Packages changed: GraphicsMagick NetworkManager-applet cups-filters emacs gettext-runtime gobject-introspection libvirt (12.7.0 -> 12.8.0) python313-setuptools (80.9.0 -> 84.0.0) soxr === Details === ==== GraphicsMagick ==== Subpackages: libGraphicsMagick++-Q16-12 libGraphicsMagick-Q16-3 libGraphicsMagick3-config - added patches CVE-2026-103118: uncontrolled recursion in the WPG file handler when processing crafted WPG files which are self-referencing [bsc#1283767] * GraphicsMagick-CVE-2026-103118.patch ==== NetworkManager-applet ==== Subpackages: NetworkManager-connection-editor NetworkManager-connection-editor-lang - Update version dependencies according to meson.build. ==== cups-filters ==== Subpackages: cups-filters-cups-browsed - No longer provide the serial backend with 0700 permissions so cupsd does no longer run it as root but as usual as user 'lp' to avoid CVE-2026-95511 "Root arbitrary file overwrite via serial ... device-URI path" https://github.com/OpenPrinting/cups-filters/security/advisories/GHSA-m74w-wg6q-vvpj "`lpadmin` user can escalate privileges to `root` via printers that uses a privileged serial backend" (bsc#1282291) Note the general security advice in the section "Allow printer admin tasks for a normal user" in https://en.opensuse.org/SDB:CUPS_in_a_Nutshell - No longer provide any other backend with 0700 permissions so cupsd does no longer run them as root but as usual as user 'lp' because running something as root by default is a generic security issue which we avoid now by default so the user must set less secure permissions manually only as specifically needed. In particular longer provide /usr/lib/cups/backend/beh /usr/lib/cups/backend/cups-brf /usr/lib/cups/backend/implicitclass with 0700 permissions by default so in particular https://bugzilla.opensuse.org/show_bug.cgi?id=1178604 re-appears but security by default is mandatory nowadays, cf. the sections "Security: Make Things Not Just Work" and "Automated print queue setup via cups-browsed" in https://en.opensuse.org/SDB:CUPS_and_SANE_Firewall_settings ==== emacs ==== Subpackages: emacs-el emacs-eln emacs-info emacs-nox etags - Disable test41 of tramp as this fails - Fix lexical bindings in site-lisp path again (boo#1277717) ==== gettext-runtime ==== Subpackages: envsubst libtextstyle0 - Add lexical-binding statement to suse-start-po-mode.el to fix emacs 31 warning on startup ==== gobject-introspection ==== Subpackages: girepository-1_0 libgirepository-1_0-1 - Add upstream setuptools84.patch to fix build with setuptools v84 ==== libvirt ==== Version update (12.7.0 -> 12.8.0) Subpackages: libvirt-client libvirt-daemon-common libvirt-daemon-config-network libvirt-daemon-driver-network libvirt-daemon-driver-nodedev libvirt-daemon-driver-qemu libvirt-daemon-driver-secret libvirt-daemon-driver-storage libvirt-daemon-driver-storage-core libvirt-daemon-driver-storage-disk libvirt-daemon-driver-storage-iscsi libvirt-daemon-driver-storage-iscsi-direct libvirt-daemon-driver-storage-logical libvirt-daemon-driver-storage-mpath libvirt-daemon-driver-storage-rbd libvirt-daemon-driver-storage-scsi libvirt-daemon-lock libvirt-daemon-log libvirt-daemon-plugin-lockd libvirt-daemon-qemu libvirt-libs - Update to libvirt 12.8.0 - bsc#1201510 - Many incremental improvements and bug fixes, see https://libvirt.org/news.html#v12-8-0-2026-10-01 ==== python313-setuptools ==== Version update (80.9.0 -> 84.0.0) - Update to 84.0.0: [#]# Features * Newline-separated keywords and platforms, which are invalid and corrupt the generated metadata, are now handled forgivingly: each line is treated as a separate item and a deprecation warning is emitted. * Extension is now a dataclass, exposing type annotations for its constructor arguments so subclasses can inherit them without redeclaring each parameter. * The C compiler modules now emit log messages through their own compilers.C.* loggers instead of the distutils root logger, part of decoupling the compilers package from distutils. * The C compilers gained a Compiler.call method – a thin wrapper over subprocess.check_call that is the modern replacement for Compiler.spawn. * The compilers no longer depend on distutils.util, distutils.version, distutils.compat, or distutils._macos_compat. * The compilers now read their build configuration from the standard library's sysconfig instead of distutils.sysconfig. * Require Python 3.10 or later. * Remove post-release tags on setuptools’ own build. [#]# Bugfixes * copy_file now preserves the full precision of the source's modification time, so a copy is no longer considered older than its source on filesystems with sub-second timestamp resolution. * Setuptools wheels no longer bundled the project’s own test modules. * MANIFEST.in matching (via FileList) is now insensitive to Unicode normalization form. * Fix the loading of launcher manifest.xml file. * Replaced deprecated json.__version__ with fixture in tests. [#]# Deprecations and Removals * Compiler.spawn is deprecated in favor of the new Compiler.call. call raises native subprocess exceptions; spawn remains as a shim that emits a DeprecationWarning and translates them to DistutilsExecError. * The compilers now define their own exception vocabulary instead of borrowing distutils' framework errors. * customize_compiler now asserts that the compiler-related config variables (CC, CXX, CFLAGS, etc.) resolve to strings, raising AssertionError if any are unexpectedly None rather than failing later with a less clear error. * pkg_resources has been removed from Setuptools. Most common uses of pkg_resources have been superseded by the importlib.resources and importlib.metadata projects. * Removed support for the –dry-run parameter to setup.py. ==== soxr ==== - Add -lm for %{arm} to fix build - Re-enable LTO for %{arm} since boo#1155011 is fixed