Packages changed: MicroOS-release (20260918 -> 20260919) at-spi2-core (2.60.6 -> 2.60.7) grub2 libsoup nvme-cli (3.0+6.g1ac60ca4b -> 3.1) pam pam-full-src permissions (1699_20260806 -> 1699_20260917) pulseaudio-qt6 (1.8.1 -> 1.9.0) sssd === Details === ==== MicroOS-release ==== Version update (20260918 -> 20260919) Subpackages: MicroOS-release-appliance MicroOS-release-dvd - automatically generated by openSUSE-release-tools/pkglistgen ==== at-spi2-core ==== Version update (2.60.6 -> 2.60.7) Subpackages: libatk-1_0-0 libatk-bridge-2_0-0 libatspi0 typelib-1_0-Atk-1_0 typelib-1_0-Atspi-2_0 - Update to version 2.60.7: + libatspi: Fix transfer annotation on atspi_document_get_text_selections. + atk-bridge: Release disconnected direct connections. ==== grub2 ==== Subpackages: grub2-common grub2-i386-efi grub2-i386-efi-bls grub2-i386-pc grub2-snapper-plugin grub2-x86_64-efi grub2-x86_64-efi-bls - Add SBAT Provides to support shim SBAT dependency checks (bsc#1278729) ==== libsoup ==== - Add libsoup-CVE-2026-85534.patch: Never send more body bytes than nghttp2 requested (bsc#1279239, CVE-2026-85534) - Add libsoup-CVE-2026-85197.patch: fix crash in on_data_read after connection has been destroyed (bsc#1279238, CVE-2026-85197) ==== nvme-cli ==== Version update (3.0+6.g1ac60ca4b -> 3.1) Subpackages: libnvme3-1 - Update to version 3.1: * Release v3.1 * doc: Regenerate all docs for v3.1 * tests: NUL-terminate literals copied into dc_entry_is_self() test data * plugin: fix out-of-bounds read of argv[1] in help() with no sub-argument * libnvme: fix NBFT entry list leak in libnvmf_discover_nbft() * huawei: guard against a null list_items in huawei_json_print_list_items() * solidigm: also guard against a null ilog in ilog_dump_identify_page() * plugins/sandisk: fix uninitialized market_name_len in enc_drive_capabilities * plugins/exclusion: fix errno reliance in read_file() * plugins/sandisk: update version * plugins/sandisk: use nvme_get_pci_ids * plugins/sandisk: port vs-smart-add-log from wdc * libnvme: reject a persona hostnqn with no hostid * shared: drop the retry loop from shr_read_file()/shr_read_file_as_string() * shared: return error codes from shr_read_file() and shr_read_file_as_string() * tests: bound the interface name copy in mock-ifaddrs init_entry() * wdc: use shr_getrandom() for the send/receive correlation handle * rpmb: use shr_getrandom() for the authentication nonce * keys: check chmod() return value in append_keyfile() * shared: add shr_getrandom() * solidigm: fix NULL DMA target in ilog_dump_pel() * tests: fix unit mismatch in test_admin_fw_download_cb's data check * innogrit: remove dead fclose() guards before the first fopen() in getcdump * solidigm: fix unreachable error-recovery path in parse_tracker_chunk_json() * nvme: fix nvme_decide_retry() always returning false * nbft: fix truncated PCI segment number in pci_sbdf_to_string() * ocp: check ocp_get_uuid_index() before issuing the get-log command * tests,tree-fabrics: check and acknowledge return values * mi-mctp: fix endian conversion direction for MPR retry time * fs-util: restore path separator unconditionally in shr_mkdir_p() * tests: check write() return value in test_read_all() * wdc: bound the device-reported Capture Diagnostics log length * solidigm: replace read_file2buffer() with shared file-reading helpers * sandisk: fix 32-bit overflow and unchecked realloc in sndk_do_cap_udui * mi-mctp-ae: bound the AE number before indexing the enabled-events map * shared: use memmove() for the sha256 intra-buffer carry-over copy * fabrics: fix NULL dereference in dc_log_decision() * netapp: fix NULL format string in netapp_smdevices_print_regular() * tests: fix NULL dereference in mi-mctp aem_handler() * ocp: fix NULL dereference and zero-fill bug in parse_event_fifo() * nvme-print: bound-check FDP config descriptor walk against log size * nvme-print: fix endian bugs and bound the EOM descriptor walk * nvme-print: fix integer overflow in EOM descriptor offset * shared: add shr_buf_has_room() * tests: fix dangling pointer in test_nvmf_sanitize_addrs() * tests: use shr_read_file_as_string() in shr_table tests * tests: fix uninitialized buffer and NULL %s in check_normalize() * shared: add shr_read_file_as_string() * scaleflux: fix scandir(3) result leak in nvme_expand_cap * wdc: fix out-of-bounds read of pre-v4 cloud smart log hardware revision * nvme-print,fabrics: fix uninitialized reads * utils: fix allocation leak in copy_options() * shannon: fix file descriptor leak in set_additional_feature() * rpmb: validate config block size before write * discoverd: honor persistent=force against EPCSD=0 * resv-plugin: size the resv report from the registrant count * ccan: cast pointers to void * in fprintf for %p format specifier * libnvme: pick the right self entry on a multi-homed DC * discoverd: use __cleanup_tid in two loops * sandisk: fix stack buffer overflow in C2 marketing-name parser * discoverd: validate DLPE target before host-side inheritance * nvme-models: fix pci.ids parser line loss * tests: check errno after rewind in capture helpers * huawei: null-check root/devices in huawei_json_print_list_items * solidigm: guard ilog->cfg dereference in ilog_dump_identify_page * libnvme: initialize TLS key IDs * exclusion: preserve errno across free/fclose in read_file * nvme-print-json: fix leaks in json_phy_rx_eom_descs * wdc: close output file via __cleanup_file in wdc_enc_get_log * lm: fix double fclose in lm_migration_send * completions: document no-trailing-space insertion checks in TESTING.md * completions: test the generator against a synthetic fixture * nvme-print-json: use CAP property fields string table * nvme-print: add CAP property fields string table * nvme-print-json: combine obj_add_str and obj_add_string duplicated * nvme-print: change string variables as constant * nvme-print-json: fix to output alloc_error * nvme-print-stdout: use libnvme API to print CAP property * nvme-types-base: fix CAP property NSSRS bit name * nvme-types-base: add CAP property NSSES bit * nvme-types-base: change file header description NVMe revision to 2.4 * micron: clamp num_entries in vs-fw-activate-history to the table size * seagate: clamp supported-log-pages count and keep JSON clean * libnvme: add test for var_size_tags 32B guard sts range * tests: cover invalid_tags() STS-too-wide rejection * libnvme: fix undefined shifts in nvme_init_var_size_tags() 32B guard case * nvme: reject out-of-range storage tag size in invalid_tags() * shared: drop dead `at_line_start = true` in shr_print_word_wrapped() * solidigm: drop dead initializer in telemetry_log_data_area_get_offset() * solidigm: report failure restoring workload-tracker config * huawei: check libnvme_get_nsid() failure in huawei_get_nvme_info() * micron: drop dead `err = 0` in micron_telemetry_log() * ocp: fix empty-description case in parse_ocp_telemetry_string_log() * ocp: drop dead m_512_sz/m_512_off initial stores in get_telemetry_dump() * sandisk: drop dead stores flagged by clang-analyze * sandisk: fix telemetry write error handling, drop a dead store * wdc: fix telemetry write error handling, drop dead stores * huawei: skip a list entry if its JSON object fails to allocate ... changelog too long, skipping 47 lines ... * feat: add remaining feature commands ==== pam ==== - Apply livepatching only for SLES, not for Factory. Keeping lto optimisation for openSUSE. * On Factory `%meson` will use `%set_build_flags`, that will set CFLAGS. - Make sure we don't lose distribution compiler flags. ==== pam-full-src ==== - Apply livepatching only for SLES, not for Factory. Keeping lto optimisation for openSUSE. * On Factory `%meson` will use `%set_build_flags`, that will set CFLAGS. - Make sure we don't lose distribution compiler flags. ==== permissions ==== Version update (1699_20260806 -> 1699_20260917) Subpackages: permctl permissions-config - Update to version 1699_20260917: * profiles: added CAP_PERFMON for ksystemstats_xe_helper (bsc#1280113) * profiles: document nvidia-modprobe's special case ==== pulseaudio-qt6 ==== Version update (1.8.1 -> 1.9.0) - Update to 1.9.0: * context: reset before reconnectDaemon * context: remove stray return in void function * server: do not return incorrect default devices * server: cleanup findByName a bit * Extract and install Qt metatypes ==== sssd ==== Subpackages: libsss_certmap0 libsss_idmap0 sssd-krb5-common sssd-ldap - Fix IDP provider cross-user impersonation; (bsc#1279915); (CVE-2026-87853); Add patch 0018-IDP-fix-user-matching-in-eval_access_token_buf.patch