Packages changed: MicroOS-release (20260826 -> 20260827) cpio nghttp3 ngtcp2 openssl-3 polkit-default-privs (1550+20260803.90784eb -> 1550+20260825.76d85e6) qemu (11.0.3 -> 11.1.0) sdbootutil (1+git20260813.357956d -> 1+git20260825.c7a5a97) selinux-policy (20260820 -> 20260826) serd (0.32.8 -> 0.32.10) wpa_supplicant (2.11 -> 2.12) === Details === ==== MicroOS-release ==== Version update (20260826 -> 20260827) Subpackages: MicroOS-release-appliance MicroOS-release-dvd - automatically generated by openSUSE-release-tools/pkglistgen ==== cpio ==== - Fix CVE-2026-66484: path traversal allows creating hard links outside intended directory via malicious tar archives (bsc#1274856) * CVE-2026-66484.patch - Fix CVE-2026-66485: denial of service via uncontrolled memory allocation from crafted archives (bsc#1274857) * CVE-2026-66485.patch - Fix CVE-2026-66486: terminal control sequence injection via crafted archive member names (bsc#1274858) * CVE-2026-66486.patch - Refresh patches to apply with -p1: * cpio-close_files_after_copy.patch * cpio-default_tape_dev.patch * cpio-dev_number.patch * cpio-eof_tape_handling.patch * cpio-open_nonblock.patch * cpio-use_new_ascii_format.patch * cpio-use_sbin_rmt.patch - Reorder patches, apply with %autosetup -p1 - Add makeinfo build requirement ==== nghttp3 ==== - Add curl-impersonate.patch backporting backward compatible changes used by curl-impersonate project ==== ngtcp2 ==== Subpackages: libngtcp2-16 libngtcp2_crypto_gnutls8 libngtcp2_crypto_ossl0 - Require boringssl-devel >= 0.20260813 at build time: the previous 0.20210430 snapshot lacks SSL_set_quic_early_data_context, so configure rejected it with a misleading "boringssl was requested but not found" failure instead of an unresolvable dependency - Add ngtcp2-boringssl-shared.patch bulding the boringssl bridge as shared library - Enable building the boringssl bridge in Factory - Add curl-impersonate.patch backporting backward compatible changes used by curl-impersonate project ==== openssl-3 ==== Subpackages: libopenssl3 - Security fix: * CVE-2026-75803: openssl: AEAD Forgeries with Empty Ciphertext When Using EVP_Cipher() (bsc#1275837) * Add openssl-CVE-2026-75803.patch - Security fixes in August 2026 release: (bsc#1274774) * CVE-2026-14456: Unbounded Memory Growth in QUIC Server Incoming Channel Queue (bsc#1274791) * CVE-2026-14457: RPK Server Signature Algorithm Selection Can Dereference a Missing Certificate (bsc#1274792) * CVE-2026-18798: QUIC Server May Trigger Double Free When Processing INITIAL Packet (bsc#1274777) * CVE-2026-34181: PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC Keys (bsc#1266343) * CVE-2026-54874: Excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795) * CVE-2026-63072: Heap Buffer Overflow in CMS Key Unwrapping (bsc#1274788) * CVE-2026-63073: Untrusted Sender DN Used as Format String in CMP Response Validation (bsc#1274796) * CVE-2026-63074: CMP Indefinite Cache Growth of ExtraCerts (bsc#1274797) * CVE-2026-63075: QUIC ACK-only Packet Retention Can Cause Memory Exhaustion (bsc#1274798) * CVE-2026-63076: Invalid Pointer Dereference in CMP Server via Crafted protectionAlg (bsc#1274790) * Add patches: openssl-CVE-2026-14456.patch openssl-CVE-2026-14457.patch openssl-CVE-2026-18798.patch openssl-CVE-2026-34181.patch openssl-CVE-2026-54874.patch openssl-CVE-2026-63072.patch openssl-CVE-2026-63073.patch openssl-CVE-2026-63074.patch openssl-CVE-2026-63075.patch openssl-CVE-2026-63076.patch ==== polkit-default-privs ==== Version update (1550+20260803.90784eb -> 1550+20260825.76d85e6) - Update to version 1550+20260825.76d85e6: * profiles: add lact profile-hook action (bsc#1274863) ==== qemu ==== Version update (11.0.3 -> 11.1.0) - Revisit the fix for bsc#1232712: * hw/display/xenfb: always register vfb and allocate console early (bsc#1232712) - Switch to ipxe-qemu: * [openSUSE][RPM] spec: stop building edk2-basetools and ipxe - Upgrade to version 11.1.0 The full list of changes are available at: https://wiki.qemu.org/ChangeLog/11.1 Highlights include: * Universal Flash Storage (UFS) emulation support for Write Booster (device-level caching) and Host-Initiated Defragmentation (HID) based on UFS 4.1 specification * vhost-host-user support for offloading real-time clock handling from the hypervisor when using virtio-rtc * GUI: improvements to virtual console handling/specifying of different character encoding and GTK/VNC improvements as well * ARM: support for new architectural CPU features (too many to list here, see full changelog) * ARM: support for new imx8mp-evk machine type (based on i.MX 8MM Evaluation kit) * ARM: 'virt' board support for specifying cache topology, 'hvf' accelerator now supports nested virtualization and vGIC * HPPA: updated to SeaBIOS-hppa v25 firmware, TLB insert fixes for HP-UX 9 * PowerPC: MPIPL support for PowerNV to preserve memory after an unexpected reset, as well as support for emulating a nest MMU * RISC-V: ISA exstention support for big-endian, Zbr/xbr0p93, Zvfbfa, fractional LMUL on vector SHA instructions, KVM support for Zicbop and BFloat16 extensions, and more * RISC-V: new board support for K230, support for Tenstorrent mvendorid, and other misc. fixes/features * s390x: KVM support for ASTFLE facility 2 (for nested) * and lots more... ==== sdbootutil ==== Version update (1+git20260813.357956d -> 1+git20260825.c7a5a97) Subpackages: sdbootutil-dracut-measure-pcr sdbootutil-snapper sdbootutil-tukit - Update to version 1+git20260825.c7a5a97: * Refactor free space calculation * Do not use /proc/cmdline in half configured systems * Warning when the recovery PIN is not validated * Show default and booted snapshots with marks * Improve detection of snapshot systems * Fix when searching for a boot entry * Fix boot order and boot order entry * Create the entries directory in the ESP * Fix get_final_pcr parser * Keep btrfs error and show it when fails * Fix set -e early exit instances * Fix measure-pcr-validator when there is no terminal * Don't include measure-pcr-validator in initrd if TPM2 is not used * Update predictions even if crypttab did not change * Improve PCR 15 signing * Detect NAME=VALUE passed as parameters and complain * When asking a password, require a terminal * Filter some warnings from pcrlock * Detect directories that are not part of the snapshot * Write bash completion errors to /dev/null * Detect when t-u apply is done and avoid data corruption * Detect pcr-oracle leftovers * Show in title that it's the initial version for transactional systems * Manually generate PCR7 measurements * Regenerate pcrlock.json when it is missing ==== selinux-policy ==== Version update (20260820 -> 20260826) Subpackages: selinux-policy-targeted - Update to version 20260826: * Fix NFS mount with xprtsec=tls / xprtsec=mtls (bsc#1275783) * named filetrans for netconfig (bsc#1275219) * Revert "Apply fix_unconfined.patch" (bsc#1275219) * sshd_session_t needs to access kanidm sshkeys (bsc#1275492) * Fix broken kanidm_sshkeys_t security context (bsc#1275492) * Initial policy for xrdp (bsc#1262291) ==== serd ==== Version update (0.32.8 -> 0.32.10) - update to 0.32.10 * Address new warnings in clang-tidy 22 * Fix writing quotes at the end of long literals ==== wpa_supplicant ==== Version update (2.11 -> 2.12) - Update to v2.12: * support RSN overriding (e.g., WPA3-Personal Compatibility Mode) * EHT/IEEE 802.11be/Wi-Fi 7 - more complete support - fix message validation issues that could enable DoS attacks - fix group key rekeying * enable SAE group 20 by default if SAE-EXT-KEY is enabled * reject unexpected SAE password identifier to avoid DoS attack against a specific STA * mandate use of SAE H2E when using password identifiers * assign VLAN when using SAE with PMKSA caching * support SPP A-MSDU negotiation * support IEEE 802.11bi functionality - changing SAE password identifiers - EPPKE - IEEE 802.1X/EAP in Authentication frames - Association frame encryption - PMKID privacy * remove the driver interface for now obsolete Host AP driver * remove the driver interface for now obsolete Atheros WEXT interface * move supported, basic, and Beacon TX rate configuration to be at BSS level instead of per-radio for all BSSs * fix various issues in Multiple-BSSID functionality * support OpenSSL 3.0 API changes * EAP-TEAP: protocol changes based on RFC 9930; this is not compatible with previous versions * support Automated Frequency Coordination (AFC) on the 6 GHz band * improve GAS/ANQP processing to support larger ANQP responses * a large number of other fixes, cleanup, and extensions * Remove included patches: - 0001-wpa_gui-Port-to-Qt6.patch - CVE-2025-24912.patch - CVE-2026-58374.patch - Require-network_ctx-and-AKMP-match-for-accepting-PMK.patch - SAE-Fix-crash-due-to-NULL-pointer-dereference-in-H2E.patch - mesh-Reject-AMPE-MIC-element-with-length-AES_BLOCK_S.patch - wpa_supplicant_support_pem_encoded_chain.patch * Refresh patches: - Revert-Mark-authorization-completed-on-driver-indica.patch - wpa_supplicant-alloc_size.patch - wpa_supplicant-flush-debug-output.patch - wpa_supplicant-sigusr1-changes-debuglevel.patch - Update build config * CONFIG_HE_OVERRIDES=y (Support HE overrides) * CONFIG_IPV6=y * CONFIG_SAE_PK=y (SAE Public Key, WPA3-Personal) * CONFIG_IEEE80211BE=y (enable native support for Wi-Fi 7) * CONFIG_PMKSA_PRIVACY=y (PMKSA caching privacy support) * CONFIG_IEEE8021X_AUTH=y (IEEE P802.11bi/D4.0, 12.16.5 ) * CONFIG_TLS_ENGINE_TRUSTED_PATH=y - Add RADIUS-Fix-Message-Authenticator-attribute-validatio.patch https://w1.fi/security/2026-5