmasq.html&quot;&gt;dnsmasq&lt;/a&gt;, &lt;a href=&quot;https://jqlang.github.io/jq/&quot;&gt;jq&lt;/a&gt;, &lt;a href=&quot;https://www.php.net/&quot;&gt;PHP&lt;/a&gt;, &lt;a href=&quot;https://openexr.com/&quot;&gt;OpenEXR&lt;/a&gt;, and the &lt;a href=&quot;https://www.kernel.org/&quot;&gt;Linux kernel&lt;/a&gt; all receiving multiple &lt;a href=&quot;https://en.wikipedia.org/wiki/Common_Vulnerabilities_and_Exposures&quot;&gt;CVE&lt;/a&gt; fixes.&lt;/p&gt;

&lt;p&gt;As always, be sure to roll back using &lt;a href=&quot;https://github.com/openSUSE/snapper&quot;&gt;snapper&lt;/a&gt; if any issues arise.&lt;/p&gt;

&lt;p&gt;For more details on the change logs for the month, visit the &lt;a href=&quot;https://lists.opensuse.org/archives/list/factory@lists.opensuse.org/&quot;&gt;openSUSE Factory mailing list&lt;/a&gt;.&lt;/p&gt;

&lt;h2 id=&quot;new-features-and-enhancements&quot;&gt;New Features and Enhancements&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://kde.org/announcements/gear/26.04.1/&quot;&gt;KDE Gear 26.04.1&lt;/a&gt;&lt;/strong&gt;: &lt;a href=&quot;https://community.kde.org/KDE_PIM/Akonadi&quot;&gt;Akonadi&lt;/a&gt; fixes a crash in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;EntityTreeView&lt;/code&gt; when selecting multiple items, and &lt;a href=&quot;https://apps.kde.org/korganizer/&quot;&gt;KOrganizer&lt;/a&gt; resolves black squares in the todo view and re-enables icons in monthview. &lt;a href=&quot;https://apps.kde.org/dolphin/&quot;&gt;Dolphin&lt;/a&gt; refines the selection panel and search popup behavior. &lt;a href=&quot;https://apps.kde.org/kate/&quot;&gt;Kate&lt;/a&gt; restores middle-click closing of tabs when the close button is disabled, &lt;a href=&quot;https://apps.kde.org/konsole/&quot;&gt;Konsole&lt;/a&gt; prevents &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;QTabBar&lt;/code&gt; from closing tabs on stray middle clicks, and &lt;a href=&quot;https://apps.kde.org/okular/&quot;&gt;Okular&lt;/a&gt; hardens fax handling against malformed &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;.g3&lt;/code&gt; inputs. &lt;a href=&quot;https://apps.kde.org/umbrello/&quot;&gt;Umbrello&lt;/a&gt; gets six bug fixes including diagram-load and Qt6 configuration crashes, and &lt;a href=&quot;https://apps.kde.org/itinerary/&quot;&gt;Itinerary&lt;/a&gt; adds new Condor PKPass and monbus.es ticket extractors.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://kde.org/announcements/frameworks/6/6.26.0&quot;&gt;KDE Frameworks 6.26.0&lt;/a&gt;&lt;/strong&gt;: &lt;a href=&quot;https://invent.kde.org/frameworks/kio&quot;&gt;KIO&lt;/a&gt; adds the Startpage search provider, expands &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;KFilePlacesModel&lt;/code&gt; with kdeconnect device support, gains MIME-type detection from text content in the paste flow, and exposes the current folder in the file widget placeholder. &lt;a href=&quot;https://invent.kde.org/frameworks/kcoreaddons&quot;&gt;KCoreAddons&lt;/a&gt; introduces &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;KAboutRelease&lt;/code&gt; for listing application release notes, parses AppStream release notes, and switches to &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;libmount&lt;/code&gt; for filesystem-type detection where available. &lt;a href=&quot;https://invent.kde.org/frameworks/kimageformats&quot;&gt;KImageFormats&lt;/a&gt; corrects EXR loading from Photoshop 2026 saves, plugs JXR memory leaks, and improves EXIF handling. &lt;a href=&quot;https://invent.kde.org/frameworks/kholidays&quot;&gt;KHolidays&lt;/a&gt; introduces &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;HolidayCategories&lt;/code&gt; and fixes Philippines Easter holidays.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://kde.org/announcements/plasma/6/6.6.5&quot;&gt;Plasma 6.6.5&lt;/a&gt;&lt;/strong&gt;: &lt;a href=&quot;https://invent.kde.org/plasma/kwin&quot;&gt;KWin&lt;/a&gt; gains numerous DRM backend fixes including correctly updating outputs only on changed GPUs, preserving custom output modes across reboots, setting full color range for RGB planes on NVIDIA, and avoiding multi-GPU copies with unsupported formats. Input handling is hardened by mapping devices to device outputs (not logical ones), processing key repeat before the accessibility monitor, and cleaning up keyboard grabs on shutdown. &lt;a href=&quot;https://invent.kde.org/plasma/kscreen&quot;&gt;KScreen&lt;/a&gt; hides the DDC/CI option when HDR is enabled and prevents off-by-one gaps when creating replicas. &lt;a href=&quot;https://apps.kde.org/discover/&quot;&gt;Discover&lt;/a&gt; corrects text color inversion in ProgressView, and &lt;a href=&quot;https://invent.kde.org/plasma/plasma-workspace&quot;&gt;Plasma Workspace&lt;/a&gt; fixes klipper clipboard updates, lockscreen timezone init races on multi-screen, and broken text legibility with the Air and Breeze Light themes. &lt;a href=&quot;https://apps.kde.org/spectacle/&quot;&gt;Spectacle&lt;/a&gt; keeps the application alive briefly after copying screenshots and fixes magnifier activation during hover events. &lt;a href=&quot;https://invent.kde.org/plasma/powerdevil&quot;&gt;PowerDevil&lt;/a&gt; addresses screen brightness getting stuck at 30 percent after a restart.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://release.gnome.org/50/&quot;&gt;GNOME&lt;/a&gt; 50.1 and 50.2&lt;/strong&gt;: These point releases bring stability and usability fixes across the GNOME desktop. &lt;a href=&quot;https://wiki.gnome.org/Projects/GDM&quot;&gt;GDM&lt;/a&gt; 50.1 fixes a failure to properly terminate conflicting graphical sessions started outside of GDM (such as ThinLinc or TigerVNC) by querying logind directly, and resolves Plymouth hanging indefinitely on headless systems or those without monitors. A bug incorrectly setting &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;XDG_SESSION_TYPE=wayland&lt;/code&gt; on X11 sessions was corrected, along with &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;XDG_DATA_DIRS&lt;/code&gt; construction that could prevent &lt;a href=&quot;https://gitlab.gnome.org/GNOME/gnome-shell&quot;&gt;GNOME Shell&lt;/a&gt; from finding its files. GNOME Shell 50.2 fixes extending screenshot area selection to monitor edges, adds rate control to VA-API H.264 screencast pipelines, and restores the “Install Updates” checkbox in the power-off/restart dialog. Autorun notifications for USB drives, spinner resets during overview search, and wiggle feedback on non-password auth failures are all corrected, and the audio input icon now only appears when actually recording. &lt;a href=&quot;https://apps.gnome.org/Settings/&quot;&gt;GNOME Control Center&lt;/a&gt; 50.2 fixes the “Show Content” notification setting, relaxes app-id validation for Global Shortcuts, and improves mobile-width label fitting in Device Security and Wellbeing panels. &lt;a href=&quot;https://gitlab.gnome.org/GNOME/gnome-session&quot;&gt;GNOME Session&lt;/a&gt; 50.1 fixes a double-free bug. For Tumbleweed users, these updates improve login reliability, screencast quality, and overall GNOME desktop polish.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://apps.kde.org/kdenetwork_filesharing/&quot;&gt;KDE Network File Sharing&lt;/a&gt; 26.04.0&lt;/strong&gt;: This update refactors the file properties plugin initialization and now automatically enables and starts the Samba service if needed when sharing folders. Service aliases are handled correctly, the user list in combo boxes is clipped with scrolling disabled for better usability, and a regression in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;smbd&lt;/code&gt; path lookup was fixed.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://gitlab.com/apparmor/apparmor&quot;&gt;AppArmor&lt;/a&gt; 5.0.0&lt;/strong&gt;: This major version bump from the 4.1 series is a significant milestone for the mandatory access control framework. The release modernizes the parser and userspace utilities, adopts a new ABI &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;abi/5.0&lt;/code&gt;, and introduces broader profile updates. Profiles for &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;samba&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;dovecot&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;postfix&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;wpa_supplicant&lt;/code&gt;, and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;syslog-ng&lt;/code&gt; are refined to better handle modern filesystem layouts. The full upstream changelog is available at the &lt;a href=&quot;https://gitlab.com/apparmor/apparmor/-/wikis/Release_Notes_5.0.0&quot;&gt;AppArmor 5.0 release notes wiki&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://gnupg.org/&quot;&gt;GnuPG&lt;/a&gt; 2.5.20&lt;/strong&gt;: This update implements GCM encryption in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;gpgsm&lt;/code&gt; (decryption was already supported in earlier versions), adds the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;--attribute&lt;/code&gt; option and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;SETATTR&lt;/code&gt; server command for including arbitrary signed or unsigned attributes in signatures, and introduces a new system attribute &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;_signingCertificateV2&lt;/code&gt;. A possible double free in the CMS parser is fixed, along with a buffer overflow in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;scdaemon&lt;/code&gt; when handling SC-HSM cards with RSA keys larger than 2 kilobits. Several agent and keyboxd fixes correct loopback pinentry caching and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;PUT_SECRET&lt;/code&gt; input handling.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://libusb.info/&quot;&gt;libusb&lt;/a&gt; 1.0.30&lt;/strong&gt;: This update introduces new APIs &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;libusb_get_device_string()&lt;/code&gt; and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;libusb_get_session_data()&lt;/code&gt; for accessing device strings without opening the device and retrieving OS-specific handles. Device removal races on non-hotplug builds are fixed and descriptor parsing memory safety is improved.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://poppler.freedesktop.org/&quot;&gt;poppler&lt;/a&gt; 26.05.0&lt;/strong&gt;: This jump from 26.02.0 rolls up three upstream releases. The release improves reconstruction of damaged files, fixes crashes in malformed documents, and removes the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;PSOutputDev&lt;/code&gt; “pipe as filename” feature for security reasons. &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;pdftotext&lt;/code&gt; gains a &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;-remove-hyphens&lt;/code&gt; option and no longer aborts on empty strings. The qt5/qt6 search APIs receive a fix for inverted continuation rectangles, and the GPG signature backend correctly marks qualified keys.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://gnupg.org/&quot;&gt;gpg2&lt;/a&gt; and &lt;a href=&quot;https://gnupg.org/software/libksba/&quot;&gt;libksba&lt;/a&gt; 1.8.0&lt;/strong&gt;: The S/MIME-related X.509 and CMS support library jumps from 1.6.8 to 1.8.0. New functions include &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;ksba_cms_add_attribute&lt;/code&gt; and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;ksba_cms_get_attribute&lt;/code&gt;, support for building &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;AuthEnvelopedData&lt;/code&gt;, and corrections to silent truncation of 64-bit length fields and overflow guard conditions in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;_ksba_ber_read_tl&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://github.com/vmware/open-vm-tools&quot;&gt;open-vm-tools&lt;/a&gt; 13.1.0&lt;/strong&gt;: This major version bump introduces support for GTK4 alongside continued GTK3 compatibility. The configure script accepts options to restrict the build to either toolkit; otherwise it picks the latest available. Several upstream GitHub issues are resolved as documented in the &lt;a href=&quot;https://github.com/vmware/open-vm-tools/blob/stable-13.1.0/ReleaseNotes.md&quot;&gt;13.1.0 Release Notes&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://fwupd.org/&quot;&gt;fwupd&lt;/a&gt; 2.1.3&lt;/strong&gt;: This update for the firmware update daemon continues to add features and hardware coverage. New capabilities include Redfish bearer token authentication, support for several XMC SPI chips, parsing of JCat files without &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;libjcat&lt;/code&gt;, native CBOR parsing (dropping &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;libcbor2&lt;/code&gt; as a dependency), and an HSI check for AMD SB-7033 (a.k.a. EntrySign). The earlier 2.1.2 release also added native EFI authenticated variable loading with ContentInfo headers and decompression-ratio limits to prevent ZIP-bomb-style emulation parsing. New hardware support spans the SHIFT6mq, SHIFTphone 8, Google Moonstone, Lenovo USB-4 dock, HP 400/405 Mouse, Parade USB hubs with GPIO control, Pixart PLP239 devices, Raydium TP devices, Sunplus cameras, and the LX Semicon SW42101 touch controller.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://pypi.org/project/cryptography/&quot;&gt;python-cryptography&lt;/a&gt; 48.0.0&lt;/strong&gt;: A major version bump that drops Python 3.8 support and changes X.509 CRL parsing so that a mismatched inner &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;TBSCertList.signature&lt;/code&gt; and outer &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;signatureAlgorithm&lt;/code&gt; raises a &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;ValueError&lt;/code&gt;. ML-KEM and ML-DSA are now supported when building against OpenSSL 3.5.0 or later (in addition to AWS-LC and BoringSSL), bringing post-quantum algorithms to upstream wheel users.&lt;/p&gt;

&lt;h2 id=&quot;key-package-updates&quot;&gt;Key Package Updates&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://kernel.org/&quot;&gt;Linux Kernel&lt;/a&gt; 7.0.9&lt;/strong&gt;: The kernel progressed through 7.0.5, 7.0.6, 7.0.7 and 7.0.9 during the month, accumulating a substantial pile of security and stability fixes. The 7.0.5 release fixed a buffer overflow in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;vrealloc_node_align()&lt;/code&gt; along with a deadlock in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;mmap_prepare&lt;/code&gt; error handling when holding rmap. The crypto subsystem received extensive fixes including memory leaks in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;atmel-aes&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;ccree&lt;/code&gt;, and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;nx842&lt;/code&gt;, a use-after-free in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;atmel-sha204a&lt;/code&gt; removal, and short digest rejection in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;authencesn&lt;/code&gt;. &lt;a href=&quot;https://netfilter.org/&quot;&gt;netfilter&lt;/a&gt; rejects zero shifts in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;nft_bitwise&lt;/code&gt;, and IPsec (&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;xfrm&lt;/code&gt;) avoids in-place decryption on shared skb fragments. NTFS3 receives integer overflow and buffer boundary checks in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;run_unpack()&lt;/code&gt;, and &lt;a href=&quot;https://erofs.docs.kernel.org/&quot;&gt;EROFS&lt;/a&gt; fixes an unsigned underflow in LZ4 overlap handling. The 7.0.6 follow-up added an &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;rxrpc&lt;/code&gt; fix for &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;DATA/RESPONSE&lt;/code&gt; packets when paged frags are present and an ALSA fasync state-check serialization. The 7.0.7 release brought multiple CVE fixes detailed below, scsi target configfs bounds tightening in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;snprintf()&lt;/code&gt;, ipmi event/receive message limits, KVM x86 shadow-paging use-after-free protection, smbdirect MR registration fixes for coalesced SG lists, and many wifi mt76 fixes for mt7921/mt7925. The 7.0.9 jump adds HID fixes (PlayStation &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;num_touch_reports&lt;/code&gt; clamp, appletb-kbd UAF on inactivity-timer cleanup, pidff integer overflow), drm/gpusvm correctness fixes, and many spi controller deregistration fixes.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://curl.se/&quot;&gt;curl&lt;/a&gt; 8.20.0&lt;/strong&gt;: This release addresses half a dozen security vulnerabilities. RTMP support is dropped entirely and SMB support is now opt-in. A new thread pool and queue system was added for async resolution, and HTTPS DNS record resolution is made more reliable. Credential handling is hardened across redirects, with digest nonces cleared on cross-origin redirects and proxy credentials cleared on port or scheme changes. The alt-svc and HSTS lists are now capped (at 5,000 entries) and expired entries are skipped when reading from file. HTTP/2 now prevents secure schemes being pushed over insecure connections, and MIME processing limits nesting to 40 levels.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.gnutls.org/&quot;&gt;GnuTLS&lt;/a&gt; 3.8.13&lt;/strong&gt;: This major security release addresses more than a dozen vulnerabilities. Three high-severity DTLS reassembly issues are fixed. Medium-severity fixes address a use-after-free in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;gnutls_pkcs11_token_set_pin()&lt;/code&gt;, an overread in RSA key exchange with PKCS#11 keys, CN fallback suppression issues with URI/SRV SANs, and intersecting empty name constraints. Lower-severity fixes cover a multi-entry OCSP response revocation bypass, a timing side-channel in PKCS#7 padding removal, and an off-by-one in PKCS#12 bag bounds checking. HPKE (Hybrid Public Key Encryption, &lt;a href=&quot;https://www.rfc-editor.org/rfc/rfc9180&quot;&gt;RFC 9180&lt;/a&gt;) is available as a technology preview, ML-DSA public key derivation from expanded private keys (&lt;a href=&quot;https://www.rfc-editor.org/rfc/rfc9881&quot;&gt;RFC 9881&lt;/a&gt;) is supported, and building with &lt;a href=&quot;https://www.lysator.liu.se/~nisse/nettle/&quot;&gt;Nettle&lt;/a&gt; 4.0 is now possible. TLS 1.3 client certificate selection is fixed for servers advertising only &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;rsa_pss_rsae_*&lt;/code&gt; algorithms, and kTLS ChaCha20-Poly1305 IV handling is corrected for TLS 1.2.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://docs.gtk.org/glib/&quot;&gt;GLib&lt;/a&gt; 2.88.1&lt;/strong&gt;: This update fixes a miscompilation with GCC 16 caused by incorrect function attribute usage. A flag confusion security issue in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;GRegex&lt;/code&gt; when using &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;G_REGEX_RAW&lt;/code&gt; is resolved, which could result in unbounded out-of-bounds heap reads off the start of a regex input string. Various minor security issues are also addressed, typically involving small out-of-bounds reads or scenarios relying on discouraged P2P D-Bus configurations.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://sqlite.org/&quot;&gt;SQLite&lt;/a&gt; 3.53.1&lt;/strong&gt;: The recovery extension is hardened against SQL injections from the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;sqlite_schema&lt;/code&gt; table of databases being recovered. A crash in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;sqlite3_deserialize()&lt;/code&gt; when overwriting a database with an open transaction is fixed (a bug dating back to version 3.23.0). A single-byte out-of-bounds read in the session module when concatenating patchsets is corrected. The EXISTS-to-JOIN optimization receives fixes for OR-optimization early-exit logic and OFFSET clause handling. A &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;printf()&lt;/code&gt; optimization regression causing &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;sqlite3_snprintf()&lt;/code&gt; to incorrectly truncate floating-point conversions is resolved, and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;sqlite3_str_free()&lt;/code&gt; no longer crashes when called on objects returned after an out-of-memory condition.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.mesa3d.org/&quot;&gt;Mesa&lt;/a&gt; 26.1.0 to 26.1.1&lt;/strong&gt;: Version 26.1.1 fixes &lt;a href=&quot;https://docs.mesa3d.org/drivers/radv.html&quot;&gt;RADV&lt;/a&gt; sample shading with required sample-shaded inputs, VRS with mipmaps on GFX10.3, acceleration structure copies with DAC, and enables a VM map update workaround for Forza Horizon 6. &lt;a href=&quot;https://docs.mesa3d.org/drivers/anv.html&quot;&gt;ANV&lt;/a&gt; (Intel) adds a SIMD32 requirement heuristic for &lt;a href=&quot;https://store.steampowered.com/agecheck/app/2054970/&quot;&gt;Dragon Dogma 2&lt;/a&gt;, fixes usage flags not propagated to ISL for explicit layouts, bumps the max compute workgroup count, and corrects timebase scale precision loss across 2^32 ticks. The &lt;a href=&quot;https://www.vulkan.org/&quot;&gt;Vulkan&lt;/a&gt; 1.4 API is now implemented, with support varying by driver with version 26.1.0. Experimental support for Intel Nova Lake P hardware is introduced. &lt;a href=&quot;https://docs.mesa3d.org/drivers/zink.html&quot;&gt;Zink&lt;/a&gt; now supports OpenGL ES 2.0 on PowerVR GPUs, expanding its reach to embedded hardware. New Vulkan and OpenGL extensions are supported across drivers including &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;VK_EXT_present_timing&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;GL_NV_timeline_semaphore&lt;/code&gt; (RadeonSI), &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;VK_QCOM_image_processing&lt;/code&gt; (Turnip), &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;VK_KHR_present_id&lt;/code&gt;, and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;VK_KHR_present_wait&lt;/code&gt;. &lt;a href=&quot;https://docs.mesa3d.org/rusticl.html&quot;&gt;Rusticl&lt;/a&gt; (OpenCL) now requires a static C++ standard library. The update delivers broader Vulkan support, improved virtualization performance, and expanded hardware compatibility.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://gstreamer.freedesktop.org/&quot;&gt;GStreamer&lt;/a&gt; 1.28.3&lt;/strong&gt;: A bugfix release with security fixes across the framework. Highlights include &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;applemedia&lt;/code&gt; vtdec stability, MoltenVK integration and planar video format handling fixes, an &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;audioresample&lt;/code&gt; regression fix on armv7hf, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;bpmdetect&lt;/code&gt; corrections for stereo and multi-channel modes, and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;webrtcsink&lt;/code&gt; support for the imx8mp &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;vpuenc_hevc&lt;/code&gt; H.265 encoder. Codec parsers receive multiple hardening fixes including a stack buffer overflow in the H.265 buffering period SEI parser, bounds checks in MPEG-TS PES header parsing, and a heap buffer overflow in MXF AES3 audio descriptor &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;write_tags&lt;/code&gt;. The &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;mxf&lt;/code&gt; and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;mpegtsdemux&lt;/code&gt; plugins receive numerous additional bounds and overflow fixes, and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;pngparse&lt;/code&gt; gets a use-after-free fix. Several memory leaks across &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;decodebin2&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;subparse&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;samiparse&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;baseparse&lt;/code&gt;, and others are also addressed.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://libexpat.github.io/&quot;&gt;expat&lt;/a&gt; 2.8.1&lt;/strong&gt;: This update jumps from 2.7.5 and addresses two security issues. A quadratic-runtime attack via attribute name collision checks is corrected, and the SipHash-based hash flooding protection now uses the full 16 bytes of salt instead of 4 to 8. The existing &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;XML_SetHashSalt&lt;/code&gt; API is deprecated and a new &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;XML_SetHashSalt16Bytes&lt;/code&gt; is introduced for callers that want to provide their own high-quality entropy.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://rsync.samba.org/&quot;&gt;rsync&lt;/a&gt; 3.4.3&lt;/strong&gt;: A security-focused release fixing six CVEs in the file-synchronization tool. Three of the six (&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;CVE-2026-29518&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;CVE-2026-43617&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;CVE-2026-43619&lt;/code&gt;) require non-default daemon configurations, two (&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;CVE-2026-43618&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;CVE-2026-43620&lt;/code&gt;) are reachable from normal pulls or normal authenticated daemon connections, and the sixth (&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;CVE-2026-45232&lt;/code&gt;) requires &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;RSYNC_PROXY&lt;/code&gt; to be set with a pathological proxy response. Detailed CVE notes appear in the security section below. The release also adds defence-in-depth hardening on adjacent paths and fixes a regression introduced by the 3.4.0 &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;secure_relative_open()&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.postgresql.org/&quot;&gt;PostgreSQL&lt;/a&gt; 18.4&lt;/strong&gt;: This point release of the database addresses 10 CVEs covering schema privilege checks, integer overflows in memory allocation calculations, time-zone name handling, path traversal in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;pg_basebackup&lt;/code&gt; and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;pg_rewind&lt;/code&gt;, subscription-name quoting in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;pg_createsubscriber&lt;/code&gt;, marking &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;PQfn()&lt;/code&gt; as unsafe, timing-safe string comparisons in authentication, recursion limits in startup packet processing, MCV statistics validation, SQL injection protection in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;contrib/spi&lt;/code&gt;, and quoting of object names in logical replication origin checks. See &lt;a href=&quot;https://www.postgresql.org/docs/release/18.4/&quot;&gt;the official 18.4 release announcement&lt;/a&gt; for full notes.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.thekelnetworks.org/projects/dnsmasq.html&quot;&gt;dnsmasq&lt;/a&gt; 2.92rel2&lt;/strong&gt;: A security-focused point release fixing six CVEs in the DNS and DHCP server. Vulnerabilities include cache poisoning that could enable DoS or attacker redirection, DNSSEC validation flaws, a heap out-of-bounds read in DNSSEC validation, a heap out-of-bounds write in DHCPv6 handling, an information disclosure flaw allowing source-check bypass, and a buffer overflow in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;extract_addresses()&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://imagemagick.org/&quot;&gt;ImageMagick&lt;/a&gt; 7.1.2.23 and 7.1.2.24&lt;/strong&gt;: The 7.1.2.24 version strengthens input validation by rejecting MTV, TGA, Cineon, and Farbfeld image files with zero columns or rows, preventing potential crashes or undefined behavior from malformed files. A new profile fuzzer is added for raw EXIF, XMP, IPTC, and ICC parsing to improve robustness. The 7.1.2.23 version rolls up many GitHub security advisories from upstream and applies an integer overflow fix tracked as &lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-31853.html&quot;&gt;CVE-2026-31853&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://openexr.com/&quot;&gt;OpenEXR&lt;/a&gt; 3.4.11&lt;/strong&gt;: A double update from 3.4.9 through 3.4.10 to 3.4.11 closes several additional CVEs in the EXR image format library. Fixes address a shift exponent overflow in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;readVariableLengthInteger()&lt;/code&gt;, an out-of-bounds read in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;IDManifest::init()&lt;/code&gt; during prefix expansion, an integer overflow in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;ImageChannel::resize&lt;/code&gt;, a signed integer overflow in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;ht_undo_impl()&lt;/code&gt; in the HTJ2K decoder, and two missed variants of the earlier DWA-decoder pointer arithmetic overflow.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://invisible-island.net/ncurses/&quot;&gt;ncurses&lt;/a&gt; 6.6.20260516&lt;/strong&gt;: Two snapshot patches bring loop limit corrections in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;lib_twait.c&lt;/code&gt;, magic-cookie initialization deferral, terminal database refinements for kitty, contour, screen4/screen5, xterm-utf8, and warp, and a &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;recur_wgetnstr()&lt;/code&gt; buffer limit correction.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://developers.hp.com/hp-linux-imaging-and-printing&quot;&gt;hplip&lt;/a&gt; 3.26.4&lt;/strong&gt;: A new release of the HP Linux Imaging and Printing project adds support for a broad range of new printers including the HP LaserJet Pro MFP 3106sdw/3105sdw, OfficeJet Pro 9730/9720/8130/8120 series, Envy 6500 series, and several DeskJet Ink Advantage models.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.lunarg.com/vulkan-sdk/&quot;&gt;Vulkan SDK&lt;/a&gt; 1.4.350&lt;/strong&gt;: Both &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;vulkan-loader&lt;/code&gt; and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;vulkan-tools&lt;/code&gt; jump from 1.4.341 to 1.4.350. &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;vulkaninfo&lt;/code&gt; now enables the device groups extension and checks extensions before querying properties, and a wrong extension being used for GGP is corrected.&lt;/p&gt;

&lt;h2 id=&quot;security-updates&quot;&gt;Security Updates&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://github.com/ecki/net-tools&quot;&gt;net-tools&lt;/a&gt; 3.14~alpha&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2024-58251.html&quot;&gt;CVE-2024-58251&lt;/a&gt;&lt;/strong&gt;: Fixes a flaw in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;netstat&lt;/code&gt; where a local user could launch a network application and cause a denial of service by locking up the terminal of a victim viewing netstat output.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://curl.se/&quot;&gt;curl&lt;/a&gt; 8.20.0&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-4873.html&quot;&gt;CVE-2026-4873&lt;/a&gt;&lt;/strong&gt;: Addresses a flaw where a connection requiring TLS could incorrectly reuse an existing unencrypted IMAP, POP3, or SMTP connection from the pool and cause the subsequent data to be transmitted in clear-text.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-5545.html&quot;&gt;CVE-2026-5545&lt;/a&gt;&lt;/strong&gt;: Resolves a vulnerability where HTTP Negotiate connections could be wrongly reused and potentially lead to authentication bypass.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-5773.html&quot;&gt;CVE-2026-5773&lt;/a&gt;&lt;/strong&gt;: Fixes a flaw where SMB connections could be reused for transfers to a different share on the same server and potentially lead to the wrong file being downloaded or uploaded.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-6253.html&quot;&gt;CVE-2026-6253&lt;/a&gt;&lt;/strong&gt;: Addresses a credential leak where proxy credentials could be exposed across a redirect to a different proxy.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-6276.html&quot;&gt;CVE-2026-6276&lt;/a&gt;&lt;/strong&gt;: Resolves a cookie leak caused by stale custom cookie host handling on subsequent requests.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-6429.html&quot;&gt;CVE-2026-6429&lt;/a&gt;&lt;/strong&gt;: Fixes a &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;.netrc&lt;/code&gt; credential leak when a proxy connection was reused across requests.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://tracker.debian.org/pkg/dpkg&quot;&gt;update-alternatives&lt;/a&gt; 1.22.22&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-2219.html&quot;&gt;CVE-2026-2219&lt;/a&gt;&lt;/strong&gt;: Addresses a flaw that could result in denial of service via an infinite CPU-spinning loop.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.gnutls.org/&quot;&gt;GnuTLS&lt;/a&gt; 3.8.13&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-33845.html&quot;&gt;CVE-2026-33845&lt;/a&gt;&lt;/strong&gt;: Resolves an integer underflow that could lead to an out-of-bounds read and potential denial of service or information disclosure.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-42009.html&quot;&gt;CVE-2026-42009&lt;/a&gt;&lt;/strong&gt;: Fixes a flaw potentially triggering undefined behavior.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-33846.html&quot;&gt;CVE-2026-33846&lt;/a&gt;&lt;/strong&gt;: Addresses a heap buffer overflow that may allow remote denial of service or memory corruption.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-42010.html&quot;&gt;CVE-2026-42010&lt;/a&gt;&lt;/strong&gt;: Resolves an authentication bypass in servers configured with RSA-PSK where usernames containing NUL characters wrongly matched ones truncated at the NUL.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-3833.html&quot;&gt;CVE-2026-3833&lt;/a&gt;&lt;/strong&gt;: Fixes a name-constraint bypass that could cause certificates that should be rejected to be accepted.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://mariadb.org/&quot;&gt;mariadb&lt;/a&gt; 11.8.6&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-32710.html&quot;&gt;CVE-2026-32710&lt;/a&gt;&lt;/strong&gt;: Addresses a heap-based buffer overflow that allows an authenticated user to crash the server and potentially achieve remote code execution.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://web.mit.edu/kerberos/&quot;&gt;krb5&lt;/a&gt;&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-40355.html&quot;&gt;CVE-2026-40355&lt;/a&gt;&lt;/strong&gt;: Resolves a NULL pointer dereference that allowed an unauthenticated remote attacker to terminate the process when a NegoEx mechanism was registered.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-40356.html&quot;&gt;CVE-2026-40356&lt;/a&gt;&lt;/strong&gt;: Fixes an integer underflow that could allow an unauthenticated remote attacker to trigger an out-of-bounds read of up to 52 bytes and potentially terminate the process.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://libsndfile.github.io/libsndfile/&quot;&gt;libsndfile&lt;/a&gt;&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-37555.html&quot;&gt;CVE-2026-37555&lt;/a&gt;&lt;/strong&gt;: Addresses an integer overflow that could lead to a heap buffer overflow or denial of service.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2025-52194.html&quot;&gt;CVE-2025-52194&lt;/a&gt;&lt;/strong&gt;: Resolves a buffer overflow that could potentially lead to memory corruption or code execution.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.qt.io/&quot;&gt;qt6-svg&lt;/a&gt;&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-6210.html&quot;&gt;CVE-2026-6210&lt;/a&gt;&lt;/strong&gt;: Fixes a type confusion and heap buffer overflow that results in an application crash.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.gnu.org/software/tar/&quot;&gt;tar&lt;/a&gt;&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2025-45582.html&quot;&gt;CVE-2025-45582&lt;/a&gt;&lt;/strong&gt;: Addresses a directory traversal flaw that allows file overwrite bypassing the standard &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;../&lt;/code&gt; protection.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://httpd.apache.org/&quot;&gt;Apache HTTP Server&lt;/a&gt; 2.4.67&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-34059.html&quot;&gt;CVE-2026-34059&lt;/a&gt;&lt;/strong&gt;: Fixes a heap over-read and memory disclosure in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;mod_proxy_ajp&lt;/code&gt; in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;ajp_parse_data()&lt;/code&gt;.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-34032.html&quot;&gt;CVE-2026-34032&lt;/a&gt;&lt;/strong&gt;: Addresses a heap buffer over-read in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;ajp_msg_get_string()&lt;/code&gt; due to a missing null-termination check.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-33857.html&quot;&gt;CVE-2026-33857&lt;/a&gt;&lt;/strong&gt;: Resolves an off-by-one out-of-bounds read in AJP getter functions.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-33523.html&quot;&gt;CVE-2026-33523&lt;/a&gt;&lt;/strong&gt;: Patches an HTTP response splitting vulnerability across multiple modules when forwarding malicious status lines.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-33007.html&quot;&gt;CVE-2026-33007&lt;/a&gt;&lt;/strong&gt;: Corrects a NULL pointer dereference in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;mod_authn_socache&lt;/code&gt; allowing an unauthenticated remote user to crash a child process in a caching forward proxy configuration.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-33006.html&quot;&gt;CVE-2026-33006&lt;/a&gt;&lt;/strong&gt;: Resolves a timing attack against &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;mod_auth_digest&lt;/code&gt; that allows a Digest authentication bypass.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-29169.html&quot;&gt;CVE-2026-29169&lt;/a&gt;&lt;/strong&gt;: Fixes a NULL pointer dereference in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;mod_dav_lock&lt;/code&gt; allowing a server crash via a malicious request.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-29168.html&quot;&gt;CVE-2026-29168&lt;/a&gt;&lt;/strong&gt;: Addresses unrestricted OCSP response handling in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;mod_md&lt;/code&gt;.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-28780.html&quot;&gt;CVE-2026-28780&lt;/a&gt;&lt;/strong&gt;: Resolves a heap buffer overflow in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;mod_proxy_ajp&lt;/code&gt; via &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;ajp_msg_check_header()&lt;/code&gt; where a malicious AJP server could write 4 attacker-controlled bytes past a heap buffer.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-24072.html&quot;&gt;CVE-2026-24072&lt;/a&gt;&lt;/strong&gt;: Fixes an &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;ap_expr&lt;/code&gt; privilege escalation in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;mod_rewrite&lt;/code&gt; allowing local &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;.htaccess&lt;/code&gt; authors to read files with the privileges of the httpd user.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-23918.html&quot;&gt;CVE-2026-23918&lt;/a&gt;&lt;/strong&gt;: Addresses a double free and possible RCE in HTTP/2 on early reset.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.php.net/&quot;&gt;PHP&lt;/a&gt; 8.5.6&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-7263.html&quot;&gt;CVE-2026-7263&lt;/a&gt;&lt;/strong&gt;: Fixes duplicate &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;xmlns&lt;/code&gt; declarations from &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Dom\XMLDocument::C14N()&lt;/code&gt; after &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;setAttributeNS()&lt;/code&gt;.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-6735.html&quot;&gt;CVE-2026-6735&lt;/a&gt;&lt;/strong&gt;: Resolves a XSS within the FPM status endpoint.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-7259.html&quot;&gt;CVE-2026-7259&lt;/a&gt;&lt;/strong&gt;: Addresses a NULL pointer dereference in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;php_mb_check_encoding()&lt;/code&gt; via &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;mb_ereg_search_init()&lt;/code&gt;.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-6104.html&quot;&gt;CVE-2026-6104&lt;/a&gt;&lt;/strong&gt;: Patches an out-of-bounds access in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;mbfl_name2encoding_ex()&lt;/code&gt;.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2025-14179.html&quot;&gt;CVE-2025-14179&lt;/a&gt;&lt;/strong&gt;: Fixes a SQL injection via NUL bytes in PDO_Firebird quoted strings.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-6722.html&quot;&gt;CVE-2026-6722&lt;/a&gt;&lt;/strong&gt;: Addresses a stale &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;SOAP_GLOBAL(ref_map)&lt;/code&gt; pointer with Apache Map.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-7261.html&quot;&gt;CVE-2026-7261&lt;/a&gt;&lt;/strong&gt;: Resolves a use-after-free after SOAP header parsing failure with &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;SOAP_PERSISTENCE_SESSION&lt;/code&gt;.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-7262.html&quot;&gt;CVE-2026-7262&lt;/a&gt;&lt;/strong&gt;: Fixes a broken Apache map value NULL check.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-7568.html&quot;&gt;CVE-2026-7568&lt;/a&gt;&lt;/strong&gt;: Addresses a signed integer overflow of a char array offset.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-7258.html&quot;&gt;CVE-2026-7258&lt;/a&gt;&lt;/strong&gt;: Patches inconsistent passing of unsigned char to &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;ctype.h&lt;/code&gt; functions.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-42371.html&quot;&gt;CVE-2026-42371&lt;/a&gt;&lt;/strong&gt;: Fixes a numeric truncation in URI parsing carried by &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;uriparser&lt;/code&gt;.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://openexr.com/&quot;&gt;OpenEXR&lt;/a&gt; 3.4.11&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-42217.html&quot;&gt;CVE-2026-42217&lt;/a&gt;&lt;/strong&gt;: Fixes a shift exponent overflow in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;readVariableLengthInteger()&lt;/code&gt;.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-42216.html&quot;&gt;CVE-2026-42216&lt;/a&gt;&lt;/strong&gt;: Addresses an out-of-bounds read in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;IDManifest::init()&lt;/code&gt; during prefix expansion.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-41142.html&quot;&gt;CVE-2026-41142&lt;/a&gt;&lt;/strong&gt;: Resolves an integer overflow in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;ImageChannel::resize&lt;/code&gt; that leads to a heap out-of-bounds write via the OpenEXRUtil public API.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-39886.html&quot;&gt;CVE-2026-39886&lt;/a&gt;&lt;/strong&gt;: Fixes an HTJ2K signed integer overflow in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;ht_undo_impl()&lt;/code&gt;.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-40244.html&quot;&gt;CVE-2026-40244&lt;/a&gt;&lt;/strong&gt;: Addresses an integer overflow in DWA &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;setupChannelData planarUncRle&lt;/code&gt; pointer arithmetic.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-40250.html&quot;&gt;CVE-2026-40250&lt;/a&gt;&lt;/strong&gt;: Resolves an integer overflow in the DWA decoder &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;outBufferEnd&lt;/code&gt; pointer arithmetic.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://rsync.samba.org/&quot;&gt;rsync&lt;/a&gt; 3.4.3&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-29518.html&quot;&gt;CVE-2026-29518&lt;/a&gt;&lt;/strong&gt;: Fixes a TOCTOU symlink race in daemon mode (&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;use chroot = no&lt;/code&gt;) allowing local privilege escalation.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-43617.html&quot;&gt;CVE-2026-43617&lt;/a&gt;&lt;/strong&gt;: Addresses an authorization bypass via hostname resolution when the daemon chroot tree lacks DNS resolution support, causing the connecting hostname to be set to &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;UNKNOWN&lt;/code&gt;.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-43618.html&quot;&gt;CVE-2026-43618&lt;/a&gt;&lt;/strong&gt;: Resolves an integer overflow in the compressed-token decoder enabling remote memory disclosure.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-43619.html&quot;&gt;CVE-2026-43619&lt;/a&gt;&lt;/strong&gt;: Fixes symlink races on path-based system calls (&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;chmod&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;lchown&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;utimes&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;rename&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;unlink&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;mkdir&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;symlink&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;mknod&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;link&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;rmdir&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;lstat&lt;/code&gt;) in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;use chroot = no&lt;/code&gt; daemon mode.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-43620.html&quot;&gt;CVE-2026-43620&lt;/a&gt;&lt;/strong&gt;: Patches an out-of-bounds read in the receiver’s &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;recv_files()&lt;/code&gt; allowing remote DoS of any client pulling from a malicious server.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-45232.html&quot;&gt;CVE-2026-45232&lt;/a&gt;&lt;/strong&gt;: Addresses an off-by-one stack out-of-bounds write in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;establish_proxy_connection()&lt;/code&gt; HTTP CONNECT proxy response parsing.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.postgresql.org/&quot;&gt;PostgreSQL&lt;/a&gt; 18.4&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-6472.html&quot;&gt;CVE-2026-6472&lt;/a&gt;&lt;/strong&gt;: Ensures the user has CREATE privilege on the schema specified.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-6473.html&quot;&gt;CVE-2026-6473&lt;/a&gt;&lt;/strong&gt;: Fixes integer overflows in memory-allocation calculations.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-6474.html&quot;&gt;CVE-2026-6474&lt;/a&gt;&lt;/strong&gt;: Guards against malicious time zone names.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-6475.html&quot;&gt;CVE-2026-6475&lt;/a&gt;&lt;/strong&gt;: Prevents path traversal in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;pg_basebackup&lt;/code&gt; and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;pg_rewind&lt;/code&gt;.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-6476.html&quot;&gt;CVE-2026-6476&lt;/a&gt;&lt;/strong&gt;: Properly quotes subscription names in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;pg_createsubscriber&lt;/code&gt;.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-6477.html&quot;&gt;CVE-2026-6477&lt;/a&gt;&lt;/strong&gt;: Marks &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;PQfn()&lt;/code&gt; as unsafe and avoids using it within libpq.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-6478.html&quot;&gt;CVE-2026-6478&lt;/a&gt;&lt;/strong&gt;: Uses timing-safe string comparisons in authentication code.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-6479.html&quot;&gt;CVE-2026-6479&lt;/a&gt;&lt;/strong&gt;: Prevents unbounded recursion while processing startup packets.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-6575.html&quot;&gt;CVE-2026-6575&lt;/a&gt;&lt;/strong&gt;: Detects faulty input when restoring attribute MCV statistics.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-6637.html&quot;&gt;CVE-2026-6637&lt;/a&gt;&lt;/strong&gt;: Prevents SQL injection and buffer overruns in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;contrib/spi&lt;/code&gt;.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-6638.html&quot;&gt;CVE-2026-6638&lt;/a&gt;&lt;/strong&gt;: Properly quotes object names in logical replication origin checks.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.thekelnetworks.org/projects/dnsmasq.html&quot;&gt;dnsmasq&lt;/a&gt; 2.92rel2&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-2291.html&quot;&gt;CVE-2026-2291&lt;/a&gt;&lt;/strong&gt;: Fixes cache poisoning that could enable DoS or attacker redirection.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-4890.html&quot;&gt;CVE-2026-4890&lt;/a&gt;&lt;/strong&gt;: Addresses a DoS vulnerability in DNSSEC validation.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-4891.html&quot;&gt;CVE-2026-4891&lt;/a&gt;&lt;/strong&gt;: Resolves a heap-based out-of-bounds read in DNSSEC validation.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-4892.html&quot;&gt;CVE-2026-4892&lt;/a&gt;&lt;/strong&gt;: Patches a heap-based out-of-bounds write in the DHCPv6 implementation.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-4893.html&quot;&gt;CVE-2026-4893&lt;/a&gt;&lt;/strong&gt;: Fixes an information disclosure flaw allowing source-check bypass.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-5172.html&quot;&gt;CVE-2026-5172&lt;/a&gt;&lt;/strong&gt;: Addresses a buffer overflow in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;extract_addresses()&lt;/code&gt;.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://libexpat.github.io/&quot;&gt;expat&lt;/a&gt; 2.8.1&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-45186.html&quot;&gt;CVE-2026-45186&lt;/a&gt;&lt;/strong&gt;: Fixes a quadratic runtime from attribute name collision checks enabling DoS through moderately sized crafted XML input.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-41080.html&quot;&gt;CVE-2026-41080&lt;/a&gt;&lt;/strong&gt;: Resolves limited hash flooding entropy by raising the hash salt size from 4-8 bytes to a full 16 bytes.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;http://www.graphicsmagick.org/&quot;&gt;GraphicsMagick&lt;/a&gt;&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-42050.html&quot;&gt;CVE-2026-42050&lt;/a&gt;&lt;/strong&gt;: Fixes a stack buffer overflow in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;XTileImage&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://imagemagick.org/&quot;&gt;ImageMagick&lt;/a&gt; 7.1.2.23&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-31853.html&quot;&gt;CVE-2026-31853&lt;/a&gt;&lt;/strong&gt;: Addresses an overflow check flaw.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://kernel.org/&quot;&gt;Linux Kernel&lt;/a&gt; 7.0.7&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-43349.html&quot;&gt;CVE-2026-43349&lt;/a&gt;&lt;/strong&gt;: Resolves a use-after-uninitialized-value access in f2fs.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-43350.html&quot;&gt;CVE-2026-43350&lt;/a&gt;&lt;/strong&gt;: Addresses an SMB client flaw requiring a full NFS-mode SID before continuing.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-43348.html&quot;&gt;CVE-2026-43348&lt;/a&gt;&lt;/strong&gt;: Fixes a &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;vmemmap_shift&lt;/code&gt; exceeding &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;MAX_FOLIO_*&lt;/code&gt; in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;mshv_vtl&lt;/code&gt;.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-43490.html&quot;&gt;CVE-2026-43490&lt;/a&gt;&lt;/strong&gt;: Validates inherited ACE SID length in ksmbd.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.gnu.org/software/libc/&quot;&gt;glibc&lt;/a&gt;&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-5928.html&quot;&gt;CVE-2026-5928&lt;/a&gt;&lt;/strong&gt;: Fixes &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;ungetwc&lt;/code&gt; operating on a byte stream.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-5450.html&quot;&gt;CVE-2026-5450&lt;/a&gt;&lt;/strong&gt;: Addresses a buffer overflow in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;scanf %mc&lt;/code&gt;.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://github.com/openSUSE/libzypp&quot;&gt;libzypp&lt;/a&gt; 17.38.9&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-44933.html&quot;&gt;CVE-2026-44933&lt;/a&gt;&lt;/strong&gt;: Prevents configured scripts from escaping the sigcheck directory.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://twisted.org/&quot;&gt;python-Twisted&lt;/a&gt; 26.4.0&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-42304.html&quot;&gt;CVE-2026-42304&lt;/a&gt;&lt;/strong&gt;: Prevents a DoS attack via resource exhaustion during DNS name decompression.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://bind9.readthedocs.io&quot;&gt;bind&lt;/a&gt;  9.20.23&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-3592.html&quot;&gt;CVE-2026-3592&lt;/a&gt;&lt;/strong&gt;: Fixes an amplification vulnerability that could be made to consume disproportionate resources.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-3039.html&quot;&gt;CVE-2026-3039&lt;/a&gt;&lt;/strong&gt;: Addresses excessive memory consumption when processing maliciously-constructed packets.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-5950.html&quot;&gt;CVE-2026-5950&lt;/a&gt;&lt;/strong&gt;: Resolves a flaw exhausting CPU and memory.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-5947.html&quot;&gt;CVE-2026-5947&lt;/a&gt;&lt;/strong&gt;: Fixes a race condition that could allow an unauthenticated remote attacker to crash the server.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-5946.html&quot;&gt;CVE-2026-5946&lt;/a&gt;&lt;/strong&gt;: Addresses multiple flaws that could cause assertion failures via recursion, UPDATE, or NOTIFY paths.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://github.com/kjd/idna&quot;&gt;python-idna&lt;/a&gt; 3.15&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-45409.html&quot;&gt;CVE-2026-45409&lt;/a&gt;&lt;/strong&gt;: Closes a bypass of the &lt;a href=&quot;https://www.suse.com/security/cve/CVE-2024-3651.html&quot;&gt;CVE-2024-3651&lt;/a&gt; mitigation by rejecting oversize inputs up-front.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://urllib3.readthedocs.io/&quot;&gt;python-urllib3&lt;/a&gt; 2.7.0&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-44432.html&quot;&gt;CVE-2026-44432&lt;/a&gt;&lt;/strong&gt;: Closes a decompression-bomb safeguard bypass in the streaming API.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-44431.html&quot;&gt;CVE-2026-44431&lt;/a&gt;&lt;/strong&gt;: Fixes HTTP pools created via &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;ProxyManager.connection_from_url&lt;/code&gt; not stripping sensitive headers when redirecting to a different host.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://github.com/libwww-perl/libwww-perl&quot;&gt;perl-libwww-perl&lt;/a&gt; 6.83&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-8368.html&quot;&gt;CVE-2026-8368&lt;/a&gt;&lt;/strong&gt;: Strips &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Authorization&lt;/code&gt; and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Proxy-Authorization&lt;/code&gt; headers on cross-origin redirects to prevent credential leakage.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://github.com/DCIT/perl-CryptX&quot;&gt;perl-CryptX&lt;/a&gt; 0.89&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-41564.html&quot;&gt;CVE-2026-41564&lt;/a&gt;&lt;/strong&gt;: Patches a security flaw in the Perl interface to LibTomCrypt.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://metacpan.org/release/Net-CIDR-Lite&quot;&gt;perl-Net-CIDR-Lite&lt;/a&gt; 0.24&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-45190.html&quot;&gt;CVE-2026-45190&lt;/a&gt;&lt;/strong&gt;: Rejects Unicode digits and trailing newlines in parser inputs.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-45191.html&quot;&gt;CVE-2026-45191&lt;/a&gt;&lt;/strong&gt;: Rejects zero-padded CIDR masks.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-40199.html&quot;&gt;CVE-2026-40199&lt;/a&gt;&lt;/strong&gt;: Fixes an IPv4-mapped IPv6 packed length flaw.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-40198.html&quot;&gt;CVE-2026-40198&lt;/a&gt;&lt;/strong&gt;: Rejects invalid uncompressed IPv6 addresses.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://metacpan.org/release/XML-LibXML&quot;&gt;perl-XML-LibXML&lt;/a&gt; 2.0212&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-8177.html&quot;&gt;CVE-2026-8177&lt;/a&gt;&lt;/strong&gt;: Prevents an out-of-bounds UTF-8 read in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;domParseChar&lt;/code&gt; by replacing it with libxml2’s &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;xmlValidateName&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://developers.hp.com/hp-linux-imaging-and-printing&quot;&gt;hplip&lt;/a&gt; 3.26.4&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-8631.html&quot;&gt;CVE-2026-8631&lt;/a&gt;&lt;/strong&gt;: Fixes a flaw in the HP Linux Imaging and Printing stack.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-8632.html&quot;&gt;CVE-2026-8632&lt;/a&gt;&lt;/strong&gt;: Addresses a second related flaw.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://xenproject.org/&quot;&gt;xen&lt;/a&gt; 4.21.1_06&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2025-54518.html&quot;&gt;CVE-2025-54518&lt;/a&gt;&lt;/strong&gt;: Mitigates AMD-SN-7052 CPU Op Cache Corruption.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Users are advised to update to the latest versions to mitigate these vulnerabilities.&lt;/p&gt;

&lt;h2 id=&quot;conclusion&quot;&gt;Conclusion&lt;/h2&gt;

&lt;p&gt;May 2026 was a steady month for &lt;a href=&quot;https://get.opensuse.org/tumbleweed/&quot;&gt;openSUSE Tumbleweed&lt;/a&gt; with point releases landing across all three major KDE stacks (&lt;a href=&quot;https://kde.org/announcements/gear/26.04.1/&quot;&gt;KDE Gear 26.04.1&lt;/a&gt;, &lt;a href=&quot;https://kde.org/announcements/frameworks/6/6.26.0&quot;&gt;Frameworks 6.26.0&lt;/a&gt;, and &lt;a href=&quot;https://kde.org/announcements/plasma/6/6.6.5&quot;&gt;Plasma 6.6.5&lt;/a&gt;). &lt;a href=&quot;https://www.mesa3d.org/&quot;&gt;Mesa&lt;/a&gt; made the leap to 26.1 with the &lt;a href=&quot;https://www.vulkan.org/&quot;&gt;Vulkan&lt;/a&gt; 1.4 API, and &lt;a href=&quot;https://gitlab.com/apparmor/apparmor&quot;&gt;AppArmor&lt;/a&gt; shipped its first 5.0 release. Sysadmins received headline updates across &lt;a href=&quot;https://httpd.apache.org/&quot;&gt;Apache HTTP Server&lt;/a&gt; 2.4.67, &lt;a href=&quot;https://www.postgresql.org/&quot;&gt;PostgreSQL&lt;/a&gt; 18.4, &lt;a href=&quot;https://rsync.samba.org/&quot;&gt;rsync&lt;/a&gt; 3.4.3, &lt;a href=&quot;https://www.thekelnetworks.org/projects/dnsmasq.html&quot;&gt;dnsmasq&lt;/a&gt; 2.92rel2, &lt;a href=&quot;https://gnupg.org/&quot;&gt;GnuPG&lt;/a&gt; 2.5.20, and &lt;a href=&quot;https://libexpat.github.io/&quot;&gt;expat&lt;/a&gt; 2.8.1 — almost all driven by &lt;a href=&quot;https://en.wikipedia.org/wiki/Common_Vulnerabilities_and_Exposures&quot;&gt;CVE&lt;/a&gt; fixes. The &lt;a href=&quot;https://www.kernel.org/&quot;&gt;Linux kernel&lt;/a&gt; progressed from 7.0.5 to 7.0.9 with broad subsystem hardening, and security was the dominant theme across &lt;a href=&quot;https://www.php.net/&quot;&gt;PHP&lt;/a&gt;, &lt;a href=&quot;https://openexr.com/&quot;&gt;OpenEXR&lt;/a&gt;, &lt;a href=&quot;https://jqlang.github.io/jq/&quot;&gt;jq&lt;/a&gt;, &lt;a href=&quot;https://imagemagick.org/&quot;&gt;ImageMagick&lt;/a&gt;, &lt;a href=&quot;https://pypi.org/project/cryptography/&quot;&gt;python-cryptography&lt;/a&gt;, &lt;a href=&quot;https://urllib3.readthedocs.io/&quot;&gt;python-urllib3&lt;/a&gt;, and a long tail of Perl networking modules.&lt;/p&gt;

&lt;h3 id=&quot;slowroll-arrivals&quot;&gt;Slowroll Arrivals&lt;/h3&gt;
&lt;p&gt;Please note that these updates also apply to &lt;a href=&quot;https://en.opensuse.org/openSUSE:Slowroll&quot;&gt;Slowroll&lt;/a&gt; and arrive between an average of 5 to 10 days after being released in Tumbleweed snapshot. This monthly approach has been consistent for many months, ensuring stability and timely enhancements for users. Updated packages for Slowroll are regularly published in emails on &lt;a href=&quot;https://lists.opensuse.org/archives/list/factory@lists.opensuse.org/&quot;&gt;openSUSE Factory mailing list&lt;/a&gt;.&lt;/p&gt;

&lt;h3 id=&quot;contributing-to-opensuse-tumbleweed&quot;&gt;Contributing to openSUSE Tumbleweed&lt;/h3&gt;
&lt;p&gt;Stay updated with the latest snapshots by subscribing to the openSUSE Factory mailing list.
For those Tumbleweed users who want to contribute or want to engage with detailed technological discussions, subscribe to the &lt;a href=&quot;https://lists.opensuse.org/archives/list/factory@lists.opensuse.org/&quot;&gt;openSUSE Factory mailing list &lt;/a&gt;. The openSUSE team encourages users to continue participating through bug reports, feature suggestions and discussions.&lt;/p&gt;

&lt;p&gt;Your contributions and feedback make openSUSE Tumbleweed better with every update. Whether reporting bugs, suggesting features, or participating in community discussions, your involvement is highly valued.&lt;/p&gt;

&lt;meta name=&quot;Linux, rolling release, developers, sysadmins, power users, KDE, Plasma, KDE Gear, KDE Frameworks, GNOME, cups, Kernel, kernel-source, Slowroll, open source, cURL, gnutls, net-tools, hplip, openEXR, dnsmasq, postreSQL, rsync, GStreamer&quot; content=&quot;HTML,CSS,XML,JavaScript&quot; /&gt;

</content:encoded>
    </item>

    <item>
      <guid>https://news.opensuse.org/2026/05/29/planet-roundup/</guid>
      <title>Planet News Roundup</title>
      <pubDate>Fri, 29 May 2026 07:00:00 +0000</pubDate>
      <link>https://news.opensuse.org/2026/05/29/planet-roundup/</link>
      <author>admin@opensuse.org (Douglas DeMaio)</author>
      <enclosure url="https://news.opensuse.org/wp-content/uploads/2025/07/planet.png" length="78165" type="image/png" />
      <description>This is a roundup of articles from the openSUSE community listed on planet.opensuse.org. The community blog aggregates a list of the featured highlights below from May 22 to 27. Blogs this week cover security vulnerabilities discovered and patched in qSnapper’s privileged D-Bus service, a new GSoC 2026 contributor joining the...</description>
      <content:encoded>&lt;p&gt;This is a roundup of articles from the openSUSE community listed on &lt;a href=&quot;https://planet.opensuse.org&quot;&gt;planet.opensuse.org&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;The community blog aggregates a list of the featured highlights below from May 22 to 27.&lt;/p&gt;

&lt;p&gt;Blogs this week cover security vulnerabilities discovered and patched in qSnapper’s privileged D-Bus service, a new GSoC 2026 contributor joining the &lt;a href=&quot;https://www.opensuse.org/&quot;&gt;openSUSE Project&lt;/a&gt;, nightly syslog-ng container images now available based on Alma Linux, a new plasmoid Scrolling Clock for KDE Plasma 6, a tip for previewing Markdown in the Kate editor, the April 2026 Krita report, the Mobile Linux Hackday in České Budějovice, &lt;a href=&quot;https://agama-project.github.io/blog/2026/05/21/agama-21&quot;&gt;Agama 21&lt;/a&gt; and more.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Here is a summary and links for each post:&lt;/strong&gt;&lt;/p&gt;

&lt;h2 id=&quot;whaleshark-opens-knopje&quot;&gt;&lt;a href=&quot;https://vizZzion.org/blog/2026/05/whaleshark-opens-knopje/&quot;&gt;Whaleshark Opens Knopje&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;&lt;a href=&quot;https://vizZzion.org/&quot;&gt;Sébas&lt;/a&gt; announces that on June 19 he will open the next edition of Knopje with a 1.5-hour melodic techno set.&lt;/p&gt;

&lt;h2 id=&quot;krita-april-2026-report&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/informe-de-abril-de-2026-de-krita.html&quot;&gt;Krita April 2026 Report&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; covers the April 2026 Krita monthly report, which announces the release of Krita 5.3.2 and 6.0.2 with two months’ worth of bug fixes and improvements including text tool enhancements, performance fixes, and an Android crash fix. The post also highlights upcoming features in development and improves wide-gamut color conversion.&lt;/p&gt;

&lt;h2 id=&quot;introducing-shared-canned-responses&quot;&gt;&lt;a href=&quot;https://openbuildservice.org/2026/05/28/request-workflow-improvements/&quot;&gt;Introducing Shared Canned Responses&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;The &lt;a href=&quot;https://openbuildservice.org/&quot;&gt;Open Build Service Blog&lt;/a&gt; introduces shared canned responses in OBS, expanding a feature that previously only allowed users to create personal canned responses under their own profiles. The update allows canned responses to now be shared across projects and packages, streamlining collaboration and communication in request workflows.&lt;/p&gt;

&lt;h2 id=&quot;how-to-install-exelearning-40-on-your-computer&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/como-instalar-exelearning-4-0-en-tu-ordenador.html&quot;&gt;How to Install exeLearning 4.0 on Your Computer&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; explains how to install exeLearning 4.0, a free and open-source tool for creating interactive digital educational resources. The post outlines the three available editions.&lt;/p&gt;

&lt;h2 id=&quot;scrolling-clock-widget-plasmoids-for-plasma-6-29&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/reloj-original-para-tu-escritorio-con-scrolling-clock-plasmoides-para-plasma-6-29.html&quot;&gt;Scrolling Clock Widget: Plasmoids for Plasma 6 (29)&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; presents Scrolling Clock, the 29th widget in their Plasma 6 plasmoid series, which displays an animated clock cycling through all digits for a unique and eye-catching desktop look. Users who enjoy the widget are encouraged to support the developer through ratings, comments, or donations on the KDE Store.&lt;/p&gt;

&lt;h2 id=&quot;previewing-markdown-files-in-the-kate-editor&quot;&gt;&lt;a href=&quot;https://victorhckinthefreeworld.com/2026/05/26/presvisualizar-archivos-markdown-en-el-editor-kate-de-kde/&quot;&gt;Previewing Markdown Files in the Kate Editor&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;&lt;a href=&quot;https://victorhckinthefreeworld.com/&quot;&gt;Victorhck&lt;/a&gt; shares a quick tip for enabling live Markdown preview inside the KDE Kate editor by activating the “Document Preview” plugin. The author notes that HTML preview does not work the same way and recommends using a browser for that format instead.&lt;/p&gt;

&lt;h2 id=&quot;nightly-syslog-ng-containers-based-on-alma-linux&quot;&gt;&lt;a href=&quot;https://peter.czanik.hu/other/syslog-ng-nightly-containers-based-on-alma-linux/&quot;&gt;Nightly syslog-ng Containers Based on Alma Linux&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;&lt;a href=&quot;https://peter.czanik.hu/&quot;&gt;Peter Czanik&lt;/a&gt; announces that nightly syslog-ng container images based on Alma Linux are now available on Docker Hub. Previously only Debian-based images were provided, but this new Alma Linux offering is built from the latest syslog-ng git snapshot packages.&lt;/p&gt;

&lt;h2 id=&quot;accepted-into-google-summer-of-code-2026-with-opensuse&quot;&gt;&lt;a href=&quot;https://mmarhin.github.io/gsoc2026blog/gsoc/opensuse/2026/05/26/accepted-into-gsoc.html&quot;&gt;Accepted into Google Summer of Code 2026 with openSUSE!&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;&lt;a href=&quot;https://mmarhin.github.io/&quot;&gt;Mario Marín&lt;/a&gt; announces on his &lt;a href=&quot;https://mmarhin.github.io/gsoc2026blog/&quot;&gt;GSoC 2026 blog&lt;/a&gt; that he has been accepted into Google Summer of Code 2026 to contribute to the openSUSE project under two mentors. Over 12 weeks, he will work on improving the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;obs-status-service&lt;/code&gt;, including better SVG visualizations, a Gitea bot for Pull Request build information, and an AI-assisted stretch goal using Log Detective to analyze failed builds. He will be posting weekly progress updates on &lt;a href=&quot;https://mmarhin.github.io/gsoc2026blog/&quot;&gt;his blog&lt;/a&gt;.&lt;/p&gt;

&lt;h2 id=&quot;qsnapper-various-security-issues-in-privileged-d-bus-service-cve-2026-41045-through-cve-2026-41049&quot;&gt;&lt;a href=&quot;https://security.opensuse.org/2026/05/26/qsnapper-dbus-issues.html&quot;&gt;qSnapper: Various Security Issues in Privileged D-Bus Service (CVE-2026-41045 through CVE-2026-41049)&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;The &lt;a href=&quot;https://security.opensuse.org/&quot;&gt;SUSE Security Team blog&lt;/a&gt; discloses five CVEs found during a security review of qSnapper, a GUI frontend for the Btrfs snapshot manager snapper. All issues were addressed through coordinated disclosure with the upstream author and fixes were shipped in the qSnapper 1.3.3 released on May 26.&lt;/p&gt;

&lt;h2 id=&quot;mobilelinux-hackday-1-in-české-budějovice&quot;&gt;&lt;a href=&quot;https://www.suse.com/c/first-mobilelinux-hackday-in-ceske-budejovice-outperforms-prague/&quot;&gt;MobileLinux Hackday #1 in České Budějovice&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;The &lt;a href=&quot;https://www.suse.com/c/&quot;&gt;SUSE Community Blog&lt;/a&gt; reports that the first Mobile Linux Hackday held in České Budějovice had a bigger turnout than the well-established Prague series with regard to attendance and synergy. The Prague series had already built a strong following over seven monthly events and the new venue signals growing momentum and geographic expansion for the Mobile Linux hackday movement in Czechia.&lt;/p&gt;

&lt;h2 id=&quot;how-to-use-desktop-icons-ng-ding-on-opensuse-16-gnome&quot;&gt;&lt;a href=&quot;https://blog.geeko.jp/ribbon/3625&quot;&gt;How to Use Desktop Icons NG (DING) on openSUSE 16 GNOME&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;The &lt;a href=&quot;https://blog.geeko.jp/&quot;&gt;Geeko Blog&lt;/a&gt; provides a fix for the Desktop Icons NG (DING) GNOME extension failing to work on openSUSE 16. The post includes the relevant error message from &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;/var/log/messages&lt;/code&gt; to help users identify the problem.&lt;/p&gt;

&lt;h2 id=&quot;long-term-support-doesnt-mean-what-you-think&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/soporte-a-largo-plazo-no-significa-lo-que-crees.html&quot;&gt;Long-Term Support Doesn’t Mean What You Think&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; summarizes a post by KDE developer Nate Graham clarifying that LTS releases promise extended maintenance and security patches, not bug-free software or guaranteed personal support. The post draws a clear distinction between free community LTS distributions and commercially supported products and suggests that Flatpak apps can help bridge the software freshness gap on stable systems.&lt;/p&gt;

&lt;h2 id=&quot;haruna-18-released--new-version-of-this-kde-media-player&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/lanzado-haruna-1-8-nueva-version-de-este-reproductor-multimedia-de-kde.html&quot;&gt;Haruna 1.8 Released – New Version of This KDE Media Player&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; announces the release of Haruna 1.8, an open-source video player built on libmpv with YouTube integration. Haruna continues to be a solid alternative to Dragon Player and Kaffeine within the KDE ecosystem.&lt;/p&gt;

&lt;h2 id=&quot;linux-saloon-202--early-edition&quot;&gt;&lt;a href=&quot;https://cubiclenate.com/2026/05/23/linux-saloon-202-early-edition/&quot;&gt;Linux Saloon 202 | Early Edition&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;&lt;a href=&quot;https://cubiclenate.com/&quot;&gt;CubicleNate&lt;/a&gt; recaps episode 202 of the Linux Saloon podcast, covering Colin’s use of his Surface Go running Cosmic Desktop, the release of Ubuntu 26.04 LTS, and updates on the Framework Computer Laptop 13 Pro.&lt;/p&gt;

&lt;h2 id=&quot;linux-saloon-203--news-flight-night&quot;&gt;&lt;a href=&quot;https://cubiclenate.com/2026/05/23/linux-saloon-203-news-flight-night/&quot;&gt;Linux Saloon 203 | News Flight Night&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;&lt;a href=&quot;https://cubiclenate.com/&quot;&gt;CubicleNate&lt;/a&gt; recaps episode 203 of the Linux Saloon podcast, during which attendees discuss Collin’s experience with stillOS, the value of operating system rollback features, and notable news including HP sponsoring the Linux Vendor Firmware Service and KDE receiving a significant investment.&lt;/p&gt;

&lt;h2 id=&quot;xe-driver-support-and-discover-improvements--this-week-in-plasma&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/soporte-para-el-controlador-xe-y-mejoras-en-discover-esta-semana-en-plasma.html&quot;&gt;Xe Driver Support and Discover Improvements – This Week in Plasma&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; translates Nate Graham’s weekly Plasma development summary. A standout community contribution added support for monitoring modern Intel Xe GPUs in System Monitor and its widgets. Discover also received several improvements including safer Flatpak data deletion sending files to the trash, a reorganized front page with the Editor’s Choice section moved higher, and case-insensitive search on the Updates page.&lt;/p&gt;

&lt;h2 id=&quot;agama-21-released&quot;&gt;&lt;a href=&quot;https://victorhckinthefreeworld.com/2026/05/22/publicado-agama-21/&quot;&gt;Agama 21 Released&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;&lt;a href=&quot;https://victorhckinthefreeworld.com/&quot;&gt;Victorhck&lt;/a&gt; summarizes the release of Agama 21. The network configuration interface was redesigned with a new form supporting bond and bridge connections in addition to Ethernet and Wi-Fi. A new boot option &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;inst.remote=0&lt;/code&gt; allows disabling remote installer access for improved security in sensitive environments.&lt;/p&gt;

&lt;h2 id=&quot;tumbleweed--review-of-the-weeks-202621&quot;&gt;Tumbleweed – Review of the Weeks 2026/21&lt;/h2&gt;

&lt;p&gt;&lt;a href=&quot;https://victorhckinthefreeworld.com/2026/05/22/opensuse-tumbleweed-revision-de-la-semana-21-de-2026/&quot;&gt;Victorhck&lt;/a&gt; and &lt;a href=&quot;https://dominique.leuenberger.net/blog/2026/05/tumbleweed-review-of-the-week-2026-21/&quot;&gt;Dominique Leuenberger’s blog&lt;/a&gt; recap week 21 with six snapshots. The releases shipped notable updates including AppArmor 5.0.0, KDE Plasma 6.6.5, Linux kernel 7.0.6 through 7.0.9, GStreamer 1.28.3, Ruby 4.0.4, and PostgreSQL 18.4. Upcoming pipeline changes include Agama 21, GCC 16 as the default system compiler, and a rework of Python 3 packaging.&lt;/p&gt;

&lt;h2 id=&quot;workshop-agentic-ai-and-total-automation-at-linux-center-valència&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/workshop-ia-agentica-y-automatizacion-total-en-linux-center-valencia.html&quot;&gt;Workshop: Agentic AI and Total Automation at Linux Center València&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; announces a hands-on workshop on agentic AI and automation taking place on June 6 at Slimbook’s Linux Center in Paterna, Valencia. The event features sessions on building intelligent agent systems using OpenClaw, privacy-respecting automation with Hermes, and a practical pair-programming workshop on Slimbook One mini PCs.&lt;/p&gt;

&lt;p&gt;View more blogs or learn to publish your own on &lt;a href=&quot;https://planet.opensuse.org&quot;&gt;planet.opensuse.org&lt;/a&gt;.&lt;/p&gt;

&lt;meta name=&quot;openSUSE, Open Source, development, Linux, secure operating systems, open source, plasma, KDE, syslog-ng, Tumbleweed, Krita, Kate, Agama, OBS, GNOME, CVE&quot; content=&quot;HTML,CSS,XML,JavaScript&quot; /&gt;

</content:encoded>
    </item>

    <item>
      <guid>https://news.opensuse.org/2026/05/21/sysextmgr/</guid>
      <title>Managing System Extensions with sysextmgrcli</title>
      <pubDate>Thu, 21 May 2026 08:00:00 +0000</pubDate>
      <link>https://news.opensuse.org/2026/05/21/sysextmgr/</link>
      <author>admin@opensuse.org (Stefan Schubert)</author>
      <enclosure url="https://news.opensuse.org/wp-content/uploads/2026/05/microos.png" length="36247" type="image/png" />
      <description>Managing System Extensions on openSUSE MicroOS with sysextmgrcli If you are running openSUSE MicroOS, you already know the drill: the root filesystem is read-only, and transactional updates are the law of the land. But what happens when you need to add software or system extensions without rebooting or messing with...</description>
      <content:encoded>&lt;h1 id=&quot;managing-system-extensions-on-opensuse-microos-with-sysextmgrcli&quot;&gt;Managing System Extensions on openSUSE MicroOS with &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;sysextmgrcli&lt;/code&gt;&lt;/h1&gt;

&lt;p&gt;If you are running &lt;a href=&quot;https://get.opensuse.org/microos/&quot;&gt;openSUSE MicroOS&lt;/a&gt;, you already know the drill: the root filesystem is read-only,
and transactional updates are the law of the land.&lt;/p&gt;

&lt;p&gt;But what happens when you need to add software or system extensions without rebooting or messing with
your base OS layers?&lt;/p&gt;

&lt;p&gt;E.g. You need strace or gdb to debug a running application, but a reboot to install this tools would
change the situation.&lt;/p&gt;

&lt;p&gt;Enter &lt;strong&gt;System Extensions (sysext images)&lt;/strong&gt; and the utility designed to make them manageable: &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;sysextmgrcli&lt;/code&gt;.&lt;/p&gt;

&lt;hr /&gt;

&lt;h2 id=&quot;what-is-sysextmgrcli&quot;&gt;What is &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;sysextmgrcli&lt;/code&gt;?&lt;/h2&gt;

&lt;p&gt;At its core, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;sysextmgrcli&lt;/code&gt; is a command-line client for managing &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;systemd-sysext&lt;/code&gt; images and has been written
by Thorsten Kukuk. It is designed specifically to play nice with the atomic nature of MicroOS.&lt;/p&gt;

&lt;p&gt;Instead of forcing you to use &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;sudo&lt;/code&gt; for every query, it talks to a background daemon (&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;sysextmgrd&lt;/code&gt;) via
&lt;strong&gt;Varlink&lt;/strong&gt;. This architecture allows unprivileged users to list existing system extension images without
needing root permissions, while the daemon handles the heavy lifting of downloads and verification via &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;systemd-pull&lt;/code&gt;.
For security reasons, root provileges are still required for installing or updating sysext images.&lt;/p&gt;

&lt;h2 id=&quot;the-architecture-smart-snapshots&quot;&gt;The Architecture: Smart Snapshots&lt;/h2&gt;

&lt;p&gt;One of the cleverest things about &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;sysextmgrcli&lt;/code&gt; is how it handles storage to be efficient and “rollback-safe”:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;/var/lib/sysext-store&lt;/strong&gt;: This is where the actual image files live. Since &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;/var&lt;/code&gt; is a separate subvolume
shared across all Btrfs snapshots, you only store the image once, saving disk space. If you have no network available,
that’s the location for storing offline or even own build sysext images via e.g. an USB device.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;/etc/extensions&lt;/strong&gt;: This directory contains &lt;strong&gt;symlinks&lt;/strong&gt; to the images in the store. Because &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;/etc&lt;/code&gt; is part of
your root snapshot, the extensions are tied to your current system state.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Why does this matter?&lt;/strong&gt; If you perform a system rollback, your symlinks roll back too. This ensures the active
sysext images always match the OS version you are currently booted into.&lt;/p&gt;

&lt;hr /&gt;

&lt;h2 id=&quot;essential-commands&quot;&gt;Essential Commands&lt;/h2&gt;

&lt;p&gt;Getting started is straightforward. Here are the primary commands you’ll use to manage your extensions:&lt;/p&gt;

&lt;h3 id=&quot;1-listing-and-checking-images&quot;&gt;1. Listing and Checking Images&lt;/h3&gt;

&lt;p&gt;Want to see what’s available or if your images are compatible with your current OS version?&lt;/p&gt;

&lt;div class=&quot;language-plaintext highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;# List all images and report compatibility
sysextmgrcli list

# Check for updates and verify compatibility
sysextmgrcli check
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;h3 id=&quot;2-installing-new-extensions&quot;&gt;2. Installing New Extensions&lt;/h3&gt;

&lt;p&gt;You can install by providing a name and a source URL. The tool automatically handles SHA256 verification and
checks if it fits your OS.&lt;/p&gt;

&lt;div class=&quot;language-plaintext highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;# --url is optional (default: https://download.opensuse.org/tumbleweed/appliances/ )
sysextmgrcli install [NAME] --url [https://your-image-repo.com](https://your-image-repo.com)
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;h3 id=&quot;3-maintenance-and-updates&quot;&gt;3. Maintenance and Updates&lt;/h3&gt;

&lt;p&gt;Updates are handled by comparing local files against remote manifests. If a newer version matches your current snapshot, it gets pulled down and symlinked.&lt;/p&gt;

&lt;div class=&quot;language-plaintext highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;# Update existing images to the latest compatible versions
sysextmgrcli update

# Clean up: Remove images in the store that are no longer referenced by any snapshot
sysextmgrcli cleanup
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;h2 id=&quot;the-activation-catch&quot;&gt;The “Activation” Catch&lt;/h2&gt;

&lt;p&gt;It is important to note that sysextmgrcli is a manager, not an activator. It handles the logistics: downloading, version checking, and symlinking. To actually “plug in” the extensions to your running system, you still use standard systemd-sysext commands:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;Manual activation: &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;systemd-sysext merge&lt;/code&gt;&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Manual deactivation: &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;systemd-sysext unmerge&lt;/code&gt;&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Enable at boot: &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;systemctl enable systemd-sysext.service&lt;/code&gt;&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;h2 id=&quot;available-default-system-extention-sysext-images&quot;&gt;Available default system extention (sysext) images:&lt;/h2&gt;

&lt;ul&gt;
  &lt;li&gt;debug (babeltrace, gdb, ltrace, strace, traceroute)&lt;/li&gt;
  &lt;li&gt;gcc (cpp, gcc, make, patch)&lt;/li&gt;
  &lt;li&gt;git (git, git-core)&lt;/li&gt;
&lt;/ul&gt;

&lt;h2 id=&quot;summary&quot;&gt;Summary&lt;/h2&gt;

&lt;h3 id=&quot;you-need-git-on-your-opensuse-microos-&quot;&gt;You need &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;git&lt;/code&gt; on your &lt;strong&gt;openSUSE MicroOS&lt;/strong&gt; ?&lt;/h3&gt;

&lt;p&gt;Just call &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;sysextmgrcli install git ; systemd-sysext merge&lt;/code&gt; and use it…&lt;/p&gt;

&lt;h3 id=&quot;you-do-not-need-git-anymore-on-your-system-&quot;&gt;You do not need ‘git’ anymore on your system ?&lt;/h3&gt;

&lt;p&gt;Just call &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;systemd-sysext unmerge&lt;/code&gt; and it is not available anymore…&lt;/p&gt;

&lt;p&gt;sysextmgrcli bridges the gap between static immutable infrastructure and the need for flexible system additions. By leveraging the Btrfs directory structure of MicroOS, it ensures your system remains clean, version-synced, and easy to manage.&lt;/p&gt;

&lt;meta name=&quot;openSUSE, Open Source, development, Linux, secure operating systems, open source, systemd, sysextmgrcli, MicroOS&quot; content=&quot;HTML,CSS,XML,JavaScript&quot; /&gt;

</content:encoded>
    </item>

    <item>
      <guid>https://news.opensuse.org/2026/05/15/planet-roundup/</guid>
      <title>Planet News Roundup</title>
      <pubDate>Fri, 15 May 2026 09:00:00 +0000</pubDate>
      <link>https://news.opensuse.org/2026/05/15/planet-roundup/</link>
      <author>admin@opensuse.org (Douglas DeMaio)</author>
      <enclosure url="https://news.opensuse.org/wp-content/uploads/2025/07/planet.png" length="78165" type="image/png" />
      <description>This is a roundup of articles from the openSUSE community listed on planet.opensuse.org. The community blog feed aggregator lists the featured highlights below from May 8 to 14. Blogs this week cover the Plasma 6.7 beta launch, sovereign Tech funds major investment in KDE, a leadership change on the openSUSE...</description>
      <content:encoded>&lt;p&gt;This is a roundup of articles from the openSUSE community listed on &lt;a href=&quot;https://planet.opensuse.org&quot;&gt;planet.opensuse.org&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;The community blog feed aggregator lists the featured highlights below from May 8 to 14.&lt;/p&gt;

&lt;p&gt;Blogs this week cover the Plasma 6.7 beta launch, sovereign Tech funds major investment in KDE, a leadership change on the openSUSE Board, two helpful Firefox tips, a Tumbleweed review, a new Plasmoid for displaying song lyrics, a KDE Frameworks update, and an openSUSE Leap 15.6 reaches end-of-life.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Here is a summary and links for each post:&lt;/strong&gt;&lt;/p&gt;

&lt;h2 id=&quot;opensuse-leap-156-reaches-end-of-life--time-to-upgrade&quot;&gt;&lt;a href=&quot;https://victorhckinthefreeworld.com/2026/05/14/opensuse-leap-15-6-llega-a-su-fin-de-vida-es-hora-de-actualizar/&quot;&gt;openSUSE Leap 15.6 Reaches End of Life – Time to Upgrade&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;&lt;a href=&quot;https://victorhckinthefreeworld.com/&quot;&gt;Victorhck&lt;/a&gt; reports that openSUSE Leap 15.6 reached its official end of life on April 30, which means it will no longer receive security patches or official support. Users are advised to migrate to openSUSE Leap 16.0 to keep their systems up to date and secure.&lt;/p&gt;

&lt;h2 id=&quot;plasma-67-beta-released&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/lanzada-la-beta-de-plasma-6-7.html&quot;&gt;Plasma 6.7 Beta Released&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; announces the launch of the Plasma 6.7 beta and invites testers to try the new release and report any bugs at bugs.kde.org ahead of the final release. Key new features include a quick light/dark mode toggle in the Brightness and Color widget and a modern new print queue application with active job badges in the Printers widget.&lt;/p&gt;

&lt;h2 id=&quot;the-syslog-ng-insider-2026-05-otel-central-log-collection-old-mac&quot;&gt;&lt;a href=&quot;https://peter.czanik.hu/other/syslog-ng-insider-2026-05-otel-compliance-mac/&quot;&gt;The syslog-ng Insider 2026-05: OTEL; Central Log Collection; Old Mac&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;&lt;a href=&quot;https://peter.czanik.hu/&quot;&gt;Peter Czanik’s Blog&lt;/a&gt; presents the 140th issue of the syslog-ng Insider monthly newsletter and covers three topics: how Databricks customers can stream logs to a data lakehouse using syslog-ng with OAuth2 authentication and the OpenTelemetry protocol; a reminder that central log collection is valuable far beyond mere compliance, benefiting operations, security, and development teams alike; and a guide to compiling the latest syslog-ng release on older Intel-based Macs where Homebrew no longer provides full support.&lt;/p&gt;

&lt;h2 id=&quot;sovereign-tech-fund-invests-over-1-million-in-kde&quot;&gt;&lt;a href=&quot;https://victorhckinthefreeworld.com/2026/05/13/sovereign-tech-fund-invierte-mas-de-1-millon-de-euros-en-el-desarrollo-de-software-kde/&quot;&gt;Sovereign Tech Fund Invests Over €1 Million in KDE&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;&lt;a href=&quot;https://victorhckinthefreeworld.com/&quot;&gt;Victorhck&lt;/a&gt; covers the announcement that the Sovereign Tech Fund will invest €1,285,200 in the KDE community across 2026 and 2027. The funding is aimed at strengthening the structural reliability and security of KDE’s core infrastructure, including Plasma and the frameworks supporting KDE’s communication services. The author translates the official KDE announcement into Spanish and shares his thoughts on the significance of the investment for the free software ecosystem.&lt;/p&gt;

&lt;h2 id=&quot;plasma-lyrics-widget--view-song-lyrics-in-plasma-6-28&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/visualiza-la-letra-de-las-canciones-con-plasma-lyrics-plasmoides-para-plasma-6-28.html&quot;&gt;Plasma Lyrics Widget – View Song Lyrics in Plasma 6 (28)&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; presents Plasma Lyrics, a new widget for KDE Plasma 6 that displays the lyrics of the currently playing songs directly on the desktop. This is the 28th entry in the blog’s ongoing series showcasing Plasmoids for Plasma 6, which is aimed at users who want richer desktop integration with their music player.&lt;/p&gt;

&lt;h2 id=&quot;fifth-update-of-plasma-66&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/quinta-actualizacion-de-plasma-6-6.html&quot;&gt;Fifth Update of Plasma 6.6&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; announces the fifth bugfix update to KDE Plasma 6.6, which was released on May 12. The update brings improved animation fluidity on high-refresh-rate displays along with the usual bug fixes and stability improvements.&lt;/p&gt;

&lt;h2 id=&quot;how-to-change-the-annoying-firefox-not-found-sound&quot;&gt;&lt;a href=&quot;https://victorhckinthefreeworld.com/2026/05/12/como-modificar-en-firefox-el-desagradable-sonido-que-reproduce-al-buscar-un-texto-que-no-encuentra/&quot;&gt;How to Change the Annoying Firefox “Not Found” Sound&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;&lt;a href=&quot;https://victorhckinthefreeworld.com/&quot;&gt;Victorhck&lt;/a&gt; shares a practical tip for Firefox users annoyed by the jarring sound the browser plays when a text search via Ctrl+F finds no match on the page. The post walks through how to replace that default sound with a system sound of the user’s own choosing.&lt;/p&gt;

&lt;h2 id=&quot;ia-med-public-health-privacy-and-brazilian-technological-sovereignty&quot;&gt;&lt;a href=&quot;https://assuntonerd.com.br/2026/05/12/ia-med-saude-publica-privacidade-e-soberania-tecnologica-brasileira/&quot;&gt;IA MED: Public Health, Privacy and Brazilian Technological Sovereignty&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;&lt;a href=&quot;https://assuntonerd.com.br/&quot;&gt;Alessandro’s Blog&lt;/a&gt; introduces IA MED, which is a an AI solution developed by MultiCortex to bring advanced language models to the public health sector with a focus on precision, privacy, and data sovereignty. The system is already operational in the city of Bebedouro, São Paulo. The post argues that vertically specialized, locally hosted AI running on cost-effective hardware represents a viable and responsible alternative to generic cloud-based AI for public health systems across Brazil.&lt;/p&gt;

&lt;h2 id=&quot;sotaque-when-ai-learns-to-speak-like-a-brazilian&quot;&gt;&lt;a href=&quot;https://assuntonerd.com.br/2026/05/12/sotaque-quando-a-ia-aprende-a-falar-como-brasileiro/&quot;&gt;SOTAQUE: When AI Learns to Speak like a Brazilian&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;&lt;a href=&quot;https://assuntonerd.com.br/&quot;&gt;Alessandro’s Blog&lt;/a&gt; introduces SOTAQUE (Speech-Oriented Training Audio for Quality Understanding and Expression), which is a community-driven initiative to build an open dataset of Brazilian Portuguese voices that captures the country’s regional diversity of accents. The project, which is published under the CDLA-Permissive-2.0 license, aims to collect up to 10,000 hours of audio so that AI speech tools better represent all Brazilians rather than defaulting to a narrow Southeastern urban standard. Anyone over 18 in Brazil can contribute by recording just a few minutes of their own voice at &lt;a href=&quot;https://sotaque.ia.br/&quot;&gt;sotaque.ia.br&lt;/a&gt;.&lt;/p&gt;

&lt;h2 id=&quot;firefox-not-displaying-japanese-or-chinese-or-korean-characters-in-plasma&quot;&gt;&lt;a href=&quot;https://victorhckinthefreeworld.com/2026/05/11/firefox-no-muestra-los-kanjis-o-caracteres-japoneses-ni-chinos-ni-koreanos-en-plasma/&quot;&gt;Firefox Not Displaying Japanese (or Chinese or Korean) Characters in Plasma&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;&lt;a href=&quot;https://victorhckinthefreeworld.com/&quot;&gt;Victorhck&lt;/a&gt; explains how to fix the issue of Firefox displaying small empty squares instead of Japanese kanji characters when browsing the web on KDE Plasma. The solution involves installing the appropriate font packages to give the browser the rendering support it needs.&lt;/p&gt;

&lt;h2 id=&quot;framework-becomes-a-kde-patron&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/framework-se-convierte-en-patrocinador-de-kde.html&quot;&gt;Framework Becomes a KDE Patron&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; announces that Framework, the company behind the modular Framework Laptop, has become an official patron of KDE e.V., and joins existing supporters such as The Qt Company, SUSE, Google, Canonical, Slimbook, and Rocky Linux. Framework founder Nirav Patel noted that KDE is extremely popular within the Framework community, while KDE e.V. President Aleix Pol highlighted that Framework’s commitment to repairability strongly aligns with KDE’s own values of sustainability and open hardware.&lt;/p&gt;

&lt;h2 id=&quot;malcontent-disk-space-exhaustion-via-globally-accessible-d-bus-api-cve-2026-44931&quot;&gt;&lt;a href=&quot;https://security.opensuse.org/2026/05/11/malcontent-disk-space-dos.html&quot;&gt;malcontent: Disk Space Exhaustion via Globally Accessible D-Bus API (CVE-2026-44931)&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;The &lt;a href=&quot;https://security.opensuse.org/&quot;&gt;SUSE Security Team Blog&lt;/a&gt; discloses CVE-2026-44931, a local denial-of-service vulnerability in malcontent, the GNOME parental control system, introduced in version 0.14.0 as part of the GNOME 50 update packaged for openSUSE. The flaw allows any unprivileged local user to slowly exhaust disk space in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;/var/lib/malcontent-timerd&lt;/code&gt; by repeatedly calling the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;RecordUsage&lt;/code&gt; D-Bus method with arbitrary app identifiers, with no upstream fix currently available. The SUSE team reported the issue privately in February 2026 and, after receiving no follow-up from upstream despite repeated contact, proceeded with public disclosure to avoid further delay.&lt;/p&gt;

&lt;h2 id=&quot;26th-update-of-kde-frameworks-6-and-the-karchive-library&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/vigesimosexta-actualizacion-de-kde-frameworks-6-y-libreria-karchive.html&quot;&gt;26th Update of KDE Frameworks 6 and the KArchive Library&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; covers the 26th update to KDE Frameworks 6, highlighting improvements to the KArchive library among other fixes across the KDE software stack. The post follows the blog’s regular cadence of documenting each KDE Frameworks release for Spanish-speaking KDE users.&lt;/p&gt;

&lt;h2 id=&quot;linux-saloon-200--open-mic-night&quot;&gt;&lt;a href=&quot;https://cubiclenate.com/2026/05/09/linux-saloon-200-open-mic-night/&quot;&gt;Linux Saloon 200 | Open Mic Night&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;&lt;a href=&quot;https://cubiclenate.com/&quot;&gt;CubicleNate’s Blog&lt;/a&gt; celebrates the 200th episode of the Linux Saloon podcast with an Open Mic Night format, where participants shared tech topics that were top of mind. Highlights included a hands-on look at the new Framework Laptop 13 Pro and its hardware improvements, a discussion about Brave’s new Origin browser on Linux, and a nostalgic trip back to the old internet covering GeoCities, webrings, and Homestar Runner.&lt;/p&gt;

&lt;h2 id=&quot;opensuse-board-leadership-change&quot;&gt;&lt;a href=&quot;https://victorhckinthefreeworld.com/2026/05/09/cambio-en-la-direccion-de-la-junta-de-opensuse/&quot;&gt;openSUSE Board Leadership Change&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;&lt;a href=&quot;https://victorhckinthefreeworld.com/&quot;&gt;Victorhck&lt;/a&gt; reports on the change at the top of the openSUSE Board. The post translates and expands on the official announcement of Gerald Pfeifer stepping down as chair on May 7 after nearly seven years in the role. He is succeeded by Jeff Mahoney, who was elected to the board in 2024.&lt;/p&gt;

&lt;h2 id=&quot;icc-profiles-in-hdr-️--this-week-in-plasma&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/perfiles-icc-en-hdr-%e2%9d%a4%ef%b8%8f-esta-semana-en-plasma.html&quot;&gt;ICC Profiles in HDR ❤️ – This Week in Plasma&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; summarizes “This Week in Plasma” with headlines featuring new support for ICC color profiles in HDR mode. This addition is a significant step forward for color-accurate workflows on Linux, particularly for photographers and designers using HDR-capable displays.&lt;/p&gt;

&lt;h2 id=&quot;ussfms-carrier&quot;&gt;&lt;a href=&quot;https://blog.jimmac.eu/posts/fms-carrier/&quot;&gt;USS/FMS Carrier&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;&lt;a href=&quot;https://blog.jimmac.eu/&quot;&gt;Jakub Steiner’s Blog&lt;/a&gt; dives into FMS Carrier, a tiny 2-operator FM synthesizer and sequencer for the Nintendo Game Boy Advance created by Ess Mattisson, the original designer of the Elektron Digitone. Jakub shares his enthusiasm for the sequencing workflow, which mirrors the building-block composition approach he loves on his Dirtywave M8 tracker.&lt;/p&gt;

&lt;h2 id=&quot;tumbleweed--review-of-the-weeks-202618--19&quot;&gt;Tumbleweed – Review of the Weeks 2026/18 &amp;amp; 19&lt;/h2&gt;

&lt;p&gt;&lt;a href=&quot;https://victorhckinthefreeworld.com/2026/05/08/opensuse-tumbleweed-revision-de-las-semanas-18-y-19-de-2026/&quot;&gt;Victorhck&lt;/a&gt; and &lt;a href=&quot;https://dominique.leuenberger.net/blog/2026/05/tumbleweed-review-of-the-weeks-2026-18-19/&quot;&gt;Dominique Leuenberger&lt;/a&gt; cover nine Tumbleweed snapshots published across weeks 18 and 19. Major package arrivals include GNOME 50.1, Linux kernel 7.0.1 through 7.0.3, glibc 2.43, systemd 260.1, Boost 1.91.0, and Mozilla Firefox 150.0.&lt;/p&gt;

&lt;h2 id=&quot;lliurex-turns-21--happy-birthday&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/lliurex-cumple-21-anos-muchas-felicidades.html&quot;&gt;LliureX Turns 21 – Happy Birthday!&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; celebrates the 21st anniversary of LliureX, a GNU/Linux distribution based on Ubuntu and KDE Plasma developed by the Valencian Community’s regional education authority in Spain. The project has been delivering a free software desktop tailored to educational environments in the Valencian Community for over two decades.&lt;/p&gt;

&lt;p&gt;View more blogs or learn to publish your own on &lt;a href=&quot;https://planet.opensuse.org&quot;&gt;planet.opensuse.org&lt;/a&gt;.&lt;/p&gt;

&lt;meta name=&quot;openSUSE, Open Source, development, Linux, secure operating systems, open source, plasma, KDE, syslog-ng, Tumbleweed, AI, funding&quot; content=&quot;HTML,CSS,XML,JavaScript&quot; /&gt;

</content:encoded>
    </item>

    <item>
      <guid>https://news.opensuse.org/2026/05/08/planet-roundup/</guid>
      <title>Planet News Roundup</title>
      <pubDate>Fri, 08 May 2026 07:00:00 +0000</pubDate>
      <link>https://news.opensuse.org/2026/05/08/planet-roundup/</link>
      <author>admin@opensuse.org (Douglas DeMaio)</author>
      <enclosure url="https://news.opensuse.org/wp-content/uploads/2025/07/planet.png" length="78165" type="image/png" />
      <description>This is a roundup of articles from the openSUSE community listed on planet.opensuse.org. The community blog feed aggregator lists the featured highlights below from May 1 to 7. Blogs this week cover a Tumbleweed review, syslog-ng with Fedora 44, the openSUSE Summit in the Americas, SUSE response to the Copy...</description>
      <content:encoded>&lt;p&gt;This is a roundup of articles from the openSUSE community listed on &lt;a href=&quot;https://planet.opensuse.org&quot;&gt;planet.opensuse.org&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;The community blog feed aggregator lists the featured highlights below from May 1 to 7.&lt;/p&gt;

&lt;p&gt;Blogs this week cover a Tumbleweed review, syslog-ng with Fedora 44, the openSUSE Summit in the Americas, SUSE response to the Copy Fail kernel vulnerability, KDE’s participation in Google Summer of Code 2026 and and much more.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Here is a summary and links for each post:&lt;/strong&gt;&lt;/p&gt;

&lt;h2 id=&quot;playing-wma-files-with-amarok-in-opensuse&quot;&gt;&lt;a href=&quot;https://victorhckinthefreeworld.com/2026/05/07/reproducir-con-amarok-archivos-wma-en-opensuse/&quot;&gt;Playing .wma Files with Amarok in openSUSE&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;&lt;a href=&quot;https://victorhckinthefreeworld.com&quot;&gt;Victorhck&lt;/a&gt; shares a practical tip for openSUSE Tumbleweed users who find that the Amarok music player won’t play .wma audio files. The root cause is that Amarok relies on GStreamer and lacks certain codec packages by default, unlike VLC which bundles its own. The fix is straightforward: add the Packman repository and install &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;gstreamer-plugins-bad&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;gstreamer-plugins-ugly&lt;/code&gt;, and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;gstreamer-plugins-libav&lt;/code&gt; via zypper.&lt;/p&gt;

&lt;h2 id=&quot;mix-of-kde-gear-2604-highlights--kde-at-30-edition&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/mix-de-novedades-de-kde-gear-26-04-edicion-kde-a-los-30.html&quot;&gt;Mix of KDE Gear 26.04 Highlights – “KDE at 30” Edition&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; wraps up its series on KDE Gear 26.04 with a roundup of smaller improvements across many applications in what is dubbed the “KDE at 30” edition, which celebrates three decades of KDE. Highlights include bug fixes for Akregator and Alligator, Angelfish defaulting to the AI-free version of DuckDuckGo, RAR extraction support in Ark’s Flatpak version, and NeoChat gaining a rich text editor with thread support.&lt;/p&gt;

&lt;h2 id=&quot;fedora-44-centos-7-and-amazon-linux-syslog-ng-questions&quot;&gt;&lt;a href=&quot;https://peter.czanik.hu/other/fedora-44-centos-7-amazon-linux-questions/&quot;&gt;Fedora 44, CentOS 7 and Amazon Linux syslog-ng Questions&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;&lt;a href=&quot;https://peter.czanik.hu&quot;&gt;Peter Czanik’s blog&lt;/a&gt; reports that Fedora 44 has shipped with syslog-ng 4.11 and that a quick test confirms everything works as expected. The post raises two open questions for the community: whether anyone is still using syslog-ng packages on the end-of-life RHEL 7 / CentOS 7, and whether the Amazon Linux 2023 Copr package should be updated to a newer release.&lt;/p&gt;

&lt;h2 id=&quot;free-software-foundation-newsletter-roundup--may-2026&quot;&gt;&lt;a href=&quot;https://victorhckinthefreeworld.com/2026/05/06/recopilacion-del-boletin-de-noticias-de-la-free-software-foundation-mayo-de-2026/&quot;&gt;Free Software Foundation Newsletter Roundup – May 2026&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;&lt;a href=&quot;https://victorhckinthefreeworld.com&quot;&gt;Victorhck&lt;/a&gt; presents a Spanish-language summary and translation of the May 2026 Free Software Foundation newsletter. Among the stories covered are Amazon’s upcoming May 20 Kindle shutdown affecting older devices and the FSF’s critique of DRM restrictions, as well as France’s announced plan to migrate some government computers from Windows to Linux.&lt;/p&gt;

&lt;h2 id=&quot;whats-new-in-kdenlive-in-kde-gear-2604--kde-at-30-edition&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/novedades-de-kdenlive-en-kde-gear-26-04-edicion-kde-a-los-30.html&quot;&gt;What’s New in Kdenlive in KDE Gear 26.04 – “KDE at 30” Edition&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; covers improvements coming to the Kdenlive video editor as part of the KDE Gear 26.04 release. The post highlights new features and refinements aimed at both new and experienced video editors on Linux.&lt;/p&gt;

&lt;h2 id=&quot;summit-draws-landmark-regional-gathering&quot;&gt;&lt;a href=&quot;https://news.opensuse.org/2026/05/05/summit-draws-landmark-regional-gathering/&quot;&gt;Summit Draws Landmark Regional Gathering&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;&lt;a href=&quot;https://news.opensuse.org/&quot;&gt;openSUSE News&lt;/a&gt; reports that 321 developers, students, and technology professionals gathered at Universidad Libre in Barranquilla, Colombia, for the first-ever openSUSE Summit in the Americas. The event marked a landmark moment for the community’s reach in the region and brought together contributors from across many nations.&lt;/p&gt;

&lt;h2 id=&quot;tumbleweed-monthly-update--april-2026&quot;&gt;&lt;a href=&quot;https://news.opensuse.org/2026/05/04/tw-monthly-update-april/&quot;&gt;Tumbleweed Monthly Update – April 2026&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;&lt;a href=&quot;https://news.opensuse.org/&quot;&gt;openSUSE News&lt;/a&gt; recaps a busy April for Tumbleweed, which highlighted the arrival of GNOME 50 and KDE Gear 26.04, and critical fixes for “Copy Fail”, which has now been patched for both Tumbleweed and Slowroll users who ran &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;zypper dup&lt;/code&gt;. The Linux kernel advanced to 7.0.2 and Mesa to 26.0.5 with raytracing fixes. Security received heavy attention with WebKitGTK, CUPS, Python, Flatpak, sudo, and OpenEXR all receiving multiple CVE fixes.&lt;/p&gt;

&lt;h2 id=&quot;accessing-opensuse-cockpit-from-a-remote-machine&quot;&gt;&lt;a href=&quot;https://victorhckinthefreeworld.com/2026/05/05/acceder-a-cockpit-de-opensuse-desde-otro-equipo-remoto/&quot;&gt;Accessing openSUSE Cockpit from a Remote Machine&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;&lt;a href=&quot;https://victorhckinthefreeworld.com&quot;&gt;Victorhck&lt;/a&gt; continues his series on the Cockpit tool being developed as a replacement for YaST in openSUSE. The tutorial walks through enabling port 9090 in the firewall to make remote access possible. This follows his earlier posts on installing Cockpit and managing software and repositories through its interface.&lt;/p&gt;

&lt;h2 id=&quot;neon-multicolor-icons-for-your-pc-beatybeam&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/iconos-multicolor-neon-para-tu-pc-beatybeam.html&quot;&gt;Neon Multicolor Icons for Your PC: BeatyBeam&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; presents BeatyBeam, a neon multicolor icon pack for KDE Plasma that is well-suited for dark themes. The pack brings vibrant, colorful icons to the desktop for users looking to personalize their visual environment.&lt;/p&gt;

&lt;h2 id=&quot;managing-software-and-repositories-in-opensuse-via-cockpit&quot;&gt;&lt;a href=&quot;https://victorhckinthefreeworld.com/2026/05/04/gestionar-software-y-repositorios-en-opensuse-mediante-cockpit/&quot;&gt;Managing Software and Repositories in openSUSE via Cockpit&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;&lt;a href=&quot;https://victorhckinthefreeworld.com&quot;&gt;Victorhck&lt;/a&gt; explains how to use Cockpit that is being developed to succeed YaST in openSUSE to manage software repositories and install or remove packages directly from the browser. The post covers the relevant Cockpit modules needed for these tasks and how they compare to equivalent YaST functionality.&lt;/p&gt;

&lt;h2 id=&quot;tux-manager--the-linux-clone-of-windows-task-manager&quot;&gt;&lt;a href=&quot;https://cubiclenate.com/2026/05/03/tux-manager-the-linux-clone-of-windows-task-manager/&quot;&gt;Tux Manager – The Linux Clone of Windows Task Manager&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;&lt;a href=&quot;https://cubiclenate.com/&quot;&gt;CubicleNate’s Blog&lt;/a&gt; takes a look at Tux Manager, a task manager application for Linux that closely mirrors the look and feel of the Windows Task Manager. The app is aimed at users coming from Windows who want a familiar interface for monitoring processes and system resources on KDE Plasma.&lt;/p&gt;

&lt;h2 id=&quot;autoround-state-of-the-art-in-quantization-for-cpuxpunvidia-gpu&quot;&gt;&lt;a href=&quot;https://assuntonerd.com.br/2026/05/03/auto-round-estado-da-arte-em-quantizacao-para-cpu-xpu-cuda/&quot;&gt;AutoRound: State of the Art in Quantization for CPU/XPU/NVIDIA GPU&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;&lt;a href=&quot;https://assuntonerd.com.br/&quot;&gt;Alessandro&lt;/a&gt; introduces AutoRound, an Intel-developed quantization toolkit for LLMs and VLMs that reduces model weights to 2, 3, 4, or 8 bits while maintaining high accuracy using signed gradient descent. Unlike naive rounding, AutoRound learns the optimal way to round weights and adjust clipping limits to minimize output error.&lt;/p&gt;

&lt;h2 id=&quot;invest-in-your-identity&quot;&gt;&lt;a href=&quot;https://blog.cornelius-schumacher.de/2026/05/invest-in-your-identity.html&quot;&gt;Invest in Your Identity&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;&lt;a href=&quot;https://blog.cornelius-schumacher.de/&quot;&gt;Cornelius Schumacher’s Blog&lt;/a&gt; offers a thoughtful reflection on the importance of building a genuine personal digital identity in the age of AI agents. The author argues that decades of authentic writing, publishing, and presentations create a personal corpus that can anchor AI tools to who you actually are.&lt;/p&gt;

&lt;h2 id=&quot;exelearning-40-released&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/lanzado-exelearning-4-0.html&quot;&gt;exeLearning 4.0 Released&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; announces the release of eXeLearning 4.0, which is an open-source tool for creating interactive educational content. The new major version demonstrates that the project remains active and evolving with new features for educators building digital learning materials.&lt;/p&gt;

&lt;h2 id=&quot;linux-saloon-199--ubuntu-2604&quot;&gt;&lt;a href=&quot;https://cubiclenate.com/2026/05/02/linux-saloon-199-ubuntu-26-04/&quot;&gt;Linux Saloon 199 | Ubuntu 26.04&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;&lt;a href=&quot;https://cubiclenate.com/&quot;&gt;CubicleNate’s Blog&lt;/a&gt; recaps episode 199 of the Linux Saloon podcast, which focused on Ubuntu 26.04 LTS and its various flavors, including user experiences and installation challenges. Participants shared their impressions of the new LTS release and discussed differences across the Ubuntu ecosystem.&lt;/p&gt;

&lt;h2 id=&quot;background-apps-and-zoom-scaling--this-week-in-plasma&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/aplicaciones-en-segundo-plano-y-escalado-con-zoom-esta-semana-en-plasma.html&quot;&gt;Background Apps and Zoom Scaling – This Week in Plasma&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; translates and summarizes the latest “This Week in Plasma” development report and covers work on background application handling. The post highlights ongoing refinements across several Plasma components aimed at improving usability and visual consistency.&lt;/p&gt;

&lt;h2 id=&quot;free-software-from-north-to-south-east-to-west-6-librelocal-meetups&quot;&gt;&lt;a href=&quot;https://victorhckinthefreeworld.com/2026/05/01/de-norte-a-sur-de-este-a-oeste-el-software-libre-presente-en-6-meetups-de-librelocal/&quot;&gt;Free Software from North to South, East to West: 6 LibreLocal Meetups&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;&lt;a href=&quot;https://victorhckinthefreeworld.com&quot;&gt;Victorhck&lt;/a&gt; highlights May 2026 as “LibreLocal month,” promoted by the Free Software Foundation as an occasion for free software supporters to organize local meetups to share ideas, learn from each other, and celebrate free software. The post spotlights six upcoming LibreLocal meetups taking place across Spain.&lt;/p&gt;

&lt;h2 id=&quot;kde-participates-in-google-summer-of-code-2026&quot;&gt;&lt;a href=&quot;https://www.kdeblog.com/kde-participa-en-google-summer-of-code-2026.html&quot;&gt;KDE Participates in Google Summer of Code 2026&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;The &lt;a href=&quot;https://www.kdeblog.com/&quot;&gt;KDE Blog&lt;/a&gt; announces that KDE is once again participating in Google Summer of Code (GSoC) 2026, welcoming student developers to contribute to KDE projects over the summer. The post outlines how the program works and encourages interested learners to apply and get involved with the KDE community.&lt;/p&gt;

&lt;h2 id=&quot;suse-responds-to-the-copyfail-vulnerability&quot;&gt;&lt;a href=&quot;https://www.suse.com/c/suse-responds-to-the-copy-fail-vulnerability/&quot;&gt;SUSE Responds to the copy.fail Vulnerability&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;&lt;a href=&quot;https://www.suse.com/c/&quot;&gt;SUSE Communities&lt;/a&gt; details the company’s response to Copy Fail, a critical Linux kernel vulnerability in the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;algif_aead&lt;/code&gt; module that allows a local non-root user to gain full root access. The post, written by Marcus Meissner, outlines which SUSE and openSUSE products are affected and confirms that patches have been issued. Users are strongly advised to apply the available updates immediately.&lt;/p&gt;

&lt;p&gt;View more blogs or learn to publish your own on &lt;a href=&quot;https://planet.opensuse.org&quot;&gt;planet.opensuse.org&lt;/a&gt;.&lt;/p&gt;

&lt;meta name=&quot;openSUSE, Open Source, development, Linux, secure operating systems, open source, plasma, Copy Fail, KDE, Cockpit, syslog-ng, Tumbleweed, AI&quot; content=&quot;HTML,CSS,XML,JavaScript&quot; /&gt;

</content:encoded>
    </item>

    <item>
      <guid>https://news.opensuse.org/2026/05/05/summit-draws-landmark-regional-gathering/</guid>
      <title>Summit Draws Landmark Regional Gathering</title>
      <pubDate>Tue, 05 May 2026 11:00:00 +0000</pubDate>
      <link>https://news.opensuse.org/2026/05/05/summit-draws-landmark-regional-gathering/</link>
      <author>admin@opensuse.org (Douglas DeMaio)</author>
      <enclosure url="https://news.opensuse.org/wp-content/uploads/2026/05/summit.png" length="303272" type="image/png" />
      <description>Three hundred twenty-one developers, students and technology professionals converged on Universidad Libre in Barranquilla, Colombia, for the first-ever openSUSE America Summit. It was a two-day event held at Universidad Libre’s campuses that wrapped up on May 1 with calls to expand open-source culture and contribution across the region. A capture...</description>
      <content:encoded>&lt;p&gt;Three hundred twenty-one developers, students and technology professionals converged on Universidad Libre in Barranquilla, Colombia, for the first-ever &lt;a href=&quot;https://events.opensuse.org/conferences/oSAMS26&quot;&gt;openSUSE America Summit&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;It was a two-day event held at &lt;a href=&quot;https://www.unilibre.edu.co/&quot;&gt;Universidad Libre’s&lt;/a&gt; campuses that wrapped up on May 1 with calls to expand open-source culture and contribution across the region.&lt;/p&gt;

&lt;p&gt;A capture the flag competition added a hands-on cybersecurity dimension to the summit, challenging participants to test their offensive and defensive skills in a live environment. The exercise drew significant interest from students and IT professionals alike.&lt;/p&gt;

&lt;p&gt;The conference drew presenters from across the globe, which reflects the international reach of the open-source community. Speakers representing Colombia, Argentina, Brazil, Mexico, the Dominican Republic, India, the United Kingdom, Germany and the United States addressed topics ranging from cybersecurity and cloud infrastructure to machine learning and community development.&lt;/p&gt;

&lt;p&gt;Luis Delascar of Colombia opened Day 2 with a presentation on Kuná Red, an offline-first, open-source mesh networking solution designed to enable communication in rural and underserved regions lacking reliable internet or cellular infrastructure. Diego Córdoba of Argentina delivered a deep dive into &lt;a href=&quot;https://www.netfilter.org/&quot;&gt;Netfilter&lt;/a&gt; and firewall architecture in openSUSE using nftables, while compatriot Andrea Navarro, also from Argentina, addressed the use of Jupyter notebooks in educational settings as an alternative to commercial cloud platforms.&lt;/p&gt;

&lt;p&gt;Patrick Fitzgerald made the case for Linux migration in an update talk titled about migrating from Windows to Linux citing growing concerns around data sovereignty, tariffs, and unreliable international partnerships as compelling reasons for individuals and organizations to move to Linux.&lt;/p&gt;

&lt;p&gt;Ram Mohan Rao Chukka and Shibi Ramachandran, both from India, presented two sessions; one on improving end-to-end testing using Kuttl to reduce broken builds, and another on intelligent drift detection and auto-remediation in ArgoCD for enterprise Kubernetes environments.&lt;/p&gt;

&lt;p&gt;Walddys Dorrejo of the Dominican Republic, an openSUSE moderator, presented on unified observability and security using Wazuh. Gabriel Bazzotti of Brazil introduced Git-based packaging for openSUSE and Anuar Harb of Mexico spoke about open-source infrastructure as the foundation for connected digital ecosystems in emerging regions.&lt;/p&gt;

&lt;p&gt;Colombian speakers  were featured prominently throughout the program. Jorge Lambrano presented a full machine learning workflow. Jorge Aguilar addressed building modern, robust open-source data platforms for demanding analytics workloads. Jesuse Bossa explored the historical and philosophical purpose of engineering and Deiner Bello showcased VisitChocó, an interactive tourism platform built with React, TypeScript and geospatial data promoting the Colombian department of Chocó. Integration of &lt;a href=&quot;https://weblate.org/&quot;&gt;Weblate&lt;/a&gt; to enable community-driven translations and expand the platform’s reach to broader audiences across Latin America and beyond is being considered.&lt;/p&gt;

&lt;p&gt;Johannes Segitz delivered two sessions. His talk about the current AI landscape and how LLMs are reshaping how people code, patch and package software was a crowd pleaser.&lt;/p&gt;

&lt;p&gt;Organized by sponsorship lead &lt;a href=&quot;https://astian.org/&quot;&gt;Astian Inc.&lt;/a&gt;, which the company behind the &lt;a href=&quot;https://astian.org/midori-browser/&quot;&gt;Midori light-weight Web Browser&lt;/a&gt; along with a network of local support from &lt;a href=&quot;https://x.com/LinuxBQ&quot;&gt;LinuxBQ&lt;/a&gt; and &lt;a href=&quot;https://www.instagram.com/redteambq/&quot;&gt;Red Team Barranquilla&lt;/a&gt;, Barranquilla’s community of free and open-source software enthusiasts organized and ran the summit April 29 through May 1.&lt;/p&gt;

&lt;p&gt;Having the event at two campuses, &lt;a href=&quot;https://maps.app.goo.gl/t5MyRg188wmo7Xt78&quot;&gt;Universidad Libre’s Central Campus&lt;/a&gt; on April 29 and &lt;a href=&quot;https://maps.app.goo.gl/c9CxJpodeW47oJJx5?g_st=ic&quot;&gt;North Campus&lt;/a&gt; on April 30, was a natural fit for the open-source event. Attendees included speakers, IT professionals and students from university had hours of discussions about openSUSE and the broader open-source ecosystem.&lt;/p&gt;

&lt;p&gt;The event was made possible with support from &lt;a href=&quot;https://www.suse.com/&quot;&gt;SUSE&lt;/a&gt; and the &lt;a href=&quot;https://geekos.org/&quot;&gt;Geeko Foundation&lt;/a&gt;, both of which help to champion growth of the &lt;a href=&quot;https://www.opensuse.org/&quot;&gt;openSUSE Project&lt;/a&gt; and the global open-source community.&lt;/p&gt;

&lt;p&gt;The choice of Barranquilla as host city may prove to be more than symbolic. Organizers and attendees have begun discussing the possibility of transforming the openSUSE America Summit into a recurring, traveling event modeled after the &lt;a href=&quot;https://events.opensuse.org&quot;&gt;openSUSE.Asia Summit&lt;/a&gt;, which rotates among countries throughout Asia. Each host nation contributes its own cultural identity and local community to the gathering.&lt;/p&gt;

&lt;p&gt;Colombia, with its growing technology sector, strong university ecosystem and passionate open-source community, makes a compelling case as a starting point and center of gravity for future events. The LinuxBQ community’s enthusiasm and the active participation of Universidad Libre students signal that the conditions for a sustainable, grassroots open-source movement in the region are already in place. If the model takes hold, future editions of the summit could travel to other nations across the Americas and the Caribbean, amplifying the voices of tech leaders throughout the region and building a collective, traveling community of experts much as the Asia Summit has done across that continent.&lt;/p&gt;

&lt;p&gt;A community barbecue on May 1 brought speakers and volunteers together to close out the event. Sessions were livestreamed and are available for viewing on the &lt;a href=&quot;https://www.youtube.com/@LinuxBQ&quot;&gt;LinuxBQ YouTube channel&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;https://www.youtube.com/live/zeKce540g8o?si=6You-TF_s8uwu-mk&quot;&gt;&lt;img src=&quot;https://img.youtube.com/vi/zeKce540g8o/0.jpg&quot; alt=&quot;openSUSE America Summit 1&quot; /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;https://www.youtube.com/live/gWHFSm61S3s?si=Pe05lpANP5ybmNIO&quot;&gt;&lt;img src=&quot;https://img.youtube.com/vi/gWHFSm61S3s/0.jpg&quot; alt=&quot;openSUSE America Summit 1&quot; /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;meta name=&quot;Linux, rolling release, developers, sysadmins, power users, summit, red team, america&quot; content=&quot;HTML,CSS,XML,JavaScript&quot; /&gt;

</content:encoded>
    </item>

    <item>
      <guid>https://news.opensuse.org/2026/05/04/tw-monthly-update-april/</guid>
      <title>Tumbleweed Monthly Update - April 2026</title>
      <pubDate>Mon, 04 May 2026 11:00:00 +0000</pubDate>
      <link>https://news.opensuse.org/2026/05/04/tw-monthly-update-april/</link>
      <author>admin@opensuse.org (Douglas DeMaio)</author>
      <enclosure url="https://news.opensuse.org/wp-content/uploads/2025/05/tw.png" length="209112" type="image/png" />
      <description>There were several software package updates for openSUSE Tumbleweed during April and the later half of the month brought some urgency with Copy Fail, which is now safe for users of the rolling release and Slowroll for those who have done a zypper dup at the end of the month....</description>
      <content:encoded>&lt;p&gt;There were several software package updates for &lt;a href=&quot;https://get.opensuse.org/tumbleweed/&quot;&gt;openSUSE Tumbleweed&lt;/a&gt; during April and the later half of the month brought some urgency with &lt;a href=&quot;https://copy.fail/&quot;&gt;Copy Fail&lt;/a&gt;, which is now safe for users of the rolling release and &lt;a href=&quot;https://en.opensuse.org/openSUSE:Slowroll&quot;&gt;Slowroll&lt;/a&gt; for those who have done a &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;zypper dup&lt;/code&gt; at the end of the month.&lt;/p&gt;

&lt;p&gt;The information about affected flavors of openSUSE was covered in a &lt;a href=&quot;https://www.suse.com/c/suse-responds-to-the-copy-fail-vulnerability/&quot;&gt;blog by the security team&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;April brought a major desktop release of &lt;a href=&quot;https://release.gnome.org/50/&quot;&gt;GNOME 50&lt;/a&gt; and there was a fourth Plasma 6.6 point release. &lt;a href=&quot;https://www.php.net/&quot;&gt;PHP&lt;/a&gt;, &lt;a href=&quot;https://www.gtk.org/&quot;&gt;GTK4&lt;/a&gt; with the new native &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;GtkSvg&lt;/code&gt; renderer, &lt;a href=&quot;https://www.sqlite.org/&quot;&gt;SQLite&lt;/a&gt;, &lt;a href=&quot;https://wiki.linuxfoundation.org/networking/iproute2&quot;&gt;iproute2&lt;/a&gt;, and &lt;a href=&quot;https://www.nano-editor.org/&quot;&gt;nano&lt;/a&gt; were among some of the develop packages updated this month. The &lt;a href=&quot;https://www.kernel.org/&quot;&gt;Linux kernel&lt;/a&gt; advances to 7.0.2, and &lt;a href=&quot;https://www.mesa3d.org/&quot;&gt;Mesa&lt;/a&gt; progressed through 26.0.4 and 26.0.5 with raytracing fixes ahead of upcoming game releases. Security received heavy attention with &lt;a href=&quot;https://webkitgtk.org/&quot;&gt;WebKitGTK&lt;/a&gt;, &lt;a href=&quot;https://www.python.org/&quot;&gt;Python&lt;/a&gt;, &lt;a href=&quot;https://www.cups.org/&quot;&gt;CUPS&lt;/a&gt;, &lt;a href=&quot;https://flatpak.org/&quot;&gt;Flatpak&lt;/a&gt;, &lt;a href=&quot;https://www.sudo.ws/&quot;&gt;sudo&lt;/a&gt;, and &lt;a href=&quot;https://openexr.com/&quot;&gt;OpenEXR&lt;/a&gt; all receiving multiple &lt;a href=&quot;https://en.wikipedia.org/wiki/Common_Vulnerabilities_and_Exposures&quot;&gt;Common Vulnerabilities and Exposures&lt;/a&gt; fixes.&lt;/p&gt;

&lt;p&gt;As always, be sure to roll back using &lt;a href=&quot;https://github.com/openSUSE/snapper&quot;&gt;snapper&lt;/a&gt; if any issues arise.&lt;/p&gt;

&lt;p&gt;For more details on the change logs for the month, visit the &lt;a href=&quot;https://lists.opensuse.org/archives/list/factory@lists.opensuse.org/&quot;&gt;openSUSE Factory mailing list&lt;/a&gt;.&lt;/p&gt;

&lt;h2 id=&quot;new-features-and-enhancements&quot;&gt;New Features and Enhancements&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://kde.org/announcements/gear/26.04.0/&quot;&gt;KDE Gear 26.04.0&lt;/a&gt;&lt;/strong&gt;: This major release updates 129 packages from the 25.12.3 series across the core PIM suite (&lt;a href=&quot;https://community.kde.org/KDE_PIM/Akonadi&quot;&gt;Akonadi&lt;/a&gt;, &lt;a href=&quot;https://apps.kde.org/kmail/&quot;&gt;KMail&lt;/a&gt;, &lt;a href=&quot;https://apps.kde.org/kontact/&quot;&gt;Kontact&lt;/a&gt;, &lt;a href=&quot;https://apps.kde.org/korganizer/&quot;&gt;KOrganizer&lt;/a&gt;), graphics tools (&lt;a href=&quot;https://apps.kde.org/gwenview/&quot;&gt;Gwenview&lt;/a&gt;, &lt;a href=&quot;https://apps.kde.org/okular/&quot;&gt;Okular&lt;/a&gt;), development tools (&lt;a href=&quot;https://apps.kde.org/kate/&quot;&gt;Kate&lt;/a&gt;, &lt;a href=&quot;https://apps.kde.org/kompare/&quot;&gt;Kompare&lt;/a&gt;, &lt;a href=&quot;https://apps.kde.org/umbrello/&quot;&gt;Umbrello&lt;/a&gt;), and system utilities (&lt;a href=&quot;https://apps.kde.org/dolphin/&quot;&gt;Dolphin&lt;/a&gt;, &lt;a href=&quot;https://apps.kde.org/konsole/&quot;&gt;Konsole&lt;/a&gt;, &lt;a href=&quot;https://apps.kde.org/kleopatra/&quot;&gt;Kleopatra&lt;/a&gt;). &lt;a href=&quot;https://apps.kde.org/dolphin/&quot;&gt;Dolphin&lt;/a&gt; prevents re-entrant signal activation across multiple view states, and &lt;a href=&quot;https://apps.kde.org/ark/&quot;&gt;Ark&lt;/a&gt; prevents silent replacement of existing files by directory entries during extraction. &lt;a href=&quot;https://apps.kde.org/okular/&quot;&gt;Okular&lt;/a&gt; avoids processing HTML with &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;QDomDocument&lt;/code&gt; and improves certificate selection, and &lt;a href=&quot;https://invent.kde.org/graphics/kdegraphics-thumbnailers&quot;&gt;kdegraphics-thumbnailers&lt;/a&gt; addresses multiple crashes for malformed files. Infrastructure-wide changes include CMake modernization, a port to QDoc documentation, and migration toward modern C++ patterns such as &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;std::shared_ptr&lt;/code&gt; over &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;QSharedPointer&lt;/code&gt;. The companion &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;ktextaddons&lt;/code&gt; library jumps from 1.8.0 to 2.0.1.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://kde.org/announcements/frameworks/6/6.25.0/&quot;&gt;KDE Frameworks 6.25.0&lt;/a&gt;&lt;/strong&gt;: This release emphasizes code quality, memory safety, and developer experience. &lt;a href=&quot;https://invent.kde.org/frameworks/kio&quot;&gt;KIO&lt;/a&gt; reverts a problematic permissions-based readability check, restores proper FTP UTF-8 negotiation, fixes WebDAV copy/move headers, and resolves multiple memory leaks across file operations and preview jobs. &lt;a href=&quot;https://invent.kde.org/frameworks/kcodecs&quot;&gt;KCodecs&lt;/a&gt; streamlines encoding detection with safer initialization, improved codec lookup performance, and removes obsolete code since Qt 6.8+ is required.&lt;a href=&quot;https://invent.kde.org/frameworks/kirigami&quot;&gt;Kirigami&lt;/a&gt; enhances component reliability by preventing dialog layer leaks and adds a configurable &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;textFormat&lt;/code&gt; property to &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;TitleSubtitle&lt;/code&gt;, while &lt;a href=&quot;https://develop.kde.org/frameworks/breeze-icons/&quot;&gt;Breeze Icons&lt;/a&gt; expands the icon set with new status icons. &lt;a href=&quot;https://invent.kde.org/frameworks/ktexteditor&quot;&gt;KTextEditor&lt;/a&gt; improves document handling by using the first line as a fallback title and adding relevant MIME types to save dialogs.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://release.gnome.org/50/&quot;&gt;GNOME 50&lt;/a&gt; for developers&lt;/strong&gt;: This release brings significant improvements to the development stack. &lt;a href=&quot;https://apps.gnome.org/Builder/&quot;&gt;Builder&lt;/a&gt; gains a new save delegate system for better draft handling, refined dark theme colors matching the &lt;a href=&quot;https://gnome.pages.gitlab.gnome.org/libadwaita/&quot;&gt;Adwaita&lt;/a&gt; palette, and more integrated help documentation. Flatpak support now moves deleted files to the trash, the LSP client better handles delete notifications, and the build pipeline supports more flexible post-install commands. &lt;a href=&quot;https://gitlab.gnome.org/GNOME/mutter&quot;&gt;Mutter&lt;/a&gt; Devkit receives a major feature expansion including HiDPI and fractional scaling simulation, multi-monitor support within a single session, clipboard integration between host and Devkit, and resizable virtual displays with emulated monitor modes — reducing the need for physical multi-monitor test setups. &lt;a href=&quot;https://www.gtk.org/&quot;&gt;GTK&lt;/a&gt; 4.22 introduces &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;GtkSvg&lt;/code&gt;, a new native in-process SVG renderer integrated with the GTK Scene Graph that supports SVG animations, passes over 1,250 tests in the resvg test suite, and maintains 60fps+ performance for trusted system icons and application resources (untrusted SVGs should still use the sandboxed &lt;a href=&quot;https://gitlab.gnome.org/sophie-h/glycin&quot;&gt;Glycin&lt;/a&gt; library). &lt;a href=&quot;https://gnome.pages.gitlab.gnome.org/libadwaita/&quot;&gt;Libadwaita&lt;/a&gt; 1.9 introduces new sidebar widgets including &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;AdwSidebar&lt;/code&gt; and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;AdwViewSwitcherSidebar&lt;/code&gt; (replacing &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;GtkStackSidebar&lt;/code&gt;), automatic support for the system-wide reduced motion preference across most widgets, context menus on &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;AdwAboutDialog&lt;/code&gt; link rows, and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;GTK_DEBUG=builder&lt;/code&gt; diagnostics for all standard widgets. Autoloaded style resources are deprecated in favor of standard CSS media queries.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://wiki.gnome.org/Projects/GDM&quot;&gt;GDM&lt;/a&gt; 50.0&lt;/strong&gt;: The most significant change for this in the &lt;a href=&quot;https://release.gnome.org/50/&quot;&gt;GNOME 50&lt;/a&gt; release is the complete removal of X11 support for GDM’s own sessions, which now always run on &lt;a href=&quot;https://wayland.freedesktop.org/&quot;&gt;Wayland&lt;/a&gt;. Features like XDMCP and the system-wide Xserver are gone, though launching other desktops’ X11 sessions via per-user X servers is still possible. Compiling GDM without Wayland support is no longer possible. With systemd v260+, remote desktop sessions and local background sessions are now granted GPU access, enabling accelerated graphics for remote sessions on distributions that restrict GPU device node permissions. service&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt; simplifies starting headless graphical sessions for RDP purposes. The &lt;/code&gt;gdm&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;/&lt;/code&gt;gdm3` user is no longer needed since GDM now fully relies on dynamically allocated users. Wtmp/utmp/btmp records now contain more useful values, especially for Wayland and headless RDP sessions.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://kde.org/announcements/changelogs/plasma/6/6.6.3-6.6.4/&quot;&gt;Plasma 6.6.4&lt;/a&gt;&lt;/strong&gt;: &lt;a href=&quot;https://invent.kde.org/plasma/kwin&quot;&gt;KWin&lt;/a&gt; fixes blur flickering after wobbly windows, improves startup feedback icon clarity, resolves crashes with accessibility keyboards, and enhances pointer scaling and key repeat handling on &lt;a href=&quot;https://wayland.freedesktop.org/&quot;&gt;Wayland&lt;/a&gt;. The &lt;a href=&quot;https://invent.kde.org/plasma/oxygen&quot;&gt;Oxygen&lt;/a&gt; theme addresses pixelated buttons under fractional scaling, restores missing menu shadows, and adds a missing switch SVG. Usability improvements include better RTL support in Kicker, proper drag initiation only after pointer movement, and refined shortcut conflict prevention in keyboard settings. &lt;a href=&quot;https://invent.kde.org/plasma/plasma-keyboard&quot;&gt;Plasma Keyboard&lt;/a&gt; hardens virtual input handling with UTF-8 length fixes and disables predictive text during capture. Other fixes improve &lt;a href=&quot;https://apps.kde.org/discover/&quot;&gt;Discover&lt;/a&gt; by correcting how it tracks the number of active transactions, &lt;a href=&quot;https://invent.kde.org/plasma/drkonqi&quot;&gt;Dr Konqi&lt;/a&gt; with more reliable crash debugging, and &lt;a href=&quot;https://apps.kde.org/spectacle/&quot;&gt;Spectacle&lt;/a&gt; with a workaround for an overlay issue introduced in Qt 6.11. Several system tray and menu rendering glitches across multiple applets are also resolved, resulting in a smoother and more resilient desktop experience.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://w3m.sourceforge.net/&quot;&gt;w3m&lt;/a&gt; 0.5.6&lt;/strong&gt;: This is a major update for the terminal web browser. New features include commands to scroll the current line to top/bottom, a change directory (CD) command, a vim-like smartcase search option, recognition of &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;aria-label&lt;/code&gt; for buttons, &lt;a href=&quot;https://en.wikipedia.org/wiki/Gopher_(protocol)&quot;&gt;gopher protocol&lt;/a&gt; support, and experimental session store and restore. The image display in the &lt;a href=&quot;https://sw.kovidgoyal.net/kitty/&quot;&gt;kitty&lt;/a&gt; terminal is fixed, and slow backward search in long lines is improved.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.libreoffice.org/&quot;&gt;LibreOffice&lt;/a&gt; 26.2.2.2&lt;/strong&gt;: This is a major version upgrade with completely new features, improvements, and bug fixes across Writer, Calc, Impress, Draw, Math, and Base. Detailed release notes are available at &lt;a href=&quot;https://wiki.documentfoundation.org/Releases/26.2.0/RC1&quot;&gt;The Document Foundation wiki&lt;/a&gt;. Bundled components are refreshed including &lt;a href=&quot;https://pdfium.googlesource.com/pdfium/&quot;&gt;PDFium&lt;/a&gt; updated from 7012 to 7471 and 2D Graphics Library &lt;a href=&quot;https://skia.org/&quot;&gt;Skia&lt;/a&gt; updated from milestone 136 to 142.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.libsdl.org/&quot;&gt;SDL3&lt;/a&gt; 3.4.2&lt;/strong&gt;: This update adds &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;SDL_HINT_OPENGL_FORCE_SRGB_FRAMEBUFFER&lt;/code&gt; to control sRGB behavior for OpenGL and OpenGL ES contexts. A long startup time on Windows caused by non-compliant input devices was fixed, along with a divide-by-zero when using Nintendo Switch 2 controllers and improved GameCube adapter handling in PC mode. Support for the Razer Raiju V5 Pro is added.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://gitlab.com/cryptsetup/cryptsetup&quot;&gt;cryptsetup&lt;/a&gt; 2.8.6&lt;/strong&gt;: This update has several disk encryption fixes. The resumed device UUID is now verified against the UUID stored in metadata, and the LUKS2 reencryption lock name was corrected. FileVault (fvault2) metadata parsing is fixed, including reading from the correct image offset. The OpenSSL crypto backend works again when built with LibreSSL and allows up to 64 concurrent threads.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.mozilla.org/en-US/firefox/new/&quot;&gt;Mozilla Firefox&lt;/a&gt; 149.0.2&lt;/strong&gt;: This update addresses multiple security vulnerabilities, including integer overflow and memory safety bugs in Graphics: Text and Graphics: WebGPU components. The update also includes enterprise-related features such as AI-feature management, prevention of built-in VPN and IP protection, and correct application of browser homepage and start page policies. Other fixes include resolution of layout issues with graphics (SVG), crash prevention for security keys and WebAuthn features, and improved handling of web page printing and website error pages. Additionally, the build process is updated to be compatible with clang-based building on Leap, with the necessary libraries specified. [Linux]&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.php.net/&quot;&gt;PHP&lt;/a&gt; 8.5.5&lt;/strong&gt;: This minor version bump from the 8.4 series brings numerous bug fixes across the core, &lt;a href=&quot;https://www.php.net/manual/en/book.dom.php&quot;&gt;DOM&lt;/a&gt;, &lt;a href=&quot;https://www.php.net/manual/en/book.opcache.php&quot;&gt;Opcache&lt;/a&gt;, and &lt;a href=&quot;https://www.php.net/manual/en/book.openssl.php&quot;&gt;OpenSSL&lt;/a&gt; modules. Notable fixes address JIT compiler arithmetic errors, memory leaks, and use-after-free vulnerabilities. The package now requires &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;libcapstone&lt;/code&gt; as a dependency.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.nano-editor.org/&quot;&gt;nano&lt;/a&gt; 9.0&lt;/strong&gt;: This is a major version bump for the popular terminal text editor. The release improves horizontal scrolling, changes how macro recording is handled, and brings other usability refinements that build on the 8.x series.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://wiki.linuxfoundation.org/networking/iproute2&quot;&gt;iproute2&lt;/a&gt; 7.0&lt;/strong&gt;: A major version bump for the Linux network configuration toolkit. New features include CAN XL support and DPLL mode setting, both of which extend networking and timing capabilities for newer hardware platforms.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://wireless.wiki.kernel.org/en/users/documentation/iw&quot;&gt;iw&lt;/a&gt; 6.17&lt;/strong&gt;: This wireless configuration tool sees a significant jump from 6.9. It adds support for &lt;a href=&quot;https://www.wi-fi.org/discover-wi-fi/security&quot;&gt;WPA3&lt;/a&gt; SAE association, EHT rate and bitrate handling for Wi-Fi 7, multi-radio RTS configuration, and endianness fixes across the wireless stack.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.gimp.org/&quot;&gt;GIMP&lt;/a&gt; 3.2.4&lt;/strong&gt;: This minor update to the GNU Image Manipulation Program continues the 3.2 series with bug fixes and incremental improvements following the 3.2.2 release.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://invisible-island.net/xterm/&quot;&gt;xterm&lt;/a&gt; 407&lt;/strong&gt;: New private modes for UTF-8 and character width reporting are introduced, and Unicode handling and window resizing functionality are improved.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://gitlab.gnome.org/GNOME/gnome-remote-desktop&quot;&gt;gnome-remote-desktop&lt;/a&gt; 50.1&lt;/strong&gt;: This minor update to the GNOME 50 release fixes a black-screen issue when using NVIDIA GPUs.&lt;/p&gt;

&lt;h2 id=&quot;key-package-updates&quot;&gt;Key Package Updates&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.kernel.org/&quot;&gt;Linux kernel&lt;/a&gt; 6.19.11 - 7.0.2&lt;/strong&gt;: The 7.0.2 update fixes an SMB client out-of-bounds read in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;smb2_ioctl_query_info&lt;/code&gt;, DACL validation in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;cifsacl&lt;/code&gt;, and directory separator handling in SMB1 UNIX mounts. F2FS receives multiple fixes including a use-after-free in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;f2fs_compress_write_end_io()&lt;/code&gt; and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;f2fs_write_end_io()&lt;/code&gt;, a memory leak in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;f2fs_rename()&lt;/code&gt;, and improved sanity checks. FUSE fixes several issues including rejection of oversized dirents in page cache, aborting on fatal signals during sync init, and ensuring device file initialization before cloning. A TOCTOU race in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;net/packet&lt;/code&gt; on mmap’d &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;vnet_hdr&lt;/code&gt; in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;tpacket_snd()&lt;/code&gt; is corrected, and crypto fixes address async decrypt skipping hash verification in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;krb5enc&lt;/code&gt; and failed PSP command handling in the CCP driver. The 7.0.1 version sees KVM SEV receive several hardening fixes including locking all vCPUs when synchronizing VMSAs for SNP launch finish, disallowing &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;LAUNCH_FINISH&lt;/code&gt; if vCPUs are actively being created, and protecting &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;sev_mem_enc_register_region()&lt;/code&gt; with proper locking. Multiple use-after-free bugs are resolved across subsystems including &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;bcache&lt;/code&gt; (crash in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;cached_dev.sb_bio&lt;/code&gt;), &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;ocfs2&lt;/code&gt; (fault handling with &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;VM_FAULT_RETRY&lt;/code&gt;), the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;em28xx&lt;/code&gt; media driver, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;blk-cgroup&lt;/code&gt; writeback, and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;ALSA 6fire&lt;/code&gt; on USB disconnect. The 6.19.11 update brings several BPF fixes including reset of register ID for &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;BPF_END&lt;/code&gt; value tracking, constant blinding for &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;PROBE_MEM32&lt;/code&gt; stores, undefined behavior in interpreter &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;sdiv&lt;/code&gt;/&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;smod&lt;/code&gt; for &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;INT_MIN&lt;/code&gt;, and unsound scalar forking in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;maybe_fork_scalars()&lt;/code&gt;. CXL receives multiple corrections including a use-after-free of &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;parent_port&lt;/code&gt; in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;cxl_detach_ep()&lt;/code&gt; and a leak in region construction. NVMe-PCI now caps queue creation to used queues, and platform support is expanded with several HP Omen and Victus laptops, OneXPlayer handheld variants, and Dell 14 Plus 2-in-1 keyboard support.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.mesa3d.org/&quot;&gt;Mesa&lt;/a&gt; 26.0.4 &amp;amp; 26.0.5&lt;/strong&gt;: The 26.0.4 out-of-schedule release combines bugfix updates and important raytracing fixes for an upcoming game. &lt;a href=&quot;https://docs.mesa3d.org/drivers/radv.html&quot;&gt;RADV&lt;/a&gt; corrects an invalid &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;hitAttributeEXT&lt;/code&gt; value when using function-call RT pipelines, fixes a memory leak in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;radv_rt_nir_to_asm&lt;/code&gt;, and emits BOP events after every draw to work around a VRS bug on GFX12. &lt;a href=&quot;https://docs.mesa3d.org/drivers/radeonsi.html&quot;&gt;RadeonSI&lt;/a&gt; fixes a missing ground texture and &lt;a href=&quot;https://docs.mesa3d.org/drivers/anv.html&quot;&gt;ANV&lt;/a&gt; (Intel) addresses flashing effects in &lt;a href=&quot;https://store.steampowered.com/app/2420110/Horizon_Forbidden_West_Complete_Edition/&quot;&gt;Horizon Forbidden West&lt;/a&gt;. &lt;a href=&quot;https://nouveau.freedesktop.org/&quot;&gt;Nouveau&lt;/a&gt; fixes a segmentation fault in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;gm200_validate_sample_locations&lt;/code&gt; triggered by Firefox on GTX 1070 Ti, and &lt;a href=&quot;https://docs.mesa3d.org/drivers/nvk.html&quot;&gt;NVK&lt;/a&gt; corrects barrier cache invalidation and viewport handling on Turing with FSR. The 26.0.5 follow-up is another bugfix release that refreshes the GL headers from libglvnd and disables Vulkan and Panfrost on armv6. Full release notes are available at the &lt;a href=&quot;https://docs.mesa3d.org/relnotes/26.0.4&quot;&gt;Mesa documentation site&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.sqlite.org/&quot;&gt;SQLite&lt;/a&gt; 3.53.0&lt;/strong&gt;: A new Query Result Formatter library is introduced in this release for the popular embedded database, and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;ALTER TABLE&lt;/code&gt; is enhanced with additional capabilities. The jump from 3.51.3 also brings query planner refinements and incremental improvements that benefit any application linking against the system SQLite.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://gitlab.gnome.org/GNOME/libxml2&quot;&gt;libxml2&lt;/a&gt; 2.15.3&lt;/strong&gt;: A point release follow-up to the major 2.15 update. Multiple security fixes are included for type confusion, double-free, and use-after-free issues in the XML parser.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;http://www.libpng.org/pub/png/libpng.html&quot;&gt;libpng16&lt;/a&gt; 1.6.57&lt;/strong&gt;: A small but security-relevant point release that fixes a use-after-free in chunk setters tracked as CVE-2026-34757.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://libjpeg-turbo.org/&quot;&gt;libjpeg-turbo&lt;/a&gt; 3.1.4.1&lt;/strong&gt;: This update to the widely used JPEG codec includes multiple API hardening fixes and improved buffer handling, providing a more robust foundation for image-processing software across the system.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://libarchive.org/&quot;&gt;libarchive&lt;/a&gt; 3.8.7&lt;/strong&gt;: A heap buffer overflow in CAB archive handling is fixed, along with a buffer overflow in the ISO9660 reader. As &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;libarchive&lt;/code&gt; is used by package managers and archive tools across the distribution, this update is broadly relevant.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://firefox-source-docs.mozilla.org/security/nss/index.html&quot;&gt;mozilla-nss&lt;/a&gt; 3.122.1&lt;/strong&gt;: This release of the Network Security Services library brings 30+ bug fixes, including patches for multiple heap use-after-free, integer overflow, and ASN.1 parsing vulnerabilities that affect TLS handling in Firefox, Thunderbird, and other consumers.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://pipewire.org/&quot;&gt;pipewire&lt;/a&gt; 1.6.4&lt;/strong&gt;: This audio and video pipeline server resolves segmentation faults, improves &lt;a href=&quot;https://jackaudio.org/&quot;&gt;JACK&lt;/a&gt; compatibility, and corrects regressions in the RAOP (AirPlay) module.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://sssd.io/&quot;&gt;SSSD&lt;/a&gt; 2.13.0&lt;/strong&gt;: The &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;pam_sss_gss&lt;/code&gt; module can now read SIDs from the Kerberos ticket PAC and apply authentication indicators via the new &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;pam_gssapi_indicators_apply&lt;/code&gt; option, supporting Active Directory’s Authentication Mechanism Assurance (AMA). Active Directory Foreign Security Principals (FSP) are now properly detected and ignored when reading nested group members. Support for the &lt;a href=&quot;https://invent.kde.org/plasma/plasma-login-manager&quot;&gt;KDE Plasma Login Manager&lt;/a&gt; is added. New options include &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;avoid_by_id_lookups&lt;/code&gt; for preferring name-based lookups, and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;interactive&lt;/code&gt;/&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;interactive_prompt&lt;/code&gt; for customizing OAuth2 prompting behavior. Cache performance is optimized for large deployments.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.multiprecision.org/mpc/&quot;&gt;mpc&lt;/a&gt; 1.4.1&lt;/strong&gt;: This complex-number arithmetic library steps from 1.3.1 to 1.4.1 and adds new functions including &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;mpc_exp10&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;mpc_exp2&lt;/code&gt;, and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;mpc_log2&lt;/code&gt;. Sign handling for imaginary parts is improved and pkg-config generation is included.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://github.com/smuellerDD/leancrypto&quot;&gt;leancrypto&lt;/a&gt; 1.7.2&lt;/strong&gt;: This cryptographic library jumps from 1.6.0 and adds post-quantum primitives ML-DSA, SLH-DSA, and ML-KEM along with an X.509 fix tracked as &lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-34610.html&quot;&gt;CVE-2026-34610&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://github.com/fedora-selinux/selinux-policy&quot;&gt;SELinux Policy&lt;/a&gt; 20260410&lt;/strong&gt;: This update contains a wide range of policy refinements. Missing Nextcloud file contexts are added, the openSUSE &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;/var/lib/php8&lt;/code&gt; path and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;/srv/www/htdocs&lt;/code&gt; Apache DocumentRoot are properly labeled. Cloud-init is now allowed to &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;domtrans&lt;/code&gt; into &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;ssh-keygen&lt;/code&gt;, and &lt;a href=&quot;https://linux.die.net/man/8/accountsd_selinux&quot;&gt;accountsd&lt;/a&gt; gains proper D-Bus communication with systemd-homed along with corrected file context labeling for &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;/usr/share/accountsservice&lt;/code&gt;. OpenSSH receives a policy adjustment allowing &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;sshd-session&lt;/code&gt; to send a generic signal to &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;sshd-auth&lt;/code&gt;. Polkit support is updated for its agent helper. Additional permissions are granted for staff and sysadm users, including reading PID1 process state, connecting to systemd-logind and lvm over Unix stream sockets, mounting &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;/proc&lt;/code&gt;, and gaining sandboxing features. Virtualization policies gain several adjustments for &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;virtqemud&lt;/code&gt; and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;virtnetworkd&lt;/code&gt;, and a new &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;local_login_allow_accountutils_fallback_mode&lt;/code&gt; boolean is introduced. The &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;snapper&lt;/code&gt; sdbootutil plugin is allowed to read kernel modules. The embedded &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;container-selinux&lt;/code&gt; is updated to v2.247.0.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.gnu.org/software/texinfo/&quot;&gt;texinfo&lt;/a&gt; 7.3&lt;/strong&gt;: The documentation format package adds new title-page commands, flexible node headings, and cross-reference features. &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;texi2any&lt;/code&gt; gains major HTML speedups, optional C implementation, improved diagnostics, and defaults updates. HTML, Info, LaTeX, XML, and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;info&lt;/code&gt; tool receive enhancements and cleanups. The updated deprecated &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;@clickstyle&lt;/code&gt; and removed old patches.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://tukaani.org/xz/&quot;&gt;XZ Utils&lt;/a&gt; 5.8.3&lt;/strong&gt;: This update fixes a buffer overflow in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;lzma_index_append()&lt;/code&gt; and an invalid memory access in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;xz&lt;/code&gt; when using &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;--files&lt;/code&gt; and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;--files0&lt;/code&gt; options. Arabic man page translations are added.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.gtk.org/&quot;&gt;GTK4&lt;/a&gt; 4.22.2&lt;/strong&gt;: The headline change is native SVG rendering via the new &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;GtkSvg&lt;/code&gt; renderer, which drops the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;librsvg&lt;/code&gt; dependency entirely for icon and image rendering. The new renderer supports animations, state names, and SVG filters, with filters now operating in linear RGB by default. The GStreamer media backend now supports gapless looping with GStreamer 1.28, and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;gtk4-rendernode-tool&lt;/code&gt; gains a new &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;filter&lt;/code&gt; command for node manipulation. Several drag-and-drop fixes are included, notably restoring the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;DropTarget::leave&lt;/code&gt; signal emission when a drop finishes. Vulkan handling is improved with fixes for &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;SWAPCHAIN_MAINTENANCE&lt;/code&gt; checks, pending offset resets on Wayland, and invalid reads. Symbolic icon fallback rendering is corrected, dmabuf support now handles fewer fds than planes, and drop shadow rendering no longer darkens transparent textures. For Tumbleweed users, this brings major rendering architecture improvements and broad stability fixes to GTK4 applications.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://webkitgtk.org/&quot;&gt;webkitgtk3&lt;/a&gt; and &lt;a href=&quot;https://webkitgtk.org/&quot;&gt;webkitgtk4&lt;/a&gt; 2.52.1&lt;/strong&gt;: Numerous security vulnerabilities are patched across both releases. Touch scrolling for small movements is smoother, and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;scrollend&lt;/code&gt; events are now correctly emitted after scroll animations. Async scrolling is improved when the main thread is busy by rendering scrollbars from the scrolling thread. The GPU process is disabled by default in this cycle. A build option to disable &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;USE_GSTREAMER&lt;/code&gt; is added for configurations without multimedia support.&lt;/p&gt;

&lt;h2 id=&quot;security-updates&quot;&gt;Security Updates&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.python.org/&quot;&gt;Python&lt;/a&gt;&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-25645.html&quot;&gt;CVE-2026-25645&lt;/a&gt;&lt;/strong&gt;: Addresses an issue in Python allowing a local attacker to pre-create malicious files that could be reused and loaded without validation.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-4519.html&quot;&gt;CVE-2026-4519&lt;/a&gt;&lt;/strong&gt;: Fixes a command-line option injection in Python’s &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;webbrowser.open()&lt;/code&gt; where leading dashes in URLs could be interpreted as browser command-line arguments.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2025-13462.html&quot;&gt;CVE-2025-13462&lt;/a&gt;&lt;/strong&gt;: Addresses an issue where Python’s tarfile module can cause crafted archives to be misinterpreted.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-4224.html&quot;&gt;CVE-2026-4224&lt;/a&gt;&lt;/strong&gt;: Resolves a stack overflow that could lead to a crash.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://pypi.org/project/cryptography/&quot;&gt;python-cryptography&lt;/a&gt; 46.0.7&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-39892.html&quot;&gt;CVE-2026-39892&lt;/a&gt;&lt;/strong&gt;: Fixes a buffer overflow that can occurr when a non-contiguous buffer was passed to APIs accepting Python buffers.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://w3m.sourceforge.net/&quot;&gt;w3m&lt;/a&gt; 0.5.6&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2023-38252.html&quot;&gt;CVE-2023-38252&lt;/a&gt;&lt;/strong&gt;: Fixes an out-of-bounds read that could allow a crafted HTML file to cause a denial of service.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2023-38253.html&quot;&gt;CVE-2023-38253&lt;/a&gt;&lt;/strong&gt;: Fixes an out-of-bounds read that could allow a crafted HTML file to cause a denial of service.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://webkitgtk.org/&quot;&gt;webkitgtk3&lt;/a&gt; and &lt;a href=&quot;https://webkitgtk.org/&quot;&gt;webkitgtk4&lt;/a&gt; 2.52.1&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2025-43213.html&quot;&gt;CVE-2025-43213&lt;/a&gt;&lt;/strong&gt;: Fixes an issue where processing maliciously crafted web content could lead to an unexpected crash.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2025-43214.html&quot;&gt;CVE-2025-43214&lt;/a&gt;&lt;/strong&gt;: Addresses a flaw where processing maliciously crafted web content could cause an unexpected crash.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2025-43457.html&quot;&gt;CVE-2025-43457&lt;/a&gt;&lt;/strong&gt;: Resolves a vulnerability where processing maliciously crafted web content could lead to an unexpected crash.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2025-43511.html&quot;&gt;CVE-2025-43511&lt;/a&gt;&lt;/strong&gt;: Fixes an issue where processing maliciously crafted web content could lead to memory corruption.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2025-46299.html&quot;&gt;CVE-2025-46299&lt;/a&gt;&lt;/strong&gt;: Addresses a flaw in WebKit where processing maliciously crafted web content could lead to unexpected behavior.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-20608.html&quot;&gt;CVE-2026-20608&lt;/a&gt;&lt;/strong&gt;: Resolves a vulnerability where processing maliciously crafted web content could lead to memory corruption.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-20635.html&quot;&gt;CVE-2026-20635&lt;/a&gt;&lt;/strong&gt;: Fixes a WebKit flaw where processing maliciously crafted web content could cause an unexpected crash.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-20636.html&quot;&gt;CVE-2026-20636&lt;/a&gt;&lt;/strong&gt;: Addresses an issue where processing maliciously crafted web content could lead to memory corruption.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-20644.html&quot;&gt;CVE-2026-20644&lt;/a&gt;&lt;/strong&gt;: Resolves a WebKit vulnerability where processing maliciously crafted web content could lead to an unexpected crash.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-20652.html&quot;&gt;CVE-2026-20652&lt;/a&gt;&lt;/strong&gt;: Fixes an issue where processing maliciously crafted web content could cause memory corruption.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-20676.html&quot;&gt;CVE-2026-20676&lt;/a&gt;&lt;/strong&gt;: Addresses a WebKit flaw where processing maliciously crafted web content could lead to unexpected behavior or a crash.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-20643.html&quot;&gt;CVE-2026-20643&lt;/a&gt;&lt;/strong&gt;: Resolves a cross-origin issue in the Navigation API where processing maliciously crafted web content could bypass the Same Origin Policy.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-20664.html&quot;&gt;CVE-2026-20664&lt;/a&gt;&lt;/strong&gt;: Fixes a WebKit memory handling flaw where processing maliciously crafted web content could cause an unexpected process crash.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-20665.html&quot;&gt;CVE-2026-20665&lt;/a&gt;&lt;/strong&gt;: Addresses an issue where processing maliciously crafted web content could prevent Content Security Policy from being enforced.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-20691.html&quot;&gt;CVE-2026-20691&lt;/a&gt;&lt;/strong&gt;: Resolves an authorization flaw where a maliciously crafted webpage could be used to fingerprint the user.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-28857.html&quot;&gt;CVE-2026-28857&lt;/a&gt;&lt;/strong&gt;: Fixes a WebKit memory handling issue where processing maliciously crafted web content could cause an unexpected process crash.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-28859.html&quot;&gt;CVE-2026-28859&lt;/a&gt;&lt;/strong&gt;: Addresses a flaw where a malicious website could process restricted web content outside the sandbox.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-28861.html&quot;&gt;CVE-2026-28861&lt;/a&gt;&lt;/strong&gt;: Resolves a logic issue where a malicious website could access script message handlers intended for other origins.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-28871.html&quot;&gt;CVE-2026-28871&lt;/a&gt;&lt;/strong&gt;: Fixes a logic flaw where visiting a maliciously crafted website could lead to a cross-site scripting attack.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://sites.google.com/site/fullycapable/&quot;&gt;libcap&lt;/a&gt; 2.78&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-4878.html&quot;&gt;CVE-2026-4878&lt;/a&gt;&lt;/strong&gt;: Addresses a race condition that could lead to local privilege escalation.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://openjdk.org/&quot;&gt;OpenJDK 25&lt;/a&gt; 25.0.3&lt;/strong&gt;:&lt;/p&gt;
&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-22007.html&quot;&gt;CVE-2026-22007&lt;/a&gt;&lt;/strong&gt;: Fixes an information disclosure vulnerability in the Security component of Java SE that could allow a local attacker to read a subset of accessible data.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-22008.html&quot;&gt;CVE-2026-22008&lt;/a&gt;&lt;/strong&gt;: Addresses a flaw in the Libraries component of Java SE that could allow an unauthenticated network attacker to modify some accessible data.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-22013.html&quot;&gt;CVE-2026-22013&lt;/a&gt;&lt;/strong&gt;: Resolves an information disclosure vulnerability in the JGSS component of Java SE that could expose critical data to an unauthenticated network attacker.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-22016.html&quot;&gt;CVE-2026-22016&lt;/a&gt;&lt;/strong&gt;: Fixes an information disclosure flaw in the JAXP component of Java SE that could allow an unauthenticated attacker to access critical data via network protocols.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-22018.html&quot;&gt;CVE-2026-22018&lt;/a&gt;&lt;/strong&gt;: Addresses a denial-of-service vulnerability in the Libraries component of Java SE that could be triggered by an unauthenticated network attacker.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-22021.html&quot;&gt;CVE-2026-22021&lt;/a&gt;&lt;/strong&gt;: Resolves a denial-of-service flaw in the JSSE component of Java SE exploitable via HTTPS by an unauthenticated attacker.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-23865.html&quot;&gt;CVE-2026-23865&lt;/a&gt;&lt;/strong&gt;: Fixes a vulnerability in the bundled FreeType library that could allow memory corruption when processing crafted font data.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-34268.html&quot;&gt;CVE-2026-34268&lt;/a&gt;&lt;/strong&gt;: A patch was added for an information disclosure issue in the Security component of Java SE that could allow a local attacker to read a subset of accessible data.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-34282.html&quot;&gt;CVE-2026-34282&lt;/a&gt;&lt;/strong&gt;: Addresses a denial-of-service vulnerability in the Networking component of Java SE that could allow an unauthenticated attacker to cause a complete crash or hang.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://flatpak.org/&quot;&gt;Flatpak&lt;/a&gt; 1.16.6&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-34078.html&quot;&gt;CVE-2026-34078&lt;/a&gt;&lt;/strong&gt;: Fixes a sandbox escape where the portal accepted app-controlled symlinks in sandbox-expose paths, allowing arbitrary host file access and code execution in the host context.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-34079.html&quot;&gt;CVE-2026-34079&lt;/a&gt;&lt;/strong&gt;: Addresses a path traversal flaw that could allow an app to delete arbitrary files on the host.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://wayland.freedesktop.org/libinput/doc/latest/&quot;&gt;libinput&lt;/a&gt; 1.31.1&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-35093.html&quot;&gt;CVE-2026-35093&lt;/a&gt;&lt;/strong&gt;: Fixes a code injection flaw where a local attacker could place a crafted Lua bytecode file in system or user configuration directories to bypass security restrictions and execute code with the privileges of the affected program.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-35094.html&quot;&gt;CVE-2026-35094&lt;/a&gt;&lt;/strong&gt;: Addresses a dangling pointer that could leak memory contents to system logs.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://github.com/OpenSC/OpenSC&quot;&gt;opensc&lt;/a&gt; 0.27.1&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2025-49010.html&quot;&gt;CVE-2025-49010&lt;/a&gt;&lt;/strong&gt;: Fixes a stack buffer overflow that could cause memory corruption.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2025-66215.html&quot;&gt;CVE-2025-66215&lt;/a&gt;&lt;/strong&gt;: Fixes a stack buffer overflow that could cause memory corruption. .&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2025-66038.html&quot;&gt;CVE-2025-66038&lt;/a&gt;&lt;/strong&gt;: Addresses an out-of-bounds read that could lead to memory corruption during smart card processing.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2025-66037.html&quot;&gt;CVE-2025-66037&lt;/a&gt;&lt;/strong&gt;: Addresses an out-of-bounds heap read that could lead to denial of service.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2025-13763.html&quot;&gt;CVE-2025-13763&lt;/a&gt;&lt;/strong&gt;: Fixes several uses of potentially uninitialized memory in OpenSC detected by fuzzers.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://tukaani.org/xz/&quot;&gt;XZ Utils&lt;/a&gt; 5.8.3&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-34743.html&quot;&gt;CVE-2026-34743&lt;/a&gt;&lt;/strong&gt;: Fixes a heap buffer overflow in XZ Utils where decoding an empty Index left lzma_index in a state that caused undersized allocation in a subsequent lzma_index_append() call.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://github.com/389ds&quot;&gt;389ds&lt;/a&gt; 3.1.4+e2562f589&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2025-14905.html&quot;&gt;CVE-2025-14905&lt;/a&gt;&lt;/strong&gt;: Fixes a heap buffer overflow caused by incorrect buffer size calculation that could potentially lead to denial of service or remote code execution.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://openexr.com/&quot;&gt;openexr&lt;/a&gt; 3.4.9&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-34589.html&quot;&gt;CVE-2026-34589&lt;/a&gt;&lt;/strong&gt;: Fixes a heap out-of-bounds write that could lead to memory corruption.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-34588.html&quot;&gt;CVE-2026-34588&lt;/a&gt;&lt;/strong&gt;: Addresses a signed 32-bit overflow leading to out-of-bounds read/write.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-34380.html&quot;&gt;CVE-2026-34380&lt;/a&gt;&lt;/strong&gt;: Resolves a signed integer overflow that could allow bounds-check bypass during PXR24 decompression.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-34379.html&quot;&gt;CVE-2026-34379&lt;/a&gt;&lt;/strong&gt;: Fixes a misaligned write leading to undefined behavior.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-34378.html&quot;&gt;CVE-2026-34378&lt;/a&gt;&lt;/strong&gt;: Addresses a signed integer overflow in generic_unpack() when parsing EXR files with crafted negative dataWindow.min.x values.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-34543.html&quot;&gt;CVE-2026-34543&lt;/a&gt;&lt;/strong&gt;: Resolves a heap information disclosure that could cause uninitialized heap memory to leak into output pixel data.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-34544.html&quot;&gt;CVE-2026-34544&lt;/a&gt;&lt;/strong&gt;: Fixes a signed integer overflow that could lead to an out-of-bounds write and memory corruption.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://gitlab.gnome.org/GNOME/evolution-data-server&quot;&gt;evolution-data-server&lt;/a&gt; 3.60.0&lt;/strong&gt;:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-2604.html&quot;&gt;CVE-2026-2604&lt;/a&gt;&lt;/strong&gt;: The advisory for this vulnerability indicates it involves an insecure local cache file removal.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://sssd.io/&quot;&gt;SSSD&lt;/a&gt; 2.13.0&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-6245.html&quot;&gt;CVE-2026-6245&lt;/a&gt;&lt;/strong&gt;: Fixes an out-of-bounds read in the PAM passkey responder.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://wiki.gnome.org/Projects/GLib&quot;&gt;glib2&lt;/a&gt; 2.88.0&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-23868.html&quot;&gt;CVE-2026-23868&lt;/a&gt;&lt;/strong&gt;: Fixes a vulnerability caused by a shallow copy that may lead to memory corruption.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-32776.html&quot;&gt;CVE-2026-32776&lt;/a&gt;&lt;/strong&gt;: Fixes a NULL pointer dereference when processing empty external parameter entity content.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-32777.html&quot;&gt;CVE-2026-32777&lt;/a&gt;&lt;/strong&gt;: Addresses an issue that could result in an infinite loop while parsing DTD content, potentially leading to a denial of service.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-32778.html&quot;&gt;CVE-2026-32778&lt;/a&gt;&lt;/strong&gt;: Resolves a NULL pointer dereference following an earlier out-of-memory condition.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.sudo.ws/&quot;&gt;sudo&lt;/a&gt;&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-35535.html&quot;&gt;CVE-2026-35535&lt;/a&gt;&lt;/strong&gt;: Fixes a privilege escalation in sudo where a failed setuid, setgid, or setgroups call during the privilege drop was not treated as a fatal error.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.cups.org/&quot;&gt;CUPS&lt;/a&gt; 2.4.17&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-27447.html&quot;&gt;CVE-2026-27447&lt;/a&gt;&lt;/strong&gt;: Fixes a case-sensitivity vulnerability in user/group handling that could allow access bypass.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-34978.html&quot;&gt;CVE-2026-34978&lt;/a&gt;&lt;/strong&gt;: Addresses a directory traversal flaw in the RSS notifier.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-34979.html&quot;&gt;CVE-2026-34979&lt;/a&gt;&lt;/strong&gt;: Resolves insufficient memory allocation for job options that could lead to buffer issues.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-34980.html&quot;&gt;CVE-2026-34980&lt;/a&gt;&lt;/strong&gt;: Fixes incomplete control character filtering in option values.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-34990.html&quot;&gt;CVE-2026-34990&lt;/a&gt;&lt;/strong&gt;: Addresses missing certificate validation over loopback connections.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-39314.html&quot;&gt;CVE-2026-39314&lt;/a&gt;&lt;/strong&gt;: Resolves a job password range check flaw.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-39316.html&quot;&gt;CVE-2026-39316&lt;/a&gt;&lt;/strong&gt;: Fixes a scheduler subscription bug that could be abused to disrupt printing.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://firefox-source-docs.mozilla.org/security/nss/index.html&quot;&gt;mozilla-nss&lt;/a&gt; 3.122.1&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;This release rolls up more than 30 fixes across the Network Security Services library, including patches for multiple heap use-after-free, integer overflow, and ASN.1 parsing vulnerabilities affecting TLS handling.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.ruby-lang.org/&quot;&gt;ruby4.0&lt;/a&gt; 4.0.3&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-41316.html&quot;&gt;CVE-2026-41316&lt;/a&gt;&lt;/strong&gt;: Fixes a vulnerability in the &lt;a href=&quot;https://docs.ruby-lang.org/en/master/ERB.html&quot;&gt;ERB&lt;/a&gt; component affecting &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Marshal.load&lt;/code&gt; operations with untrusted data.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://lxml.de/&quot;&gt;python-lxml&lt;/a&gt; 6.1.0&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-41066.html&quot;&gt;CVE-2026-41066&lt;/a&gt;&lt;/strong&gt;: Fixes an external entity injection (XXE) vulnerability in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;iterparse()&lt;/code&gt; that could allow disclosure of local files or server-side request forgery.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://gitlab.freedesktop.org/xorg/lib/libxpm&quot;&gt;libXpm&lt;/a&gt;&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-4367.html&quot;&gt;CVE-2026-4367&lt;/a&gt;&lt;/strong&gt;: Addresses an out-of-bounds read when parsing crafted XPM image files that could lead to information disclosure or a crash.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.thekelnetworks.org/projects/dnsmasq.html&quot;&gt;dnsmasq&lt;/a&gt;&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-6507.html&quot;&gt;CVE-2026-6507&lt;/a&gt;&lt;/strong&gt;: Fixes an out-of-bounds write in DHCP BOOTREPLY processing that could be triggered by a malicious DHCP server response.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;http://www.libpng.org/pub/png/libpng.html&quot;&gt;libpng16&lt;/a&gt; 1.6.57&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-34757.html&quot;&gt;CVE-2026-34757&lt;/a&gt;&lt;/strong&gt;: Fixes a use-after-free in chunk setters that could lead to memory corruption.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://libarchive.org/&quot;&gt;libarchive&lt;/a&gt; 3.8.7&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;Fixes a heap buffer overflow in CAB archive handling and a buffer overflow in the ISO9660 reader. Both flaws could be triggered by crafted archive files and are relevant given libarchive’s broad use across packaging and extraction tools.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://gitlab.gnome.org/GNOME/libxml2&quot;&gt;libxml2&lt;/a&gt; 2.15.3&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;This release rolls up multiple security fixes including a type confusion issue, a double-free, and a use-after-free in the XML parser.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://imagemagick.org/&quot;&gt;ImageMagick&lt;/a&gt; 7.1.2.19&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-33905.html&quot;&gt;CVE-2026-33905&lt;/a&gt;&lt;/strong&gt;: Fixes a flaw that could be triggered by crafted images and lead to a crash or memory corruption.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;http://www.graphicsmagick.org/&quot;&gt;GraphicsMagick&lt;/a&gt;&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-33535.html&quot;&gt;CVE-2026-33535&lt;/a&gt;&lt;/strong&gt;: Addresses an out-of-bounds write in X11 display interaction that could lead to a crash or potential code execution.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-26284.html&quot;&gt;CVE-2026-26284&lt;/a&gt;&lt;/strong&gt;: Fixes a heap overflow that could be triggered while processing crafted images.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://github.com/smuellerDD/leancrypto&quot;&gt;leancrypto&lt;/a&gt; 1.7.2&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;strong&gt;&lt;a href=&quot;https://www.suse.com/security/cve/CVE-2026-34610.html&quot;&gt;CVE-2026-34610&lt;/a&gt;&lt;/strong&gt;: Fixes an X.509 parsing flaw that could lead to certificate validation bypass.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;https://www.openldap.org/&quot;&gt;openldap2&lt;/a&gt; 2.6.13&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;Addresses a heap buffer overflow in &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;parse_whsp&lt;/code&gt; and a potential NULL pointer dereference, both of which could be triggered by malformed input to the LDAP server.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Users are advised to update to the latest versions to mitigate these vulnerabilities.&lt;/p&gt;

&lt;h2 id=&quot;conclusion&quot;&gt;Conclusion&lt;/h2&gt;

&lt;p&gt;April 2026 was a busy month for &lt;a href=&quot;https://get.opensuse.org/tumbleweed/&quot;&gt;openSUSE Tumbleweed&lt;/a&gt; with two of the largest desktop releases of the year landing back to back: &lt;a href=&quot;https://release.gnome.org/50/&quot;&gt;GNOME 50&lt;/a&gt; and &lt;a href=&quot;https://kde.org/announcements/gear/26.04.0/&quot;&gt;KDE Gear 26.04.0&lt;/a&gt;. &lt;a href=&quot;https://www.gtk.org/&quot;&gt;GTK4&lt;/a&gt; 4.22 introduced the new native &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;GtkSvg&lt;/code&gt; renderer and dropped the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;librsvg&lt;/code&gt; dependency for icon rendering, while &lt;a href=&quot;https://www.libreoffice.org/&quot;&gt;LibreOffice&lt;/a&gt; 26.2 brought a fresh major office suite. Developers received major version bumps across &lt;a href=&quot;https://www.php.net/&quot;&gt;PHP&lt;/a&gt; 8.5, &lt;a href=&quot;https://www.sqlite.org/&quot;&gt;SQLite&lt;/a&gt; 3.53, &lt;a href=&quot;https://wiki.linuxfoundation.org/networking/iproute2&quot;&gt;iproute2&lt;/a&gt; 7.0, &lt;a href=&quot;https://www.nano-editor.org/&quot;&gt;nano&lt;/a&gt; 9.0, and the &lt;a href=&quot;https://wireless.wiki.kernel.org/en/users/documentation/iw&quot;&gt;iw&lt;/a&gt; wireless tool. Security continued to be a heavy theme with &lt;a href=&quot;https://webkitgtk.org/&quot;&gt;WebKitGTK&lt;/a&gt;, &lt;a href=&quot;https://www.cups.org/&quot;&gt;CUPS&lt;/a&gt;, &lt;a href=&quot;https://www.python.org/&quot;&gt;Python&lt;/a&gt;, &lt;a href=&quot;https://flatpak.org/&quot;&gt;Flatpak&lt;/a&gt;, &lt;a href=&quot;https://www.sudo.ws/&quot;&gt;sudo&lt;/a&gt;, and &lt;a href=&quot;https://openexr.com/&quot;&gt;OpenEXR&lt;/a&gt; all receiving multiple &lt;a href=&quot;https://en.wikipedia.org/wiki/Common_Vulnerabilities_and_Exposures&quot;&gt;CVE&lt;/a&gt; fixes alongside a steady cadence of cryptographic library hardening from &lt;a href=&quot;https://firefox-source-docs.mozilla.org/security/nss/index.html&quot;&gt;mozilla-nss&lt;/a&gt;, &lt;a href=&quot;https://www.gnupg.org/software/libgcrypt/&quot;&gt;libgcrypt&lt;/a&gt;, and &lt;a href=&quot;https://github.com/smuellerDD/leancrypto&quot;&gt;leancrypto&lt;/a&gt;.&lt;/p&gt;

&lt;h3 id=&quot;slowroll-arrivals&quot;&gt;Slowroll Arrivals&lt;/h3&gt;
&lt;p&gt;Please note that these updates also apply to &lt;a href=&quot;https://en.opensuse.org/openSUSE:Slowroll&quot;&gt;Slowroll&lt;/a&gt; and arrive between an average of 5 to 10 days after being released in Tumbleweed snapshot. This monthly approach has been consistent for many months, ensuring stability and timely enhancements for users. Updated packages for Slowroll are regularly published in emails on &lt;a href=&quot;https://lists.opensuse.org/archives/list/factory@lists.opensuse.org/&quot;&gt;openSUSE Factory mailing list&lt;/a&gt;.&lt;/p&gt;

&lt;h3 id=&quot;contributing-to-opensuse-tumbleweed&quot;&gt;Contributing to openSUSE Tumbleweed&lt;/h3&gt;
&lt;p&gt;Stay updated with the latest snapshots by subscribing to the openSUSE Factory mailing list.
For those Tumbleweed users who want to contribute or want to engage with detailed technological discussions, subscribe to the &lt;a href=&quot;https://lists.opensuse.org/archives/list/factory@lists.opensuse.org/&quot;&gt;openSUSE Factory mailing list &lt;/a&gt;. The openSUSE team encourages users to continue participating through bug reports, feature suggestions and discussions.&lt;/p&gt;

&lt;p&gt;Your contributions and feedback make openSUSE Tumbleweed better with every update. Whether reporting bugs, suggesting features, or participating in community discussions, your involvement is highly valued.&lt;/p&gt;

&lt;meta name=&quot;Linux, rolling release, developers, sysadmins, power users,
KDE, Plasma, KDE Gear, KDE Frameworks,
GNOME, cups, Wayland, Kernel, kernel-source, Slowroll, open source, copyfail&quot; content=&quot;HTML,CSS,XML,JavaScript&quot; /&gt;

</content:encoded>
    </item>

    <item>
      <guid>https://news.opensuse.org/2026/04/29/opensuse-asia-summit-2026-call-for-speakers/</guid>
      <title>openSUSE Asia Summit 2026 Call for Speakers</title>
      <pubDate>Wed, 29 Apr 2026 17:30:00 +0000</pubDate>
      <link>https://news.opensuse.org/2026/04/29/opensuse-asia-summit-2026-call-for-speakers/</link>
      <author>admin@opensuse.org (openSUSE Asia Summit Team)</author>
      <enclosure url="https://news.opensuse.org/wp-content/uploads/2025/12/yogyakarta.png" length="286780" type="image/png" />
      <description>We are excited to announce that the Call for Speakers for openSUSE.Asia Summit 2026 is now open! This year, the Summit will take place on October 3–4, 2026, at the Teaching Industry Learning Center (TILC), Vocational School, Universitas Gadjah Mada (UGM), Yogyakarta, Indonesia. For more details, stay tuned to our...</description>
      <content:encoded>&lt;p&gt;We are excited to announce that the Call for Speakers for &lt;a href=&quot;https://events.opensuse.org/conferences/oSAS26&quot;&gt;openSUSE.Asia Summit 2026&lt;/a&gt; is now open! This year, the Summit will take place on October 3–4, 2026, at the Teaching Industry Learning Center (TILC), Vocational School, Universitas Gadjah Mada (UGM), Yogyakarta, Indonesia. For more details, stay tuned to our official channels and &lt;a href=&quot;https://news.opensuse.org/&quot;&gt;news portal&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;The openSUSE.Asia committee invites speakers from all backgrounds to share their knowledge, experience, and passion for openSUSE and open source. Speakers may also apply for support from the &lt;a href=&quot;https://en.opensuse.org/openSUSE:Travel_Support_Program&quot;&gt;openSUSE Travel Support Program (TSP)&lt;/a&gt;. We encourage everyone, near or far, to submit their proposals and join us in Yogyakarta!&lt;/p&gt;

&lt;h3 id=&quot;topics&quot;&gt;Topics&lt;/h3&gt;

&lt;p&gt;The examples of the topics (not limited to) are as the following:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;openSUSE (e.g., Leap, Tumbleweed, Micro OS, Open Build Services, openQA, YaST)&lt;/li&gt;
  &lt;li&gt;Desktop environments and applications (e.g., GNOME, KDE, XFCE)&lt;/li&gt;
  &lt;li&gt;Office suite, graphic art, multimedia (e.g., LibreOffice, Calligra, GIMP, Inkscape)&lt;/li&gt;
  &lt;li&gt;Multilingualization support (e.g., input methods, translation)&lt;/li&gt;
  &lt;li&gt;Cloud, Virtualization, Container, and Container Orchestration (e.g., Kubernetes, Rancher)&lt;/li&gt;
  &lt;li&gt;Package supply-chain security, vulnerability management&lt;/li&gt;
  &lt;li&gt;Embedded and IoT&lt;/li&gt;
  &lt;li&gt;Other applications running on openSUSE&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Topics that are not related to a specific technology are also welcome. For example:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;An overview of FLOSS technologies&lt;/li&gt;
  &lt;li&gt;Development, Quality Assurance, Translation&lt;/li&gt;
  &lt;li&gt;Tips &amp;amp; Tricks, Experience stories (success or fail), Best practice&lt;/li&gt;
  &lt;li&gt;Marketing and community management&lt;/li&gt;
  &lt;li&gt;Education&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;types-of-sessions&quot;&gt;Types of sessions&lt;/h3&gt;

&lt;p&gt;We are inviting proposals for these two types of sessions.&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;Long talks with presentation (45 min. + Q&amp;amp;A)&lt;/li&gt;
  &lt;li&gt;Short talks with presentation (30 min. + Q&amp;amp;A)&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Lighting talk sessions (5 min.) will be announced later.&lt;/p&gt;

&lt;h3 id=&quot;schedule&quot;&gt;Schedule&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;Proposal submission deadline: 1 July, 2026&lt;/li&gt;
  &lt;li&gt;Notification to speakers: 21 July, 2026&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;how-to-submit-your-proposal-document&quot;&gt;How to submit your proposal document&lt;/h3&gt;

&lt;p&gt;Please submit your proposal at &lt;a href=&quot;https://events.opensuse.org/conferences/oSAS26/&quot;&gt;events.opensuse.org&lt;/a&gt;. If you do not have a SUSE community account, please sign up before submitting your proposal.&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;You must follow &lt;a href=&quot;https://en.opensuse.org/openSUSE:Conference_code_of_conduct&quot;&gt;the openSUSE Conference Code of Conduct&lt;/a&gt;.&lt;/li&gt;
  &lt;li&gt;Your proposal should be written in English, between 130 and 250 words, and have a clear, relevant title.&lt;/li&gt;
  &lt;li&gt;Please check for spelling and grammar before submitting, using tools like LibreOffice, Google Docs, or Grammarly.&lt;/li&gt;
  &lt;li&gt;See &lt;a href=&quot;https://en.opensuse.org/openSUSE:Asia_Summit_How_to_Write_a_Good_Proposal&quot;&gt;our guide&lt;/a&gt; for tips on writing a great proposal.&lt;/li&gt;
  &lt;li&gt;If you need help, contact &lt;a href=&quot;https://en.opensuse.org/openSUSE:Asia_Organization_Committee#The_list_of_committees&quot;&gt;committee members&lt;/a&gt; in your country or region.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 id=&quot;requirements-for-your-presentation&quot;&gt;Requirements for your presentation&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;You may present in English or Bahasa Indonesia, but all documents and slides must be in English.&lt;/li&gt;
  &lt;li&gt;Speakers must be present at the venue; prerecorded videos and remote presentations are not allowed.&lt;/li&gt;
&lt;/ul&gt;
</content:encoded>
    </item>

    <item>
      <guid>https://news.opensuse.org/2026/04/28/quantum-opensuse/</guid>
      <title>Quantum-Resilient Cryptography in the openSUSE Ecosystem</title>
      <pubDate>Tue, 28 Apr 2026 04:00:00 +0000</pubDate>
      <link>https://news.opensuse.org/2026/04/28/quantum-opensuse/</link>
      <author>admin@opensuse.org (Alessandro de Oliveira Faria)</author>
      <enclosure url="https://news.opensuse.org/wp-content/uploads/2026/04/logo-libzupt.jpg" length="23395" type="image/jpeg" />
      <description>It is with great joy that I officially announce the release in the openSUSE family (Leap and Tumbleweed) of the new package focused on cryptography resistant to the post-quantum era. The libzupt library is designed to offer encryption and decryption of files and binary data in memory using a hybrid...</description>
      <content:encoded>&lt;p&gt;It is with great joy that I officially announce the release in the openSUSE family (Leap and Tumbleweed) of the new package focused on cryptography resistant to the post-quantum era.&lt;/p&gt;

&lt;p&gt;The &lt;a href=&quot;https://software.opensuse.org/package/libzupt&quot;&gt;libzupt&lt;/a&gt; library is designed to offer encryption and decryption of files and binary data in memory using a hybrid approach based on &lt;strong&gt;ML-KEM-768 + X25519.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;libzupt&lt;/strong&gt; is a modern SDK that simplifies the adoption of post-quantum cryptography in real-world applications. Currently, it has initial support for C++, Python, and Java, with support for Node.js (under development). Its goal is to make the implementation of advanced cryptographic mechanisms accessible without compromising usability for developers.&lt;/p&gt;

&lt;p&gt;libzupt, created by Alessandro de Oliveira Faria, is a modern SDK that simplifies the adoption of post-quantum cryptography in real-world applications. Currently, it has initial support for C++, Python, and Java, with Node.js support (under development). Its goal is to make the implementation of advanced cryptographic mechanisms accessible without compromising usability for developers.&lt;/p&gt;

&lt;p&gt;The project originates from the &lt;strong&gt;Zupt&lt;/strong&gt; initiative, conceived by Cristian Cezar Moisés. As a tribute, the library inherited the name of the original project. Zupt, in turn, is a compression and backup tool that already incorporated advanced concepts such as authenticated AES-256 encryption and post-quantum key encapsulation.&lt;/p&gt;

&lt;p&gt;The motivation behind libzupt is directly linked to the evolution of modern cryptography. The ML-KEM algorithm was standardized by &lt;a href=&quot;https://csrc.nist.gov/pubs/fips/203/final&quot;&gt;NIST on August 13, 2024&lt;/a&gt;, as a secure key encapsulation mechanism for post-quantum scenarios. It allows for the secure establishment of keys even in insecure channels, anticipating future threats.&lt;/p&gt;

&lt;p&gt;Below is a simple example of using libzupt in Python:&lt;/p&gt;

&lt;div class=&quot;language-plaintext highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;import zupt
encryptor = zupt.Encryptor(keypair.public_key)
message = b&quot;Hello, Post-Quantum World! This is a secret message.&quot;
ciphertext, enc_header = encryptor.encrypt(message)

&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;The main benefit of natively providing this library in openSUSE, is that it allows current applications to be prepared for a scenario where quantum computing could compromise classical algorithms, such as Shor’s Algorithm.&lt;/p&gt;

&lt;p&gt;By combining traditional cryptography with mechanisms resistant to quantum computing, libzupt adds a strategic layer of protection. This enables the development of more resilient systems, ensuring the confidentiality and integrity of data in the long term, even in the face of technological evolution.&lt;/p&gt;

&lt;p&gt;For more information, go to &lt;a href=&quot;https://software.opensuse.org/package/libzupt&quot;&gt;software opensuse&lt;/a&gt; or the &lt;a href=&quot;https://github.com/cabelo/libzupt&quot;&gt;source&lt;/a&gt;.&lt;/p&gt;

</content:encoded>
    </item>

  </channel>
</rss>

