SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-298 Recommended update for libostree moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for libostree fixes the following issues: - Version update 2024.10: + enable composefs by default, various composefs fixes. + core: Always sort incoming xattrs. + sign-ed25519: Fix error message of validate_length. + profiles-fuse: when fuse execution fails it still returns exit code 0. + documentation updates. + deploy: Don't recompute verity checksums if not enabled (performance improvement). + various prepare-root fixes. - Drop rcFOO symlinks. + Adapt to a change in libcurl that caused ostree to start crashing. + switchroot: Stop making /sysroot mount private. + bugfix for "transient-etc" users, root.transient switch to tmpfs. + sysroot: check if deployments are in the same stateroot, turn on bootloader-naming-2 by default. + sepolicy: Fix publicity mismatch for ostree_sepolicy_host_enabled. + main: Ignore SIGPIPE when printing version. + bootloader/grub2: Don't do anything if we have static configs. + kargs: parse spaces in kargs input and keep quotes. + Ensure boot directory is open before accessing it for early pruning. + checkout: Always replace existing content with overlay mode. + Expand ostree admin pin command. + Finalize "deployment finalization locking" feature. + Add ostree admin post-copy. + Speed-up through reflinks. + Improvements to system root and bootloader. + Bug fixes, documentation updates, and developer fixes. libostree-2024.10-150500.3.9.4.src.rpm libostree-2024.10-150500.3.9.4.x86_64.rpm libostree-devel-2024.10-150500.3.9.4.x86_64.rpm typelib-1_0-OSTree-1_0-2024.10-150500.3.9.4.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-1638 Security update for openssh moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for openssh fixes the following issue: Security fixes: - CVE-2025-32728: Fixed logic error in DisableForwarding option (bsc#1241012) Other fixes: - Fix ssh client segfault with GSSAPIKeyExchange=yes in ssh_kex2 due to gssapi proposal not being correctly initialized (bsc#1236826). The problem was introduced in the rebase of the patch for 9.6p1 - Enable --with-logind to call the SetTTY dbus method in systemd. This allows "wall" to print messages in ssh ttys (bsc#1239671) openssh-askpass-gnome-9.6p1-150600.6.26.1.src.rpm openssh-askpass-gnome-9.6p1-150600.6.26.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-1696 Recommended update for brasero moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for brasero fixes the following issue: - Prefer "application/vnd.efi.iso" to "application/x-cd-image" mime type for ISO images (bsc#1240410). brasero-3.12.3-150600.10.3.2.src.rpm brasero-3.12.3-150600.10.3.2.x86_64.rpm brasero-devel-3.12.3-150600.10.3.2.x86_64.rpm brasero-lang-3.12.3-150600.10.3.2.noarch.rpm libbrasero-burn3-1-3.12.3-150600.10.3.2.x86_64.rpm libbrasero-media3-1-3.12.3-150600.10.3.2.x86_64.rpm libbrasero-utils3-1-3.12.3-150600.10.3.2.x86_64.rpm typelib-1_0-BraseroBurn-3_2_0-3.12.3-150600.10.3.2.x86_64.rpm typelib-1_0-BraseroMedia-3_2_0-3.12.3-150600.10.3.2.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-1572 Security update for libraw moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for libraw fixes the following issues: - CVE-2025-43961: Fixed out-of-bounds read in the Fujifilm 0xf00c tag parser in metadata/tiff.cpp (bsc#1241643) - CVE-2025-43962: Fixed out-of-bounds read when tag 0x412 processing in phase_one_correct function (bsc#1241585) - CVE-2025-43963: Fixed out-of-buffer access during phase_one_correct in decoders/load_mfbacks.cpp (bsc#1241642) - CVE-2025-43964: Fixed tag 0x412 processing in phase_one_correct does not enforce minimum w0 and w1 values (bsc#1241584) libraw-0.21.1-150600.3.5.1.src.rpm libraw23-0.21.1-150600.3.5.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-1464 Security update for ImageMagick moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for ImageMagick fixes the following issues: - CVE-2025-43965: Fixed mishandling of image depth after SetQuantumFormat is used in MIFF image processing. (bsc#1241659) - CVE-2025-46393: Fixed mishandling of packet_size leads to rendering of channels in arbitrary order in multispectral MIFF image processing. (bsc#1241658) ImageMagick-7.1.0.9-150400.6.30.1.src.rpm ImageMagick-config-7-upstream-7.1.0.9-150400.6.30.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-1559 Security update for audiofile moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for audiofile fixes the following issues: - CVE-2019-13147: Fixed NULL pointer dereference in ulaw2linear_buf that could lead to DOS (bsc#1140031). - CVE-2022-24599: unverified user input when processing audio files can lead to information leak (bsc#1196487). audiofile-0.3.6-150000.3.12.1.src.rpm audiofile-devel-0.3.6-150000.3.12.1.x86_64.rpm libaudiofile1-0.3.6-150000.3.12.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-1582 Security update for brltty moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for brltty fixes the following issues: - Avoid having brlapi.key temporarily world-readable during creation (bsc#1235438). brltty-6.6-150600.3.3.1.src.rpm brltty-6.6-150600.3.3.1.x86_64.rpm brltty-driver-at-spi2-6.6-150600.3.3.1.x86_64.rpm brltty-driver-brlapi-6.6-150600.3.3.1.x86_64.rpm brltty-driver-speech-dispatcher-6.6-150600.3.3.1.x86_64.rpm brltty-lang-6.6-150600.3.3.1.noarch.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-1781 Recommended update for pipewire moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for pipewire fixes the following issue: - Add patch from upstream to make pipewire not run as root at all (bsc#1222762). gstreamer-plugin-pipewire-1.0.5+git36.60deeb2-150600.3.6.2.x86_64.rpm pipewire-1.0.5+git36.60deeb2-150600.3.6.2.src.rpm pipewire-1.0.5+git36.60deeb2-150600.3.6.2.x86_64.rpm pipewire-lang-1.0.5+git36.60deeb2-150600.3.6.2.noarch.rpm pipewire-spa-tools-1.0.5+git36.60deeb2-150600.3.6.2.x86_64.rpm pipewire-tools-1.0.5+git36.60deeb2-150600.3.6.2.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-1565 Security update for open-vm-tools moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for open-vm-tools fixes the following issues: Update to 12.5.2: Security fixes: - CVE-2025-22247: Fixed Insecure file handling (bsc#1243106) Other fixes: - Fixed GCC 15 compile time error (bsc#1241938) - Fix building with containerd 1.7.25+ (bsc#1237147) Full changelog: https://github.com/vmware/open-vm-tools/blob/stable-12.5.2/ReleaseNotes.md https://github.com/vmware/open-vm-tools/blob/stable-12.5.2/open-vm-tools/ChangeLog open-vm-tools-12.5.2-150600.3.12.1.src.rpm open-vm-tools-desktop-12.5.2-150600.3.12.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-2215 Recommended update for firewalld moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for firewalld fixes the following issue: Align with up to update python stack tools. This update also ships python311-firewall and python311-dbus-python to the Python3 Module. firewall-applet-2.0.1-150600.3.9.1.noarch.rpm firewall-config-2.0.1-150600.3.9.1.noarch.rpm firewalld-2.0.1-150600.3.9.1.src.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-2170 Security update for yelp moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for yelp fixes the following issues: - CVE-2025-3155: JavaScript code execution and arbitrary file read through specially crafted help files and ghelp scheme URLs (bsc#1240688). libyelp0-42.2-150600.3.3.1.x86_64.rpm yelp-42.2-150600.3.3.1.src.rpm yelp-42.2-150600.3.3.1.x86_64.rpm yelp-devel-42.2-150600.3.3.1.x86_64.rpm yelp-lang-42.2-150600.3.3.1.noarch.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-2168 Security update for yelp-xsl moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for yelp-xsl fixes the following issues: - CVE-2025-3155: JavaScript code execution and arbitrary file read through specially crafted help files and ghelp scheme URLs (bsc#1240688). yelp-xsl-41.1-150400.3.3.1.noarch.rpm yelp-xsl-41.1-150400.3.3.1.src.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-1737 Security update for gstreamer-plugins-bad important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for gstreamer-plugins-bad fixes the following issues: - CVE-2025-3887: Fixed possible RCE vulnerability via buffer overflow in H265 Codec Parsing (bsc#1242809). gstreamer-plugins-bad-1.24.0-150600.4.3.1.src.rpm gstreamer-plugins-bad-1.24.0-150600.4.3.1.x86_64.rpm gstreamer-plugins-bad-devel-1.24.0-150600.4.3.1.x86_64.rpm gstreamer-plugins-bad-lang-1.24.0-150600.4.3.1.noarch.rpm libgstadaptivedemux-1_0-0-1.24.0-150600.4.3.1.x86_64.rpm libgstanalytics-1_0-0-1.24.0-150600.4.3.1.x86_64.rpm libgstbadaudio-1_0-0-1.24.0-150600.4.3.1.x86_64.rpm libgstbasecamerabinsrc-1_0-0-1.24.0-150600.4.3.1.x86_64.rpm libgstcodecparsers-1_0-0-1.24.0-150600.4.3.1.x86_64.rpm libgstcodecs-1_0-0-1.24.0-150600.4.3.1.x86_64.rpm libgstcuda-1_0-0-1.24.0-150600.4.3.1.x86_64.rpm libgstdxva-1_0-0-1.24.0-150600.4.3.1.x86_64.rpm libgstinsertbin-1_0-0-1.24.0-150600.4.3.1.x86_64.rpm libgstisoff-1_0-0-1.24.0-150600.4.3.1.x86_64.rpm libgstmpegts-1_0-0-1.24.0-150600.4.3.1.x86_64.rpm libgstmse-1_0-0-1.24.0-150600.4.3.1.x86_64.rpm libgstsctp-1_0-0-1.24.0-150600.4.3.1.x86_64.rpm libgsturidownloader-1_0-0-1.24.0-150600.4.3.1.x86_64.rpm libgstva-1_0-0-1.24.0-150600.4.3.1.x86_64.rpm libgstvulkan-1_0-0-1.24.0-150600.4.3.1.x86_64.rpm libgstwayland-1_0-0-1.24.0-150600.4.3.1.x86_64.rpm libgstwebrtc-1_0-0-1.24.0-150600.4.3.1.x86_64.rpm libgstwebrtcnice-1_0-0-1.24.0-150600.4.3.1.x86_64.rpm typelib-1_0-CudaGst-1_0-1.24.0-150600.4.3.1.x86_64.rpm typelib-1_0-GstAnalytics-1_0-1.24.0-150600.4.3.1.x86_64.rpm typelib-1_0-GstBadAudio-1_0-1.24.0-150600.4.3.1.x86_64.rpm typelib-1_0-GstCodecs-1_0-1.24.0-150600.4.3.1.x86_64.rpm typelib-1_0-GstCuda-1_0-1.24.0-150600.4.3.1.x86_64.rpm typelib-1_0-GstDxva-1_0-1.24.0-150600.4.3.1.x86_64.rpm typelib-1_0-GstInsertBin-1_0-1.24.0-150600.4.3.1.x86_64.rpm typelib-1_0-GstMpegts-1_0-1.24.0-150600.4.3.1.x86_64.rpm typelib-1_0-GstMse-1_0-1.24.0-150600.4.3.1.x86_64.rpm typelib-1_0-GstPlay-1_0-1.24.0-150600.4.3.1.x86_64.rpm typelib-1_0-GstPlayer-1_0-1.24.0-150600.4.3.1.x86_64.rpm typelib-1_0-GstVa-1_0-1.24.0-150600.4.3.1.x86_64.rpm typelib-1_0-GstWebRTC-1_0-1.24.0-150600.4.3.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-1746 Security update for webkit2gtk3 important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for webkit2gtk3 fixes the following issues: Update to version 2.48.2. Security issues fixed: - CVE-2025-31205: lack of checks may lead to cross-origin data exfiltration through a malicious website (bsc#1243282). - CVE-2025-31204: improper memory handling when processing certain web content may lead to memory corruption (bsc#1243286). - CVE-2025-31206: type confusion issue when processing certain web content may lead to an unexpected crash (bsc#1243288). - CVE-2025-31215: lack of checks when processing certain web content may lead to an unexpected crash (bsc#1243289). - CVE-2025-31257: improper memory handling when processing certain web content may lead to an unexpected crash (bsc#1243596). - CVE-2025-24223: improper memory handling when processing certain web content may lead to memory corruption (bsc#1243424). Other changes and issues fixed: - Enable CSS overscroll behavior by default. - Change threaded rendering implementation to use Skia API instead of WebCore display list that is not thread safe. - Fix rendering when device scale factor change comes before the web view geometry update. - Fix network process crash on exit. - Fix the build with ENABLE_RESOURCE_USAGE=OFF. - Fix several crashes and rendering issues. WebKitGTK-4.1-lang-2.48.2-150600.12.40.2.noarch.rpm libjavascriptcoregtk-4_1-0-2.48.2-150600.12.40.2.x86_64.rpm libwebkit2gtk-4_1-0-2.48.2-150600.12.40.2.x86_64.rpm typelib-1_0-JavaScriptCore-4_1-2.48.2-150600.12.40.2.x86_64.rpm typelib-1_0-WebKit2-4_1-2.48.2-150600.12.40.2.x86_64.rpm typelib-1_0-WebKit2WebExtension-4_1-2.48.2-150600.12.40.2.x86_64.rpm webkit2gtk-4_1-injected-bundles-2.48.2-150600.12.40.2.x86_64.rpm webkit2gtk3-2.48.2-150600.12.40.2.src.rpm webkit2gtk3-devel-2.48.2-150600.12.40.2.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-2183 Recommended update for libnvidia-egl-x11 moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for libnvidia-egl-x11 fixes the following issues: - Use upstream URL - Update to official version 1.0.1 libnvidia-egl-x11-1.0.1-150700.4.3.1.src.rpm libnvidia-egl-x11-devel-1.0.1-150700.4.3.1.x86_64.rpm libnvidia-egl-x111-1.0.1-150700.4.3.1.x86_64.rpm libnvidia-egl-x111-32bit-1.0.1-150700.4.3.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-2182 Recommended update for libnvidia-egl-wayland moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for libnvidia-egl-wayland fixes the following issues: - Fix an issue causing EGL_EXT_present_opaque to be advertised on non-Wayland EGLDisplays - Moved XML documentation to -devel package libnvidia-egl-wayland-1.1.19-150700.3.3.1.src.rpm libnvidia-egl-wayland1-32bit-1.1.19-150700.3.3.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-2005 Security update for gdm important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for gdm fixes the following issues: - CVE-2025-6018: Removes pam_env from auth stack for security reason (bsc#1243226). gdm-45.0.1-150700.12.5.1.src.rpm gdm-45.0.1-150700.12.5.1.x86_64.rpm gdm-devel-45.0.1-150700.12.5.1.x86_64.rpm gdm-lang-45.0.1-150700.12.5.1.noarch.rpm gdm-schema-45.0.1-150700.12.5.1.noarch.rpm gdm-systemd-45.0.1-150700.12.5.1.noarch.rpm gdmflexiserver-45.0.1-150700.12.5.1.noarch.rpm libgdm1-45.0.1-150700.12.5.1.x86_64.rpm typelib-1_0-Gdm-1_0-45.0.1-150700.12.5.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-2188 Security update for ImageMagick moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for ImageMagick fixes the following issues: Security issues fixed: - CVE-2025-43965: mishandling of image depth after SetQuantumFormat is used in MIFF image processing (bsc#1241659). - CVE-2025-46393: mishandling of packet_size and rendering of channels in arbitrary order in multispectral MIFF image processing (bsc#1241658). Other issues fixed: - Restore SUSE specific hardening config policies that got lost in refactoring (bsc#1243622). ImageMagick-7.1.1.43-150700.3.3.1.src.rpm ImageMagick-7.1.1.43-150700.3.3.1.x86_64.rpm ImageMagick-config-7-SUSE-7.1.1.43-150700.3.3.1.x86_64.rpm ImageMagick-config-7-upstream-limited-7.1.1.43-150700.3.3.1.x86_64.rpm ImageMagick-config-7-upstream-open-7.1.1.43-150700.3.3.1.x86_64.rpm ImageMagick-config-7-upstream-secure-7.1.1.43-150700.3.3.1.x86_64.rpm ImageMagick-config-7-upstream-websafe-7.1.1.43-150700.3.3.1.x86_64.rpm ImageMagick-devel-7.1.1.43-150700.3.3.1.x86_64.rpm libMagick++-7_Q16HDRI5-7.1.1.43-150700.3.3.1.x86_64.rpm libMagick++-devel-7.1.1.43-150700.3.3.1.x86_64.rpm libMagickCore-7_Q16HDRI10-7.1.1.43-150700.3.3.1.x86_64.rpm libMagickWand-7_Q16HDRI10-7.1.1.43-150700.3.3.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-1768 Recommended update for libwnck important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for libwnck fixes the following issues: - Fix declaration after labelcerror reported by compiler. (glgo#GNOME/libwnck!67) - Update to version 43.2 (bsc#1241297): + Add WnckHandle to the docs. + Add missing build dependency. + Do not restore original event mask. - Switch to source service for tarball/source. - Update to version 43.1: + Return correct number of application windows. + Avoid showing pointless tooltips. + Do not remove underscores form window titles. + Do not crash if XRes 1.2 is not available. + Do not crash if display is not available. - Fixed upstream. - BuildRequire gettext-devel instead of gettext: allow OBS to shortcut through gettext-runtime-mini. libwnck-3-0-43.2-150600.3.3.1.x86_64.rpm libwnck-43.2-150600.3.3.1.src.rpm libwnck-devel-43.2-150600.3.3.1.x86_64.rpm libwnck-lang-43.2-150600.3.3.1.noarch.rpm typelib-1_0-Wnck-3_0-43.2-150600.3.3.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-1814 Security update for MozillaFirefox important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for MozillaFirefox fixes the following issues: Update to Mozilla Firefox ESR 128.11 (MFSA 2025-44, bsc#1243353): - MFSA-TMP-2025-0001: Double-free in libvpx encoder (bmo#1962421) - CVE-2025-5263: Error handling for script execution was incorrectly isolated from web content (bmo#1960745) - CVE-2025-5264: Potential local code execution in "Copy as cURL" command (bmo#1950001) - CVE-2025-5265: Potential local code execution in "Copy as cURL" command (bmo#1962301) - CVE-2025-5266: Script element events leaked cross-origin resource status (bmo#1965628) - CVE-2025-5267: Clickjacking vulnerability could have led to leaking saved payment card details (bmo#1954137) - CVE-2025-5268: Memory safety bugs fixed in Firefox 139, Thunderbird 139, Firefox ESR 128.11, and Thunderbird 128.11 (bmo#1950136, bmo#1958121, bmo#1960499, bmo#1962634) - CVE-2025-5269: Memory safety bug fixed in Firefox ESR 128.11 and Thunderbird 128.11 (bmo#1924108) MozillaFirefox-128.11.0-150200.152.185.1.src.rpm MozillaFirefox-128.11.0-150200.152.185.1.x86_64.rpm MozillaFirefox-devel-128.11.0-150200.152.185.1.noarch.rpm MozillaFirefox-translations-common-128.11.0-150200.152.185.1.x86_64.rpm MozillaFirefox-translations-other-128.11.0-150200.152.185.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-2892 Optional update for oath-toolkit low SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for brltty provides the following fix: - Ship missing latest updates on specific architectures: system-user-brltty to x86_64. brltty to s390x. brltty-6.6-150600.3.5.1.src.rpm brltty-6.6-150600.3.5.1.x86_64.rpm brltty-driver-at-spi2-6.6-150600.3.5.1.x86_64.rpm brltty-driver-brlapi-6.6-150600.3.5.1.x86_64.rpm brltty-driver-speech-dispatcher-6.6-150600.3.5.1.x86_64.rpm brltty-lang-6.6-150600.3.5.1.noarch.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-2129 Optional update for MozillaFirefox-branding-SLE moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for MozillaFirefox-branding-SLE fixes the following issues: - Rebuild and ship MozillaFirefox-branding-SLE to LTSS, no source change (bsc#1243790) MozillaFirefox-branding-SLE-128-150200.9.18.1.src.rpm MozillaFirefox-branding-SLE-128-150200.9.18.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-1968 Security update for wireshark moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for wireshark fixes the following issues: - CVE-2025-5601: Dissection engine crash (bsc#1244081). wireshark-4.2.12-150600.18.23.1.src.rpm wireshark-devel-4.2.12-150600.18.23.1.x86_64.rpm wireshark-ui-qt-4.2.12-150600.18.23.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-2352 Security update for ffmpeg moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for ffmpeg fixes the following issues: - CVE-2022-1475: Fixed integer overflow in g729_parse() in llibavcodec/g729_parser.c (bsc#1198898). - CVE-2024-36616: Fixed integer overflow in the component libavformat/westwood_vqa.c (bsc#1234018). - CVE-2024-36617: Fixed integer overflow vulnerability in the FFmpeg CAF decoder (bsc#1234019). - CVE-2024-36618: Fixed vulnerability in the AVI demuxer of the libavformat library (bsc#1234020). ffmpeg-3.4.2-150200.11.64.1.src.rpm libavcodec57-3.4.2-150200.11.64.1.x86_64.rpm libavutil-devel-3.4.2-150200.11.64.1.x86_64.rpm libavutil55-3.4.2-150200.11.64.1.x86_64.rpm libpostproc-devel-3.4.2-150200.11.64.1.x86_64.rpm libpostproc54-3.4.2-150200.11.64.1.x86_64.rpm libswresample-devel-3.4.2-150200.11.64.1.x86_64.rpm libswresample2-3.4.2-150200.11.64.1.x86_64.rpm libswscale-devel-3.4.2-150200.11.64.1.x86_64.rpm libswscale4-3.4.2-150200.11.64.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-2240 Recommended update for openssh moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for openssh fixes the following issue: - "scp" on SLE 15 ignores write directory permissions for group and world (bsc#1241667). openssh-askpass-gnome-9.6p1-150600.6.29.2.src.rpm openssh-askpass-gnome-9.6p1-150600.6.29.2.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-2226 Security update for vim moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for vim fixes the following issues: - CVE-2024-41965: Fixed improper neutralization of argument delimiters in zip.vim that could have led to data loss (bsc#1228776). - CVE-2025-29768: Fixed double-free in dialog_changed() (bsc#1239602). gvim-9.1.1406-150500.20.27.1.x86_64.rpm vim-9.1.1406-150500.20.27.1.src.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-2122 Security update for MozillaFirefox important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for MozillaFirefox fixes the following issues: Update to MozillaFirefox 128.12.0 (MFSA 2025-23, bsc#1244670): - CVE-2025-6424: Use-after-free in FontFaceSet - CVE-2025-6425: The WebCompat WebExtension shipped with Firefox exposed a persistent UUID - CVE-2025-6426: No warning when opening executable terminal files on macOS - CVE-2025-6429: Incorrect parsing of URLs could have allowed embedding of youtube.com - CVE-2025-6430: Content-Disposition header ignored when a file is included in an embed or object tag MozillaFirefox-128.12.0-150200.152.188.1.src.rpm MozillaFirefox-128.12.0-150200.152.188.1.x86_64.rpm MozillaFirefox-devel-128.12.0-150200.152.188.1.noarch.rpm MozillaFirefox-translations-common-128.12.0-150200.152.188.1.x86_64.rpm MozillaFirefox-translations-other-128.12.0-150200.152.188.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-2210 Recommended update for open-vm-tools moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for open-vm-tools fixes the following issues: - Update to open-vm-tools 13.0.0 based on build 24696409. (bsc#1245169): There are no new features in the open-vm-tools 13.0.0 release. This is primarily a maintenance release that addresses a few issues, including: + The vm-support script has been updated to collect the open-vm-tools log files from the Linux guest and information from the systemd journal. + Github pull requests has been integrated and issues fixed. Please see the Resolved Issues section of the Release Notes. - Add patch: Currently the "telinit 6" command is used to reboot a Linux VM following Guest OS Customization. As the classic Linux init system, SysVinit, is deprecated in favor of a newer init system, systemd, the telinit command may not be available on the base Linux OS. This change adds support to Guest OS Customization for the systemd init system. If the modern init system, systemd, is available, then a "systemctl reboot" command will be used to trigger reboot. Otherwise, the "telinit 6" command will be used assuming the traditional init system, SysVinit, is still available. - Drop patch now contained in 13.0.0: - Ran /usr/lib/obs/service/source_validators/helpers/fix_changelog to fix changes file where source validator was failing. open-vm-tools-13.0.0-150600.3.15.1.src.rpm open-vm-tools-desktop-13.0.0-150600.3.15.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-2655 Recommended update for mutter moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for mutter fixes the following issue: - Fix: Gnome shell crash on startup with mutter scroll event (bsc#1245592). mutter-45.3-150700.12.3.2.src.rpm mutter-45.3-150700.12.3.2.x86_64.rpm mutter-devel-45.3-150700.12.3.2.x86_64.rpm mutter-lang-45.3-150700.12.3.2.noarch.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-3611 Recommended update for mutter moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for mutter fixes the following issues: - Fix: Gnome shell crash on startup with mutter scroll event. - Fix lagging after applying a patch for syncing mutter and x11 (bsc#1247940). - Fixing crash introduced from a previous patch when entering NULL entries (bsc#1248456, bsc#1249075, bsc#1241155, bsc#1245592). mutter-45.3-150700.12.12.2.src.rpm mutter-45.3-150700.12.12.2.x86_64.rpm mutter-devel-45.3-150700.12.12.2.x86_64.rpm mutter-lang-45.3-150700.12.12.2.noarch.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-2703 Security update for djvulibre moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for djvulibre fixes the following issues: - CVE-2025-53367: Fixed a bug where a crafted document may lead to an out of bound write. (bsc#1245773) djvulibre-3.5.27-150200.11.17.1.src.rpm libdjvulibre-devel-3.5.27-150200.11.17.1.x86_64.rpm libdjvulibre21-3.5.27-150200.11.17.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-2529 Security update for MozillaFirefox, MozillaFirefox-branding-SLE important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for MozillaFirefox, MozillaFirefox-branding-SLE fixes the following issues: MozillaFirefox is updated to the 140ESR series. Firefox Extended Support Release 140.0esr ESR: * General - Reader View now has an enhanced Text and Layout menu with new options for character spacing, word spacing, and text alignment. These changes offer a more accessible reading experience. - Reader View now has a Theme menu with additional Contrast and Gray options. You can also select custom colors for text, background, and links from the Custom tab. - Firefox will now offer to temporarily remember when users grant permissions to sites (e.g. geolocation). Temporary permissions will be removed either after one hour or when the tab is closed. - Firefox now includes safeguards to prevent sites from abusing the history API by generating excessive history entries, which can make navigating with the back and forward buttons difficult by cluttering the history. This intervention ensures that such entries, unless interacted with by the user, are skipped when using the back and forward buttons. - Firefox now identifies all links in PDFs and turns them into hyperlinks. - You can now copy links from background tabs using the tabstrip context menu on macOS and Linux. - Users on macOS and Linux are now given the option to close only the current tab if the Quit keyboard shortcut is used while multiple tabs are open in the window. (bmo#None) * Sidebar and Tabs - You can now enable the updated Firefox sidebar in Settings > General > Browser Layout to quickly access multiple tools in one click, without leaving your main view. Sidebar tools include an AI chatbot of your choice, bookmarks, history, and tabs from devices you sync with your Mozilla account. - Keep a lot of tabs open? Try our new vertical tabs layout to quickly scan your list of tabs. With vertical tabs, your open and pinned tabs appear in the sidebar instead of along the top of the browser. To turn on vertical tabs, right-click on the toolbar near the top of the browser and select Turn on Vertical Tabs. If you’ve enabled the updated sidebar, you can also go to Customize sidebar and check Vertical tabs. Early testers report feeling more organized after using vertical tabs for a few days. - Stay productive and organized with less effort by grouping related tabs together. One simple way to create a group is to drag a tab onto another, pause until you see a highlight, then drop to create the group. Tab groups can be named, color-coded, and are always saved. You can close a group and reopen it later. - A tab preview is now displayed when hovering the mouse over background tabs, making it easier to locate the desired tab without needing to switch tabs. - The sidebar to view tabs from other devices can now be opened via the Tab overview menu. * Security & Privacy - HTTPS is replacing HTTP as the default protocol in the address bar on non-local sites. If a site is not available via HTTPS, Firefox will fall back to HTTP. - Firefox now blocks third-party cookie access when Enhanced Tracking Protection's Strict mode is enabled. - Firefox now has a new anti-tracking feature, Bounce Tracking Protection, which is now available in Enhanced Tracking Protection's "Strict" mode. This feature detects bounce trackers based on their redirect behavior and periodically purges their cookies and site data to block tracking. - Firefox now enforces certificate transparency, requiring web servers to provide sufficient proof that their certificates were publicly disclosed before they will be trusted. This only affects servers using certificates issued by a certificate authority in Mozilla's Root CA Program. - Smartblock Embeds allows users to selectively unblock certain social media embeds that are blocked in ETP Strict and Private Browsing modes. Currently, support is limited to a few embed types, with more to be added in future updates. - Firefox now upgrades page loads to HTTPS by default and gracefully falls back to HTTP if the secure connection fails. This behavior is known as HTTPS-First. - The "Copy Without Site Tracking" menu item was renamed to "Copy Clean Link" to help clarify expectations around what the feature does. "Copy Clean Link" is a list based approach to remove - known tracking parameters from links. This option can also now be used on plain text links. - The Clear browsing data and cookies dialog now allows clearing saved form info separately from browsing history. * Translations - Firefox now allows translating selected text portions to different languages after a full-page translation. - Full-Page Translations are now available within Firefox extension pages that start with the moz-extension:// URL scheme. - When suggesting a default translation language, Firefox will now take into consideration languages you have previously used for translations. - Added support for many new languages in Firefox translation. * Linux - Firefox now supports touchpad hold gestures on Linux. This means that kinetic (momentum) scrolling can now be interrupted by placing two fingers on the touchpad. * Developer: - Firefox now supports text fragments, which allows users to link directly to a specific portion of text in a web document via a special URL fragment. - Debugger log-point values are now automatically converted into profiler markers, making it easy to add information to the marker timeline directly from the Debugger. - The Debugger's directory root is now scoped to the specific domain where it was set, which aligns with typical usage and avoids applying it across unrelated domains. This builds on previous improvements such as a redesigned UI and easier removal of the root setting. Setting a directory root updates the Source List to show only the selected directory and its children. (Learn more) - The Network Blocking feature in the Network panel now blocks HTTP requests in addition to blocking responses. - The Network panel displays information about Early Hints, including a dedicated indicator for the 103 HTTP status code in the user interface. - The Network panel now allows overriding network request responses with local files. - The filter setting in the Network panel is now preserved across DevTools Toolbox sessions. - A new column has been added to the Network panel to display the full path of the request URL. This enhancement makes helps developers quickly view and analyze complete request paths. - Introduced a new console command `$$$` that allows searching the page, including within shadow roots. - Improved support for debugging web extensions, such as automatically reloading the web extension's source code in the Debugger when the extension is reloaded. Workers are now available in the Console panel’s context selector and breakpoints function correctly in content scripts. - In the Inspector Fonts panel, we now display fonts metadata, like the font version, designer, vendor, license, etc. - Added support for the import map integrity field, allowing you to ensure the integrity of dynamically or statically imported modules. - Implemented support for `Error.isError`, enabling brand checks to determine whether an object is an instance of Error. (Learn more) - Added support for the `error.captureStackTrace` extension to improve compatibility with other browsers. (Learn more: http://github.com/tc39/proposal-error-capturestacktrace) * Enterprise: - The UserMessaging policy has been updated with a new option to allow disabling Firefox Labs in preferences. - The Preferences policy has been updated to allow setting the preference security.pki.certificate_transparency.mode. - HTTPS-First is now on by default. You can manage this behavior using the HttpsOnlyMode and HttpAllowlist policies. - An internal change has been made to Firefox that removes `XPCOMUtils.defineLazyGetter`. For most people, this shouldn't matter, but if you encounter problems with AutoConfig or third party software like PolicyPak, this might be the cause. You'll need to reach out to your provider. - Firefox now supports the Content Analysis SDK for integrating DLP software. For more information, see this post. - The SearchEngines policy is now available on all versions of Firefox (not just the ESR). Various security fixes MFSA 2025-51 (bsc#1244670): * CVE-2025-6424 (bmo#1966423) Use-after-free in FontFaceSet * CVE-2025-6425 (bmo#1717672) The WebCompat WebExtension shipped with Firefox exposed a persistent UUID * CVE-2025-6426 (bmo#1964385) No warning when opening executable terminal files on macOS * CVE-2025-6427 (bmo#1966927) connect-src Content Security Policy restriction could be bypassed * CVE-2025-6428 (bmo#1970151) Firefox for Android opened URLs specified in a link querystring parameter * CVE-2025-6429 (bmo#1970658) Incorrect parsing of URLs could have allowed embedding of youtube.com * CVE-2025-6430 (bmo#1971140) Content-Disposition header ignored when a file is included in an embed or object tag * CVE-2025-6431 (bmo#1942716) The prompt in Firefox for Android that asks before opening a link in an external application could be bypassed * CVE-2025-6432 (bmo#1943804) DNS Requests leaked outside of a configured SOCKS proxy * CVE-2025-6433 (bmo#1954033) WebAuthn would allow a user to sign a challenge on a webpage with an invalid TLS certificate * CVE-2025-6434 (bmo#1955182) HTTPS-Only exception screen lacked anti-clickjacking delay * CVE-2025-6435 (bmo#1950056, bmo#1961777) Save as in Devtools could download files without sanitizing the extension * CVE-2025-6436 (bmo#1941377, bmo#1960948, bmo#1966187, bmo#1966505, bmo#1970764) Memory safety bugs fixed in Firefox 140 and Thunderbird 140 Various security fixes MFSA 2025-59 (bsc#1246664): - CVE-2025-8027: JavaScript engine only wrote partial return value to stack - CVE-2025-8028: Large branch table could lead to truncated instruction - CVE-2025-8029: javascript: URLs executed on object and embed tags - CVE-2025-8036: DNS rebinding circumvents CORS - CVE-2025-8037: Nameless cookies shadow secure cookies - CVE-2025-8030: Potential user-assisted code execution in “Copy as cURL” command - CVE-2025-8031: Incorrect URL stripping in CSP reports - CVE-2025-8032: XSLT documents could bypass CSP - CVE-2025-8038: CSP frame-src was not correctly enforced for paths - CVE-2025-8039: Search terms persisted in URL bar - CVE-2025-8033: Incorrect JavaScript state machine for generators - CVE-2025-8034: Memory safety bugs fixed in Firefox ESR 115.26, Firefox ESR 128.13, Thunderbird ESR 128.13, Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141 - CVE-2025-8040: Memory safety bugs fixed in Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141 - CVE-2025-8035: Memory safety bugs fixed in Firefox ESR 128.13, Thunderbird ESR 128.13, Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141 MozillaFirefox-140.1.0-150200.152.193.1.src.rpm MozillaFirefox-140.1.0-150200.152.193.1.x86_64.rpm MozillaFirefox-branding-SLE-140-150200.9.21.1.src.rpm MozillaFirefox-branding-SLE-140-150200.9.21.1.x86_64.rpm MozillaFirefox-devel-140.1.0-150200.152.193.1.noarch.rpm MozillaFirefox-translations-common-140.1.0-150200.152.193.1.x86_64.rpm MozillaFirefox-translations-other-140.1.0-150200.152.193.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-2580 Recommended update for firewalld moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for firewalld fixes the following issues: - Do not recommend python311-firewalld (bsc#1246100) firewall-applet-2.0.1-150600.3.12.1.noarch.rpm firewall-config-2.0.1-150600.3.12.1.noarch.rpm firewalld-2.0.1-150600.3.12.1.src.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-3094 Optional update for NetworkManager low SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for NetworkManager fixes the following issue - Add NetworkManager-wwan to SLE-Module-Desktop-Applications_15-SP7 (bsc#1246113) NetworkManager-1.44.2-150600.3.4.1.src.rpm NetworkManager-1.44.2-150600.3.4.1.x86_64.rpm NetworkManager-wwan-1.44.2-150600.3.4.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-2510 Security update for ImageMagick important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for ImageMagick fixes the following issues: - CVE-2025-53014: Fixed an off-by-one error may cause an out-of-bounds memory access (bsc#1246530) - CVE-2025-53019: Fixed format specifiers in a filename template may cause a memory leak (bsc#1246534) - CVE-2025-53101: Fixed input manipulation may lead to an out-of-bound write (bsc#1246529) ImageMagick-7.1.0.9-150400.6.33.1.src.rpm ImageMagick-config-7-upstream-7.1.0.9-150400.6.33.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-2801 Security update for ImageMagick moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for ImageMagick fixes the following issues: - CVE-2025-53014: Fixed an off-by-one error may cause an out-of-bounds memory access (bsc#1246530) - CVE-2025-53015: Fixed specific XMP file conversion may cause an infinite loop (bsc#1246531) - CVE-2025-53019: Fixed format specifiers in a filename template may cause a memory leak (bsc#1246534) - CVE-2025-53101: Fixed input manipulation may lead to an out-of-bound write (bsc#1246529) Other fix: - Crop filename pattern %03d no longer works in ImageMagick 7 (bsc#1247475) ImageMagick-7.1.1.43-150700.3.8.1.src.rpm ImageMagick-7.1.1.43-150700.3.8.1.x86_64.rpm ImageMagick-config-7-SUSE-7.1.1.43-150700.3.8.1.x86_64.rpm ImageMagick-config-7-upstream-limited-7.1.1.43-150700.3.8.1.x86_64.rpm ImageMagick-config-7-upstream-open-7.1.1.43-150700.3.8.1.x86_64.rpm ImageMagick-config-7-upstream-secure-7.1.1.43-150700.3.8.1.x86_64.rpm ImageMagick-config-7-upstream-websafe-7.1.1.43-150700.3.8.1.x86_64.rpm ImageMagick-devel-7.1.1.43-150700.3.8.1.x86_64.rpm libMagick++-7_Q16HDRI5-7.1.1.43-150700.3.8.1.x86_64.rpm libMagick++-devel-7.1.1.43-150700.3.8.1.x86_64.rpm libMagickCore-7_Q16HDRI10-7.1.1.43-150700.3.8.1.x86_64.rpm libMagickWand-7_Q16HDRI10-7.1.1.43-150700.3.8.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-2990 Security update for ffmpeg moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for ffmpeg fixes the following issues: - CVE-2025-7700: Fixed NULL Pointer Dereference in FFmpeg ALS Decoder (libavcodec/alsdec.c) (bsc#1246790). ffmpeg-3.4.2-150200.11.67.1.src.rpm libavcodec57-3.4.2-150200.11.67.1.x86_64.rpm libavutil-devel-3.4.2-150200.11.67.1.x86_64.rpm libavutil55-3.4.2-150200.11.67.1.x86_64.rpm libpostproc-devel-3.4.2-150200.11.67.1.x86_64.rpm libpostproc54-3.4.2-150200.11.67.1.x86_64.rpm libswresample-devel-3.4.2-150200.11.67.1.x86_64.rpm libswresample2-3.4.2-150200.11.67.1.x86_64.rpm libswscale-devel-3.4.2-150200.11.67.1.x86_64.rpm libswscale4-3.4.2-150200.11.67.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-2765 Security update for webkit2gtk3 important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for webkit2gtk3 fixes the following issues: Updated to version 2.48.5: - CVE-2025-31273: Fixed a vulnerability where processing maliciously crafted web content could lead to memory corruption. (bsc#1247564) - CVE-2025-31278: Fixed a vulnerability where processing maliciously crafted web content may lead to memory corruption. (bsc#1247563) - CVE-2025-43211: Fixed a vulnerability where processing web content may lead to a denial-of-service. (bsc#1247562) - CVE-2025-43212: Fixed a vulnerability where processing maliciously crafted web content may lead to an unexpected Safari crash. (bsc#1247595) - CVE-2025-43216: Fixed a vulnerability where processing maliciously crafted web content may lead to an unexpected Safari crash. (bsc#1247596) - CVE-2025-43227: Fixed a vulnerability where processing maliciously crafted web content may disclose sensitive user information. (bsc#1247597) - CVE-2025-43228: Fixed a vulnerability where visiting a malicious website may lead to address bar spoofing. (bsc#1247598) - CVE-2025-43240: Fixed a vulnerability where a download's origin may be incorrectly associated. (bsc#1247599) - CVE-2025-43265: Fixed a vulnerability where processing maliciously crafted web content may disclose internal states of the app. (bsc#1247600) - CVE-2025-6558: Fixed a vulnerability where processing maliciously crafted web content may lead to an unexpected Safari crash. (bsc#1247742) Other fixes: - Improve emoji font selection with USE_SKIA=ON. - Improve playback of multimedia streams from blob URLs. - Fix the build with USE_SKIA_OPENTYPE_SVG=ON and USE_SYSPROF_CAPTURE=ON. - Fix crash when using a WebKitWebView widget in an offscreen window. - Fix several crashes and rendering issues. - Fix a crash introduced by the new threaded rendering implementation using Skia API. - Improve rendering performance by recording layers once and replaying every dirty region in different worker threads. - Fix a crash when setting WEBKIT_SKIA_GPU_PAINTING_THREADS=0. - Fix a reference cycle in webkitmediastreamsrc preventing its disposal. - Increase mem_per_process again to avoid running out of memory. WebKitGTK-4.1-lang-2.48.5-150600.12.43.1.noarch.rpm libjavascriptcoregtk-4_1-0-2.48.5-150600.12.43.1.x86_64.rpm libwebkit2gtk-4_1-0-2.48.5-150600.12.43.1.x86_64.rpm typelib-1_0-JavaScriptCore-4_1-2.48.5-150600.12.43.1.x86_64.rpm typelib-1_0-WebKit2-4_1-2.48.5-150600.12.43.1.x86_64.rpm typelib-1_0-WebKit2WebExtension-4_1-2.48.5-150600.12.43.1.x86_64.rpm webkit2gtk-4_1-injected-bundles-2.48.5-150600.12.43.1.x86_64.rpm webkit2gtk3-2.48.5-150600.12.43.1.src.rpm webkit2gtk3-devel-2.48.5-150600.12.43.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-3152 Security update for ImageMagick important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for ImageMagick fixes the following issues: - CVE-2025-55004: Fixed heap buffer over-read in in ReadOneMNGIMage when processing images with separate alpha channels (bsc#1248076). - CVE-2025-55005: Fixed heap buffer overflow when transforming from Log to sRGB colorspaces (bsc#1248077). - CVE-2025-55154: Fixed integer overflow when performing magnified size calculations in ReadOneMNGIMage (bsc#1248078). - CVE-2025-55160: Fixed undefined behavior due to function-type-mismatch in CloneSplayTree (bsc#1248079). - CVE-2025-55212: Fixed division-by-zero in ThumbnailImage() when passing a geometry string containing only a colon to `montage -geometry` (bsc#1248767). - CVE-2025-55298: Fixed heap overflow due to format string bug vulnerability (bsc#1248780). - CVE-2025-57803: Fixed heap out-of-bounds (OOB) write due to 32-bit integer overflow (bsc#1248784). Other fixes: - Fixed output file placeholders (bsc#1247475). ImageMagick-7.1.0.9-150400.6.40.1.src.rpm ImageMagick-config-7-upstream-7.1.0.9-150400.6.40.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-3286 Recommended update for gtk3 moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for gtk3 fixes the following issues: - Fixed issue with window dimensions (bsc#1247503) gtk3-3.24.43-150600.3.10.1.src.rpm gtk3-devel-doc-3.24.43-150600.3.10.1.noarch.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-3122 Recommended update for libnvidia-egl-wayland moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for libnvidia-egl-wayland fixes the following issues: - Update nvidia driver to version 580.76.05 (bsc#1247907) * Add support for tegradisp-drm libnvidia-egl-wayland-1.1.20-150700.3.6.1.src.rpm libnvidia-egl-wayland1-32bit-1.1.20-150700.3.6.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-3121 Recommended update for libnvidia-egl-x11 moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for libnvidia-egl-x11 fixes the following issues: - Update nvidia driver to version 580.76.05 (bsc#1247907) - Increment the version number to 1.0.3 - egl-x11: Add support for tegradisp drm - Increment version number to 1.0.2 - Do not close the syncfd in WaitImplicitFence - Fix the error reporting in WaitTimelinePoint libnvidia-egl-x11-1.0.3-150700.4.6.1.src.rpm libnvidia-egl-x11-devel-1.0.3-150700.4.6.1.x86_64.rpm libnvidia-egl-x111-1.0.3-150700.4.6.1.x86_64.rpm libnvidia-egl-x111-32bit-1.0.3-150700.4.6.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-3008 Security update for MozillaFirefox important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for MozillaFirefox fixes the following issues: - Firefox Extended Support Release 140.2.0 ESR MFSA 2025-67 (bsc#1248162) * CVE-2025-9179 (bmo#1979527): Sandbox escape due to invalid pointer in the Audio/Video: GMP component * CVE-2025-9180 (bmo#1979782): Same-origin policy bypass in the Graphics: Canvas2D component * CVE-2025-9181 (bmo#1977130): Uninitialized memory in the JavaScript Engine component * CVE-2025-9182 (bmo#1975837): Denial-of-service due to out-of-memory in the Graphics: WebRender component * CVE-2025-9183 (bmo#1976102): Spoofing issue in the Address Bar component * CVE-2025-9184 (bmo#1929482, bmo#1976376, bmo#1979163, bmo#1979955): Memory safety bugs fixed in Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142 * CVE-2025-9185 (bmo#1970154, bmo#1976782, bmo#1977166): Memory safety bugs fixed in Firefox ESR 115.27, Firefox ESR 128.14, Thunderbird ESR 128.14, Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142 * CVE-2025-9187 (bmo#1825621, bmo#1970079, bmo#1976736, bmo#1979072): Memory safety bugs fixed in Firefox 142 and Thunderbird 142 - Other fixes: * Ensure the use of the correct file-picker on KDE (bsc#1226112) MozillaFirefox-140.2.0-150200.152.198.1.src.rpm MozillaFirefox-140.2.0-150200.152.198.1.x86_64.rpm MozillaFirefox-devel-140.2.0-150200.152.198.1.noarch.rpm MozillaFirefox-translations-common-140.2.0-150200.152.198.1.x86_64.rpm MozillaFirefox-translations-other-140.2.0-150200.152.198.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-3244 Security update for raptor moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for raptor fixes the following issues: - CVE-2024-57823: Fixed integer underflow when normalizing a URI with the turtle parser (bsc#1235673) - CVE-2024-57822: Fixed heap buffer overread when parsing triples with the nquads parser (bsc#1235674) libraptor-devel-2.0.15-150200.9.18.1.x86_64.rpm libraptor2-0-2.0.15-150200.9.18.1.x86_64.rpm raptor-2.0.15-150200.9.18.1.src.rpm raptor-2.0.15-150200.9.18.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-3449 Security update for cairo low SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for cairo fixes the following issues: - CVE-2025-50422: Fixed Poppler crash on malformed input (bsc#1247589) - Update to version 1.18.4: + The dependency on LZO has been made optional through a build time configuration toggle. + You can build Cairo against a Freetype installation that does not have the FT_Color type. + Cairo tests now build on Solaris 11.4 with GCC 14. + The DirectWrite backend now builds on MINGW 11. + The DirectWrite backend now supports font variations and proper glyph coverage. - Use tarball in lieu of source service due to freedesktop gitlab migration, will switch back at next release at the latest. - Add pkgconfig(lzo2) BuildRequires: New optional dependency, build lzo2 support feature. - Convert to source service: allows for easier upgrades by the GNOME team. - Update to version 1.18.2: + The malloc-stats code has been removed from the tests directory + Cairo now requires a version of pixman equal to, or newer than, 0.40. + There have been multiple build fixes for newer versions of GCC for MSVC; for Solaris; and on macOS 10.7. + PNG errors caused by loading malformed data are correctly propagated to callers, so they can handle the case. + Both stroke and fill colors are now set when showing glyphs on a PDF surface. + All the font options are copied when creating a fallback font object. + When drawing text on macOS, Cairo now tries harder to select the appropriate font name. + Cairo now prefers the COLRv1 table inside a font, if one is available. + Cairo requires a C11 toolchain when building. cairo-1.18.4-150600.3.3.1.src.rpm libcairo2-32bit-1.18.4-150600.3.3.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-3300 Security update for vim moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for vim fixes the following issues: Updated to 9.1.1629: - CVE-2025-53905: Fixed malicious tar archive may causing a path traversal in Vim’s tar.vim plugin (bsc#1246604) - CVE-2025-53906: Fixed malicious zip archive may causing a path traversal in Vim’s zip (bsc#1246602) - CVE-2025-55157: Fixed use-after-free in internal tuple reference management (bsc#1247938) - CVE-2025-55158: Fixed double-free in internal typed value (typval_T) management (bsc#1247939) gvim-9.1.1629-150500.20.33.1.x86_64.rpm vim-9.1.1629-150500.20.33.1.src.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-3113 Security update for ImageMagick important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for ImageMagick fixes the following issues: - CVE-2025-55004: Fixed heap buffer over-read in in ReadOneMNGIMage when processing images with separate alpha channels (bsc#1248076). - CVE-2025-55005: Fixed heap buffer overflow when transforming from Log to sRGB colorspaces (bsc#1248077). - CVE-2025-55154: Fixed integer overflow when performing magnified size calculations in ReadOneMNGIMage can lead to out-of-bounds write (bsc#1248078). - CVE-2025-55160: Fixed undefined behavior due to function-type-mismatch in CloneSplayTree (bsc#1248079). - CVE-2025-55212: Fixed division-by-zero in ThumbnailImage() when passing a geometry string containing only a colon to `montage -geometry` (bsc#1248767). - CVE-2025-55298: Fixed heap overflow due to format string bug vulnerability (bsc#1248780). - CVE-2025-57803: Fixed heap out-of-bounds (OOB) write due to 32-bit integer overflow (bsc#1248784). ImageMagick-7.1.1.43-150700.3.13.1.src.rpm ImageMagick-7.1.1.43-150700.3.13.1.x86_64.rpm ImageMagick-config-7-SUSE-7.1.1.43-150700.3.13.1.x86_64.rpm ImageMagick-config-7-upstream-limited-7.1.1.43-150700.3.13.1.x86_64.rpm ImageMagick-config-7-upstream-open-7.1.1.43-150700.3.13.1.x86_64.rpm ImageMagick-config-7-upstream-secure-7.1.1.43-150700.3.13.1.x86_64.rpm ImageMagick-config-7-upstream-websafe-7.1.1.43-150700.3.13.1.x86_64.rpm ImageMagick-devel-7.1.1.43-150700.3.13.1.x86_64.rpm libMagick++-7_Q16HDRI5-7.1.1.43-150700.3.13.1.x86_64.rpm libMagick++-devel-7.1.1.43-150700.3.13.1.x86_64.rpm libMagickCore-7_Q16HDRI10-7.1.1.43-150700.3.13.1.x86_64.rpm libMagickWand-7_Q16HDRI10-7.1.1.43-150700.3.13.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-3261 Security update for cups important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for cups fixes the following issues: - CVE-2024-47175: no validation of IPP attributes in `ppdCreatePPDFromIPP2` when writing to a temporary PPD file allows for the injection of attacker-controlled data to the resulting PPD (bsc#1230932). - CVE-2025-58060: no password check when `AuthType` is set to anything but `Basic` and a request is made with an `Authorization: Basic` header (bsc#1249049). - CVE-2025-58364: unsafe deserialization and validation of printer attributes leads to NULL pointer dereference (bsc#1249128). cups-2.2.7-150000.3.72.1.src.rpm libcups2-32bit-2.2.7-150000.3.72.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-3599 Security update for qt6-base moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for qt6-base fixes the following issues: - CVE-2025-5455: processing of malformed data in `qDecodeDataUrl()` can trigger assertion and cause a crash (bsc#1243958). - CVE-2025-30348: complex algorithm used in `encodeText` in QDom when processing XML data can cause low performance (bsc#1239896). libQt6Core6-6.6.3-150600.3.6.1.x86_64.rpm libQt6DBus6-6.6.3-150600.3.6.1.x86_64.rpm libQt6Gui6-6.6.3-150600.3.6.1.x86_64.rpm libQt6Network6-6.6.3-150600.3.6.1.x86_64.rpm libQt6OpenGL6-6.6.3-150600.3.6.1.x86_64.rpm libQt6Sql6-6.6.3-150600.3.6.1.x86_64.rpm libQt6Test6-6.6.3-150600.3.6.1.x86_64.rpm libQt6Widgets6-6.6.3-150600.3.6.1.x86_64.rpm qt6-base-6.6.3-150600.3.6.1.src.rpm qt6-network-tls-6.6.3-150600.3.6.1.x86_64.rpm qt6-networkinformation-glib-6.6.3-150600.3.6.1.x86_64.rpm qt6-networkinformation-nm-6.6.3-150600.3.6.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-3294 Security update for wireshark moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for wireshark fixes the following issues: Update to version 4.2.13. Security issues fixed: - CVE-2025-9817: SSH dissector crash due to NULL pointer dereference when processing malformed packet traces (bsc#1249090). Other issues fixed: - Bug in UDS dissector with Service ReadDataByPeriodicIdentifier Response. - Incorrectly parsed `application/x-www-form-urlencoded` key following a name-value byte sequence with no `=`. - DNP3 time stamp not working after epoch time (year 2038). - Bug in LZ77 decoder; reads a 16-bit length when it should read a 32-bit length. - Further features, bug fixes and updated protocol support as listed in: * https://www.wireshark.org/docs/relnotes/wireshark-4.2.13.html wireshark-4.2.13-150600.18.26.1.src.rpm wireshark-devel-4.2.13-150600.18.26.1.x86_64.rpm wireshark-ui-qt-4.2.13-150600.18.26.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-3723 Security update for libqt5-qtbase moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for libqt5-qtbase fixes the following issues: Security issues fixed: - CVE-2025-5455: processing of malformed data in `qDecodeDataUrl()` can trigger assertion and cause a crash (bsc#1243958). - CVE-2025-30348: complex algorithm used in `encodeText` in QDom when processing XML data can cause low performance (bsc#1239896). Other issues fixed: - Initialize a member variable in `QObjectPrivate::Signal` that was uninitialized under some circumstances. - Fix a crash when parsing a particular glyph in a particular font. - Avoid repeatedly registering xsettings callbacks when switching cursor themes. - Check validity of RandR output info before using it. - Fix reparenting a window so it takes effect even if there are no other state changes to the window. libQt5OpenGLExtensions-devel-static-5.15.12+kde151-150600.3.9.1.x86_64.rpm libQt5Sql5-mysql-5.15.12+kde151-150600.3.9.1.x86_64.rpm libQt5Sql5-postgresql-5.15.12+kde151-150600.3.9.1.x86_64.rpm libQt5Sql5-unixODBC-5.15.12+kde151-150600.3.9.1.x86_64.rpm libqt5-qtbase-5.15.12+kde151-150600.3.9.1.src.rpm libqt5-qtbase-platformtheme-gtk3-5.15.12+kde151-150600.3.9.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-3510 Security update for ImageMagick moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for ImageMagick fixes the following issues: - CVE-2025-57807: heap out-of-bounds write can lead to memory corruption (bsc#1249362). ImageMagick-7.1.1.43-150700.3.16.1.src.rpm ImageMagick-7.1.1.43-150700.3.16.1.x86_64.rpm ImageMagick-config-7-SUSE-7.1.1.43-150700.3.16.1.x86_64.rpm ImageMagick-config-7-upstream-limited-7.1.1.43-150700.3.16.1.x86_64.rpm ImageMagick-config-7-upstream-open-7.1.1.43-150700.3.16.1.x86_64.rpm ImageMagick-config-7-upstream-secure-7.1.1.43-150700.3.16.1.x86_64.rpm ImageMagick-config-7-upstream-websafe-7.1.1.43-150700.3.16.1.x86_64.rpm ImageMagick-devel-7.1.1.43-150700.3.16.1.x86_64.rpm libMagick++-7_Q16HDRI5-7.1.1.43-150700.3.16.1.x86_64.rpm libMagick++-devel-7.1.1.43-150700.3.16.1.x86_64.rpm libMagickCore-7_Q16HDRI10-7.1.1.43-150700.3.16.1.x86_64.rpm libMagickWand-7_Q16HDRI10-7.1.1.43-150700.3.16.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-3616 Security update for ImageMagick moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for ImageMagick fixes the following issues: - CVE-2025-57807: heap out-of-bounds write can lead to memory corruption (bsc#1249362). ImageMagick-7.1.0.9-150400.6.43.1.src.rpm ImageMagick-config-7-upstream-7.1.0.9-150400.6.43.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-3291 Security update for MozillaFirefox important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for MozillaFirefox fixes the following issues: Firefox Extended Support Release 140.3.0 ESR (bsc#1249391). MFSA 2025-75: * CVE-2025-10527 (bmo#1984825) Sandbox escape due to use-after-free in the Graphics: Canvas2D component * CVE-2025-10528 (bmo#1986185) Sandbox escape due to undefined behavior, invalid pointer in the Graphics: Canvas2D component * CVE-2025-10529 (bmo#1970490) Same-origin policy bypass in the Layout component * CVE-2025-10532 (bmo#1979502) Incorrect boundary conditions in the JavaScript: GC component * CVE-2025-10533 (bmo#1980788) Integer overflow in the SVG component * CVE-2025-10536 (bmo#1981502) Information disclosure in the Networking: Cache component * CVE-2025-10537 (bmo#1938220, bmo#1980730, bmo#1981280, bmo#1981283, bmo#1984505, bmo#1985067) Memory safety bugs fixed in Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143 MozillaFirefox-140.3.0-150200.152.201.1.src.rpm MozillaFirefox-140.3.0-150200.152.201.1.x86_64.rpm MozillaFirefox-devel-140.3.0-150200.152.201.1.noarch.rpm MozillaFirefox-translations-common-140.3.0-150200.152.201.1.x86_64.rpm MozillaFirefox-translations-other-140.3.0-150200.152.201.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-3333 Security update for avahi moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for avahi fixes the following issues: - CVE-2024-52615: wide-area DNS uses constant source port for queries and can expose the Avahi-daemon to DNS spoofing attacks (bsc#1233421). avahi-0.8-150600.15.9.1.src.rpm avahi-autoipd-0.8-150600.15.9.1.x86_64.rpm avahi-glib2-0.8-150600.15.9.1.src.rpm avahi-utils-gtk-0.8-150600.15.9.1.x86_64.rpm libavahi-gobject-devel-0.8-150600.15.9.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-4119 Optional update for gnome-desktop low SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for bind fixes the following issues: - Ship libgnome-desktop-4-devel Desktop-Applications Module for 15-SP7 (bsc#1249416) gnome-desktop-44.0-150600.3.2.1.src.rpm gnome-desktop-lang-44.0-150600.3.2.1.noarch.rpm libgnome-desktop-3-20-44.0-150600.3.2.1.x86_64.rpm libgnome-desktop-3-devel-44.0-150600.3.2.1.x86_64.rpm libgnome-desktop-3_0-common-44.0-150600.3.2.1.x86_64.rpm libgnome-desktop-4-2-44.0-150600.3.2.1.x86_64.rpm libgnome-desktop-4-devel-44.0-150600.3.2.1.x86_64.rpm typelib-1_0-GnomeBG-4_0-44.0-150600.3.2.1.x86_64.rpm typelib-1_0-GnomeDesktop-3_0-44.0-150600.3.2.1.x86_64.rpm typelib-1_0-GnomeDesktop-4_0-44.0-150600.3.2.1.x86_64.rpm typelib-1_0-GnomeRR-4_0-44.0-150600.3.2.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-3434 Security update for open-vm-tools important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for open-vm-tools fixes the following issues: - CVE-2025-41244: local privilege escalation via the Service Discovery Plugin (bsc#1250373). open-vm-tools-13.0.0-150600.3.18.1.src.rpm open-vm-tools-desktop-13.0.0-150600.3.18.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-3462 Security update for MozillaFirefox important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for MozillaFirefox fixes the following issues: Update to Firefox Extended Support Release 140.3.1 ESR (bsc#1250452). - Improved reliability when HTTP/3 connections fail: Firefox no longer forces HTTP/2 during fallback, allowing the server to choose the protocol and preventing stalls on some sites. MozillaFirefox-140.3.1-150200.152.204.1.src.rpm MozillaFirefox-140.3.1-150200.152.204.1.x86_64.rpm MozillaFirefox-devel-140.3.1-150200.152.204.1.noarch.rpm MozillaFirefox-translations-common-140.3.1-150200.152.204.1.x86_64.rpm MozillaFirefox-translations-other-140.3.1-150200.152.204.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-3851 Recommended update for vim moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for vim fixes the following issues: - Fix regression in vim: xxd -a shows no output (bsc#1250593). Backported from 9.1.1683 (xxd: Avoid null dereference in autoskip colorless). - Fix vim compatible mode is not switched off earlier (bsc#1229750). Nocompatible must be set before the syntax highlighting is turned on. gvim-9.1.1629-150500.20.38.1.x86_64.rpm vim-9.1.1629-150500.20.38.1.src.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-3535 Security update for open-vm-tools important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for open-vm-tools fixes the following issues: - CVE-2025-41244: fixed a local privilege escalation vulnerability (bnc#1250373). open-vm-tools-13.0.5-150600.3.21.1.src.rpm open-vm-tools-desktop-13.0.5-150600.3.21.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-3629 Security update for gstreamer-plugins-rs important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for gstreamer-plugins-rs fixes the following issues: Update to version 0.12.11 (jsc#PED-13826): - CVE-2024-32650: Fixed infinite loop in rustls::conn::ConnectionCommon:complete_io() with proper client input (bsc#1223219). gstreamer-plugins-rs-0.12.11-150600.3.3.1.src.rpm gstreamer-plugins-rs-0.12.11-150600.3.3.1.x86_64.rpm gstreamer-plugins-rs-devel-0.12.11-150600.3.3.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-3949 Security update for colord moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for colord fixes the following issues: - CVE-2021-42523: The original fix was wrong and did not properly free the error, resulting in a crash that has now been addressed (bsc#1250750). colord-1.4.6-150600.3.8.1.src.rpm colord-color-profiles-1.4.6-150600.3.8.1.x86_64.rpm libcolord-devel-1.4.6-150600.3.8.1.x86_64.rpm libcolorhug2-1.4.6-150600.3.8.1.x86_64.rpm typelib-1_0-Colord-1_0-1.4.6-150600.3.8.1.x86_64.rpm typelib-1_0-Colorhug-1_0-1.4.6-150600.3.8.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-3701 Security update for webkit2gtk3 important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for webkit2gtk3 fixes the following issues: - CVE-2025-43343: improved memory handling in web content processing to prevent process crash (bsc#1251975) - CVE-2025-43272: improved memory handling to prevent unexpected process crash (bsc#1250439) - CVE-2025-43342: correctness issue was addressed with improved checks to prevent unexcepted process crash (bsc#1250440) - CVE-2025-43356: improved handling of caches to prevent sensor access without consent (bsc#1250441) - CVE-2025-43368: improved memory management to prevent a use-after-free (bsc#1250442) WebKitGTK-4.1-lang-2.50.1-150600.12.48.3.noarch.rpm libjavascriptcoregtk-4_1-0-2.50.1-150600.12.48.3.x86_64.rpm libwebkit2gtk-4_1-0-2.50.1-150600.12.48.3.x86_64.rpm typelib-1_0-JavaScriptCore-4_1-2.50.1-150600.12.48.3.x86_64.rpm typelib-1_0-WebKit2-4_1-2.50.1-150600.12.48.3.x86_64.rpm typelib-1_0-WebKit2WebExtension-4_1-2.50.1-150600.12.48.3.x86_64.rpm webkit2gtk-4_1-injected-bundles-2.50.1-150600.12.48.3.x86_64.rpm webkit2gtk3-2.50.1-150600.12.48.3.src.rpm webkit2gtk3-devel-2.50.1-150600.12.48.3.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-3811 Security update for wireshark moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for wireshark fixes the following issues: - CVE-2025-11626: fixed MONGO dissector infinite loop (bsc#1251933). wireshark-4.2.14-150600.18.29.1.src.rpm wireshark-devel-4.2.14-150600.18.29.1.x86_64.rpm wireshark-ui-qt-4.2.14-150600.18.29.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-3775 Security update for MozillaFirefox important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for MozillaFirefox fixes the following issues: Update to Firefox Extended Support Release 140.4.0 ESR (bsc#1251263). - CVE-2025-11708: Use-after-free in MediaTrackGraphImpl::GetInstance() - CVE-2025-11709: Out of bounds read/write in a privileged process triggered by WebGL textures - CVE-2025-11710: Cross-process information leaked due to malicious IPC messages - CVE-2025-11711: Some non-writable Object properties could be modified - CVE-2025-11712: An OBJECT tag type attribute overrode browser behavior on web resources without a content-type - CVE-2025-11713: Potential user-assisted code execution in “Copy as cURL” command - CVE-2025-11714: Memory safety bugs fixed in Firefox ESR 115.29, Firefox ESR 140.4, Thunderbird ESR 140.4, Firefox 144 and Thunderbird 144 - CVE-2025-11715: Memory safety bugs fixed in Firefox ESR 140.4, Thunderbird ESR 140.4, Firefox 144 and Thunderbird 144 MozillaFirefox-140.4.0-150200.152.207.1.src.rpm MozillaFirefox-140.4.0-150200.152.207.1.x86_64.rpm MozillaFirefox-devel-140.4.0-150200.152.207.1.noarch.rpm MozillaFirefox-translations-common-140.4.0-150200.152.207.1.x86_64.rpm MozillaFirefox-translations-other-140.4.0-150200.152.207.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-3845 Security update for fetchmail moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for fetchmail fixes the following issues: - CVE-2025-61962: fixed a denial of service condition (bsc#1251194) fetchmail-6.4.22-150600.35.3.1.src.rpm fetchmailconf-6.4.22-150600.35.3.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-3867 Security update for ImageMagick moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for ImageMagick fixes the following issues: - CVE-2025-62171: Fixed incomplete fix for integer overflow in BMP Decoder (bsc#1252282). ImageMagick-7.1.1.43-150700.3.19.1.src.rpm ImageMagick-7.1.1.43-150700.3.19.1.x86_64.rpm ImageMagick-config-7-SUSE-7.1.1.43-150700.3.19.1.x86_64.rpm ImageMagick-config-7-upstream-limited-7.1.1.43-150700.3.19.1.x86_64.rpm ImageMagick-config-7-upstream-open-7.1.1.43-150700.3.19.1.x86_64.rpm ImageMagick-config-7-upstream-secure-7.1.1.43-150700.3.19.1.x86_64.rpm ImageMagick-config-7-upstream-websafe-7.1.1.43-150700.3.19.1.x86_64.rpm ImageMagick-devel-7.1.1.43-150700.3.19.1.x86_64.rpm libMagick++-7_Q16HDRI5-7.1.1.43-150700.3.19.1.x86_64.rpm libMagick++-devel-7.1.1.43-150700.3.19.1.x86_64.rpm libMagickCore-7_Q16HDRI10-7.1.1.43-150700.3.19.1.x86_64.rpm libMagickWand-7_Q16HDRI10-7.1.1.43-150700.3.19.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-3796 Security update for ImageMagick moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for ImageMagick fixes the following issues: - CVE-2025-62171: Fixed incomplete fix for integer overflow in BMP Decoder (bsc#1252282). ImageMagick-7.1.0.9-150400.6.46.1.src.rpm ImageMagick-config-7-upstream-7.1.0.9-150400.6.46.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-3860 Optional update for firewalld-legacy low SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for firewalld-legacy fixes the following issues: - Provide v1.3.4 as installable option due to slow firewall rule generation introduced in the 2.x.x series (jsc#PED-13314). firewall-applet-1.3.4-150600.13.3.1.noarch.rpm firewall-config-1.3.4-150600.13.3.1.noarch.rpm firewalld-1.3.4-150600.13.3.1.src.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-3946 Security update for openjpeg moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for openjpeg fixes the following issues: - CVE-2023-39327: Fixed that malicious files can cause a large loop that continuously prints warning messages on the terminal (bsc#1227410). Other bug fixes: - Ensure no bundled libraries are used (bsc#1250467). libopenjpeg1-1.5.2-150000.4.15.1.x86_64.rpm openjpeg-1.5.2-150000.4.15.1.src.rpm openjpeg-devel-1.5.2-150000.4.15.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-3947 Security update for jasper moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for jasper fixes the following issues: - Update to 4.2.8: - CVE-2025-8837: Fixed a bug in the JPC decoder that could cause bad memory accesses if the debug level is set sufficiently high (bsc#1247901). - CVE-2025-8836: Added some missing range checking on several coding parameters in the JPC encoder (bsc#1247902). - CVE-2025-8835: Added a check for a missing color component in the jas_image_chclrspc function (bsc#1247904). - CVE-2023-51257: Fixed invalid memory write bug (bsc#1218802). jasper-4.2.8-150600.4.5.1.src.rpm libjasper-devel-4.2.8-150600.4.5.1.x86_64.rpm libjasper7-4.2.8-150600.4.5.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-1870 Security update for mozjs115 important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for mozjs115 fixes the following issues - CVE-2026-32776: libexpat: NULL pointer dereference when processing empty external parameter entities inside an entity declaration value (bsc#1259728). - CVE-2026-32777: libexpat: denial of service due to infinite loop in DTD content parsing (bsc#1259713). - CVE-2026-32778: libexpat: NULL pointer dereference in `setContext` on retry after an out-of-memory condition (bsc#1259731). libmozjs-115-0-115.4.0-150600.3.14.1.x86_64.rpm mozjs115-115.4.0-150600.3.14.1.src.rpm mozjs115-devel-115.4.0-150600.3.14.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-3956 Security update for ImageMagick moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for ImageMagick fixes the following issues: - CVE-2025-62594: Fixed unsigned underflow and division-by-zero that can lead to OOB pointer arithmetic and process crash. (bsc#1252749) ImageMagick-7.1.1.43-150700.3.22.1.src.rpm ImageMagick-7.1.1.43-150700.3.22.1.x86_64.rpm ImageMagick-config-7-SUSE-7.1.1.43-150700.3.22.1.x86_64.rpm ImageMagick-config-7-upstream-limited-7.1.1.43-150700.3.22.1.x86_64.rpm ImageMagick-config-7-upstream-open-7.1.1.43-150700.3.22.1.x86_64.rpm ImageMagick-config-7-upstream-secure-7.1.1.43-150700.3.22.1.x86_64.rpm ImageMagick-config-7-upstream-websafe-7.1.1.43-150700.3.22.1.x86_64.rpm ImageMagick-devel-7.1.1.43-150700.3.22.1.x86_64.rpm libMagick++-7_Q16HDRI5-7.1.1.43-150700.3.22.1.x86_64.rpm libMagick++-devel-7.1.1.43-150700.3.22.1.x86_64.rpm libMagickCore-7_Q16HDRI10-7.1.1.43-150700.3.22.1.x86_64.rpm libMagickWand-7_Q16HDRI10-7.1.1.43-150700.3.22.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-3985 Security update for ImageMagick moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for ImageMagick fixes the following issues: - CVE-2025-62594: Fixed unsigned underflow and division-by-zero that can lead to OOB pointer arithmetic and process crash. (bsc#1252749) ImageMagick-7.1.0.9-150400.6.51.1.src.rpm ImageMagick-config-7-upstream-7.1.0.9-150400.6.51.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-4067 Security update for openssh moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for openssh fixes the following issues: - CVE-2025-61984: Fixed code execution via control characters in usernames when a ProxyCommand is used (bsc#1251198) - CVE-2025-61985: Fixed code execution via '\0' character in ssh:// URI when a ProxyCommand is used (bsc#1251199) openssh-askpass-gnome-9.6p1-150600.6.34.1.src.rpm openssh-askpass-gnome-9.6p1-150600.6.34.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-4223 Recommended update for glu important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for glu fixes the following issues: - Fix the %licence tag (bsc#1252149) * Add missing LICENSE file * Fix license string glu-9.0.0-150200.10.3.1.src.rpm glu-devel-9.0.0-150200.10.3.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-4173 Security update for MozillaFirefox important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for MozillaFirefox fixes the following issues: - Update to Firefox Extended Support Release 140.5.0 ESR (bsc#1253188) - CVE-2025-13012: Race condition in the Graphics component. - CVE-2025-13016: Incorrect boundary conditions in the JavaScript: WebAssembly component. - CVE-2025-13017: Same-origin policy bypass in the DOM: Notifications component. - CVE-2025-13018: Mitigation bypass in the DOM: Security component. - CVE-2025-13019: Same-origin policy bypass in the DOM: Workers component. - CVE-2025-13013: Mitigation bypass in the DOM: Core & HTML component. - CVE-2025-13020: Use-after-free in the WebRTC: Audio/Video component. - CVE-2025-13014: Use-after-free in the Audio/Video component. - CVE-2025-13015: Spoofing issue in Firefox. MozillaFirefox-140.5.0-150200.152.210.1.src.rpm MozillaFirefox-140.5.0-150200.152.210.1.x86_64.rpm MozillaFirefox-devel-140.5.0-150200.152.210.1.noarch.rpm MozillaFirefox-translations-common-140.5.0-150200.152.210.1.x86_64.rpm MozillaFirefox-translations-other-140.5.0-150200.152.210.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-4118 Recommended update for freetype2 important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for freetype2 fixes the following issues: - Fix the %licence tag (bsc#1252148) * package FTL.TXT and GPLv2.TXT as %license ft2demos-2.10.4-150000.4.25.1.nosrc.rpm ftdump-2.10.4-150000.4.25.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-4290 Security update for cups moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for cups fixes the following issues: - CVE-2025-61915: Fixed a local denial-of-service via cupsd.conf update and related issues. (bsc#1253783) - CVE-2025-58436: Fixed an issue where a slow client communication leads to a possible DoS attack. (bsc#1244057) cups-2.2.7-150000.3.77.1.src.rpm libcups2-32bit-2.2.7-150000.3.77.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-4291 Security update for libmicrohttpd important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for libmicrohttpd fixes the following issues: - CVE-2025-59777: Fixed NULL pointer dereference via specially crafted packet sent by an attacker (bsc#1253177) - CVE-2025-62689: Fixed heap-based buffer overflow via specially crafted packet sent by an attacker (bsc#1253178) libmicrohttpd-0.9.77-150600.3.3.1.src.rpm libmicrohttpd-devel-0.9.77-150600.3.3.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-4353 Security update for fontforge low SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for fontforge fixes the following issues: - CVE-2025-50949: Fixed a memory leak in the DlgCreate8 function. (bsc#1252652) fontforge-20200314-150200.3.12.1.src.rpm fontforge-20200314-150200.3.12.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-4319 Security update for cups important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for cups fixes the following issues: - The fix for CVE-2025-58436 causes a regression where GTK applications will hang. (bsc#1254353) See also https://github.com/OpenPrinting/cups/issues/1429 The fix has been temporary disabled. cups-2.2.7-150000.3.80.1.src.rpm libcups2-32bit-2.2.7-150000.3.80.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-4348 Recommended update for ibus important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for ibus fixes the following issues: - Fix: Barcode scanner input gets jumbled when ibus is running and an application written in certain frameworks has focus (bsc#1252250): * After libX11 is fixed about the XIM jumbled input issues, too quick focus change can causes a freeze with barcode reader * Fix the synchronous "ProcessKeyEvent" D-Bus method in ibus-x11 * Add ibus_input_context_set_post_process_key_event() and ibus_input_context_post_process_key_event() ibus-1.5.28-150600.3.3.1.src.rpm ibus-1.5.28-150600.3.3.1.x86_64.rpm ibus-devel-1.5.28-150600.3.3.1.x86_64.rpm ibus-dict-emoji-1.5.28-150600.3.3.1.noarch.rpm ibus-gtk-1.5.28-150600.3.3.1.x86_64.rpm ibus-gtk3-1.5.28-150600.3.3.1.x86_64.rpm ibus-lang-1.5.28-150600.3.3.1.noarch.rpm libibus-1_0-5-1.5.28-150600.3.3.1.x86_64.rpm typelib-1_0-IBus-1_0-1.5.28-150600.3.3.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-4425 Security update for cups moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for cups fixes the following issues: Security issues fixed: - CVE-2025-58436: single client sending slow messages to cupsd can delay the application and make it unusable for other clients (bsc#1244057). Other issues fixed: - Update the CVE-2025-58436 patch to fix a regression that causes GTK applications to hang (bsc#1254353). cups-2.2.7-150000.3.83.1.src.rpm libcups2-32bit-2.2.7-150000.3.83.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-21 Security update for webkit2gtk3 important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for webkit2gtk3 fixes the following issues: Update to version 2.50.4. Security issues fixed: - CVE-2025-13502: processing of maliciously crafted payloads by the GLib remote inspector server may lead to a UIProcess crash due to an out-of-bounds read and an integer underflow (bsc#1254208). - CVE-2025-13947: use of the file drag-and-drop mechanism may lead to remote information disclosure due to a lack of verification of the origins of drag operations (bsc#1254473). - CVE-2025-14174: processing maliciously crafted web content may lead to memory corruption due to improper validation (bsc#1255497). - CVE-2025-43392: websites may exfiltrate image data cross-origin due to issues with cache handling (bsc#1254165). - CVE-2025-43421: processing maliciously crafted web content may lead to an unexpected process crash due to enabled array allocation sinking (bsc#1254167). - CVE-2025-43425: processing maliciously crafted web content may lead to an unexpected process crash due to improper memory handling (bsc#1254168). - CVE-2025-43427: processing maliciously crafted web content may lead to an unexpected process crash due to issues with state management (bsc#1254169). - CVE-2025-43429: processing maliciously crafted web content may lead to an unexpected process crash due to a buffer overflow issue (bsc#1254174). - CVE-2025-43430: processing maliciously crafted web content may lead to an unexpected process crash due to issues with state management (bsc#1254172). - CVE-2025-43431: processing maliciously crafted web content may lead to memory corruption due to improper memory handling (bsc#1254170). - CVE-2025-43432: processing maliciously crafted web content may lead to an unexpected process crash due to a use-after-free issue (bsc#1254171). - CVE-2025-43434: processing maliciously crafted web content may lead to an unexpected process crash due to a use-after-free issue (bsc#1254179). - CVE-2025-43440: processing maliciously crafted web content may lead to an unexpected process crash due to missing checks (bsc#1254177). - CVE-2025-43443: processing maliciously crafted web content may lead to an unexpected process crash due to missing checks (bsc#1254176). - CVE-2025-43458: processing maliciously crafted web content may lead to an unexpected process crash due to issues with state management (bsc#1254498). - CVE-2025-43501: processing maliciously crafted web content may lead to an unexpected process crash due to a buffer overflow issue (bsc#1255194). - CVE-2025-43529: processing maliciously crafted web content may lead to arbitrary code execution due to a use-after-free issue (bsc#1255198). - CVE-2025-43531: processing maliciously crafted web content may lead to an unexpected process crash due to a race condition (bsc#1255183). - CVE-2025-43535: processing maliciously crafted web content may lead to an unexpected process crash due to improper memory handling (bsc#1255195). - CVE-2025-43536: processing maliciously crafted web content may lead to an unexpected process crash due to a use-after-free issue (bsc#1255200). - CVE-2025-43541: processing maliciously crafted web content may lead to an unexpected process crash due to type confusion (bsc#1255191). - CVE-2025-66287: processing maliciously crafted web content may lead to an unexpected process crash due to improper memory handling (bsc#1254509). Other issues fixed and changes: - Version 2.50.4: * Correctly handle the program name passed to the sleep disabler. * Ensure GStreamer is initialized before using the Quirks. * Fix several crashes and rendering issues. - Version 2.50.3: * Fix seeking and looping of media elements that set the "loop" property. * Fix several crashes and rendering issues. - Version 2.50.2: * Prevent unsafe URI schemes from participating in media playback. * Make jsc_value_array_buffer_get_data() function introspectable. * Fix logging in to Google accounts that have a WebAuthn second factor configured. * Fix loading webkit://gpu when there are no threads configured for GPU rendering. * Fix rendering gradiants that use the CSS hue interpolation method. * Fix pasting image data from the clipboard. * Fix font-family selection when the font name contains spaces. * Fix the build with standard C libraries that lack execinfo.h, like Musl or uClibc. * Fix capturing canvas snapshots in the Web Inspector. * Fix several crashes and rendering issues. - Fix a11y regression where AT-SPI roles were mapped incorrectly. WebKitGTK-4.1-lang-2.50.4-150600.12.54.1.noarch.rpm libjavascriptcoregtk-4_1-0-2.50.4-150600.12.54.1.x86_64.rpm libwebkit2gtk-4_1-0-2.50.4-150600.12.54.1.x86_64.rpm typelib-1_0-JavaScriptCore-4_1-2.50.4-150600.12.54.1.x86_64.rpm typelib-1_0-WebKit2-4_1-2.50.4-150600.12.54.1.x86_64.rpm typelib-1_0-WebKit2WebExtension-4_1-2.50.4-150600.12.54.1.x86_64.rpm webkit2gtk-4_1-injected-bundles-2.50.4-150600.12.54.1.x86_64.rpm webkit2gtk3-2.50.4-150600.12.54.1.src.rpm webkit2gtk3-devel-2.50.4-150600.12.54.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-4424 Security update for MozillaFirefox important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for MozillaFirefox fixes the following issues: Update to Firefox Extended Support Release 140.6.0 ESR (bsc#1254551). - MFSA 2025-94 * CVE-2025-14321: use-after-free in the WebRTC: Signaling component. * CVE-2025-14322: sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component. * CVE-2025-14323: privilege escalation in the DOM: Notifications component. * CVE-2025-14324: JIT miscompilation in the JavaScript Engine: JIT component. * CVE-2025-14325: JIT miscompilation in the JavaScript Engine: JIT component. * CVE-2025-14328: privilege escalation in the Netmonitor component. * CVE-2025-14329: privilege escalation in the Netmonitor component. * CVE-2025-14330: JIT miscompilation in the JavaScript Engine: JIT component. * CVE-2025-14331: same-origin policy bypass in the Request Handling component. * CVE-2025-14333: memory safety bugs. MozillaFirefox-140.6.0-150200.152.213.1.src.rpm MozillaFirefox-140.6.0-150200.152.213.1.x86_64.rpm MozillaFirefox-devel-140.6.0-150200.152.213.1.noarch.rpm MozillaFirefox-translations-common-140.6.0-150200.152.213.1.x86_64.rpm MozillaFirefox-translations-other-140.6.0-150200.152.213.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-4427 Security update for ImageMagick important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for ImageMagick fixes the following issues: - CVE-2025-65955: possible use-after-free/double-free in `Options::fontFamily` when clearing a family can lead to crashes or memory corruption (bsc#1254435). - CVE-2025-66628: possible integer overflow in the TIM image parser's `ReadTIMImage` function can lead to arbitrary memory disclosure on 32-bit systems (bsc#1254820). ImageMagick-7.1.1.43-150700.3.27.1.src.rpm ImageMagick-7.1.1.43-150700.3.27.1.x86_64.rpm ImageMagick-config-7-SUSE-7.1.1.43-150700.3.27.1.x86_64.rpm ImageMagick-config-7-upstream-limited-7.1.1.43-150700.3.27.1.x86_64.rpm ImageMagick-config-7-upstream-open-7.1.1.43-150700.3.27.1.x86_64.rpm ImageMagick-config-7-upstream-secure-7.1.1.43-150700.3.27.1.x86_64.rpm ImageMagick-config-7-upstream-websafe-7.1.1.43-150700.3.27.1.x86_64.rpm ImageMagick-devel-7.1.1.43-150700.3.27.1.x86_64.rpm libMagick++-7_Q16HDRI5-7.1.1.43-150700.3.27.1.x86_64.rpm libMagick++-devel-7.1.1.43-150700.3.27.1.x86_64.rpm libMagickCore-7_Q16HDRI10-7.1.1.43-150700.3.27.1.x86_64.rpm libMagickWand-7_Q16HDRI10-7.1.1.43-150700.3.27.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-13 Security update for ImageMagick important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for ImageMagick fixes the following issues: - CVE-2025-65955: possible use-after-free/double-free in `Options::fontFamily` when clearing a family can lead to crashes or memory corruption (bsc#1254435). - CVE-2025-66628: possible integer overflow in the TIM image parser's `ReadTIMImage` function can lead to arbitrary memory disclosure on 32-bit systems (bsc#1254820). - CVE-2025-68469: crash due to heap buffer overflow when processing a specially crafted TIFF file (bsc#1255391). ImageMagick-7.1.0.9-150400.6.58.1.src.rpm ImageMagick-config-7-upstream-7.1.0.9-150400.6.58.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-4440 Security update for wireshark moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for wireshark fixes the following issues: - CVE-2025-13499: Fixed Kafka dissector crash due to malformed packet (bsc#1254108). - CVE-2025-13946: Fixed MEGACO dissector infinite loop that allows denial of service (bsc#1254472). wireshark-4.2.14-150600.18.32.1.src.rpm wireshark-devel-4.2.14-150600.18.32.1.x86_64.rpm wireshark-ui-qt-4.2.14-150600.18.32.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-4501 Security update for taglib low SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for taglib fixes the following issues: - CVE-2023-47466: application crash when processing specially crafted WAV files during tag writing operations (bsc#1243499). libtag-devel-1.13.1-150600.3.3.1.x86_64.rpm libtag_c0-1.13.1-150600.3.3.1.x86_64.rpm taglib-1.13.1-150600.3.3.1.src.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-44 Security update for mozjs60 moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for mozjs60 fixes the following issues: - CVE-2024-45492: embedded expat: detect integer overflow in function nextScaffoldPart (bsc#1230038) - CVE-2024-45491: embedded expat: detect integer overflow in dtdCopy (bsc#1230037) - CVE-2024-45490: embedded expat: reject negative len for XML_ParseBuffer (bsc#1230036) - CVE-2024-50602: libexpat: DoS via XML_ResumeParser (bsc#1232602) mozjs60-60.9.0-150200.6.8.1.src.rpm mozjs60-devel-60.9.0-150200.6.8.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-64 Recommended update for libmicrohttpd moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for libmicrohttpd fixes the following issues: - Fix: libmicrohttpd 0.9.77: test_tricky_url fails during %check (bsc#1254301). libmicrohttpd-0.9.77-150600.3.6.1.src.rpm libmicrohttpd-devel-0.9.77-150600.3.6.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-87 Security update for libheif moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for libheif fixes the following issues: - CVE-2025-68431: Fixed heap buffer over-read in `HeifPixelImage::overlay()` via crafted HEIF that exercises the overlay image item (bsc#1255735) libheif-1.19.5-150700.3.3.1.src.rpm libheif1-1.19.5-150700.3.3.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-73 Security update for ImageMagick moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for ImageMagick fixes the following issues: - CVE-2025-68618: read a malicious SVG file may result in a DoS attack (bsc#1255821). - CVE-2025-68950: check for circular references in mvg files may lead to stack overflow (bsc#1255822). - CVE-2025-69204: an integer overflow can lead to a DoS attack (bsc#1255823). ImageMagick-7.1.1.43-150700.3.30.1.src.rpm ImageMagick-7.1.1.43-150700.3.30.1.x86_64.rpm ImageMagick-config-7-SUSE-7.1.1.43-150700.3.30.1.x86_64.rpm ImageMagick-config-7-upstream-limited-7.1.1.43-150700.3.30.1.x86_64.rpm ImageMagick-config-7-upstream-open-7.1.1.43-150700.3.30.1.x86_64.rpm ImageMagick-config-7-upstream-secure-7.1.1.43-150700.3.30.1.x86_64.rpm ImageMagick-config-7-upstream-websafe-7.1.1.43-150700.3.30.1.x86_64.rpm ImageMagick-devel-7.1.1.43-150700.3.30.1.x86_64.rpm libMagick++-7_Q16HDRI5-7.1.1.43-150700.3.30.1.x86_64.rpm libMagick++-devel-7.1.1.43-150700.3.30.1.x86_64.rpm libMagickCore-7_Q16HDRI10-7.1.1.43-150700.3.30.1.x86_64.rpm libMagickWand-7_Q16HDRI10-7.1.1.43-150700.3.30.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-72 Security update for ImageMagick moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for ImageMagick fixes the following issues: - CVE-2025-68618: read a malicious SVG file may result in a DoS attack (bsc#1255821). - CVE-2025-68950: check for circular references in mvg files may lead to stack overflow (bsc#1255822). ImageMagick-7.1.0.9-150400.6.61.1.src.rpm ImageMagick-config-7-upstream-7.1.0.9-150400.6.61.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-243 Security update for librsvg moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for librsvg fixes the following issues: Update to version 2.57.4 - bsc#1243867: + CVE-2024-12224: RUSTSEC-2024-0421 - idna accepts Punycode labels that do not produce any non-ASCII when decoded. + RUSTSEC-2024-0404 - Unsoundness in anstream. librsvg-2.57.4-150600.3.3.1.src.rpm librsvg-devel-2.57.4-150600.3.3.1.x86_64.rpm typelib-1_0-Rsvg-2_0-2.57.4-150600.3.3.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-260 Security update for MozillaFirefox important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for MozillaFirefox fixes the following issues: Update to Firefox Extended Support Release 140.7.0 ESR (bsc#1256340). - MFSA 2026-03 * CVE-2026-0877: Mitigation bypass in the DOM: Security component * CVE-2026-0878: Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component * CVE-2026-0879: Sandbox escape due to incorrect boundary conditions in the Graphics component * CVE-2026-0880: Sandbox escape due to integer overflow in the Graphics component * CVE-2026-0882: Use-after-free in the IPC component * CVE-2025-14327: Spoofing issue in the Downloads Panel component * CVE-2026-0883: Information disclosure in the Networking component * CVE-2026-0884: Use-after-free in the JavaScript Engine component * CVE-2026-0885: Use-after-free in the JavaScript: GC component * CVE-2026-0886: Incorrect boundary conditions in the Graphics component * CVE-2026-0887: Clickjacking issue, information disclosure in the PDF Viewer component * CVE-2026-0890: Spoofing issue in the DOM: Copy-Paste and Drag-Drop component * CVE-2026-0891: Memory safety bugs fixed in Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 147 MozillaFirefox-140.7.0-150200.152.216.1.src.rpm MozillaFirefox-140.7.0-150200.152.216.1.x86_64.rpm MozillaFirefox-devel-140.7.0-150200.152.216.1.noarch.rpm MozillaFirefox-translations-common-140.7.0-150200.152.216.1.x86_64.rpm MozillaFirefox-translations-other-140.7.0-150200.152.216.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-259 Security update for avahi moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for avahi fixes the following issues: - CVE-2025-68276: Fixed refuse to create wide-area record browsers when wide-area is off (bsc#1256498) - CVE-2025-68471: Fixed DoS bug by changing assert to return (bsc#1256500) - CVE-2025-68468: Fixed DoS bug by removing incorrect assertion (bsc#1256499) avahi-0.8-150600.15.12.1.src.rpm avahi-autoipd-0.8-150600.15.12.1.x86_64.rpm avahi-glib2-0.8-150600.15.12.1.src.rpm avahi-utils-gtk-0.8-150600.15.12.1.x86_64.rpm libavahi-gobject-devel-0.8-150600.15.12.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-201 Recommended update for libheif moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for libheif fixes the following issue: - missing aom, jpeg, dav1d, ffmpeg plugins are shipped to the Desktop Applications module (bsc#1249446). libheif-1.19.5-150700.3.5.1.src.rpm libheif-aom-1.19.5-150700.3.5.1.x86_64.rpm libheif-dav1d-1.19.5-150700.3.5.1.x86_64.rpm libheif-jpeg-1.19.5-150700.3.5.1.x86_64.rpm libheif-rav1e-1.19.5-150700.3.5.1.x86_64.rpm libheif1-1.19.5-150700.3.5.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-237 Security update for wireshark moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for wireshark fixes the following issues: - CVE-2026-0959: IEEE 802.11 dissector crash (bsc#1256734). - CVE-2026-0960: HTTP3 dissector infinite loop (bsc#1256736). - CVE-2026-0962: SOME/IP-SD dissector crash (bsc#1256739). wireshark-4.2.14-150600.18.35.1.src.rpm wireshark-devel-4.2.14-150600.18.35.1.x86_64.rpm wireshark-ui-qt-4.2.14-150600.18.35.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-437 Security update for ImageMagick important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for ImageMagick fixes the following issues: - CVE-2026-22770: improper pointer initialization can cause denial of service (bsc#1256969). - CVE-2026-23874: manipulation of digital images can lead to stack overflow (bsc#1256976). - CVE-2026-23876: maliciously crafted image can lead to heap buffer overflow (bsc#1256962). - CVE-2026-23952: processing comment tag can cause null pointer dereference (bsc#1257076). ImageMagick-7.1.1.43-150700.3.33.1.src.rpm ImageMagick-7.1.1.43-150700.3.33.1.x86_64.rpm ImageMagick-config-7-SUSE-7.1.1.43-150700.3.33.1.x86_64.rpm ImageMagick-config-7-upstream-limited-7.1.1.43-150700.3.33.1.x86_64.rpm ImageMagick-config-7-upstream-open-7.1.1.43-150700.3.33.1.x86_64.rpm ImageMagick-config-7-upstream-secure-7.1.1.43-150700.3.33.1.x86_64.rpm ImageMagick-config-7-upstream-websafe-7.1.1.43-150700.3.33.1.x86_64.rpm ImageMagick-devel-7.1.1.43-150700.3.33.1.x86_64.rpm libMagick++-7_Q16HDRI5-7.1.1.43-150700.3.33.1.x86_64.rpm libMagick++-devel-7.1.1.43-150700.3.33.1.x86_64.rpm libMagickCore-7_Q16HDRI10-7.1.1.43-150700.3.33.1.x86_64.rpm libMagickWand-7_Q16HDRI10-7.1.1.43-150700.3.33.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-503 Security update for ImageMagick important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for ImageMagick fixes the following issues: - CVE-2026-23874: manipulation of digital images can lead to stack overflow (bsc#1256976). - CVE-2026-23876: maliciously crafted image can lead to heap buffer overflow (bsc#1256962). - CVE-2026-23952: processing comment tag can cause null pointer dereference (bsc#1257076). ImageMagick-7.1.0.9-150400.6.64.1.src.rpm ImageMagick-config-7-upstream-7.1.0.9-150400.6.64.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-428 Recommended update for open-vm-tools moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for open-vm-tools fixes the following issues: - update to 13.0.10 based on build 25056151: (bsc#1257357): * There are no new features in the open-vm-tools 13.0.10 release. * This is primarily a maintenance release that addresses a fix. * A minor enhancement has been made for Guest OS Customization. * The DeployPkg plugin has been updated to handle a new cloud-init error code that signals a recoverable error and allow cloud-init to finish running. open-vm-tools-13.0.10-150600.3.24.1.src.rpm open-vm-tools-desktop-13.0.10-150600.3.24.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-780 Security update for tracker-miners moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for tracker-miners fixes the following issues: - CVE-2026-1764: heap buffer overflow leads to denial of service or information disclosure when parsing MP3 files (bsc#1257606). - CVE-2026-1765: denial of Service and potential information disclosure via crafted MP3 files (bsc#1257607). - CVE-2026-1766: denial of Service and information disclosure via malformed MP3 files (bsc#1257608). - CVE-2026-1767: heap buffer overflow leading to denial of service or information disclosure via malformed MP3 ID3 tags (bsc#1257609). tracker-miner-files-3.6.2-150600.4.6.1.x86_64.rpm tracker-miners-3.6.2-150600.4.6.1.src.rpm tracker-miners-3.6.2-150600.4.6.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-820 Recommended update for libnvidia-egl-wayland moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for libnvidia-egl-wayland fixes the following issues: - update to version 1.1.22: * egl-wayland: remove extraneous call to wl_display_rou - update to version 1.1.21: * fix loading libdrm when wl_drm is not available * add FP16 DRM format - requires some fixes to the core driver to fully work however - fixed build against sle15-sp6/Leap 15.6 libnvidia-egl-wayland-1.1.22-150700.3.9.1.src.rpm libnvidia-egl-wayland1-32bit-1.1.22-150700.3.9.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-1036 Recommended update for libnvidia-egl-x11 moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for libnvidia-egl-x11 fixes the following issues: - bump version number to 1.0.5: * fix building on FreeBSD * rename a patch - update to v1.0.4 tarball/version 1.0.5: * fix attribute handling for eglCreateWindowPixmapSur * handle eglQuerySurface EGL_RENDER_BUFFER * enable implicit sync if we re-talking to the NVIDIA libnvidia-egl-x11-1.0.5-150700.4.9.1.src.rpm libnvidia-egl-x11-devel-1.0.5-150700.4.9.1.x86_64.rpm libnvidia-egl-x111-1.0.5-150700.4.9.1.x86_64.rpm libnvidia-egl-x111-32bit-1.0.5-150700.4.9.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-611 Security update for MozillaFirefox important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for MozillaFirefox fixes the following issues: - Update to Firefox 140.7.1 ESR - CVE-2026-2447: Fixed a heap buffer overflow in libvpx. (bsc#1258231) MozillaFirefox-140.7.1-150200.152.219.1.src.rpm MozillaFirefox-140.7.1-150200.152.219.1.x86_64.rpm MozillaFirefox-devel-140.7.1-150200.152.219.1.noarch.rpm MozillaFirefox-translations-common-140.7.1-150200.152.219.1.x86_64.rpm MozillaFirefox-translations-other-140.7.1-150200.152.219.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-1169 Security update for wireshark important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for wireshark fixes the following issues: Update Wireshark to version 4.6.4 (jsc#PED-15400). - CVE-2024-9780: ITS dissector crash (bsc#1231475). - CVE-2024-9781: AppleTalk and RELOAD Framing dissector crash (bsc#1231476). - CVE-2024-11595: Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark (bsc#1233594). - CVE-2024-11596: Buffer Over-read in Wireshark (bsc#1233593). - CVE-2025-1492: Uncontrolled Recursion in Wireshark (bsc#1237414). - CVE-2025-5601: Column handling crashes in Wireshark allows denial of service (bsc#1244081). - CVE-2025-9817: NULL Pointer Dereference in ssh dissector (bsc#1249090). - CVE-2025-13499: a malformed packet can lead to a Kafka dissector crash (bsc#1254108). - CVE-2025-13674: injecting a malformed packet can cause a crash (bsc#1254262). - CVE-2025-13945: HTTP3 dissector crash in Wireshark 4.6.0 and 4.6.1 allows denial of service (bsc#1254471). - CVE-2025-13946: MEGACO dissector infinite loop in Wireshark 4.6.0 to 4.6.1 and 4.4.0 to 4.4.11 allows denial of service (bsc#1254472). - CVE-2026-0959: denial of service via IEEE 802.11 protocol dissector crash (bsc#1256734). - CVE-2026-0960: denial of Service via HTTP3 protocol dissector infinite loop (bsc#1256736). - CVE-2026-0961: denial of Service vulnerability in BLF file parser (bsc#1256738). - CVE-2026-0962: denial of Service via SOME/IP-SD protocol dissector crash (bsc#1256739). - CVE-2026-3201: missing limit checks in USB HID protocol dissector's `parse_report_descriptor` function can lead to memory exhaustion (bsc#1258907). - CVE-2026-3202: missing checks in NTS-KE protocol dissector can lead to crash (bsc#1258908). - CVE-2026-3203: missing length checks in the RF4CE Profile protocol dissector can lead to illegal memory access and crash (bsc#1258909). Also libvirt was rebuilt against wireshark for the libvirt plugin. wireshark-4.6.4-150700.21.8.1.src.rpm wireshark-devel-4.6.4-150700.21.8.1.x86_64.rpm wireshark-ui-qt-4.6.4-150700.21.8.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-871 Security update for MozillaFirefox important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for MozillaFirefox fixes the following issues: Update to Firefox Extended Support Release 140.8.0 ESR (MFSA 2026-15) (bsc#1258568): - CVE-2026-2757: Incorrect boundary conditions in the WebRTC: Audio/Video component - CVE-2026-2758: Use-after-free in the JavaScript: GC component - CVE-2026-2759: Incorrect boundary conditions in the Graphics: ImageLib component - CVE-2026-2760: Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component - CVE-2026-2761: Sandbox escape in the Graphics: WebRender component - CVE-2026-2762: Integer overflow in the JavaScript: Standard Library component - CVE-2026-2763: Use-after-free in the JavaScript Engine component - CVE-2026-2764: JIT miscompilation, use-after-free in the JavaScript Engine: JIT component - CVE-2026-2765: Use-after-free in the JavaScript Engine component - CVE-2026-2766: Use-after-free in the JavaScript Engine: JIT component - CVE-2026-2767: Use-after-free in the JavaScript: WebAssembly component - CVE-2026-2768: Sandbox escape in the Storage: IndexedDB component - CVE-2026-2769: Use-after-free in the Storage: IndexedDB component - CVE-2026-2770: Use-after-free in the DOM: Bindings (WebIDL) component - CVE-2026-2771: Undefined behavior in the DOM: Core & HTML component - CVE-2026-2772: Use-after-free in the Audio/Video: Playback component - CVE-2026-2773: Incorrect boundary conditions in the Web Audio component - CVE-2026-2774: Integer overflow in the Audio/Video component - CVE-2026-2775: Mitigation bypass in the DOM: HTML Parser component - CVE-2026-2776: Sandbox escape due to incorrect boundary conditions in the Telemetry component in External Software - CVE-2026-2777: Privilege escalation in the Messaging System component - CVE-2026-2778: Sandbox escape due to incorrect boundary conditions in the DOM: Core & HTML component - CVE-2026-2779: Incorrect boundary conditions in the Networking: JAR component - CVE-2026-2780: Privilege escalation in the Netmonitor component - CVE-2026-2781: Integer overflow in the Libraries component in NSS - CVE-2026-2782: Privilege escalation in the Netmonitor component - CVE-2026-2783: Information disclosure due to JIT miscompilation in the JavaScript Engine: JIT component - CVE-2026-2784: Mitigation bypass in the DOM: Security component - CVE-2026-2785: Invalid pointer in the JavaScript Engine component - CVE-2026-2786: Use-after-free in the JavaScript Engine component - CVE-2026-2787: Use-after-free in the DOM: Window and Location component - CVE-2026-2788: Incorrect boundary conditions in the Audio/Video: GMP component - CVE-2026-2789: Use-after-free in the Graphics: ImageLib component - CVE-2026-2790: Same-origin policy bypass in the Networking: JAR component - CVE-2026-2791: Mitigation bypass in the Networking: Cache component - CVE-2026-2792: Memory safety bugs fixed in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148 - CVE-2026-2793: Memory safety bugs fixed in Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148 MozillaFirefox-140.8.0-150200.152.222.1.src.rpm MozillaFirefox-140.8.0-150200.152.222.1.x86_64.rpm MozillaFirefox-devel-140.8.0-150200.152.222.1.noarch.rpm MozillaFirefox-translations-common-140.8.0-150200.152.222.1.x86_64.rpm MozillaFirefox-translations-other-140.8.0-150200.152.222.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-851 Security update for ImageMagick important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for ImageMagick fixes the following issues: - CVE-2026-24481: Possible Heap Information Disclosure in PSD ZIP Decompression (bsc#1258743). - CVE-2026-24484: denial of service vulnerability via multi-layer nested MVG to SVG conversion (bsc#1258790). - CVE-2026-24485: denial of service via malformed PCD file processing (bsc#1258791). - CVE-2026-25576: Out of bounds read in multiple coders that read raw pixel data (bsc#1258748). - CVE-2026-25637: Denial of Service via crafted image due to memory leak (bsc#1258759). - CVE-2026-25638: Denial of Service due to memory leak in image processing (bsc#1258793). - CVE-2026-25795: Denial of Service due to NULL pointer dereference during temporary file creation failure (bsc#1258792). - CVE-2026-25796: Memory leak of watermark Image object in ReadSTEGANOImage on multiple error/early-return paths (bsc#1258757). - CVE-2026-25797: Code injection in various encoders (bsc#1258770). - CVE-2026-25798: NULL Pointer Dereference in ClonePixelCacheRepository via crafted image (bsc#1258787). - CVE-2026-25799: Division-by-Zero in YUV sampling factor validation leads to crash (bsc#1258786). - CVE-2026-25897: Out-of-bounds heap write via integer overflow in sun decoder (bsc#1258799). - CVE-2026-25898: Information disclosure or denial of service via crafted image with invalid pixel index (bsc#1258807). - CVE-2026-25965: Policy bypass through path traversal allows reading restricted content despite secured policy (bsc#1258785). - CVE-2026-25966: Security Policy Bypass through config/policy-secure.xml via "fd handler" leads to stdin/stdout access (bsc#1258780). - CVE-2026-25967: Stack buffer overflow in FTXT reader via oversized integer field (bsc#1258779). - CVE-2026-25968: MSL attribute stack buffer overflow leads to out of bounds write (bsc#1258776). - CVE-2026-25969: Memory Leak in coders/ashlar.c (bsc#1258775). - CVE-2026-25970: Memory corruption and denial of service via signed integer overflow in SIXEL decoder (bsc#1258802). - CVE-2026-25971: MSL: Stack overflow in ProcessMSLScript (bsc#1258774). - CVE-2026-25982: Heap Out-of-Bounds Read in DCM Decoder (bsc#1258772). - CVE-2026-25983: Denial of service via crafted MSL script (bsc#1258805). - CVE-2026-25985: Memory allocation with excessive without limits in the internal SVG decoder (bsc#1258812). - CVE-2026-25986: Denial of Service via malicious YUV image processing (bsc#1258818). - CVE-2026-25987: Memory disclosure and denial of service via crafted MAP files (bsc#1258821). - CVE-2026-25988: Denial of Service due to memory leak in image processing (bsc#1258810). - CVE-2026-25989: Integer overflow or wraparound and incorrect conversion between numeric types in the internal SVG decoder (bsc#1258771). - CVE-2026-26066: Infinite loop when writing IPTCTEXT leads to denial of service via crafted profile (bsc#1258769). - CVE-2026-26283: Possible infinite loop in JPEG encoder when using `jpeg: extent` (bsc#1258767). - CVE-2026-26284: Heap overflow in pcd decoder leads to out of bounds read (bsc#1258765). - CVE-2026-26983: Invalid MSL <map> can result in a use after free (bsc#1258763). - CVE-2026-27798: Heap Buffer Over-read in WaveletDenoise when processing small images (bsc#1259018). - CVE-2026-27799: ImageMagick has a heap Buffer Over-read in its DJVU image format handler (bsc#1259017). ImageMagick-7.1.1.43-150700.3.37.1.src.rpm ImageMagick-7.1.1.43-150700.3.37.1.x86_64.rpm ImageMagick-config-7-SUSE-7.1.1.43-150700.3.37.1.x86_64.rpm ImageMagick-config-7-upstream-limited-7.1.1.43-150700.3.37.1.x86_64.rpm ImageMagick-config-7-upstream-open-7.1.1.43-150700.3.37.1.x86_64.rpm ImageMagick-config-7-upstream-secure-7.1.1.43-150700.3.37.1.x86_64.rpm ImageMagick-config-7-upstream-websafe-7.1.1.43-150700.3.37.1.x86_64.rpm ImageMagick-devel-7.1.1.43-150700.3.37.1.x86_64.rpm libMagick++-7_Q16HDRI5-7.1.1.43-150700.3.37.1.x86_64.rpm libMagick++-devel-7.1.1.43-150700.3.37.1.x86_64.rpm libMagickCore-7_Q16HDRI10-7.1.1.43-150700.3.37.1.x86_64.rpm libMagickWand-7_Q16HDRI10-7.1.1.43-150700.3.37.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-853 Security update for ImageMagick important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for ImageMagick fixes the following issues: - CVE-2026-24481: Possible Heap Information Disclosure in PSD ZIP Decompression (bsc#1258743). - CVE-2026-24484: denial of service vulnerability via multi-layer nested MVG to SVG conversion (bsc#1258790). - CVE-2026-24485: denial of service via malformed PCD file processing (bsc#1258791). - CVE-2026-25576: Out of bounds read in multiple coders that read raw pixel data (bsc#1258748). - CVE-2026-25637: Denial of Service via crafted image due to memory leak (bsc#1258759). - CVE-2026-25638: Denial of Service due to memory leak in image processing (bsc#1258793). - CVE-2026-25795: Denial of Service due to NULL pointer dereference during temporary file creation failure (bsc#1258792). - CVE-2026-25796: Memory leak of watermark Image object in ReadSTEGANOImage on multiple error/early-return paths (bsc#1258757). - CVE-2026-25797: Code injection in various encoders (bsc#1258770). - CVE-2026-25798: NULL Pointer Dereference in ClonePixelCacheRepository via crafted image (bsc#1258787). - CVE-2026-25799: Division-by-Zero in YUV sampling factor validation leads to crash (bsc#1258786). - CVE-2026-25897: Out-of-bounds heap write via integer overflow in sun decoder (bsc#1258799). - CVE-2026-25898: Information disclosure or denial of service via crafted image with invalid pixel index (bsc#1258807). - CVE-2026-25965: Policy bypass through path traversal allows reading restricted content despite secured policy (bsc#1258785). - CVE-2026-25966: Security Policy Bypass through config/policy-secure.xml via "fd handler" leads to stdin/stdout access (bsc#1258780). - CVE-2026-25970: Memory corruption and denial of service via signed integer overflow in SIXEL decoder (bsc#1258802). - CVE-2026-25971: MSL: Stack overflow in ProcessMSLScript (bsc#1258774). - CVE-2026-25983: Denial of service via crafted MSL script (bsc#1258805). - CVE-2026-25986: Denial of Service via malicious YUV image processing (bsc#1258818). - CVE-2026-25987: Memory disclosure and denial of service via crafted MAP files (bsc#1258821). - CVE-2026-25988: Denial of Service due to memory leak in image processing (bsc#1258810). - CVE-2026-25989: Integer overflow or wraparound and incorrect conversion between numeric types in the internal SVG decoder (bsc#1258771). - CVE-2026-26066: Infinite loop when writing IPTCTEXT leads to denial of service via crafted profile (bsc#1258769). - CVE-2026-26284: Heap overflow in pcd decoder leads to out of bounds read (bsc#1258765). - CVE-2026-26983: Invalid MSL <map> can result in a use after free (bsc#1258763). - CVE-2026-27798: Heap Buffer Over-read in WaveletDenoise when processing small images (bsc#1259018). - CVE-2026-27799: ImageMagick has a heap Buffer Over-read in its DJVU image format handler (bsc#1259017). ImageMagick-7.1.0.9-150400.6.68.2.src.rpm ImageMagick-config-7-upstream-7.1.0.9-150400.6.68.2.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-929 Recommended update for gedit important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for gedit fixes the following issues: - Disable externaltools plugin to prevent crash (bsc#1255717). gedit-46.1-150600.3.3.1.src.rpm gedit-46.1-150600.3.3.1.x86_64.rpm gedit-devel-46.1-150600.3.3.1.x86_64.rpm gedit-lang-46.1-150600.3.3.1.noarch.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-910 Security update for vim moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for vim fixes the following issues: Update Vim to version 9.2.0110: - CVE-2025-53906: Fixed that malicious zip archive may cause a path traversal in Vim's zip (bsc#1246602). - CVE-2026-26269: Fixed Netbeans specialKeys stack buffer overflow (bsc#1258229). - CVE-2026-28417: Fixed that a crafted URL parsed by netrw plugin can lead to execute arbitrary shell commands (bsc#1259051). - CVE-2026-28418: Fixed that a malformed tags file can cause an heap-based buffer overflow out-of-bounds read (bsc#1259052) - CVE-2026-28419: Fixed processing a malformed tags file containing a delimiter can lead to a crash (bsc#1259053) - CVE-2026-28420: Fixed that processing maximum combining characters in terminal emulator can lead to heap-based buffer overflow write (bsc#1259054) - CVE-2026-28421: Fixed that a crafted swap file can cause a heap-buffer-overflow and a segmentation fault - CVE-2026-28422: Fixed that a malicious modeline or plugin can trigger a stack-buffer-overflow (bsc#1259056) gvim-9.2.0110-150500.20.43.1.x86_64.rpm vim-9.2.0110-150500.20.43.1.src.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-960 Security update for gvfs important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for gvfs fixes the following issues: - CVE-2026-28295: information disclosure when processing untrusted PASV responses from FTP servers (bsc#1258953). - CVE-2026-28296: arbitrary FTP command injection due to unsanitized CRLF sequences in user supplied file paths (bsc#1258954). gvfs-1.52.2-150600.3.3.1.src.rpm gvfs-1.52.2-150600.3.3.1.x86_64.rpm gvfs-backend-afc-1.52.2-150600.3.3.1.x86_64.rpm gvfs-backend-samba-1.52.2-150600.3.3.1.x86_64.rpm gvfs-backends-1.52.2-150600.3.3.1.x86_64.rpm gvfs-devel-1.52.2-150600.3.3.1.noarch.rpm gvfs-fuse-1.52.2-150600.3.3.1.x86_64.rpm gvfs-lang-1.52.2-150600.3.3.1.noarch.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-1202 Security update for ImageMagick important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for ImageMagick fixes the following issues: - CVE-2026-24484: denial of service vulnerability via multi-layer nested MVG to SVG conversion (bsc#1258790). - CVE-2026-28493: integer overflow in the SIXEL decoder leads to out-of-bounds write (bsc#1259446). - CVE-2026-28494: missing bounds checks in the morphology kernel parsing functions can lead to a stack buffer overflow (bsc#1259447). - CVE-2026-28686: undersized output buffer allocation in the PCL encoder can lead to a heap buffer overflow (bsc#1259448). - CVE-2026-28687: heap use-after-free vulnerability in the MSL decoder via a crafted MSL file (bsc#1259450). - CVE-2026-28688: heap use-after-free in the MSL encoder when a cloned image is destroyed twice (bsc#1259451). - CVE-2026-28689: `domain="path"` authorization is checked before final file open/use and allows for read/write bypass via symlink swaps (bsc#1259452). - CVE-2026-28690: missing bounds check in the MNG encoder can lead to a stack buffer overflow (bsc#1259456). - CVE-2026-28691: missing check in the JBIG decoder can lead to an uninitialized pointer dereference (bsc#1259455). - CVE-2026-28692: 32-bit integer overflow in MAT decoder can lead to a heap buffer over-read (bsc#1259457). - CVE-2026-28693: integer overflow in the DIB coder can lead to an out-of-bounds read or write (bsc#1259466). - CVE-2026-30883: missing bounds check when encoding a PNG image can lead to a heap buffer over-write (bsc#1259467). - CVE-2026-30929: improper use of fixed-size stack buffer in `MagnifyImage`can lead to a stack buffer overflow (bsc#1259468). - CVE-2026-30931: value truncation in the UHDR encoder can lead to a heap buffer overflow (bsc#1259469). - CVE-2026-30935: heap-based buffer over-read in BilateralBlurImage (bsc#1259497). - CVE-2026-30936: Heap Buffer Overflow in WaveletDenoiseImage (bsc#1259464). - CVE-2026-30937: Heap buffer overflow in XWD encoder due to CARD32 arithmetic overflow (bsc#1259463). - CVE-2026-31853: heap buffer overflow leads to crash in the SFW decoder of 32-bit systems when processing extremely large images (bsc#1259528). - CVE-2026-32259: memory allocation fails can lead to out of bound write (bsc#1259612). - CVE-2026-32636: Denial of Service via out-of-bounds write in NewXMLTree method (bsc#1259872). - CVE-2026-33535: Out-of-Bounds write of a zero byte in X11 display interaction (bsc#1260874). - CVE-2026-33536: Denial of Service via out-of-bounds write (bsc#1260879). ImageMagick-7.1.1.43-150700.3.42.1.src.rpm ImageMagick-7.1.1.43-150700.3.42.1.x86_64.rpm ImageMagick-config-7-SUSE-7.1.1.43-150700.3.42.1.x86_64.rpm ImageMagick-config-7-upstream-limited-7.1.1.43-150700.3.42.1.x86_64.rpm ImageMagick-config-7-upstream-open-7.1.1.43-150700.3.42.1.x86_64.rpm ImageMagick-config-7-upstream-secure-7.1.1.43-150700.3.42.1.x86_64.rpm ImageMagick-config-7-upstream-websafe-7.1.1.43-150700.3.42.1.x86_64.rpm ImageMagick-devel-7.1.1.43-150700.3.42.1.x86_64.rpm libMagick++-7_Q16HDRI5-7.1.1.43-150700.3.42.1.x86_64.rpm libMagick++-devel-7.1.1.43-150700.3.42.1.x86_64.rpm libMagickCore-7_Q16HDRI10-7.1.1.43-150700.3.42.1.x86_64.rpm libMagickWand-7_Q16HDRI10-7.1.1.43-150700.3.42.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-1497 Security update for ImageMagick important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for ImageMagick fixes the following issues: - CVE-2026-24484: denial of service via multi-layer nested MVG to SVG conversion (bsc#1258790). - CVE-2026-28493: integer overflow in the SIXEL decoder leads to out-of-bounds write (bsc#1259446). - CVE-2026-28494: missing bounds checks in the morphology kernel parsing functions can lead to a stack buffer overflow (bsc#1259447). - CVE-2026-28686: undersized output buffer allocation in the PCL encoder can lead to a heap buffer overflow (bsc#1259448). - CVE-2026-28687: heap use-after-free vulnerability in the MSL decoder via a crafted MSL file (bsc#1259450). - CVE-2026-28688: heap use-after-free in the MSL encoder when a cloned image is destroyed twice (bsc#1259451). - CVE-2026-28689: `domain="path"` authorization is checked before final file open/use and allows for read/write bypass via symlink swaps (bsc#1259452). - CVE-2026-28690: missing bounds check in the MNG encoder can lead to a stack buffer overflow (bsc#1259456). - CVE-2026-28691: missing check in the JBIG decoder can lead to an uninitialized pointer dereference (bsc#1259455). - CVE-2026-28692: 32-bit integer overflow in MAT decoder can lead to a heap buffer over-read (bsc#1259457). - CVE-2026-28693: integer overflow in the DIB coder can lead to an out-of-bounds read or write (bsc#1259466). - CVE-2026-30883: missing bounds check when encoding a PNG image can lead to a heap buffer over-write (bsc#1259467). - CVE-2026-30929: improper use of fixed-size stack buffer in `MagnifyImage`can lead to a stack buffer overflow (bsc#1259468). - CVE-2026-30936: heap buffer overflow in `WaveletDenoiseImage` (bsc#1259464). - CVE-2026-30937: heap buffer overflow in XWD encoder due to CARD32 arithmetic overflow (bsc#1259463). - CVE-2026-31853: heap buffer overflow leads to crash in the SFW decoder of 32-bit systems when processing extremely large images (bsc#1259528). - CVE-2026-32259: memory allocation failure in the SIXEL encoder can lead to a stack out-of-bound write (bsc#1259612). - CVE-2026-32636: denial of service via out-of-bounds write in `NewXMLTree` method (bsc#1259872). - CVE-2026-33535: out-of-Bounds write of a zero byte in X11 display interaction (bsc#1260874). - CVE-2026-33536: denial of Service via a stack out-of-bounds write in `InterpretImageFilename` (bsc#1260879). - CVE-2026-33905: denial of service via out-of-bounds read in `-sample` operation (bsc#1262097). ImageMagick-7.1.0.9-150400.6.75.1.src.rpm ImageMagick-config-7-upstream-7.1.0.9-150400.6.75.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-1161 Recommended update for gnome-shell important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for gnome-shell fixes the following issues: - Fix: L3: GDM smartcard login hangs/fails after PIN entry (bsc#1258238) * Don't assume this._user is always defined - Fix: GNOME Shell built-in screencast feature does not work (bsc#1235036) * Correct expected bus name for streams gnome-extensions-45.3-150700.11.3.1.x86_64.rpm gnome-shell-45.3-150700.11.3.1.src.rpm gnome-shell-45.3-150700.11.3.1.x86_64.rpm gnome-shell-devel-45.3-150700.11.3.1.x86_64.rpm gnome-shell-lang-45.3-150700.11.3.1.noarch.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-1660 Security update for libheif low SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for libheif fixes the following issues: - CVE-2026-3949: Manipulation of the argument size of a malicious frame can lead to out-of-bounds read (bsc#1259541). libheif-1.19.5-150700.3.8.1.src.rpm libheif-aom-1.19.5-150700.3.8.1.x86_64.rpm libheif-dav1d-1.19.5-150700.3.8.1.x86_64.rpm libheif-jpeg-1.19.5-150700.3.8.1.x86_64.rpm libheif-rav1e-1.19.5-150700.3.8.1.x86_64.rpm libheif1-1.19.5-150700.3.8.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-1364 Security update for webkit2gtk3 important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for webkit2gtk3 fixes the following issues: Update to version 2.52.0. Security issues fixed: - CVE-2023-43010: processing maliciously crafted web content may lead to memory corruption (bsc#1259950). - CVE-2025-31223: processing maliciously crafted web content may lead to memory corruption (bsc#1259949). - CVE-2025-31277: processing maliciously crafted web content may lead to memory corruption (bsc#1259948). - CVE-2025-43213: processing maliciously crafted web content may lead to an unexpected crash (bsc#1259947). - CVE-2025-43214: processing maliciously crafted web content may lead to an unexpected crash (bsc#1259946). - CVE-2025-43433: processing maliciously crafted web content may lead to memory corruption (bsc#1259945). - CVE-2025-43438: processing maliciously crafted web content may lead to an unexpected crash (bsc#1259944). - CVE-2025-43441: processing maliciously crafted web content may lead to an unexpected process crash (bsc#1259943). - CVE-2025-43457: processing maliciously crafted web content may lead to an unexpected crash (bsc#1259942). - CVE-2025-43511: processing maliciously crafted web content may lead to an unexpected process crash (bsc#1259941). - CVE-2025-46299: processing maliciously crafted web content may disclose internal states of an app (bsc#1259940). - CVE-2026-20608: processing maliciously crafted web content may lead to an unexpected process crash (bsc#1259939). - CVE-2026-20635: processing maliciously crafted web content may lead to an unexpected process crash (bsc#1259938). - CVE-2026-20636: processing maliciously crafted web content may lead to an unexpected process crash (bsc#1259937). - CVE-2026-20643: processing maliciously crafted web content may bypass Same Origin Policy (bsc#1261172). - CVE-2026-20644: processing maliciously crafted web content may lead to an unexpected process crash (bsc#1259936). - CVE-2026-20652: a remote attacker may be able to cause a denial-of-service (bsc#1259935). - CVE-2026-20664: processing maliciously crafted web content may lead to an unexpected process crash (bsc#1261173). - CVE-2026-20665: processing maliciously crafted web content may prevent Content Security Policy from being enforced (bsc#1261174). - CVE-2026-20676: a website may be able to track users through web extensions (bsc#1259934). - CVE-2026-20691: a maliciously crafted webpage may be able to fingerprint the user (bsc#1261175). - CVE-2026-28857: processing maliciously crafted web content may lead to an unexpected process crash (bsc#1261176). - CVE-2026-28859: a malicious website may be able to process restricted web content outside the sandbox (bsc#1261177). - CVE-2026-28861: a malicious website may be able to access script message handlers intended for other origins (bsc#1261178). - CVE-2026-28871: visiting a maliciously crafted website may lead to a cross-site scripting attack (bsc#1261179). Other updates and bugfixes: - Make scrolling with touch input smoother for small movements. - Fix estimated load progress of downloads when Content-Length value is wrong. - Ensure that "scrollend" events are correctly emitted after scroll animations. - Reduce the amount of useless MPRIS notifications produced by MediaSession when the information about media being played is incomplete. - Support turning off USE_GSTREAMER to configure the build with all multimedia features disabled. - Add Sysprof marks for mouse events. - Fix MediaSession icon for iheart.com not being displayed. - Fix the build with USE_GSTREAMER_GL disabled. - Fix the build with librice version 0.3.0 or newer. - Fix several crashes and rendering issues. - Translation updates: Georgian. WebKitGTK-4.1-lang-2.52.1-150600.12.63.1.noarch.rpm libjavascriptcoregtk-4_1-0-2.52.1-150600.12.63.1.x86_64.rpm libwebkit2gtk-4_1-0-2.52.1-150600.12.63.1.x86_64.rpm typelib-1_0-JavaScriptCore-4_1-2.52.1-150600.12.63.1.x86_64.rpm typelib-1_0-WebKit2-4_1-2.52.1-150600.12.63.1.x86_64.rpm typelib-1_0-WebKit2WebExtension-4_1-2.52.1-150600.12.63.1.x86_64.rpm webkit2gtk-4_1-injected-bundles-2.52.1-150600.12.63.1.x86_64.rpm webkit2gtk3-2.52.1-150600.12.63.1.src.rpm webkit2gtk3-devel-2.52.1-150600.12.63.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-1126 Security update for MozillaFirefox important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for MozillaFirefox fixes the following issues: Update to Firefox 140.9.0 ESR (MFSA 2026-22, bsc#1260083): - CVE-2026-4684: Race condition, use-after-free in the Graphics: WebRender component - CVE-2026-4685: Incorrect boundary conditions in the Graphics: Canvas2D component - CVE-2026-4686: Incorrect boundary conditions in the Graphics: Canvas2D component - CVE-2026-4687: Sandbox escape due to incorrect boundary conditions in the Telemetry component - CVE-2026-4688: Sandbox escape due to use-after-free in the Disability Access APIs component - CVE-2026-4689: Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component - CVE-2026-4690: Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component - CVE-2026-4691: Use-after-free in the CSS Parsing and Computation component - CVE-2026-4692: Sandbox escape in the Responsive Design Mode component - CVE-2026-4693: Incorrect boundary conditions in the Audio/Video: Playback component - CVE-2026-4694: Incorrect boundary conditions, integer overflow in the Graphics component - CVE-2026-4695: Incorrect boundary conditions in the Audio/Video: Web Codecs component - CVE-2026-4696: Use-after-free in the Layout: Text and Fonts component - CVE-2026-4697: Incorrect boundary conditions in the Audio/Video: Web Codecs component - CVE-2026-4698: JIT miscompilation in the JavaScript Engine: JIT component - CVE-2026-4699: Incorrect boundary conditions in the Layout: Text and Fonts component - CVE-2026-4700: Mitigation bypass in the Networking: HTTP component - CVE-2026-4701: Use-after-free in the JavaScript Engine component - CVE-2026-4702: JIT miscompilation in the JavaScript Engine component - CVE-2026-4704: Denial-of-service in the WebRTC: Signaling component - CVE-2026-4705: Undefined behavior in the WebRTC: Signaling component - CVE-2026-4706: Incorrect boundary conditions in the Graphics: Canvas2D component - CVE-2026-4707: Incorrect boundary conditions in the Graphics: Canvas2D component - CVE-2026-4708: Incorrect boundary conditions in the Graphics component - CVE-2026-4709: Incorrect boundary conditions in the Audio/Video: GMP component - CVE-2026-4710: Incorrect boundary conditions in the Audio/Video component - CVE-2026-4711: Use-after-free in the Widget: Cocoa component - CVE-2026-4712: Information disclosure in the Widget: Cocoa component - CVE-2026-4713: Incorrect boundary conditions in the Graphics component - CVE-2026-4714: Incorrect boundary conditions in the Audio/Video component - CVE-2026-4715: Uninitialized memory in the Graphics: Canvas2D component - CVE-2026-4716: Incorrect boundary conditions, uninitialized memory in the JavaScript Engine component - CVE-2026-4717: Privilege escalation in the Netmonitor component - CVE-2025-59375: Denial-of-service in the XML component - CVE-2026-4718: Undefined behavior in the WebRTC: Signaling component - CVE-2026-4719: Incorrect boundary conditions in the Graphics: Text component - CVE-2026-4720: Memory safety bugs fixed in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149 - CVE-2026-4721: Memory safety bugs fixed in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149 MozillaFirefox-140.9.0-150200.152.225.1.src.rpm MozillaFirefox-140.9.0-150200.152.225.1.x86_64.rpm MozillaFirefox-devel-140.9.0-150200.152.225.1.noarch.rpm MozillaFirefox-translations-common-140.9.0-150200.152.225.1.x86_64.rpm MozillaFirefox-translations-other-140.9.0-150200.152.225.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-1360 Security update for tigervnc important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for tigervnc fixes the following issues: - CVE-2026-34352: Fixed permissions to prevent other users from observing the screen, or modifying what is sent to the client. (bsc#1260871) libXvnc-devel-1.14.1-150700.4.3.1.x86_64.rpm tigervnc-1.14.1-150700.4.3.1.src.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-1443 Security update for NetworkManager moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for NetworkManager fixes the following issue: Security fixes: - CVE-2025-9615: Fixed non-admin user using others' certificates (bsc#1257359). Other fixes: - Fixed renew dhcp lease when software devices' MAC is empty (bsc#1225498, glfd#NetworkManager/NetworkManager#1587). NetworkManager-1.44.2-150600.3.7.1.src.rpm NetworkManager-1.44.2-150600.3.7.1.x86_64.rpm NetworkManager-wwan-1.44.2-150600.3.7.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-1441 Security update for avahi moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for avahi fixes the following issue: - CVE-2026-24401: avahi-daemon can be crashed via a segmentation fault by sending an unsolicited mDNS response containing a recursive CNAME record (bsc#1257235). avahi-0.8-150600.15.15.1.src.rpm avahi-autoipd-0.8-150600.15.15.1.x86_64.rpm avahi-glib2-0.8-150600.15.15.1.src.rpm avahi-utils-gtk-0.8-150600.15.15.1.x86_64.rpm libavahi-gobject-devel-0.8-150600.15.15.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-1607 Security update for vim important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for vim fixes the following issues: Update to version 9.2.0280. - CVE-2026-34982: missing input validation allows for a modeline sandbox bypass and can lead to arbitrary OS command execution (bsc#1261271). - CVE-2026-34714: missing checks allow for a `tabpanel` modeline escape and can lead to arbitrary OS command execution (bsc#1261191). - CVE-2026-33412: improper escaping of newline characters allows for command injection in `glob` and can lead to arbitrary code execution (bsc#1259985). gvim-9.2.0280-150500.20.46.1.x86_64.rpm vim-9.2.0280-150500.20.46.1.src.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-1555 Security update for libraw important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for libraw fixes the following issues: - CVE-2026-5342: out-of-bounds read via `LibRaw::nikon_load_padded_packed_raw` (bsc#1261499). - CVE-2026-20884: integer overflow and heap buffer overflow via `deflate_dng_load_raw` (bsc#1261671). - CVE-2026-20889: heap-based buffer overflow in `x3f_thumb_loader`(bsc#1261672). - CVE-2026-20911: heap-based buffer overflow in `HuffTable::initval`(bsc#1261673). - CVE-2026-21413: heap-based buffer overflow in `lossless_jpeg_load_raw` (bsc#1261674). - CVE-2026-24450: integer overflow and heap buffer overflow via `uncompressed_fp_dng_load_raw` (bsc#1261675). - CVE-2026-24660: heap-based buffer overflow in `x3f_load_huffman` (bsc#1261676). libraw-0.21.1-150600.3.10.1.src.rpm libraw23-0.21.1-150600.3.10.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-1322 Security update for MozillaFirefox important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for MozillaFirefox fixes the following issues: - Update to 149.0.2 and 140.9.1esr (bsc#1261663). - CVE-2026-5731: Memory safety bugs fixed in Firefox ESR 115.34.1, Firefox ESR 140.9.1, Thunderbird ESR 140.9.1, Firefox 149.0.2 and Thunderbird 149.0.2. - CVE-2026-5732: Incorrect boundary conditions, integer overflow in the Graphics: Text component. - CVE-2026-5734: Memory safety bugs fixed in Firefox ESR 140.9.1, Thunderbird ESR 140.9.1, Firefox 149.0.2 and Thunderbird 149.0.2. MozillaFirefox-140.9.1-150200.152.228.1.src.rpm MozillaFirefox-140.9.1-150200.152.228.1.x86_64.rpm MozillaFirefox-devel-140.9.1-150200.152.228.1.noarch.rpm MozillaFirefox-translations-common-140.9.1-150200.152.228.1.x86_64.rpm MozillaFirefox-translations-other-140.9.1-150200.152.228.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-1399 Security update for cups important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for cups fixes the following issue: - CVE-2026-34990: Local print admin token disclosure using temporary printers (bsc#1261568). cups-2.2.7-150000.3.86.1.src.rpm libcups2-32bit-2.2.7-150000.3.86.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-1598 Security update for ImageMagick important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for ImageMagick fixes the following issues: - CVE-2026-33899: Denial of Service via out-of-bounds write in XML parsing (bsc#1262154). - CVE-2026-33900: Denial of Service via integer truncation in viff encoder (bsc#1262156). - CVE-2026-33901: Denial of Service due to heap buffer overflow in MVG decoder (bsc#1262155). - CVE-2026-33902: Denial of Service via deeply nested expression in FX parser (bsc#1262153). - CVE-2026-33905: Denial of service via out-of-bounds read in -sample operation (bsc#1262097). - CVE-2026-33908: Denial of Service via deeply nested XML file processing (bsc#1262152). - CVE-2026-34238: Denial of Service via integer overflow in despeckle operation (bsc#1262147). - CVE-2026-40169: Denial of Service via crafted image leading to out-of-bounds write (bsc#1262150). - CVE-2026-40183: Denial of Service via heap write overflow in JXL encoder (bsc#1262145). - CVE-2026-40310: Denial of service via heap out-of-bounds write in JP2 encoder (bsc#1262148). - CVE-2026-40311: Denial of Service via heap use-after-free in XMP profile processing (bsc#1262146). - CVE-2026-40312: Denial of Service via malicious MSL file processing (bsc#1262149). ImageMagick-7.1.1.43-150700.3.47.1.src.rpm ImageMagick-7.1.1.43-150700.3.47.1.x86_64.rpm ImageMagick-config-7-SUSE-7.1.1.43-150700.3.47.1.x86_64.rpm ImageMagick-config-7-upstream-limited-7.1.1.43-150700.3.47.1.x86_64.rpm ImageMagick-config-7-upstream-open-7.1.1.43-150700.3.47.1.x86_64.rpm ImageMagick-config-7-upstream-secure-7.1.1.43-150700.3.47.1.x86_64.rpm ImageMagick-config-7-upstream-websafe-7.1.1.43-150700.3.47.1.x86_64.rpm ImageMagick-devel-7.1.1.43-150700.3.47.1.x86_64.rpm libMagick++-7_Q16HDRI5-7.1.1.43-150700.3.47.1.x86_64.rpm libMagick++-devel-7.1.1.43-150700.3.47.1.x86_64.rpm libMagickCore-7_Q16HDRI10-7.1.1.43-150700.3.47.1.x86_64.rpm libMagickWand-7_Q16HDRI10-7.1.1.43-150700.3.47.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-1600 Security update for flatpak important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for flatpak fixes the following issues: - CVE-2026-34078: Arbitrary code execution via crafted symlinks in sandbox-expose options (bsc#1261769). - CVE-2026-34079: Arbitrary file deletion on host via improper cache file path validation (bsc#1261770). flatpak-1.16.0-150600.3.9.1.src.rpm flatpak-1.16.0-150600.3.9.1.x86_64.rpm flatpak-devel-1.16.0-150600.3.9.1.x86_64.rpm flatpak-remote-flathub-1.16.0-150600.3.9.1.noarch.rpm flatpak-zsh-completion-1.16.0-150600.3.9.1.noarch.rpm libflatpak0-1.16.0-150600.3.9.1.x86_64.rpm system-user-flatpak-1.16.0-150600.3.9.1.noarch.rpm typelib-1_0-Flatpak-1_0-1.16.0-150600.3.9.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-2732 Security update for cups moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for cups fixes the following issues - CVE-2026-27447: Authorization bypass via case-insensitive group-member lookup (bsc#1261572). - CVE-2026-34978: Path traversal in RSS notify-recipient-uri enables file write outside CacheDir/rss (bsc#1261571). - CVE-2026-34979: Heap overflow in `get_options()` (bsc#1261570). - CVE-2026-34980: Shared PostScript queue lets anonymous Print-Job requests reach `lp` code execution over the network (bsc#1261569). - CVE-2026-39314: negative `job-password-supported` attribute can lead to a denial of service (bsc#1261743). - CVE-2026-39316: dangling subscription pointer can lead to a denial of service (1261742). cups-2.2.7-150000.3.93.1.src.rpm libcups2-32bit-2.2.7-150000.3.93.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-1649 Security update for MozillaFirefox important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for MozillaFirefox fixes the following issue: Update to Firefox Extended Support Release 140.10.0 ESR (bsc#1262230, MFSA 2026-32): - CVE-2026-6746: Use-after-free in the DOM: Core & HTML component. - CVE-2026-6747: Use-after-free in the WebRTC component. - CVE-2026-6748: Uninitialized memory in the Audio/Video: Web Codecs component. - CVE-2026-6749: Information disclosure due to uninitialized memory in the Graphics: Canvas2D component. - CVE-2026-6750: Privilege escalation in the Graphics: WebRender component. - CVE-2026-6751: Uninitialized memory in the Audio/Video: Web Codecs component. - CVE-2026-6752: Incorrect boundary conditions in the WebRTC component. - CVE-2026-6753: Incorrect boundary conditions in the WebRTC component. - CVE-2026-6754: Use-after-free in the JavaScript Engine component. - CVE-2026-6757: Invalid pointer in the JavaScript: WebAssembly component. - CVE-2026-6759: Use-after-free in the Widget: Cocoa component. - CVE-2026-6761: Privilege escalation in the Networking component. - CVE-2026-6762: Spoofing issue in the DOM: Core & HTML component. - CVE-2026-6763: Mitigation bypass in the File Handling component. - CVE-2026-6764: Incorrect boundary conditions in the DOM: Device Interfaces component. - CVE-2026-6765: Information disclosure in the Form Autofill component. - CVE-2026-6766: Incorrect boundary conditions in the Libraries component in NSS. - CVE-2026-6767: Other issue in the Libraries component in NSS. - CVE-2026-6769: Privilege escalation in the Debugger component. - CVE-2026-6770: Other issue in the Storage: IndexedDB component. - CVE-2026-6771: Mitigation bypass in the DOM: Security component. - CVE-2026-6772: Incorrect boundary conditions in the Libraries component in NSS. - CVE-2026-6776: Incorrect boundary conditions in the WebRTC: Networking component. - CVE-2026-6785: Memory safety bugs fixed in Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150. - CVE-2026-6786: Memory safety bugs fixed in Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150. MozillaFirefox-140.10.0-150200.152.231.1.src.rpm MozillaFirefox-140.10.0-150200.152.231.1.x86_64.rpm MozillaFirefox-devel-140.10.0-150200.152.231.1.noarch.rpm MozillaFirefox-translations-common-140.10.0-150200.152.231.1.x86_64.rpm MozillaFirefox-translations-other-140.10.0-150200.152.231.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-1636 Security update for fontforge important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for fontforge fixes the following issue: - CVE-2025-15270: Remote Code Execution via malicious SFD file parsing (bsc#1256031). fontforge-20200314-150200.3.15.1.src.rpm fontforge-20200314-150200.3.15.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-1939 Security update for PackageKit important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for PackageKit fixes the following issue: - CVE-2026-41651: race condition allows for arbitrary RPM package installation as root and can lead to LPE (bsc#1262220). PackageKit-1.2.8-150600.4.14.1.src.rpm True PackageKit-1.2.8-150600.4.14.1.x86_64.rpm True PackageKit-backend-zypp-1.2.8-150600.4.14.1.x86_64.rpm True PackageKit-devel-1.2.8-150600.4.14.1.x86_64.rpm True PackageKit-lang-1.2.8-150600.4.14.1.noarch.rpm True libpackagekit-glib2-18-1.2.8-150600.4.14.1.x86_64.rpm True libpackagekit-glib2-devel-1.2.8-150600.4.14.1.x86_64.rpm True typelib-1_0-PackageKitGlib-1_0-1.2.8-150600.4.14.1.x86_64.rpm True SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-1712 Security update for openexr important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for openexr fixes the following issues: - CVE-2026-40244: Integer overflow in DWA setupChannelData planarUncRle pointer arithmetic (bsc#1262426). - CVE-2026-40250: Integer overflow in DWA decoder outBufferEnd pointer arithmetic (bsc#1262425). libIlmImf-2_2-23-2.2.1-150000.3.46.1.x86_64.rpm libIlmImfUtil-2_2-23-2.2.1-150000.3.46.1.x86_64.rpm openexr-2.2.1-150000.3.46.1.src.rpm openexr-devel-2.2.1-150000.3.46.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-1750 Security update for librsvg important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for librsvg fixes the following issue: - CVE-2026-25727: time: parsing of user-provided input by the RFC 2822 date parser can lead to stack exhaustion (bsc#1257922). librsvg-2.57.4-150600.3.8.2.src.rpm librsvg-devel-2.57.4-150600.3.8.2.x86_64.rpm typelib-1_0-Rsvg-2_0-2.57.4-150600.3.8.2.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-2712 Security update for xdg-desktop-portal moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for xdg-desktop-portal fixes the following issue: - CVE-2026-40354: File deletion via symlink attack (bsc#1262045). xdg-desktop-portal-1.18.2-150600.4.6.1.src.rpm xdg-desktop-portal-1.18.2-150600.4.6.1.x86_64.rpm xdg-desktop-portal-devel-1.18.2-150600.4.6.1.x86_64.rpm xdg-desktop-portal-lang-1.18.2-150600.4.6.1.noarch.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-2029 Security update for vim moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for vim fixes the following issue: Security fixes: - CVE-2026-39881: command injection in NetBeans interface can lead to arbitrary file reads and writes (bsc#1261833). Other fixes: - Update to 9.2.0398. * 9.2.0398: MS-Windows: missing strptime() support * 9.2.0397: tabpanel: double-click opens a new tab * 9.2.0396: tests: Test_error_callback_terminal is flaky on macOS * 9.2.0395: tests: Test_backupskip() may read from $HOME * 9.2.0394: xxd: offsets greater than LONG_MAX print as negative * 9.2.0393: MS-Windows: link error with XPM support on UCRT64 * 9.2.0392: tests: Some tests are flaky * 9.2.0391: tests: Comment in test_vim9_cmd breaks syntax highlighting * 9.2.0390: filetype: some Beancount files are not recognized * 9.2.0389: DECRQM still leaves stray "pp" on Apple Terminal.app * 9.2.0388: strange indent in update_topline() * 9.2.0387: DECRQM request may leave stray chars in terminal * 9.2.0386: No scroll/scrollbar support in the tabpanel * 9.2.0385: Integer overflow with "ze" and large 'sidescrolloff' * 9.2.0384: stale Insstart after <Cmd> cursor move breaks undo * 9.2.0383: [security]: runtime(netrw): shell-injection via sftp: and file: URLs * 9.2.0382: Wayland: focus-stealing is non-working * 9.2.0381: Vim9: Missing check_secure() in exec_instructions() * 9.2.0380: completion: a few issues in completion code * 9.2.0379: gui.color_approx is never used * 9.2.0378: Using int as bool type in win_T struct * 9.2.0377: Using int as bool type in gui_T struct * 9.2.0376: Vim9: elseif condition compiled in dead branch * 9.2.0375: prop_find() does not find a virt text in starting line * 9.2.0374: c_CTRL-{G,T} does not handle offset * 9.2.0373: Ctrl-R mapping not triggered during completion * 9.2.0372: pum: rendering issues with multibyte text and opacity * 9.2.0371: filetype: ghostty config files are not recognized * 9.2.0370: duplicate code with literal string_T assignment * 9.2.0369: multiple definitions of STRING_INIT macro * 9.2.0368: too many strlen() calls when adding strings to dicts * 9.2.0367: runtime(netrw): ~ note expanded on MS Windows * 9.2.0366: pum: flicker when updating pum in place * 9.2.0365: using int as bool * 9.2.0364: tests: test_smoothscroll_textoff_showbreak() fails * 9.2.0363: Vim9: variable shadowed by script-local function * 9.2.0362: division by zero with smoothscroll and small windows * 9.2.0361: tests: no tests for ch_listen() with IPs * 9.2.0360: Cannot handle mouse-clicks in the tabpanel * 9.2.0359: wrong VertSplitNC highlighting on winbar * 9.2.0358: runtime(vimball): still path traversal attacks possible * 9.2.0357: [security]: command injection via backticks in tag files * 9.2.0356: Cannot apply 'scrolloff' context lines at end of file * 9.2.0355: runtime(tar): missing path traversal checks in tar#Extract() * 9.2.0354: filetype: not all Bitbake include files are recognized * 9.2.0353: Missing out-of-memory check in register.c * 9.2.0352: 'winhighlight' of left window blends into right window * 9.2.0351: repeat_string() can be improved * 9.2.0350: Enabling modelines poses a risk * 9.2.0349: cannot style non-current window separator * 9.2.0348: potential buffer underrun when setting statusline like option * 9.2.0347: Vim9: script-local variable not found * 9.2.0346: Wrong cursor position when entering command line window * 9.2.0345: Wrong autoformatting with 'autocomplete' * 9.2.0344: channel: ch_listen() can bind to network interface * 9.2.0343: tests: test_clientserver may fail on slower systems * 9.2.0342: tests: test_excmd.vim leaves swapfiles behind * 9.2.0341: some functions can be run from the sandbox * 9.2.0340: pum_redraw() may cause flicker * 9.2.0339: regexp: nfa_regmatch() allocates and frees too often * 9.2.0338: Cannot handle mouseclicks in the tabline * 9.2.0337: list indexing broken on big-endian 32-bit platforms * 9.2.0336: libvterm: no terminal reflow support * 9.2.0335: json_encode() uses recursive algorithm * 9.2.0334: GTK: window geometry shrinks with with client-side decorations * 9.2.0333: filetype: PklProject files are not recognized * 9.2.0332: popup: still opacity rendering issues * 9.2.0331: spellfile: stack buffer overflows in spell file generation * 9.2.0330: tests: some patterns in tar and zip plugin tests not strict enough * 9.2.0329: tests: test_indent.vim leaves swapfiles behind * 9.2.0328: Cannot handle mouseclicks in the statusline * 9.2.0327: filetype: uv scripts are not detected * 9.2.0326: runtime(tar): but with dotted path * 9.2.0325: runtime(tar): bug in zstd handling * 9.2.0324: 0x9b byte not unescaped in <Cmd> mapping * 9.2.0323: filetype: buf.lock files are not recognized * 9.2.0322: tests: test_popupwin fails * 9.2.0321: MS-Windows: No OpenType font support * 9.2.0320: several bugs with text properties * 9.2.0319: popup: rendering issues with partially transparent popups * 9.2.0318: cannot configure opacity for popup menu * 9.2.0317: listener functions do not check secure flag * 9.2.0316: [security]: command injection in netbeans interface via defineAnnoType * 9.2.0315: missing bound-checks * 9.2.0314: channel: can bind to all network interfaces * 9.2.0313: Callback channel not registered in GUI * 9.2.0312: C-type names are marked as translatable * 9.2.0311: redrawing logic with text properties can be improved * 9.2.0310: unnecessary work in vim_strchr() and find_term_bykeys() * 9.2.0309: Missing out-of-memory check to may_get_cmd_block() * 9.2.0308: Error message E1547 is wrong * 9.2.0307: more mismatches between return types and documentation * 9.2.0306: runtime(tar): some issues with lz4 support * 9.2.0305: mismatch between return types and documentation * 9.2.0304: tests: test for 9.2.0285 doesn't always fail without the fix * 9.2.0303: tests: zip plugin tests don't check for warning message properly * 9.2.0302: runtime(netrw): RFC2396 decoding double escaping spaces * 9.2.0301: Vim9: void function return value inconsistent * 9.2.0300: The vimball plugin needs some love * 9.2.0299: runtime(zip): may write using absolute paths * 9.2.0298: Some internal variables are not modified * 9.2.0297: libvterm: can improve CSI overflow code * 9.2.0296: Redundant and incorrect integer pointer casts in drawline.c * 9.2.0295: 'showcmd' shows wrong Visual block size with 'linebreak' * 9.2.0294: if_lua: lua interface does not work with lua 5.5 * 9.2.0293: :packadd may lead to heap-buffer-overflow * 9.2.0292: E340 internal error when using method call on void value * 9.2.0291: too many strlen() calls * 9.2.0290: Amiga: no support for AmigaOS 3.x * 9.2.0289: 'linebreak' may lead to wrong Visual block highlighting * 9.2.0288: libvterm: signed integer overflow parsing long CSI args * 9.2.0287: filetype: not all ObjectScript routines are recognized * 9.2.0286: still some unnecessary (int) casts in alloc() * 9.2.0285: :syn sync grouphere may go beyond end of line * 9.2.0284: tabpanel: crash when tabpanel expression returns variable line count * 9.2.0283: unnecessary (int) casts before alloc() calls * 9.2.0282: tests: Test_viminfo_len_overflow() fails * 9.2.0281: tests: Test_netrw_FileUrlEdit.. fails on Windows gvim-9.2.0398-150500.20.49.1.x86_64.rpm vim-9.2.0398-150500.20.49.1.src.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-2297 Security update for avahi moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for avahi fixes the following issue: - CVE-2026-34933: Prior to version 0.9-rc4, any unprivileged local user can crash avahi-daemon by sending a single D-Bus method call with conflicting publish flags (bsc#1261546). avahi-0.8-150600.15.18.1.src.rpm avahi-autoipd-0.8-150600.15.18.1.x86_64.rpm avahi-glib2-0.8-150600.15.18.1.src.rpm avahi-utils-gtk-0.8-150600.15.18.1.x86_64.rpm libavahi-gobject-devel-0.8-150600.15.18.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-1872 Security update for firewalld moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for firewalld fixes the following issue: - CVE-2026-4948: local unprivileged users can modify the runtime firewall state without proper authentication due to D-Bus setter mis-authorizations (bsc#1260903). firewall-applet-2.0.1-150600.3.15.1.noarch.rpm firewall-config-2.0.1-150600.3.15.1.noarch.rpm firewalld-2.0.1-150600.3.15.1.src.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-1817 Security update for mozjs60 important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for mozjs60 fixes the following issues - CVE-2026-32776: libexpat: NULL pointer dereference when processing empty external parameter entities inside an entity declaration value (bsc#1259728). - CVE-2026-32777: libexpat: denial of service due to infinite loop in DTD content parsing (bsc#1259713). - CVE-2026-32778: libexpat: NULL pointer dereference in `setContext` on retry after an out-of-memory condition (bsc#1259731). mozjs60-60.9.0-150200.6.11.1.src.rpm mozjs60-devel-60.9.0-150200.6.11.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-2745 Security update for firewalld-legacy moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for firewalld-legacy fixes the following issue - CVE-2026-4948: local unprivileged users can modify firewall state due to D-Bus setter mis-authorizations (bsc#1260903). firewall-applet-1.3.4-150600.13.6.1.noarch.rpm firewall-config-1.3.4-150600.13.6.1.noarch.rpm firewalld-1.3.4-150600.13.6.1.src.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-1829 Security update for MozillaFirefox important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for MozillaFirefox fixes the following issues Updated to Firefox Extended Support Release 140.10.1 ESR (bsc#1263110,MFSA 2026-36): - CVE-2026-7320: Information disclosure due to incorrect boundary conditions in the Audio/Video component. - CVE-2026-7321: Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component. - CVE-2026-7322: Memory safety bugs fixed in Firefox ESR 115.35.1, Firefox ESR 140.10.1 and Firefox 150.0.1. - CVE-2026-7323: Memory safety bugs fixed in Firefox ESR 140.10.1 and Firefox 150.0.1. MozillaFirefox-140.10.1-150200.152.234.1.src.rpm MozillaFirefox-140.10.1-150200.152.234.1.x86_64.rpm MozillaFirefox-devel-140.10.1-150200.152.234.1.noarch.rpm MozillaFirefox-translations-common-140.10.1-150200.152.234.1.x86_64.rpm MozillaFirefox-translations-other-140.10.1-150200.152.234.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3224 Security update for SVT-AV1, libyuv0, libaom3 important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for SVT-AV1, libyuv0, libaom3 fixes the following issues: - CVE-2026-56208: untrusted encoder configuration inputs can lead to a heap-based buffer overflow and a process crash (bsc#1268650). - CVE-2026-56209: crafted video frames with specific Y-plane pixel values can lead to an arbitrary memory write (bsc#1268651). - CVE-2026-56210: missing bounds check on layer_id inputs can lead to an out-of-bounds heap read (bsc#1268653). - CVE-2026-56211: out-of-range spatial/temporal layer selection can lead to remote code execution (bsc#1268655). Bug fixes: - Add SVT-AV1, libyuv0, libaom3 to Basesystem, no source changes. (bsc#1263678). SVT-AV1-1.8.0-150600.3.2.5.src.rpm aom-tools-3.7.1-150600.3.9.1.x86_64.rpm libSvtAv1Enc1-1.8.0-150600.3.2.5.x86_64.rpm libaom-3.7.1-150600.3.9.1.src.rpm libaom-devel-3.7.1-150600.3.9.1.x86_64.rpm libaom-devel-doc-3.7.1-150600.3.9.3.noarch.rpm libaom-devel-doc-3.7.1-150600.3.9.3.src.rpm libaom3-3.7.1-150600.3.9.1.x86_64.rpm libyuv-20230517+a377993-150600.3.4.2.src.rpm libyuv-devel-20230517+a377993-150600.3.4.2.x86_64.rpm libyuv-tools-20230517+a377993-150600.3.4.2.x86_64.rpm libyuv0-20230517+a377993-150600.3.4.2.x86_64.rpm libaom3-32bit-3.7.1-150600.3.9.1.x86_64.rpm libyuv0-32bit-20230517+a377993-150600.3.4.2.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-1876 Security update for openssh important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for openssh fixes the following issues - CVE-2026-35385: a file downloaded by scp may be installed setuid or setgid (bsc#1261427). - CVE-2026-35414: mishandling of authorized_keys principals option (bsc#1261430). openssh-askpass-gnome-9.6p1-150600.6.37.1.src.rpm openssh-askpass-gnome-9.6p1-150600.6.37.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-2023 Security update for ImageMagick important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for ImageMagick fixes the following issues - CVE-2026-31853: heap buffer overflow leads to crash in the SFW decoder of 32-bit systems when processing extremely large images (bsc#1259528). - CVE-2026-42050: Stack buffer overflow in XTileImage (bsc#1265048). ImageMagick-7.1.1.43-150700.3.52.1.src.rpm ImageMagick-7.1.1.43-150700.3.52.1.x86_64.rpm ImageMagick-config-7-SUSE-7.1.1.43-150700.3.52.1.x86_64.rpm ImageMagick-config-7-upstream-limited-7.1.1.43-150700.3.52.1.x86_64.rpm ImageMagick-config-7-upstream-open-7.1.1.43-150700.3.52.1.x86_64.rpm ImageMagick-config-7-upstream-secure-7.1.1.43-150700.3.52.1.x86_64.rpm ImageMagick-config-7-upstream-websafe-7.1.1.43-150700.3.52.1.x86_64.rpm ImageMagick-devel-7.1.1.43-150700.3.52.1.x86_64.rpm libMagick++-7_Q16HDRI5-7.1.1.43-150700.3.52.1.x86_64.rpm libMagick++-devel-7.1.1.43-150700.3.52.1.x86_64.rpm libMagickCore-7_Q16HDRI10-7.1.1.43-150700.3.52.1.x86_64.rpm libMagickWand-7_Q16HDRI10-7.1.1.43-150700.3.52.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-2020 Security update for ImageMagick important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for ImageMagick fixes the following issues - CVE-2026-31853: heap buffer overflow leads to crash in the SFW decoder of 32-bit systems when processing extremely large images (bsc#1259528). - CVE-2026-42050: Stack buffer overflow in XTileImage (bsc#1265048). ImageMagick-7.1.0.9-150400.6.80.1.src.rpm ImageMagick-config-7-upstream-7.1.0.9-150400.6.80.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-2114 Security update for openexr important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for openexr fixes the following issue - CVE-2026-41142: integer overflow in `ImageChannel: resize` can lead to a heap out-of-bounds write via OpenEXRUtil public API (bsc#1264356). libIlmImf-2_2-23-2.2.1-150000.3.49.1.x86_64.rpm libIlmImfUtil-2_2-23-2.2.1-150000.3.49.1.x86_64.rpm openexr-2.2.1-150000.3.49.1.src.rpm openexr-devel-2.2.1-150000.3.49.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-2837 Security update for libexif moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for libexif fixes the following issues - CVE-2026-40385: Fixed information disclosure and crashes via integer overflow in Nikon MakerNote handling (bsc#1262000) - CVE-2026-40386: Fixed denial of service and information disclosure via integer underflow in MakerNote decoding (bsc#1262001) - CVE-2026-32775: Fixed Buffer overwrite via integer underflow in MakerNotes decoding (bsc#1259755) libexif-0.6.22-150000.5.12.1.src.rpm libexif-devel-0.6.22-150000.5.12.1.x86_64.rpm libexif12-0.6.22-150000.5.12.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-2109 Security update for MozillaFirefox important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for MozillaFirefox fixes the following issues Update to Firefox Extended Support Release 140.11.0 ESR MFSA 2026-41, MFSA 2026-48 (bsc#1265212, bsc#1264378): - CVE-2026-8090: Use-after-free in the DOM: Networking component. - CVE-2026-8092: Memory safety bugs fixed in Firefox ESR 115.35.2, Firefox ESR 140.10.2 and Firefox 150.0.2. - CVE-2026-8094: Other issue in the WebRTC component. - CVE-2026-8388: Incorrect boundary conditions in the JavaScript Engine: JIT component. - CVE-2026-8391: Other issue in the JavaScript Engine component. - CVE-2026-8401: Sandbox escape in the Profile Backup component. - CVE-2026-8946: Incorrect boundary conditions in the Audio/Video: Web Codecs component. - CVE-2026-8947: Use-after-free in the DOM: Bindings (WebIDL) component. - CVE-2026-8949: Integer overflow in the Widget: Win32 component. - CVE-2026-8950: Same-origin policy bypass in the Networking: HTTP component. - CVE-2026-8953: Sandbox escape due to use-after-free in the Disability Access APIs component. - CVE-2026-8954: Incorrect boundary conditions, integer overflow in the Audio/Video component. - CVE-2026-8955: Privilege escalation in the DOM: Workers component. - CVE-2026-8956: Integer overflow in the Networking: JAR component. - CVE-2026-8957: Privilege escalation in the Enterprise Policies component. - CVE-2026-8958: Information disclosure, sandbox escape in the Security: Process Sandboxing component. - CVE-2026-8959: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. - CVE-2026-8961: Spoofing issue in the Form Autofill component. - CVE-2026-8962: Mitigation bypass in the DOM: Security component. - CVE-2026-8968: Denial-of-service due to invalid pointer in the Audio/Video: Web Codecs component. - CVE-2026-8970: Privilege escalation in the Security component. - CVE-2026-8974: Memory safety bugs fixed in Firefox ESR 140.11 and Firefox 151. - CVE-2026-8975: Memory safety bugs fixed in Firefox ESR 115.36, Firefox ESR 140.11 and Firefox 151. MozillaFirefox-140.11.0-150200.152.239.1.src.rpm MozillaFirefox-140.11.0-150200.152.239.1.x86_64.rpm MozillaFirefox-devel-140.11.0-150200.152.239.1.noarch.rpm MozillaFirefox-translations-common-140.11.0-150200.152.239.1.x86_64.rpm MozillaFirefox-translations-other-140.11.0-150200.152.239.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-2584 Security update for exiv2 moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for exiv2 fixes the following issues - CVE-2021-34334: DoS due to integer overflow in loop counter (bsc#1189338). - CVE-2026-25884: out-of-bounds read in `CrwMap: decode0x0805` (bsc#1259083). - CVE-2026-27596: integer overflow in `LoaderNative: getData()` leads to out-of-bounds read (bsc#1259084). - CVE-2026-27631: crash due to uncaught exception when trying to create `std: vector` larger than `max_size()` (bsc#1259085). Changes for exiv2: * Minor bugs and fixes - Other improvements * exivsimple has array index errors when stripping quotes form TIFF parser,Binary array elements should be decoded using the Add option -K Key (--key Key) to specify one or more keys to "exiv2 -eX" followed by "exiv2 -iX" produces invalid XMP - This release introduces support for Postscript (EPS) images. XMP metadata can be read and written from/to EPS images and previews are accessible. Further it includes a new build environment for MSVC 64 bit - fix build with gcc 4.3 (upstream backport) * Fix "Since v0.14 the version check macro doesn't work in a precompiler exiv2-0.27.5-150400.15.7.1.src.rpm libexiv2-27-0.27.5-150400.15.7.1.x86_64.rpm libexiv2-devel-0.27.5-150400.15.7.1.x86_64.rpm libexiv2-xmp-static-0.27.5-150400.15.7.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-2088 Recommended update for open-vm-tools moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for open-vm-tools fixes the following issues: - Update to 13.1.0 release based on build 25218885 (bsc#1265304): * Support for GNOME Toolkit version 4 * New release of the Salt-Minion integration script * Fallback to ignore systemd inhibitors during guest poweroff / reboot * Fix: vmware-vgauth-smoketest: no VGAuthLib.vmsg file * Fix: Inline comment breaks "disable_vmware_customization" check * For a more complete description of what is new in this release: https://github.com/vmware/open-vm-tools/blob/stable-13.1.0/ReleaseNotes.md#whatsnew https://github.com/vmware/open-vm-tools/blob/stable-13.1.0/ReleaseNotes.md#resolved-issues - Fix build with glibc 2.43 (bsc#1257312) open-vm-tools-13.1.0-150600.3.27.1.src.rpm open-vm-tools-desktop-13.1.0-150600.3.27.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-2235 Security update for evince important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for evince fixes the following issue - CVE-2026-46529: improper argument sanitization can lead to command injection (bsc#1265880). evince-45.0-150600.3.3.1.src.rpm evince-45.0-150600.3.3.1.x86_64.rpm evince-devel-45.0-150600.3.3.1.x86_64.rpm evince-lang-45.0-150600.3.3.1.noarch.rpm evince-plugin-djvudocument-45.0-150600.3.3.1.x86_64.rpm evince-plugin-dvidocument-45.0-150600.3.3.1.x86_64.rpm evince-plugin-pdfdocument-45.0-150600.3.3.1.x86_64.rpm evince-plugin-psdocument-45.0-150600.3.3.1.x86_64.rpm evince-plugin-tiffdocument-45.0-150600.3.3.1.x86_64.rpm evince-plugin-xpsdocument-45.0-150600.3.3.1.x86_64.rpm libevdocument3-4-45.0-150600.3.3.1.x86_64.rpm libevview3-3-45.0-150600.3.3.1.x86_64.rpm typelib-1_0-EvinceDocument-3_0-45.0-150600.3.3.1.x86_64.rpm typelib-1_0-EvinceView-3_0-45.0-150600.3.3.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-2236 Security update for vim important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for vim fixes the following issues - CVE-2026-42307: Prior to version 9.2.0383, an OS command injection vulnerability exists in the netrw standard plugin bundled with Vim (bsc#1264706). - CVE-2026-43961: Vimscript Code Injection in netrw NetrwMarkFile() via crafted filename (bsc#1265349). - CVE-2026-44656: Prior to version 9.2.0435, an OS command injection vulnerability exists in Vim's: find command-line completion (bsc#1264707). - CVE-2026-45130: Prior to version 9.2.0450, a heap buffer overflow exists in read_compound() in src/spellfile.c when loading a crafted spell file (.spl) with UTF-8 encoding active (bsc#1264708). - CVE-2026-46483: command injection via ` tar#Vimuntar()` in `runtime/autoload/tar.vim` when decompressing `.tgz` archives on Unix-like systems (bsc#1265360). Changes for vim: - Update to v9.2.0530. - Fix for incorrectly detecting scientific parameter files as bitbake recipies. (bsc#1262395) gvim-9.2.0530-150500.20.52.1.x86_64.rpm vim-9.2.0530-150500.20.52.1.src.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-2371 Security update for openssh important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for openssh fixes the following issues - CVE-2026-3497: information disclosure or denial of service due to uninitialized variables (bsc#1259642). - CVE-2026-35385: a file downloaded by scp may be installed setuid or setgid (bsc#1261427). - CVE-2026-35388: omitted connection multiplexing confirmation for proxy-mode multiplexing sessions (bsc#1261441). - CVE-2026-35414: mishandling of authorized_keys principals option (bsc#1261430). - potential security issue when validating mac (bsc#1264568). openssh-askpass-gnome-9.6p1-150600.6.42.1.src.rpm openssh-askpass-gnome-9.6p1-150600.6.42.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-2622 Security update for libheif important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for libheif fixes the following issues Update to 1.23.0: - CVE-2025-68431: heap buffer over-read in `HeifPixelImage: overlay()` via crafted HEIF that exercises the overlay image item (bsc#1255735). - CVE-2026-3950: manipulation of the component stsz/stts can lead to out-of-bounds read (bsc#1259544). - CVE-2026-32738: Heap OOB Read / SEGV Crash via Zero samples_per_chunk in stsc (bsc#1265874). - CVE-2026-32739: Infinite Loop DoS in stts Sample Duration Lookup (bsc#1265875). - CVE-2026-32740: Heap-Buffer-Overflow Write in Grid Tile Chroma Compositing (bsc#1265876). - CVE-2026-32741: heap buffer overflow in decode_mask_image() (bsc#1265877). - CVE-2026-32814: Uninitialized Heap Memory Information Leak via Failed Grid Tiles (bsc#1265878). - CVE-2026-32882: Heap Buffer OOB Read in overlay compositing due to wrong alpha stride (bsc#1265879). - CVE-2026-41069: Out-of-bounds vector access leading to invalid dereference (bsc#1265979). - CVE-2026-41071: Heap buffer over-read in SampleAuxInfoReader via crafted HEIF sequence file with mismatched saiz sample count (bsc#1265980). - CVE-2026-47178: Heap Out Of Bounds Write in unci subsystem (bsc#1265981). - CVE-2026-47247: Heap Information Disclosure via Grid Image Gap + Uninitialized Pixel Plane Allocation (bsc#1265982). - CVE-2026-47251: integer overflow bypass in vvdec_push_data2 (bsc#1265983). - CVE-2026-47254: Heap Buffer Overflow in `Track: get_next_sample_raw_data()` -- OOB Chunk Vector Access (bsc#1265987). - CVE-2026-47709: NULL pointer dereference in heif_image_handle_get_image_tiling for malformed unci image missing ispe (bsc#1265988). - CVE-2026-47714: Integer overflow in inline mask size calculation causes undersized buffer allocation (bsc#1265989). - CVE-2026-48029: heap OOB read in ImageItem_Grid: decode_grid_tile via irot-induced tile-coordinate underflow (bsc#1265990). - CVE-2026-49271: Wrapped icef compressed-unit range check causes out-of-bounds read in uncompressed HEIF decoder (bsc#1266282). - CVE-2026-50142: unbounded heap allocation in HEIF sequence parser (bsc#1267455). - Heap buffer overflow via uint32_t stride overflow in image plane allocation (+ 2 additional instances) (bsc#1265997). - Incorrect byte-count initialization in BitstreamRange constructor allows container-boundary check bypass (bsc#1265995). - Integer Overflow in SampleAuxInfoReader Offset Calculation (bsc#1265992). - Out-of-bounds read and assertion-based DoS in EXIF parsing (find_exif_tag / read32) with short EXIF TIFF payload (bsc#1265996). - Out-of-bounds write in inline mask region API when source mask exceeds declared region (bsc#1266281). Changes for libheif: - version update to 1.23.0: * add API functions to read and write metadata: ambient viewing environment nominal diffuse white luminance * adds a output_image_nclx_profile_passthrough option to heif_decoding_options * CVE-2026-50142 (GHSA-jvmp-j3cw-84mh) - unbounded heap allocation in HEIF sequence parser (stsz fixed-size mode missing bound check) - version update to 1.22.2: * build issues with OpenJPEG plugin (#1813) * non-plain C in header (#1812) * CVE-2026-49271 (GHSA-r7qj-cg5r-r6vf) - Wrapped icef compressed-unit range check causes out-of-bounds read in uncompressed HEIF decoder * CVE TBD (GHSA-5hqq-636x-r3cr) - Out-of-bounds write in inline mask region API when source mask exceeds declared region - update to 1.22.0: * This is a large release with substantial new functionality, mainly focusing on generalized image formats (e.g., multi- spectral images) and a reworked implementation of ISO/IEC 23001-17 (lossless image codec). * HDR up to 64 bpp * Multi-component images with arbitrary component layouts (multi-spectral images, arbitrary non-visual data) * Filter-array (Bayer / mosaic) images, with debayering in color transformation pipeline * Metadata: chroma-sample location (cloc), sample non- uniformity (snuc), sensor bad-pixel map (sbpm), polarization pattern (splz) * heif-dec can now convert to WebP (thanks to @torusrxxx). * heif-enc can now accept input from WebP, HEIF, pure raw files (including floating point pixel data), and CMYK JPEG (converted to RGB). * TIFF input can now read many TIFF formats used in geospatial imaging, like: 16-bit, signed integers, float samples, tiled TIFFs, GeoTIFF overview images, CMYK JPEG, YCbCr-as-JPEG. TIFFs with image tiling and multi-resolution layers are now reproduced as HEIFs when converted. * PNG decoder/encoder: cICP, cLLI, and mDCV chunk support (#1697). * heif-dec: auto-correct option to fix known input errors (e.g. mismatched NCLX/VUI). * Image, Track, Sequence samples, image component GIMI content IDs * Embedding of Turtle (.ttl) metadata files; automatic parsing of GIMI content IDs from Turtle * AOM encoder plugin now auto-selects IQ tune mode * mini-box syntax updated to the current HEIF version 4 draft (thanks @bradh for the initial implementation) * unif brand (globally-unique-ID) support * OMAF (omnidirectional images): indicate ISO/IEC 23000-22 spherical/omnidirectional image projection * alpha bit-depth tracked through the color-conversion pipeline * CVE-2026-32738 (GHSA-7f2h-cmpf-v9ww) : Heap OOB Read / SEGV Crash via Zero samples_per_chunk in stsc (bsc#1265874) * CVE-2026-32739 (GHSA-j9g7-q9hv-gq8c) : Infinite Loop DoS in stts Sample Duration Lookup (bsc#1265875) * CVE-2026-32740 (GHSA-frfr-f3vg-2g6j) : Heap-Buffer-Overflow Write in Grid Tile Chroma Compositing (bsc#1265876) * CVE-2026-32741 (GHSA-j3w5-7whq-p37q) : heap buffer overflow in decode_mask_image() (bsc#1265877) * CVE-2026-32814 (GHSA-4m8r-34pg-rvwc) : Uninitialized Heap Memory Information Leak via Failed Grid Tiles (bsc#1265878) * CVE-2026-32882 (GHSA-hg7q-rjr2-8x46) : Heap Buffer OOB Read in overlay compositing due to wrong alpha stride (bsc#1265879) * CVE-2026-41069 (GHSA-p82x-fpmv-576r) : Out-of-bounds vector access leading to invalid dereference (bsc#1265979) * CVE-2026-41071 (GHSA-xj92-xjff-h8w3) : Heap buffer over-read in SampleAuxInfoReader via crafted HEIF sequence file with mismatched saiz sample count (bsc#1265980) * CVE-2026-47178 (GHSA-5x55-x5pf-9c6g) : Heap Out Of Bounds Write in unci subsystem (bsc#1265981) * CVE-2026-47247 (GHSA-2vh6-whr3-cmq3) : Heap Information Disclosure via Grid Image Gap + Uninitialized Pixel Plane Allocation (bsc#1265982) * CVE-2026-47251 (GHSA-p6q9-fhf2-vj9v) : Incomplete fix for (bsc#1265983) CVE-2026-3949: integer overflow bypass in vvdec_push_data2 * CVE-2026-47254 (GHSA-wqjg-4x9g-6cvg) : Heap Buffer Overflow in `Track::get_next_sample_raw_data()` -- OOB Chunk Vector Access (bsc#1265987) * CVE-2026-47709 (GHSA-4h72-vqgp-9376) : NULL pointer dereference in heif_image_handle_get_image_tiling for malformed unci image missing ispe (bsc#1265988) * CVE-2026-47714 (GHSA-h4wm-6wwf-qvhx) : Integer overflow in inline mask size calculation causes undersized buffer allocation (bsc#1265989) * CVE-2026-48029 (GHSA-6x5f-qchq-cxqv) : heap OOB read in ImageItem_Grid::decode_grid_tile via irot-induced tile- coordinate underflow (bsc#1265990) * (GHSA-95jx-g5vf-cpp8) : Integer Overflow in SampleAuxInfoReader Offset Calculation (bsc#1265992) * (GHSA-p4r6-6972-g26m) : Incorrect byte-count initialization in BitstreamRange constructor allows container-boundary check bypass (bsc#1265995) * (GHSA-jh2w-m72q-q595) : Out-of-bounds read and assertion- based DoS in EXIF parsing (find_exif_tag / read32) with short EXIF TIFF payload (bsc#1265996) * (GHSA-9h96-c44j-jpq9) : Heap buffer overflow via uint32_t stride overflow in image plane allocation (bsc#1265997) * ## Build / CI * requires C++20 * oss-fuzz integration overhauled * fuzzers for tile API, generic API surface, and per-codec encoders - update to 1.21.2: * build script for JS/WASM now supports building with JPEG2000 and "ISO23001-17 Uncompressed" support. * image sequence SAI data now works when using the OpenH264 decoder plugin - update to 1.21.1: * This patch release only fixes a build error with some GCC versions because of a missing #include. - update to 1.21.0: * This release adds full support for reading and writing HEIF image sequences. libheif will now encode HEIF image sequences with all included codecs. * Since HEIF image sequences are very similar to MP4 videos, this new version is also capable of decoding most MP4 videos (without audio, of course). * heif-enc documentation for sequence encoding * API documentation for reading and writing sequences * Support for image sequences with alpha channels. For most codecs, the alpha channel will be stored in a separate, auxiliary, monochrome track. For ISO/IEC 23001-17 (uncompressed) streams, the alpha channel is stored in the main video track. * Support for sequence track edit lists to define the number of sequence repetitions (without actually repeating the video data). * New encoder plugin using x264 to write H.264-compressed video streams and images. * The FFmpeg decoder plugin will now decode both H.265 and H.264. * Support for HEIF text items and language properties. * CVEs fixed: CVE-2025-68431 - update to 1.20.2: - When opening tiled images, do not check against maximum image size immediately to allow for tile-based decoding of very large images. - Several smaller fixes in writing image sequences - CMake option to disable building of heif-view, which pulls in dependency on SDL - Fixes reading/writing of GIMI content IDs - Some build fixes - Remove conditionals for openh264, we can build against noopenh264 - update to 1.20.1: - Fixes a bug in decoder plugin loading. - Changes from 1.20.0: - Sequences: - API for reading and writing image sequences. You can read and write sequences for all codecs (not just H.265 / AV1, but also JPEG-2000, ISO-23001-17 uncompressed, ...). Currently only intra-coded sequences are supported. - API for reading and writing metadata sequences. The metadata tracks can contain any raw timed data. - Support for SAI (sample auxiliary information). Timed samples (from image sequences or metadata) can have auxiliary data attached. Currently we support TAI timestamps and GIMI content description IDs. - Support for track references. - The API for sequences is described here: https://github.com/strukturag/libheif/wiki/Reading-and-Writing-Sequences - New command line tool heif-view to show HEIF sequences (requires libSDL). - Other new features: - You can specify a security limit for the maximum total memory libheif may use for decoding. This is easier to handle than specifying limits on the maximum image size or single memory allocations. - Support for TAI timestamps (in images and sequences) has been promoted from experimental to stable. - FFMPEG plugin now supports HDR decoding - Header files are now split into individual headers by topic. However, it should still be backwards compatible with heif.h being a catch-all covering the old content. For new functionality (sequences, TAI), you will need to include the specific headers. - All struct names of the API are now also typedefs. - add build requires for brotli which it looks for since 1.18 - prepare building heif-view - update to 1.19.8: * Set essential flag for transformative properties as required by MIAF. This fixes the display of AVIF images with transformations encoded by libheif in Chrome, which checks whether this flag is set. This mainly affected images encoded by ImageMagick. * If the environment variable LIBHEIF_SECURITY_LIMITS is set to OFF, libheif will not check any security limits. This can be used if a user works with large images and the application software does not allow to adjust the libheif security limits. * Resolved processing 16-bit JPEG-2000 - update to 1.19.7: * Fixes a build error with SVT-AV1 encoder plugin when using reduced symbol visibility - update to 1.19.6: * C++ and Go wrapper licenses have been changed to MIT * supports SVT-AV1 v3.0.0 encoder * support emscripten builds for ES6 modules - Use correct license (these were changed in 2018) - Ensure Name: is conditionalized for the multibuild flavors to not overwrite the .src.rpm (which is a processed .spec) and to allow OBS to properly distinguish them flavors. libheif-1.23.0-150700.3.15.1.src.rpm libheif-aom-1.23.0-150700.3.15.1.x86_64.rpm libheif-dav1d-1.23.0-150700.3.15.1.x86_64.rpm libheif-jpeg-1.23.0-150700.3.15.1.x86_64.rpm libheif-rav1e-1.23.0-150700.3.15.1.x86_64.rpm libheif1-1.23.0-150700.3.15.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3080 Recommended update for gvfs moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for gvfs fixes the following issues: - Fix crash of cancelled pending operation. (bsc#1261625) gvfs-1.52.2-150600.3.6.1.src.rpm gvfs-1.52.2-150600.3.6.1.x86_64.rpm gvfs-backend-afc-1.52.2-150600.3.6.1.x86_64.rpm gvfs-backend-samba-1.52.2-150600.3.6.1.x86_64.rpm gvfs-backends-1.52.2-150600.3.6.1.x86_64.rpm gvfs-devel-1.52.2-150600.3.6.1.noarch.rpm gvfs-fuse-1.52.2-150600.3.6.1.x86_64.rpm gvfs-lang-1.52.2-150600.3.6.1.noarch.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-2229 Security update for hplip critical SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for hplip fixes the following issues Security issues: - CVE-2025-43023: weak code signing DSA key used to generate package signatures can lead to key spoofing and malicious software installation (bsc#1266031). - CVE-2026-8631: escalation of privileges and/or arbitrary code execution via an integer overflow in the hpcups processing path (bsc#1266023). - CVE-2026-8632: escalation of privileges and/or arbitrary code execution via operating system command injection (bsc#1266024). - Unauthenticated remote (LAN) denial-of-service in the SLP parser (ReDoS). (bsc#1245358) - URI parameter injection via unsanitized USB serial number. (bsc#1209401) Non security issues: - Can't set up fax for HP OfficeJet 3830 (bsc#1257529). - hplip requires foomatic-filters which does not exist in Leap 16 (bsc#1250481). - Update to HPLIP 3.26.4 hplip-3.26.4-150700.4.3.1.src.rpm hplip-3.26.4-150700.4.3.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-2376 Security update for webkit2gtk3 important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for webkit2gtk3 fixes the following issues Update to version 2.52.4: Security fixes: - CVE-2026-28847: processing maliciously crafted web content may lead to an unexpected process crash or arbitrary code execution due to a heap buffer overflow (bsc#1267506). - CVE-2026-28883: processing maliciously crafted web content may lead to an unexpected process crash due to a use-after- free issue (bsc#1267507). - CVE-2026-28901: processing maliciously crafted web content may lead to an unexpected process crash due to improper memory handling (bsc#1267508). - CVE-2026-28902: processing maliciously crafted web content may lead to an unexpected process crash due to improper memory handling (bsc#1267509). - CVE-2026-28903: processing maliciously crafted web content may lead to an unexpected process crash due to improper memory handling (bsc#1267510). - CVE-2026-28904: processing maliciously crafted web content may lead to an unexpected process crash due to improper memory handling (bsc#1267511). - CVE-2026-28905: processing maliciously crafted web content may lead to an unexpected process crash due to improper memory handling (bsc#1267512). - CVE-2026-28907: processing maliciously crafted web content may prevent Content Security Policy from being enforced due to improper input validation (bsc#1267513). - CVE-2026-28942: processing maliciously crafted web content may lead to an unexpected crash due to use-after-free (bsc#1267514). - CVE-2026-28946: processing maliciously crafted web content may lead to an unexpected crash due to a use-after-free (bsc#1267515). - CVE-2026-28947: rocessing maliciously crafted web content may lead to an unexpected crash due to a use-after-free (bsc#1267516). - CVE-2026-28953: processing maliciously crafted web content may lead to an unexpected process crash due to improper memory handling (bsc#1267517). - CVE-2026-28955: processing maliciously crafted web content may lead to an unexpected process crash due to improper memory handling (bsc#1267518). - CVE-2026-28958: an app may be able to access sensitive user data due to improper data protection (bsc#1267519). - CVE-2026-43658: processing maliciously crafted web content may lead to an unexpected crash due to improper memory handling (bsc#1267520). - CVE-2026-43660: processing maliciously crafted web content may prevent Content Security Policy from being enforced due to issues with logic (bsc#1267521). Other fixes: - Add patch to fix a crash on evolution (bsc#1264745). Changes: + Add support for half-width fonts. + Improve content filter compilation by avoiding file copies. + Improve handling of out of disk space conditions when the NetworkProcess tried to write data in caches. + Improve how the CMake build system checks whether libatomic is required. + Fix painting scrollbars when their width changes. + Fix playback of certain YouTube videos with low frame rates. + Fix webkit://gpu not working in systems where neither libGL.so.1 nor libOpenGL.so.0 are available. + Fix the build with librice 0.4 or newer when the GStreamer WebRTC backend is enabled at build configuration time. + Fix the build with USE_GSTREAMER_WEBRTC=OFF. + Fix the build with USE_GBM=OFF. + Fix several crashes and rendering issues. + Add support for the "scrollbar-color" CSS property. + Fix some emoji glyphs being rendered as missing glyph boxes. + Fix JavaScriptCore crashes on architectures other than x86_64. + Fix the build on s390x. + Changes in version 2.52.2: + Improve handling of real-time threads. + Fix scrollbar rendering glitches visible in some GPU configurations. + Fix V4L2 hardware accelerated media codecs now working due to overly restrictive sandbox device access rules. + Fix leak of bitmap images in webkit_favicon_database_get_favicon_finish(). + Fix the build with USE_GTK4=OFF. WebKitGTK-4.1-lang-2.52.4-150600.12.68.1.noarch.rpm libjavascriptcoregtk-4_1-0-2.52.4-150600.12.68.1.x86_64.rpm libwebkit2gtk-4_1-0-2.52.4-150600.12.68.1.x86_64.rpm typelib-1_0-JavaScriptCore-4_1-2.52.4-150600.12.68.1.x86_64.rpm typelib-1_0-WebKit2-4_1-2.52.4-150600.12.68.1.x86_64.rpm typelib-1_0-WebKit2WebExtension-4_1-2.52.4-150600.12.68.1.x86_64.rpm webkit2gtk-4_1-injected-bundles-2.52.4-150600.12.68.1.x86_64.rpm webkit2gtk3-2.52.4-150600.12.68.1.src.rpm webkit2gtk3-devel-2.52.4-150600.12.68.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3115 Security update for vorbis-tools moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for vorbis-tools fixes the following issue - CVE-2026-34253: buffer underflow in the `ogg123` utility in function `remotethread` of `remote.c` (bsc#1265361). vorbis-tools-1.4.0-150000.3.6.1.src.rpm vorbis-tools-1.4.0-150000.3.6.1.x86_64.rpm vorbis-tools-lang-1.4.0-150000.3.6.1.noarch.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-2988 Recommended update for hplip moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for hplip fixes the following issues: - hp-plugin: fix plugin installation from local file - fix errors with python2-incompatible syntax - Spec file: fix python-gobject2 dependency under SLE12 hplip-3.26.4-150700.4.8.1.src.rpm hplip-3.26.4-150700.4.8.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-2580 Security update for ImageMagick important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for ImageMagick fixes the following issues This update for ImageMagick fixes the following issues - CVE-2026-33899: Denial of Service via out-of-bounds write in XML parsing (bsc#1262154). - CVE-2026-33900: Denial of Service via integer truncation in viff encoder (bsc#1262156). - CVE-2026-33901: Denial of Service due to heap buffer overflow in MVG decoder (bsc#1262155). - CVE-2026-33908: Denial of Service via deeply nested XML file processing (bsc#1262152). - CVE-2026-34238: Denial of Service via integer overflow in despeckle operation (bsc#1262147). - CVE-2026-40169: Denial of Service via crafted image leading to out-of-bounds write (bsc#1262150). - CVE-2026-40310: Denial of service via heap out-of-bounds write in JP2 encoder (bsc#1262148). - CVE-2026-40311: Denial of Service via heap use-after-free in XMP profile processing (bsc#1262146). - CVE-2026-42050: Stack buffer overflow in XTileImage (bsc#1265048). - CVE-2026-42326: Information disclosure via malicious IPTC input file (bsc#1268092). - CVE-2026-45031: Denial of Service due to resource policy bypass in PSD decoder (bsc#1268094). - CVE-2026-45359: Information Disclosure via Invalid Connected-Components Value (bsc#1268095). - CVE-2026-45624: Data exposure due to image processing vulnerability (bsc#1268096). - CVE-2026-45664: Denial of Service due to excessive resource use in MNG coder (bsc#1268101). - CVE-2026-46520: Denial of Service via out-of-bounds write when processing multiple images (bsc#1268112). - CVE-2026-46521: out of bounds write can occur due to a missing check when using LZMA compression in the MIFF encoder (bsc#1268124). - CVE-2026-46522: denial of service via crafted MIFF file due to a missing check in the MIFF decoder (bsc#1268126). - CVE-2026-46523: heap-use-after-free via a crafted MSL image (bsc#1268125). - CVE-2026-46559: heap buffer over-write of a single byte when specifying certain options due to n incorrect check in the JP2 (bsc#1268121). - CVE-2026-46692: heap buffer over-write in the server process via an attacker who can connect to a magick -distribute- cache service (bsc#1268120). - CVE-2026-46693: file descriptor hijacking in the server process when a race condition is met via an attacker who can connect to a magick -distribute-cache service (bsc#1268117). - CVE-2026-47165: distributed pixel cache was originally designed to operate without a challenge--response authentication model (bsc#1268114). - CVE-2026-47166: heap buffer over-read in the server process via an attacker who can connect to a magick -distribute- cache service (bsc#1268113). - CVE-2026-48734: Stack Overflow in MVG decoder (bsc#1268122). - CVE-2026-48994: heap buffer over-write due to a missing check of a return value in the MAT decoder on 32-bit systems (bsc#1268111). - CVE-2026-49218: denial of service due to a missing check in the DCM decoder (bsc#1268110). - CVE-2026-53460: out-of-Memory condition due to a missing check for maximum memory request in AcquireAlignedMemory (bsc#1268108). - CVE-2026-53463: null pointer deference due to passing incorrect arguments in the distort operation (bsc#1268105). - CVE-2026-53464: small memory leak due to providing invalid options to the wand option parser (bsc#1268103). ImageMagick-7.1.0.9-150400.6.87.1.src.rpm ImageMagick-config-7-upstream-7.1.0.9-150400.6.87.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-2877 Security update for ImageMagick important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for ImageMagick fixes the following issues: - CVE-2026-53466: integer overflow in the XCF decoder can result in an out-of-bounds read when a crafted image is read (bsc#1270073). - CVE-2026-53467: allocated memory left unchanged in the MNG decoder can lead to a heap information disclosure (bsc#1270074). - CVE-2026-55594: missing depth check in the MVG decoder will result in a stack overflow when a crafted image is provided (bsc#1270077). - CVE-2026-55595: providing invalid arguments to the `connected-components` option can lead to an infinite loop (bsc#1270079). - CVE-2026-55597: incorrect handling of arguments can cause a heap buffer over-write in the JP2 encoder (bsc#1270080). - CVE-2026-56361: off-by-one error in morphology validation can lead to an out-of-bounds read (bsc#1270001). - CVE-2026-56363: integer overflow leading to a division by zero in binomial kernel processing can cause an application crash (bsc#1270002). - CVE-2026-56364: memory leak in `LoadOpenCLDeviceBenchmark` function when parsing malformed OpenCL device profile XML files with unclosed device elements (bsc#1270003). - CVE-2026-56374: missing boundary checks can lead to a heap buffer overflow in the FTXT encoder when parsing `ftxt:format` (bsc#1271099). - CVE-2026-56379: arbitrary MVG drawing command injection via the SVG decoder when processing specially crafted SVG files (bsc#1268878). - CVE-2026-42050: stack buffer overflow via a malicious MIFF file (bsc#1265048). - CVE-2026-42326: out-of-bounds read of single byte via malicious IPTC file (bsc#1268092). - CVE-2026-45031: missing check in the PSD decoder allows bypass of the list-length resource policy when decoding a PSD image (bsc#1268094). - CVE-2026-45358: off-by-one error in the meta encoder can lead to an out-of-bounds read of a single byte (bsc#1268102). - CVE-2026-45359: heap buffer overread via invalid `connected-components` value (bsc#1268095). - CVE-2026-45624: performing a polynomial distortion can lead to an out-of-bounds over-read of 24 bytes (bsc#1268096). - CVE-2026-45664: missing check in the MNG coder can lead to excessive resource use and a DoS (bsc#1268101). - CVE-2026-46520: out-of-bounds write when processing multiple images with different dimensions (bsc#1268112). - CVE-2026-46521: missing check when using LZMA compression in the MIFF encoder can lead to an out-of-bounds write (bsc#1268124). - CVE-2026-46522: missing check in the MIFF decoder can lead to a denial of service via crafted MIFF file (bsc#1268126). - CVE-2026-46523: heap use-after-free via a crafted MSL image (bsc#1268125). - CVE-2026-46557: missing depth check can lead to a stack buffer overflow in the fx operation when processing a crafted argument (bsc#1268123). - CVE-2026-46559: incorrect check in the JP2 can lead to a heap buffer overwrite of a single byte when specifying certain options (bsc#1268121). - CVE-2026-46692: heap buffer overwrite in the server process via an attacker who can connect to a magick -distribute- cache service (bsc#1268120). - CVE-2026-46693: file descriptor hijacking in the server process when a race condition is met via an attacker who can connect to a magick -distribute-cache service (bsc#1268117). - CVE-2026-47165: distributed pixel cache was designed to operate without a challenge-response authentication model (bsc#1268114). - CVE-2026-47166: heap buffer overread in the server process via an attacker who can connect to a magick -distribute- cache service (bsc#1268113). - CVE-2026-48724: heap buffer underwrite in the Floyd-Steinberg depth dithering (bsc#1268116). - CVE-2026-48734: missing depth or visited-set check can lead to a stack buffer overflow in the MVG decoder (bsc#1268122). - CVE-2026-48994: missing check of a return value in the MAT decoder can lead to a heap buffer overwrite on 32-bit systems (bsc#1268111). - CVE-2026-49218: missing check in the DCM decoder can lead to a DoS (bsc#1268110). - CVE-2026-53460: missing check for maximum memory request in `AcquireAlignedMemory` can lead to an OOM condition (bsc#1268108). - CVE-2026-53461: incorrect loop in the ICON decoder can lead to an out-of-bounds heap write (bsc#1268107). - CVE-2026-53463: passing incorrect arguments in the distort operation can lead to NULL pointer dereference (bsc#1268105). - CVE-2026-53464: providing invalid options to the wand option parser can lead to a memory leak (bsc#1268103). - CVE-2026-56367: integer overflow in the PSB (PSD v2) RLE decoding path can lead to an heap out-of-bounds read (bsc#1268645). - CVE-2026-56368: improper memory management can lead to memory leak in multiple coders that write raw pixel data (bsc#1269064). - CVE-2026-56370: out-of-bounds access in `ConnectedComponentsImage()` when processing `connected-components:*` artifacts with invalid indices (bsc#1269063). - CVE-2026-56371: memory leak in `coders/txt.c` when processing TXT files with texture attributes (bsc#1268879). - CVE-2026-56376: heap use-after-free in the meta coder can lead to denial of service via specially crafted image files (bsc#1268880). - GHSA-3j4x-rwrx-xxj9: possible use-after-free write in PDB decoder (bsc#1268640). ImageMagick-7.1.1.43-150700.3.65.1.src.rpm ImageMagick-7.1.1.43-150700.3.65.1.x86_64.rpm ImageMagick-config-7-SUSE-7.1.1.43-150700.3.65.1.x86_64.rpm ImageMagick-config-7-upstream-limited-7.1.1.43-150700.3.65.1.x86_64.rpm ImageMagick-config-7-upstream-open-7.1.1.43-150700.3.65.1.x86_64.rpm ImageMagick-config-7-upstream-secure-7.1.1.43-150700.3.65.1.x86_64.rpm ImageMagick-config-7-upstream-websafe-7.1.1.43-150700.3.65.1.x86_64.rpm ImageMagick-devel-7.1.1.43-150700.3.65.1.x86_64.rpm libMagick++-7_Q16HDRI5-7.1.1.43-150700.3.65.1.x86_64.rpm libMagick++-devel-7.1.1.43-150700.3.65.1.x86_64.rpm libMagickCore-7_Q16HDRI10-7.1.1.43-150700.3.65.1.x86_64.rpm libMagickWand-7_Q16HDRI10-7.1.1.43-150700.3.65.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-2582 Security update for MozillaFirefox important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for MozillaFirefox fixes the following issues: NOTE: This update was retracted as it contained incorrect provides/obsolets on mozilla-nss-certs. Update to Firefox 140.12.0 ESR (MFSA 2026-58, bsc#1268071): - CVE-2026-12289: Privilege escalation in the Graphics: WebRender component. - CVE-2026-12290: Memory safety bug fixed in Firefox ESR 140.12. - CVE-2026-12291: Use-after-free in the Networking: HTTP component. - CVE-2026-12292: Incorrect boundary conditions in the Web Audio component. - CVE-2026-12294: Sandbox escape in the DOM: Workers component. - CVE-2026-12295: Sandbox escape in the DOM: Navigation component. - CVE-2026-12296: Sandbox escape in the Security: Process Sandboxing component. - CVE-2026-12297: Sandbox escape due to incorrect boundary conditions in the Networking component. - CVE-2026-12298: Memory safety bug fixed in Firefox ESR 140.12. - CVE-2026-12299: JIT miscompilation in the DOM: Core & HTML component. - CVE-2026-12302: Mitigation bypass in the DOM: Security component. - CVE-2026-12304: Same-origin policy bypass in the Networking: Cookies component. - CVE-2026-12305: Memory safety bug fixed in Firefox ESR 140.12. - CVE-2026-12306: Memory safety bug fixed in Firefox ESR 140.12. - CVE-2026-12307: Memory safety bug fixed in Firefox ESR 140.12. - CVE-2026-12308: Memory safety bug fixed in Firefox ESR 140.12. - CVE-2026-12309: Memory safety bug fixed in Firefox ESR 140.12. - CVE-2026-12310: Memory safety bug fixed in Firefox ESR 140.12. - CVE-2026-12311: Information disclosure, sandbox escape in the Security: Process Sandboxing component. - CVE-2026-12312: Memory safety bug fixed in Firefox ESR 140.12. - CVE-2026-12313: Information disclosure, sandbox escape in the Security: Process Sandboxing component. - CVE-2026-12314: Memory safety bug fixed in Firefox ESR 140.12. - CVE-2026-12315: Mitigation bypass in the DOM: Security component. - CVE-2026-12324: Incorrect boundary conditions in the Graphics: CanvasWebGL component. - CVE-2026-12325: Denial-of-service in the Graphics: ImageLib component. - CVE-2026-12327: Memory safety bugs fixed in Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152. - CVE-2026-12328: Memory safety bugs fixed in Firefox ESR 115.37, Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152. - CVE-2026-12329: Memory safety bug fixed in Firefox ESR 140.12. - CVE-2026-12330: Incorrect boundary conditions in the Internationalization component. MozillaFirefox-140.12.0-150200.152.242.1.src.rpm MozillaFirefox-140.12.0-150200.152.242.1.x86_64.rpm MozillaFirefox-devel-140.12.0-150200.152.242.1.noarch.rpm MozillaFirefox-translations-common-140.12.0-150200.152.242.1.x86_64.rpm MozillaFirefox-translations-other-140.12.0-150200.152.242.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-2446 Recommended update for libmbim moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update ships missing packages for libmbim. libmbim-1.30.0-150700.3.2.1.src.rpm libmbim-1.30.0-150700.3.2.1.x86_64.rpm libmbim-devel-1.30.0-150700.3.2.1.x86_64.rpm libmbim-glib4-1.30.0-150700.3.2.1.x86_64.rpm typelib-1_0-Mbim-1_0-1.30.0-150700.3.2.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-2760 Security update for libnfs important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for libnfs fixes the following issue - CVE-2026-53689: integer overflow during a connection to a crafted NFS server (bsc#1268135). Changes for libnfs: - Add libnfs-CVE-2026-53689.patch: ZDR: check the string size for sanity (bsc#1268135 CVE-2026-53689). libnfs-1.11.0-150000.3.3.1.src.rpm libnfs-devel-1.11.0-150000.3.3.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-2744 Security update for gstreamer-plugins-bad important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for gstreamer-plugins-bad fixes the following issue - CVE-2026-52719: gstreamer1-plugins-bad-free: GStreamer: Out-of-bounds read via JPEG segment length validation in VA decoder (bsc#1268401). gstreamer-plugins-bad-1.24.0-150600.4.6.1.src.rpm gstreamer-plugins-bad-1.24.0-150600.4.6.1.x86_64.rpm gstreamer-plugins-bad-devel-1.24.0-150600.4.6.1.x86_64.rpm gstreamer-plugins-bad-lang-1.24.0-150600.4.6.1.noarch.rpm libgstadaptivedemux-1_0-0-1.24.0-150600.4.6.1.x86_64.rpm libgstanalytics-1_0-0-1.24.0-150600.4.6.1.x86_64.rpm libgstbadaudio-1_0-0-1.24.0-150600.4.6.1.x86_64.rpm libgstbasecamerabinsrc-1_0-0-1.24.0-150600.4.6.1.x86_64.rpm libgstcodecparsers-1_0-0-1.24.0-150600.4.6.1.x86_64.rpm libgstcodecs-1_0-0-1.24.0-150600.4.6.1.x86_64.rpm libgstcuda-1_0-0-1.24.0-150600.4.6.1.x86_64.rpm libgstdxva-1_0-0-1.24.0-150600.4.6.1.x86_64.rpm libgstinsertbin-1_0-0-1.24.0-150600.4.6.1.x86_64.rpm libgstisoff-1_0-0-1.24.0-150600.4.6.1.x86_64.rpm libgstmpegts-1_0-0-1.24.0-150600.4.6.1.x86_64.rpm libgstmse-1_0-0-1.24.0-150600.4.6.1.x86_64.rpm libgstsctp-1_0-0-1.24.0-150600.4.6.1.x86_64.rpm libgsturidownloader-1_0-0-1.24.0-150600.4.6.1.x86_64.rpm libgstva-1_0-0-1.24.0-150600.4.6.1.x86_64.rpm libgstvulkan-1_0-0-1.24.0-150600.4.6.1.x86_64.rpm libgstwayland-1_0-0-1.24.0-150600.4.6.1.x86_64.rpm libgstwebrtc-1_0-0-1.24.0-150600.4.6.1.x86_64.rpm libgstwebrtcnice-1_0-0-1.24.0-150600.4.6.1.x86_64.rpm typelib-1_0-CudaGst-1_0-1.24.0-150600.4.6.1.x86_64.rpm typelib-1_0-GstAnalytics-1_0-1.24.0-150600.4.6.1.x86_64.rpm typelib-1_0-GstBadAudio-1_0-1.24.0-150600.4.6.1.x86_64.rpm typelib-1_0-GstCodecs-1_0-1.24.0-150600.4.6.1.x86_64.rpm typelib-1_0-GstCuda-1_0-1.24.0-150600.4.6.1.x86_64.rpm typelib-1_0-GstDxva-1_0-1.24.0-150600.4.6.1.x86_64.rpm typelib-1_0-GstInsertBin-1_0-1.24.0-150600.4.6.1.x86_64.rpm typelib-1_0-GstMpegts-1_0-1.24.0-150600.4.6.1.x86_64.rpm typelib-1_0-GstMse-1_0-1.24.0-150600.4.6.1.x86_64.rpm typelib-1_0-GstPlay-1_0-1.24.0-150600.4.6.1.x86_64.rpm typelib-1_0-GstPlayer-1_0-1.24.0-150600.4.6.1.x86_64.rpm typelib-1_0-GstVa-1_0-1.24.0-150600.4.6.1.x86_64.rpm typelib-1_0-GstWebRTC-1_0-1.24.0-150600.4.6.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3053 Security update for ImageMagick important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for ImageMagick fixes the following issues - CVE-2026-53466: integer overflow in the XCF decoder can result in an out-of-bounds read when a crafted image is read (bsc#1270073). - CVE-2026-53467: allocated memory left unchanged in the MNG decoder can lead to a heap information disclosure (bsc#1270074). - CVE-2026-55594: missing depth check in the MVG decoder will result in a stack overflow when a crafted image is provided (bsc#1270077). - CVE-2026-55595: providing invalid arguments to the `connected-components` option can lead to an infinite loop (bsc#1270079). - CVE-2026-55597: incorrect handling of arguments can cause a heap buffer over-write in the JP2 encoder (bsc#1270080). - CVE-2026-56361: off-by-one error in morphology validation can lead to an out-of-bounds read (bsc#1270001). - CVE-2026-56363: integer overflow leading to a division by zero in binomial kernel processing can cause an application crash (bsc#1270002). - CVE-2026-56364: memory leak in `LoadOpenCLDeviceBenchmark` function when parsing malformed OpenCL device profile XML files with unclosed device elements (bsc#1270003). - CVE-2026-56365: memory leak in PNG encoder when writing a MNG image (bsc#1270004). - CVE-2026-56367: integer overflow in the PSB (PSD v2) RLE decoding path can lead to an heap out-of-bounds read (bsc#1268645). - CVE-2026-56368: improper memory management can lead to memory leak in multiple coders that write raw pixel data (bsc#1269064). - CVE-2026-56370: out-of-bounds access in `ConnectedComponentsImage()` when processing `connected-components:*` artifacts with invalid indices (bsc#1269063). - CVE-2026-56371: memory leak in `coders/txt.c` when processing TXT files with texture attributes (bsc#1268879). - CVE-2026-56376: heap use-after-free in the meta coder can lead to denial of service via specially crafted image files (bsc#1268880). - CVE-2026-56379: arbitrary MVG drawing command injection via the SVG decoder when processing specially crafted SVG files (bsc#1268878). - GHSA-3j4x-rwrx-xxj9: possible use-after-free write in PDB decoder (bsc#1268640). ImageMagick-7.1.0.9-150400.6.96.1.src.rpm ImageMagick-config-7-upstream-7.1.0.9-150400.6.96.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-2739 Security update for fontforge important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for fontforge fixes the following issues - CVE-2025-15269: Remote Code Execution via Use-After-Free in SFD file parsing (bsc#1256032). - CVE-2025-15275: Arbitrary code execution via SFD file parsing buffer overflow (bsc#1256025). - CVE-2025-15279: Remote Code Execution via heap-based buffer overflow in BMP file parsing (bsc#1256013). fontforge-20200314-150200.3.18.1.src.rpm fontforge-20200314-150200.3.18.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3458 Security update for vim important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for vim fixes the following issues: This update for vim fixes the following issues: Security issues fixed: - CVE-2026-59856: Arbitrary Code Execution via PHP Omni-Completion (bsc#1271194). - CVE-2026-59857: Out-of-bounds Write in SAL Soundfolding (bsc#1271195). - CVE-2026-59858: Arbitrary Code Execution via C Omni-Completion (bsc#1271193). Non security issue fixed: - Guard suse.vimrc against re-entry to prevent an infinite sourcing loop (bsc#1271684). - allow 'wrap' and 'linebreak' to be set from a modeline (bsc#1268162). Changes for vim: - Updated to version 9.2.0780: * filetype detect missing from completion (9.2.0726). * popup images not rendered correctly when unfocused (9.2.0727). * filetype: supertux info pattern is relative to current dir (9.2.0728). * % skips parens on continued quoted lines (9.2.0729). * GTK4 GUI tabline is not updated (9.2.0730). * GTK4 GUI scrollbar size not updated when restoring a session (9.2.0731). * session: terminal restored using absolute columns/rows (9.2.0732). * GTK3: GUI slow on X11 since dropping the alpha channel (9.2.0733). * function pointer passed to STRNCMP() instead of a length (9.2.0734). * tests: comment test can be improved (9.2.0737). * completion: 'autocompletedelay' blocks the main loop and drops autocommands (9.2.0739). * GTK4: scrollbar wrongly displayed (9.2.0740). * complete_check() does not return TRUE for mapped input (9.2.0741). * filetype: SSH keys and related filetypes not recognized (9.2.0742). * string macros silently accept a size of the wrong type (9.2.0743). * popup_atcursor() closes immediately on white space (9.2.0744). * cscope: connection leak when growing the array fails (9.2.0747). * 'autocompletedelay' interferes with CTRL-G U (9.2.0748). * 'autocompletedelay' interferes with i_CTRL-K (9.2.0749). * completion: 'autocompletedelay' deferral leaks state (9.2.0750). * GTK3 GUI is slow under Wayland (9.2.0751). * GTK4: drag-and-drop does not support HTML (9.2.0752). * GTK GUI deferred redraw skipped on 'lazyredraw' (9.2.0753). * repeated completion length lookup in search_for_exact_line (9.2.0754). * 'autocomplete' behaves inconsistently when recording (9.2.0755). * session with multiple tabpages sets 'winminheight' to 0 (9.2.0756). * pum: no opacity when background not set for Popup menu group (9.2.0758). * some code for 'autocompletedelay' is no longer needed (9.2.0759). * compiler warning for using potentially uninitialized var (9.2.0760). * runtime(netrw): Unix: unable to open '\' file (9.2.0761). * duplicated sub-option name check in :set completion (9.2.0762). * compiler warning about unused function (9.2.0764). * popup: opacity popup over a terminal is not cleared when moved (9.2.0765). * quick_tab entries for empty letters point to the wrong index (9.2.0766). * legacy/vim9cmd modifiers do not set script version for options values (9.2.0767). * legacy/vim9cmd modifiers are not exclusive (9.2.0768). * conversion to utf-16be using iconv is inconsistent (9.2.0769). * dict_add_dict() has inconsistent ownership on failure (9.2.0770). * dict_add_list() has inconsistent ownership on failure (9.2.0771). * Vim9: null dereference inside alloc_type() (9.2.0772). * memory leak in evalfunc.c on alloc failure (9.2.0773). * memory leak in f_getscriptinfo() on alloc failure (9.2.0774). * memory leak in highlight_get_info() on alloc failure (9.2.0775). * memory leak in sign_getlist() on alloc failure (9.2.0776). * memory leak in add_defer() on alloc failure (9.2.0777). * memory leak in compile_dict() on alloc failure (9.2.0778). * memory leak in type_name_func() on alloc failure (9.2.0779). * memory leak in evalvars.c on alloc failure (9.2.0780). - Updated to version 9.2.0725: * GTK: preedit font size is wrong for fractional point sizes (9.2.0532). * '[ mark moved to end of inserted text after CTRL-R CTRL-P paste (9.2.0533). * GTK UI does not support fullscreen mode (9.2.0534). * GTK4: mouse popup menu does not show up at mouse pointer (9.2.0537). * Cannot keep leading whitespace in %{} statusline expr (9.2.0538). * filetype: too many Bitbake include files are recognized (9.2.0539). * Vim9: endclass/endenum/endinterface can give errors (9.2.0541). * Vim9: wrong error when redeclaring a typed variable (9.2.0543). * GTK4: window blank after a resize or drag (9.2.0544). * popup: blending uses hardcoded fallback colors (9.2.0545). * configure: GTK4 build requires GTK >= 4.10 (9.2.0546). * "%v" in 'errorformat' is affected by 'tabstop' (9.2.0547). * GTK4: terminal and pty job output is not processed (9.2.0548). * Cursor wrong after autoindent strip is skipped (9.2.0549). * GTK4: 'mousehide' unhides cursor when switching tabs (9.2.0550). * filetype: Tolk files are not recognized (9.2.0551). * GTK4: F10 does nothing when the menubar is hidden (9.2.0552). * runtime(netrw): netrw rejects hostnames containing _ (9.2.0553). * GTK4: memory leak in free_menu() (9.2.0554). * too many strlen() in ex_substitute() (9.2.0555). * GTK4: scrollbars not shown and do not respond to clicks (9.2.0556). * filetype: Kawasaki Robots files are not recognized (9.2.0557). * filetype: Popcap Reanimation files are not recognized (9.2.0558). * filetype: Kaitai struct files are not recogonized (9.2.0559). * filetype: busybox shebang lines are not recognized (9.2.0560). * [security]: possible code execution with python3complete (9.2.0561). * filetype: SGF files are not recognized (9.2.0562). * GTK3/Wayland: crash with right mouse-button in tabline (9.2.0563). * GTK4: tabline does not respond to mouse clicks (9.2.0564). * [security]: out-of-bounds read in update_snapshot() (9.2.0565). * <C-w>f duplicates window if do_ecmd() is aborted (9.2.0566). * dict function name allocation failure not handled (9.2.0567). * pythoncomplete: g:pythoncomplete_allow_import had no effect (9.2.0568). * out-of-bounds access in libvterm CSI 8 t resize (9.2.0569). * GTK4: mouse wheel scrolling does not work correctly (9.2.0570). * Vim9: memory leak in compile_nested_function() on failure (9.2.0571). * lines disappear with wrapping virtual text after a double-width char (9.2.0572). * Vim9: missing EX_WHOLE on some block keywords (9.2.0573). * popup_create() not blocked in secure/sandbox (9.2.0576). * GTK4: window resizing issues (9.2.0577). * GTK4: :unmenu does not remove entries from the menubar (9.2.0578). * :mksession, :mkview and :mkvimrc emit legacy Vim script (9.2.0579). * xxd: binary output is not colored with -R (9.2.0580). * After maximizing and deleting the quickfix buffer, window height is wrong (9.2.0581). * GTK4: compile error when XFONTSET is defined (9.2.0582). * completion: indent not ignored for fuzzy line completion (9.2.0583). * GTK4: missing UI features (9.2.0584). * line number wrong after undoing a deletion in quickfix buffer (9.2.0585). * Crash with TextPut autocmd when pasting in terminal buffer (9.2.0586). * GTK4: left scrollbar overlaps drawarea (9.2.0587). * GTK4: drawing area loses focus after closing a menubar popover (9.2.0588). * filetype: xinitrc files are not recognized (9.2.0589). * GTK4: drawing area loses focus shape on popup menu open (9.2.0590). * 'scrolljump' ignored when scrolling up (9.2.0591). * Error when restoring session with terminal window (9.2.0592). * :wqall ignores term_setkill() on running terminal buffers (9.2.0593). * Use-after-free with ":wqall" and a running terminal job (9.2.0594). * MS-Windows: Wrong buffer size calculation for gvimext (9.2.0595). * cmdline completion popup cannot be scrolled with the mouse (9.2.0596). * [security]: possible code execution with python complete (9.2.0597). * popup: title set with popup_setoptions() is not shown (9.2.0599). * clientserver method needs to be given as argument (9.2.0600). * matchfuzzypos() returns garbage positions for long candidates (9.2.0601). * popup: No opacity when background not set for Popup group (9.2.0602). * possible heap-buffer-overflow when resizing the GUI (9.2.0603). * GTK4: does not support all clipboard formats (9.2.0606). * GTK4: inputdialog() does not work as expected (9.2.0607). * popup_setoptions()/ch_setoptions() does not check secure mode (9.2.0608). * completion info popup cannot be scrolled with the keyboard (9.2.0609). * cindent: closing brace in a comment affects the next line's indent (9.2.0610). * MS-Windows: evim.exe not working with VIMDLL (9.2.0611). * Cannot render images in popup windows (9.2.0612). * opacity popup leaves stale cells (9.2.0614). * sixel encoder drops pixels on the right edge of shapes (9.2.0615). * GTK4: use-after-free on clipboard read timeout (9.2.0616). * GvimExt: does not support different runtime dirs (9.2.0617). * use-after-free in popup_getoptions() on dict_add() failure (9.2.0618). * integer overflow in popup image size validation (9.2.0619). * runtime(netrw): fix 2match pattern rebuild (9.2.0620). * 'autoindent' not stripped with virtualedit=onemore (9.2.0621). * str2blob() does not work with wide UTF-16 encoding (9.2.0622). * possible integer overflow in spellfile tree bounds check (9.2.0623). * C-N/C-P cannot be mapped in complete() completion (9.2.0624). * GTK4: Link error when Wayland is disabled (9.2.0625). * Vim9: illegal characters allowed in dict key names with dot notation (9.2.0626). * :vim9cmd source handles all scripts as Vim9 script (9.2.0627). * popup image: wrong overlap layering, kitty laggy (9.2.0628). * 0x80 and 0x9b byte not unescaped when check for valid abbr (9.2.0629). * popup images: kitty images output in GUI mode (9.2.0630). * DECRQM and SGR Mouse not supported in foot terminal (9.2.0631). * GTK4: no support for hardware-accelerated rendering (9.2.0632). * MS-Windows: No support for kitty graphics support in terminal (9.2.0633). * GTK4: no minimum resize limit (9.2.0634). * checking the syntax contains/cluster list is slow (9.2.0635). * popup image: stale pixels under RGBA animation frames (9.2.0636). * sixel: anti-aliased RGBA images render with visible outline (9.2.0637). * cannot return matches containing spaces from a custom completion (9.2.0638). * gq with 'formatprg' fails on an empty buffer (9.2.0639). * the "%" command jumps to parens and braces inside comments (9.2.0640). * GTK4: crash in gui_mch_menu_hidden() (9.2.0641). * statusline: buffer overflow with item groups (9.2.0642). * Missing Image ifdefs (9.2.0643). * popup image: duplicate sync-output code (9.2.0644). * Composing chars no longer accepted in end-id abbr (9.2.0645). * GTK3 GUI slow on HiDPI/4K with software rendering (9.2.0646). * matchfuzzypos() false exact match for long equal-length candidates (9.2.0647). * MS-Windows: Compile warnings (9.2.0648). * filetype: tf files sometimes incorrectly recognized (9.2.0649). * Vim aborts at startup when built with the example -O2 CFLAGS (9.2.0650). * completion: 'smartcase' doesn't work with 'longest' (9.2.0651). * popup: stale kitty image after clipwindow scrolls out of view (9.2.0652). * [security]: out-of-bounds write in tree_count_words() (9.2.0653). * GTK4: using uninitialised colors in gui_mch_init() (9.2.0654). * GTK4: missing NULL checks in vim_form_measure() (9.2.0655). * completion: using wrong tolower() in smartcase filtering (9.2.0656). * GTK4: missing menu when right-clicking in tabline (9.2.0657). * xxd: signed integer overflow in huntype() (9.2.0658). * GTK4: no balloon support in GUI (9.2.0659). * Dragging the scrollbar does not trigger WinScrolled (9.2.0660). * unintended wipe of Vim's temp dir, causes errors (9.2.0661). * [security] Stack out-of-bounds write in dump_prefixes() (9.2.0662). * [security]: runtime(netrw): code injection in local file deletion (9.2.0663). * GTK4: GTK critical error on exit printed (9.2.0665). * Terminal-Normal mode does not color empty lines with a background color (9.2.0666). * patch 9.2.0590 was wrong (9.2.0667). * GTK4: minimum horizontal size is too small (9.2.0668). * GTK4: toolbar can be improved (9.2.0669). * [security]: Out-of-bounds read with text properties (9.2.0670). * [security]: possible out-of-bounds read with sodium encrypted files (9.2.0671). * corrupted text property causes internal error (9.2.0672). * configure: clears dynamic ruby linker flags (9.2.0674). * MS-Windows: cannot switch to a buffer with '%' in its name (9.2.0676). * Cannot clear the alternate file register # (9.2.0677). * [security]: potential powershell code execution in zip.vim (9.2.0678). * [security]: Out-of-bounds read with text property virtual text (9.2.0679). * keytrans() doesn't replace '|' and '\' (9.2.0680). * configure: -lruby added even for a dynamic ruby build (9.2.0681). * Wrong dot-repeat when calling complete() while filtering completion (9.2.0682). * filetype completion mishandles finished sub options (9.2.0683). * :reg # does not display the value of the '#' register (9.2.0684). * clipboard.c does not get the Wayland CFLAGS on GTK2 (9.2.0685). * style: strcmp usage is inconsistent (9.2.0686). * popup_image_composites_frames() has improper if block scope (9.2.0687). * Terminal-Normal mode does not show the Visual selection on a colored empty line (9.2.0688). * the "%" command is slow on a long line with many slashes (9.2.0689). * Solaris: swap file names are too long (9.2.0690). * Solaris: Test_terminal_composing_unicode() fails (9.2.0691). * GTK2: build failure, popup images not drawn correctly (9.2.0692). * Solaris: some tests faiures due to Solaris peculiarities (9.2.0694). * Solaris: test_delete_temp_dir() fails because of missing flock (9.2.0695). * GTK4: A few issues with toolbar support (9.2.0696). * possible overflow when parsing CSI keys (9.2.0697). * [security]: Out-of-bounds write with soundfold() (9.2.0698). * [security]: possible code execution with python complete (9.2.0699). * configure: -lrt requirement for timer_create not detected (9.2.0700). * :windo and :tabdo create an extra window with 'winfixbuf' (9.2.0702). * session file does not store relative Vim9 autoload imports (9.2.0703). * GTK4: not handling mouse events (9.2.0704). * :delete # silently fails to update "# and clobbers "0 (9.2.0705). * completion: popup misplaced when text before it is concealed (9.2.0707). * Leaks in do_autocmd in error case (9.2.0708). * GTK4: a few minor issues (9.2.0709). * GTK4 GUI resize handling can be improved (9.2.0710). * leak in ins_compl_infercase_gettext() in error case (9.2.0711). * GTK4: dialogs not handling mnemonics correctly (9.2.0712). * completion: ruler not updated correctly when the popup menu is visible (9.2.0713). * Coverity warns for NULL deref (9.2.0714). * Coverity warns about copy/paste error in hl_blend_attr() (9.2.0715). * filetype: not all supertux files are recognized (9.2.0716). * :syn sync without an argument also lists syntax cluster (9.2.0718). * GTK4: default menu is lacking (9.2.0719). * GTK4: no support for browsefilter (9.2.0720). * serverlist() returns strings separated by \n (9.2.0721). * GTK4: find/replace dialog can be improved (9.2.0722). * term_start() does not support "noclose" (9.2.0723). * use-after-free when freeing exit_cb job on exit (9.2.0724). gvim-9.2.0780-150500.20.61.2.x86_64.rpm vim-9.2.0780-150500.20.61.2.src.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-2814 Security update for MozillaFirefox important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for MozillaFirefox fixes the following issues: - Removed obsolete mozilla-nss-certs and recommends p11-kit-nss-trust (bsc#1269226) Update to Firefox 140.12.0 ESR (MFSA 2026-58, bsc#1268071): - CVE-2026-12289: Privilege escalation in the Graphics: WebRender component. - CVE-2026-12290: Memory safety bug fixed in Firefox ESR 140.12. - CVE-2026-12291: Use-after-free in the Networking: HTTP component. - CVE-2026-12292: Incorrect boundary conditions in the Web Audio component. - CVE-2026-12294: Sandbox escape in the DOM: Workers component. - CVE-2026-12295: Sandbox escape in the DOM: Navigation component. - CVE-2026-12296: Sandbox escape in the Security: Process Sandboxing component. - CVE-2026-12297: Sandbox escape due to incorrect boundary conditions in the Networking component. - CVE-2026-12298: Memory safety bug fixed in Firefox ESR 140.12. - CVE-2026-12299: JIT miscompilation in the DOM: Core & HTML component. - CVE-2026-12302: Mitigation bypass in the DOM: Security component. - CVE-2026-12304: Same-origin policy bypass in the Networking: Cookies component. - CVE-2026-12305: Memory safety bug fixed in Firefox ESR 140.12. - CVE-2026-12306: Memory safety bug fixed in Firefox ESR 140.12. - CVE-2026-12307: Memory safety bug fixed in Firefox ESR 140.12. - CVE-2026-12308: Memory safety bug fixed in Firefox ESR 140.12. - CVE-2026-12309: Memory safety bug fixed in Firefox ESR 140.12. - CVE-2026-12310: Memory safety bug fixed in Firefox ESR 140.12. - CVE-2026-12311: Information disclosure, sandbox escape in the Security: Process Sandboxing component. - CVE-2026-12312: Memory safety bug fixed in Firefox ESR 140.12. - CVE-2026-12313: Information disclosure, sandbox escape in the Security: Process Sandboxing component. - CVE-2026-12314: Memory safety bug fixed in Firefox ESR 140.12. - CVE-2026-12315: Mitigation bypass in the DOM: Security component. - CVE-2026-12324: Incorrect boundary conditions in the Graphics: CanvasWebGL component. - CVE-2026-12325: Denial-of-service in the Graphics: ImageLib component. - CVE-2026-12327: Memory safety bugs fixed in Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152. - CVE-2026-12328: Memory safety bugs fixed in Firefox ESR 115.37, Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152. - CVE-2026-12329: Memory safety bug fixed in Firefox ESR 140.12. - CVE-2026-12330: Incorrect boundary conditions in the Internationalization component. MozillaFirefox-140.12.0-150200.152.245.1.src.rpm MozillaFirefox-140.12.0-150200.152.245.1.x86_64.rpm MozillaFirefox-devel-140.12.0-150200.152.245.1.noarch.rpm MozillaFirefox-translations-common-140.12.0-150200.152.245.1.x86_64.rpm MozillaFirefox-translations-other-140.12.0-150200.152.245.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3036 Security update for yelp important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for yelp fixes the following issue - CVE-2026-13601: overly permissive Content Security Policy allows host file disclosure via Flatpak applications (bsc#1269625). libyelp0-42.2-150600.3.6.1.x86_64.rpm yelp-42.2-150600.3.6.1.src.rpm yelp-42.2-150600.3.6.1.x86_64.rpm yelp-devel-42.2-150600.3.6.1.x86_64.rpm yelp-lang-42.2-150600.3.6.1.noarch.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3169 Security update for openexr moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for openexr fixes the following issues - CVE-2026-54920: unchecked integer overflows in Image::resize() followed by an exception can lead to an invalid delete via uninitialized pointers (bsc#1269703). - CVE-2026-55059: row setter utilizing dataWindow.min.x instead of min.y can lead to a heap out-of-bounds write (bsc#1269702). - CVE-2026-55373: integer overflow in roundListSizeUp() wrapping a 32-bit unsigned value to zero can lead to an infinite loop (bsc#1269701). libIlmImf-2_2-23-2.2.1-150000.3.52.1.x86_64.rpm libIlmImfUtil-2_2-23-2.2.1-150000.3.52.1.x86_64.rpm openexr-2.2.1-150000.3.52.1.src.rpm openexr-devel-2.2.1-150000.3.52.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3058 Security update for gstreamer-plugins-bad important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for gstreamer-plugins-bad fixes the following issues - CVE-2026-12892: 1-byte heap out-of-bounds read in H.264 NAL extension slice parser (bsc#1268971). - CVE-2026-14935: webrtcbin accepts remote SDP without a=fingerprint due to inverted presence check (bsc#1271051). - CVE-2026-52720: invalid check of total area instead of individual dimensions could trigger a heap out-of-bounds write (bsc#1268406). - CVE-2026-52721: crafted PCAP records during IPv4 or TCP header parsing could cause an out-of-bounds read (bsc#1268408). - CVE-2026-52722: crafted VMnc stream with large cursor dimensions can overflow signed integer (bsc#1268410). - CVE-2026-53702: incorrect loop bound during H.265 SEI message parsing could result in a stack buffer overflow (bsc#1268168). - CVE-2026-59692: unvalidated peer certificate Subject DN printed during a DTLS handshake could cause a stack buffer overflow (bsc#1271168). gstreamer-plugins-bad-1.24.0-150600.4.9.1.src.rpm gstreamer-plugins-bad-1.24.0-150600.4.9.1.x86_64.rpm gstreamer-plugins-bad-devel-1.24.0-150600.4.9.1.x86_64.rpm gstreamer-plugins-bad-lang-1.24.0-150600.4.9.1.noarch.rpm libgstadaptivedemux-1_0-0-1.24.0-150600.4.9.1.x86_64.rpm libgstanalytics-1_0-0-1.24.0-150600.4.9.1.x86_64.rpm libgstbadaudio-1_0-0-1.24.0-150600.4.9.1.x86_64.rpm libgstbasecamerabinsrc-1_0-0-1.24.0-150600.4.9.1.x86_64.rpm libgstcodecparsers-1_0-0-1.24.0-150600.4.9.1.x86_64.rpm libgstcodecs-1_0-0-1.24.0-150600.4.9.1.x86_64.rpm libgstcuda-1_0-0-1.24.0-150600.4.9.1.x86_64.rpm libgstdxva-1_0-0-1.24.0-150600.4.9.1.x86_64.rpm libgstinsertbin-1_0-0-1.24.0-150600.4.9.1.x86_64.rpm libgstisoff-1_0-0-1.24.0-150600.4.9.1.x86_64.rpm libgstmpegts-1_0-0-1.24.0-150600.4.9.1.x86_64.rpm libgstmse-1_0-0-1.24.0-150600.4.9.1.x86_64.rpm libgstsctp-1_0-0-1.24.0-150600.4.9.1.x86_64.rpm libgsturidownloader-1_0-0-1.24.0-150600.4.9.1.x86_64.rpm libgstva-1_0-0-1.24.0-150600.4.9.1.x86_64.rpm libgstvulkan-1_0-0-1.24.0-150600.4.9.1.x86_64.rpm libgstwayland-1_0-0-1.24.0-150600.4.9.1.x86_64.rpm libgstwebrtc-1_0-0-1.24.0-150600.4.9.1.x86_64.rpm libgstwebrtcnice-1_0-0-1.24.0-150600.4.9.1.x86_64.rpm typelib-1_0-CudaGst-1_0-1.24.0-150600.4.9.1.x86_64.rpm typelib-1_0-GstAnalytics-1_0-1.24.0-150600.4.9.1.x86_64.rpm typelib-1_0-GstBadAudio-1_0-1.24.0-150600.4.9.1.x86_64.rpm typelib-1_0-GstCodecs-1_0-1.24.0-150600.4.9.1.x86_64.rpm typelib-1_0-GstCuda-1_0-1.24.0-150600.4.9.1.x86_64.rpm typelib-1_0-GstDxva-1_0-1.24.0-150600.4.9.1.x86_64.rpm typelib-1_0-GstInsertBin-1_0-1.24.0-150600.4.9.1.x86_64.rpm typelib-1_0-GstMpegts-1_0-1.24.0-150600.4.9.1.x86_64.rpm typelib-1_0-GstMse-1_0-1.24.0-150600.4.9.1.x86_64.rpm typelib-1_0-GstPlay-1_0-1.24.0-150600.4.9.1.x86_64.rpm typelib-1_0-GstPlayer-1_0-1.24.0-150600.4.9.1.x86_64.rpm typelib-1_0-GstVa-1_0-1.24.0-150600.4.9.1.x86_64.rpm typelib-1_0-GstWebRTC-1_0-1.24.0-150600.4.9.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3194 Security update for ImageMagick moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for ImageMagick fixes the following issues - CVE-2026-56375: possible memory leak in ASHLAR coder when action fails (bsc#1271495). - CVE-2026-61464: heap buffer overwrite in X11 import with crafted window title (bsc#1271496). - CVE-2026-61859: policy bypass in script operation due to missing checks (bsc#1271497). - CVE-2026-61860: use-after-free when `freetype` initialization fails (bsc#1271494). - CVE-2026-61862: information disclosure when printing profiles with debug enabled (bsc#1271493). - CVE-2026-61863: memory leak in TIFF encoder when a temporary file could not be created (bsc#1271492). - CVE-2026-61864: memory leak in color transformation to log colorspace when operation fails (bsc#1271491). - CVE-2026-61865: memory leak in hough lines operation when an operation fails (bsc#1271490). - CVE-2026-61866: memory leak in JNG encoder when a blob could not be opened (bsc#1271489). - CVE-2026-61867: memory leak in TIFF encoder when an allocation fails (bsc#1271488). - CVE-2026-61868: memory leak in YUV decoder when opening of blob fails (bsc#1271487). - CVE-2026-61869: memory leak in MIFF encoder when allocation fails (bsc#1271486). - CVE-2026-61871: memory leak in ICON decoder when allocation fails (bsc#1271485). - CVE-2026-61872: memory leak in TIFF encoder when invalid `tiff:tile-geometry` is specified (bsc#1271484). - CVE-2026-55628: policy bypass in concatenate operation due to missing checks (bsc#1270081). - CVE-2026-56362: heap buffer overflow read in `GetPixelIndex` due to metadata-cache desynchronization in `OpenPixelCache` (bsc#1271100). - CVE-2026-56366: META reader memory leak in the APP1JPEG input path (bsc#1271316). - CVE-2026-56372: heap buffer overflow read in magnify operation via unrecognized `magnify:method` value (bsc#1271314). - CVE-2026-56373: possible use-after-free write in PDB decoder (bsc#1268640 bsc#1271315). - CVE-2026-56377: policy bypass can create or truncate files (bsc#1270006). - CVE-2026-61465: policy bypass possible with matrix-backed operations (bsc#1271313). - CVE-2026-61857: heap use-after-free via XMP profile could result in a crash (bsc#1271312). - CVE-2026-61858: policy bypass in APNG encoder and delegates due to a missing check (bsc#1271311). - CVE-2026-61861: use-after-free in `FormatMagickCaption` when memory allocation fails (bsc#1271294). - CVE-2026-61870: memory leak in VIFF encoder when allocation fails (bsc#1271293). ImageMagick-7.1.1.43-150700.3.70.1.src.rpm ImageMagick-7.1.1.43-150700.3.70.1.x86_64.rpm ImageMagick-config-7-SUSE-7.1.1.43-150700.3.70.1.x86_64.rpm ImageMagick-config-7-upstream-limited-7.1.1.43-150700.3.70.1.x86_64.rpm ImageMagick-config-7-upstream-open-7.1.1.43-150700.3.70.1.x86_64.rpm ImageMagick-config-7-upstream-secure-7.1.1.43-150700.3.70.1.x86_64.rpm ImageMagick-config-7-upstream-websafe-7.1.1.43-150700.3.70.1.x86_64.rpm ImageMagick-devel-7.1.1.43-150700.3.70.1.x86_64.rpm libMagick++-7_Q16HDRI5-7.1.1.43-150700.3.70.1.x86_64.rpm libMagick++-devel-7.1.1.43-150700.3.70.1.x86_64.rpm libMagickCore-7_Q16HDRI10-7.1.1.43-150700.3.70.1.x86_64.rpm libMagickWand-7_Q16HDRI10-7.1.1.43-150700.3.70.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3193 Security update for ImageMagick moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for ImageMagick fixes the following issues - CVE-2026-55628: policy bypass in concatenate operation due to missing checks (bsc#1270081). - CVE-2026-56362: heap buffer overflow read in `GetPixelIndex` due to metadata-cache desynchronization in `OpenPixelCache` (bsc#1271100). - CVE-2026-56366: META reader memory leak in the APP1JPEG input path (bsc#1271316). - CVE-2026-56372: heap buffer overflow read in magnify operation via unrecognized `magnify:method` value (bsc#1271314). - CVE-2026-56373: possible use-after-free write in PDB decoder (bsc#1268640 bsc#1271315). - CVE-2026-56375: possible memory leak in ASHLAR coder when action fails (bsc#1271495). - CVE-2026-56377: policy bypass can create or truncate files (bsc#1270006). - CVE-2026-61464: heap buffer overwrite in X11 import with crafted window title (bsc#1271496). - CVE-2026-61465: policy bypass possible with matrix-backed operations (bsc#1271313). - CVE-2026-61857: heap use-after-free via XMP profile could result in a crash (bsc#1271312). - CVE-2026-61858: policy bypass in APNG encoder and delegates due to a missing check (bsc#1271311). - CVE-2026-61859: policy bypass in script operation due to missing checks (bsc#1271497). - CVE-2026-61861: use-after-free in `FormatMagickCaption` when memory allocation fails (bsc#1271294). - CVE-2026-61862: information disclosure when printing profiles with debug enabled (bsc#1271493). - CVE-2026-61863: memory leak in TIFF encoder when a temporary file could not be created (bsc#1271492). - CVE-2026-61864: memory leak in color transformation to log colorspace when operation fails (bsc#1271491). - CVE-2026-61865: memory leak in hough lines operation when an operation fails (bsc#1271490). - CVE-2026-61866: memory leak in JNG encoder when a blob could not be opened (bsc#1271489). - CVE-2026-61867: memory leak in TIFF encoder when an allocation fails (bsc#1271488). - CVE-2026-61868: memory leak in YUV decoder when opening of blob fails (bsc#1271487). - CVE-2026-61869: memory leak in MIFF encoder when allocation fails (bsc#1271486). - CVE-2026-61870: memory leak in VIFF encoder when allocation fails (bsc#1271293). - CVE-2026-61872: memory leak in TIFF encoder when invalid `tiff:tile-geometry` is specified (bsc#1271484). ImageMagick-7.1.0.9-150400.6.101.1.src.rpm ImageMagick-config-7-upstream-7.1.0.9-150400.6.101.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3149 Security update for ffmpeg moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for ffmpeg fixes the following issue - CVE-2025-10256: NULL pointer dereference in Firequalizer filter (bsc#1249431). ffmpeg-3.4.2-150200.11.70.1.src.rpm libavcodec57-3.4.2-150200.11.70.1.x86_64.rpm libavutil-devel-3.4.2-150200.11.70.1.x86_64.rpm libavutil55-3.4.2-150200.11.70.1.x86_64.rpm libpostproc-devel-3.4.2-150200.11.70.1.x86_64.rpm libpostproc54-3.4.2-150200.11.70.1.x86_64.rpm libswresample-devel-3.4.2-150200.11.70.1.x86_64.rpm libswresample2-3.4.2-150200.11.70.1.x86_64.rpm libswscale-devel-3.4.2-150200.11.70.1.x86_64.rpm libswscale4-3.4.2-150200.11.70.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3221 Security update for MozillaFirefox critical SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for MozillaFirefox fixes the following issue: - Firefox Extended Support Release 140.13.0 ESR (MFSA 2026-70, bsc#1271649): - CVE-2026-15718: Invalid pointer in the JavaScript: WebAssembly component. - CVE-2026-15719: Site isolation issue in the DOM: Navigation component. - CVE-2026-16349: Same-origin policy bypass in the DOM: Navigation component. - CVE-2026-16350: Incorrect boundary conditions in the Audio/Video: cubeb component. - CVE-2026-16351: Sandbox escape due to use-after-free in the DOM: Navigation component. - CVE-2026-16352: Sandbox escape due to use-after-free in the Disability Access APIs component. - CVE-2026-16353: Invalid pointer in the DOM: Bindings (WebIDL) component. - CVE-2026-16354: Information disclosure in the Graphics: ImageLib component. - CVE-2026-16355: JIT miscompilation in the JavaScript Engine: JIT component. - CVE-2026-16356: Sandbox escape due to use-after-free in the Disability Access APIs component. - CVE-2026-16357: Incorrect boundary conditions in the Graphics component. - CVE-2026-16358: Site isolation issue in the Graphics: WebRender component. - CVE-2026-16359: Incorrect boundary conditions in the Audio/Video: GMP component. - CVE-2026-16360: Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153. - CVE-2026-16361: Memory safety bugs fixed in Firefox ESR 115.38 and Firefox ESR 140.13. - CVE-2026-16362: Use-after-free in the WebRTC: Audio/Video component. - CVE-2026-16363: JIT miscompilation in the JavaScript: WebAssembly component. - CVE-2026-16368: Incorrect boundary conditions in the JavaScript: WebAssembly component. - CVE-2026-16369: Integer overflow in the JavaScript: WebAssembly component. - CVE-2026-16371: Privilege escalation in the DOM: Navigation component. - CVE-2026-16374: Information disclosure in the Framework component in DevTools. - CVE-2026-16375: Site isolation issue in the Networking: HTTP component. - CVE-2026-16377: Mitigation bypass in the PDF Viewer component. - CVE-2026-16379: Privilege escalation in the DOM: Content Processes component. - CVE-2026-16381: Same-origin policy bypass in the Networking: DNS component. - CVE-2026-16383: Mitigation bypass in the DOM: Networking component. - CVE-2026-16387: Site isolation issue in the Networking component. - CVE-2026-16390: Mitigation bypass in the Enterprise Policies component. - CVE-2026-16391: Information disclosure in the Storage: IndexedDB component. - CVE-2026-16396: Privilege escalation in WebExtensions. - CVE-2026-16405: Information disclosure in the Networking: WebSockets component. - CVE-2026-16412: Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153. MozillaFirefox-140.13.0-150200.152.248.1.src.rpm MozillaFirefox-140.13.0-150200.152.248.1.x86_64.rpm MozillaFirefox-devel-140.13.0-150200.152.248.1.noarch.rpm MozillaFirefox-translations-common-140.13.0-150200.152.248.1.x86_64.rpm MozillaFirefox-translations-other-140.13.0-150200.152.248.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3218 Security update for avahi moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for avahi fixes the following issue: - CVE-2025-59529: local DoS due to simple protocol server ignoring client limit CLIENTS_MAX (bsc#1255451). avahi-0.8-150600.15.21.1.src.rpm avahi-autoipd-0.8-150600.15.21.1.x86_64.rpm avahi-glib2-0.8-150600.15.21.1.src.rpm avahi-utils-gtk-0.8-150600.15.21.1.x86_64.rpm libavahi-gobject-devel-0.8-150600.15.21.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3338 Security update for webkit2gtk3 important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for webkit2gtk3 fixes the following issues: - CVE-2024-4367: missing type check when handling fonts in PDF.js can allow arbitrary JavaScript execution (bsc#1271638). - CVE-2026-39872: maliciously crafted web content can lead to an unexpected process crash (bsc#1271638). - CVE-2026-43663: maliciously crafted web content can lead to an unexpected process crash (bsc#1271638). - CVE-2026-43676: out-of-bounds access when processing web content can lead to an unexpected Safari crash (bsc#1271638). - CVE-2026-43699: use-after-free issue when processing web content can lead to an unexpected process crash (bsc#1271638). - CVE-2026-43701: malicious website can process restricted web content outside the sandbox (bsc#1271638). - CVE-2026-43705: type confusion issue when processing web content can lead to memory corruption (bsc#1271638). - CVE-2026-43707: memory corruption issue when processing web content can lead to an unexpected process crash (bsc#1271638). - CVE-2026-43712: maliciously crafted web content can lead to an unexpected process crash (bsc#1271638). - CVE-2026-43713: visiting a website can leak sensitive data due to a permissions issue (bsc#1271638). - CVE-2026-43715: use-after-free issue when processing web content can lead to memory corruption (bsc#1271638). - CVE-2026-43716: maliciously crafted web content can lead to an unexpected Safari crash (bsc#1271638). - CVE-2026-43720: use-after-free issue when processing web content can lead to an unexpected Safari crash (bsc#1271638). - CVE-2026-43721: malicious website can silently hijack clipboard data (bsc#1271638). - CVE-2026-43725: unvalidated input can allow a malicious website to process restricted web content outside the sandbox (bsc#1271638). - CVE-2026-43726: use-after-free issue when processing web content can lead to an unexpected process crash (bsc#1271638). - CVE-2026-43727: use-after-free issue when processing web content can lead to an unexpected Safari crash (bsc#1271638). - CVE-2026-43731: use-after-free issue when processing web content can lead to memory corruption (bsc#1271638). - CVE-2026-43732: path handling issue when processing web content can disclose sensitive user information (bsc#1271638). - CVE-2026-43734: use-after-free issue when processing web content can lead to an unexpected process crash (bsc#1271638). - CVE-2026-43740: maliciously crafted web content can result in the disclosure of process memory (bsc#1271638). - CVE-2026-43742: use-after-free issue when processing web content can lead to an unexpected process crash (bsc#1271638). - CVE-2026-43745: out-of-bounds write issue when processing web content can lead to an unexpected Safari crash (bsc#1271638). Changes for webkit2gtk3: - Update to version 2.52.5: * Fire scrollend event for instant programmatic scrolls. * Increase network idle connection timeout to 115 seconds. * Add User-Agent quirk for HBO Max. * Fix the build with system malloc. WebKitGTK-4.1-lang-2.52.5-150600.12.71.1.noarch.rpm libjavascriptcoregtk-4_1-0-2.52.5-150600.12.71.1.x86_64.rpm libwebkit2gtk-4_1-0-2.52.5-150600.12.71.1.x86_64.rpm typelib-1_0-JavaScriptCore-4_1-2.52.5-150600.12.71.1.x86_64.rpm typelib-1_0-WebKit2-4_1-2.52.5-150600.12.71.1.x86_64.rpm typelib-1_0-WebKit2WebExtension-4_1-2.52.5-150600.12.71.1.x86_64.rpm webkit2gtk-4_1-injected-bundles-2.52.5-150600.12.71.1.x86_64.rpm webkit2gtk3-2.52.5-150600.12.71.1.src.rpm webkit2gtk3-devel-2.52.5-150600.12.71.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3336 Security update for ImageMagick important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for ImageMagick fixes the following issue: - Extend CVE-2026-56379 patch by f63c78b (bsc#1268878). ImageMagick-7.1.1.43-150700.3.73.1.src.rpm ImageMagick-7.1.1.43-150700.3.73.1.x86_64.rpm ImageMagick-config-7-SUSE-7.1.1.43-150700.3.73.1.x86_64.rpm ImageMagick-config-7-upstream-limited-7.1.1.43-150700.3.73.1.x86_64.rpm ImageMagick-config-7-upstream-open-7.1.1.43-150700.3.73.1.x86_64.rpm ImageMagick-config-7-upstream-secure-7.1.1.43-150700.3.73.1.x86_64.rpm ImageMagick-config-7-upstream-websafe-7.1.1.43-150700.3.73.1.x86_64.rpm ImageMagick-devel-7.1.1.43-150700.3.73.1.x86_64.rpm libMagick++-7_Q16HDRI5-7.1.1.43-150700.3.73.1.x86_64.rpm libMagick++-devel-7.1.1.43-150700.3.73.1.x86_64.rpm libMagickCore-7_Q16HDRI10-7.1.1.43-150700.3.73.1.x86_64.rpm libMagickWand-7_Q16HDRI10-7.1.1.43-150700.3.73.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3335 Security update for ImageMagick important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for ImageMagick fixes the following issue - Extend CVE-2026-56379 patch by f63c78b (bsc#1268878). ImageMagick-7.1.0.9-150400.6.104.1.src.rpm ImageMagick-config-7-upstream-7.1.0.9-150400.6.104.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3404 Security update for PackageKit moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for PackageKit fixes the following issues: - CVE-2026-10294: manipulation of the argument frontend-socket can lead to improper authorization (bsc#1267250). PackageKit-1.2.8-150600.4.17.1.src.rpm True PackageKit-1.2.8-150600.4.17.1.x86_64.rpm True PackageKit-backend-zypp-1.2.8-150600.4.17.1.x86_64.rpm True PackageKit-devel-1.2.8-150600.4.17.1.x86_64.rpm True PackageKit-lang-1.2.8-150600.4.17.1.noarch.rpm True libpackagekit-glib2-18-1.2.8-150600.4.17.1.x86_64.rpm True libpackagekit-glib2-devel-1.2.8-150600.4.17.1.x86_64.rpm True typelib-1_0-PackageKitGlib-1_0-1.2.8-150600.4.17.1.x86_64.rpm True SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3527 Security update for gstreamer-plugins-bad moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for gstreamer-plugins-bad fixes the following issue: - CVE-2026-52718: byte count instead of a bit count in gst_av1_parser_parse_tile_list_obu() can cause parser desynchronization and an application crash (bsc#1268394). gstreamer-plugins-bad-1.24.0-150600.4.12.1.src.rpm gstreamer-plugins-bad-1.24.0-150600.4.12.1.x86_64.rpm gstreamer-plugins-bad-devel-1.24.0-150600.4.12.1.x86_64.rpm gstreamer-plugins-bad-lang-1.24.0-150600.4.12.1.noarch.rpm libgstadaptivedemux-1_0-0-1.24.0-150600.4.12.1.x86_64.rpm libgstanalytics-1_0-0-1.24.0-150600.4.12.1.x86_64.rpm libgstbadaudio-1_0-0-1.24.0-150600.4.12.1.x86_64.rpm libgstbasecamerabinsrc-1_0-0-1.24.0-150600.4.12.1.x86_64.rpm libgstcodecparsers-1_0-0-1.24.0-150600.4.12.1.x86_64.rpm libgstcodecs-1_0-0-1.24.0-150600.4.12.1.x86_64.rpm libgstcuda-1_0-0-1.24.0-150600.4.12.1.x86_64.rpm libgstdxva-1_0-0-1.24.0-150600.4.12.1.x86_64.rpm libgstinsertbin-1_0-0-1.24.0-150600.4.12.1.x86_64.rpm libgstisoff-1_0-0-1.24.0-150600.4.12.1.x86_64.rpm libgstmpegts-1_0-0-1.24.0-150600.4.12.1.x86_64.rpm libgstmse-1_0-0-1.24.0-150600.4.12.1.x86_64.rpm libgstsctp-1_0-0-1.24.0-150600.4.12.1.x86_64.rpm libgsturidownloader-1_0-0-1.24.0-150600.4.12.1.x86_64.rpm libgstva-1_0-0-1.24.0-150600.4.12.1.x86_64.rpm libgstvulkan-1_0-0-1.24.0-150600.4.12.1.x86_64.rpm libgstwayland-1_0-0-1.24.0-150600.4.12.1.x86_64.rpm libgstwebrtc-1_0-0-1.24.0-150600.4.12.1.x86_64.rpm libgstwebrtcnice-1_0-0-1.24.0-150600.4.12.1.x86_64.rpm typelib-1_0-CudaGst-1_0-1.24.0-150600.4.12.1.x86_64.rpm typelib-1_0-GstAnalytics-1_0-1.24.0-150600.4.12.1.x86_64.rpm typelib-1_0-GstBadAudio-1_0-1.24.0-150600.4.12.1.x86_64.rpm typelib-1_0-GstCodecs-1_0-1.24.0-150600.4.12.1.x86_64.rpm typelib-1_0-GstCuda-1_0-1.24.0-150600.4.12.1.x86_64.rpm typelib-1_0-GstDxva-1_0-1.24.0-150600.4.12.1.x86_64.rpm typelib-1_0-GstInsertBin-1_0-1.24.0-150600.4.12.1.x86_64.rpm typelib-1_0-GstMpegts-1_0-1.24.0-150600.4.12.1.x86_64.rpm typelib-1_0-GstMse-1_0-1.24.0-150600.4.12.1.x86_64.rpm typelib-1_0-GstPlay-1_0-1.24.0-150600.4.12.1.x86_64.rpm typelib-1_0-GstPlayer-1_0-1.24.0-150600.4.12.1.x86_64.rpm typelib-1_0-GstVa-1_0-1.24.0-150600.4.12.1.x86_64.rpm typelib-1_0-GstWebRTC-1_0-1.24.0-150600.4.12.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3414 Security update for ImageMagick moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for ImageMagick fixes the following issues: - CVE-2026-62343: heap buffer overwrite in morphology operation when an invalid kernel is provided (bsc#1272575). - CVE-2026-62363: heap buffer overwrite in fx operation when processing a crafted argument (bsc#1272582). - CVE-2026-62946: integer overflow in JNX decoder can lead to heap buffer overwrite when processing extremely large files on 32-bit builds (bsc#1272580). - CVE-2026-66011: memory leak in the magick command-line interface when invalid options are provided (bsc#1272577). - GHSA-hc76-7mpc-qjqh: code injection in HTML encoder due to incomplete fix of CVE-2026-25797 (bsc#1272579). ImageMagick-7.1.1.43-150700.3.76.1.src.rpm ImageMagick-7.1.1.43-150700.3.76.1.x86_64.rpm ImageMagick-config-7-SUSE-7.1.1.43-150700.3.76.1.x86_64.rpm ImageMagick-config-7-upstream-limited-7.1.1.43-150700.3.76.1.x86_64.rpm ImageMagick-config-7-upstream-open-7.1.1.43-150700.3.76.1.x86_64.rpm ImageMagick-config-7-upstream-secure-7.1.1.43-150700.3.76.1.x86_64.rpm ImageMagick-config-7-upstream-websafe-7.1.1.43-150700.3.76.1.x86_64.rpm ImageMagick-devel-7.1.1.43-150700.3.76.1.x86_64.rpm libMagick++-7_Q16HDRI5-7.1.1.43-150700.3.76.1.x86_64.rpm libMagick++-devel-7.1.1.43-150700.3.76.1.x86_64.rpm libMagickCore-7_Q16HDRI10-7.1.1.43-150700.3.76.1.x86_64.rpm libMagickWand-7_Q16HDRI10-7.1.1.43-150700.3.76.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3413 Security update for ImageMagick moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for ImageMagick fixes the following issues: - CVE-2026-62343: heap buffer overwrite in morphology operation when an invalid kernel is provided (bsc#1272575). - CVE-2026-62946: integer overflow in JNX decoder can lead to heap buffer overwrite when processing extremely large files on 32-bit builds (bsc#1272580). - GHSA-hc76-7mpc-qjqh: code injection in HTML encoder due to incomplete fix of CVE-2026-25797 (bsc#1272579). ImageMagick-7.1.0.9-150400.6.107.1.src.rpm ImageMagick-config-7-upstream-7.1.0.9-150400.6.107.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3605 Security update for openssh important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for openssh fixes the following issues: - Backported support for the mlkemx25519 key exchange from upstream (jsc#PED-16473). - CVE-2026-59995: sftp: location of downloaded files not properly constrained when `sftp server:/path .` is used with an attacker-controlled server (bsc#1271044). - CVE-2026-59996: scp: file placed in the parent directory of an intended target directory when copy occurs between two remote destinations (bsc#1271046). - CVE-2026-59997: sshd: `internal-sftp` command lines are silently truncated after the 9th argument (bsc#1271048). - CVE-2026-59998: sshd: undocumented security-relevant `GSSAPIStrictAcceptorCheck` behavior in Windows Active Directory is not documented (bsc#1271049). - CVE-2026-59999: sshd: `DisableForwarding=yes` does not override `PermitTunnel=yes` (bsc#1271052). - CVE-2026-60000: sshd: pre-authentication denial of service when GSSAPIAuthentication is enabled (bsc#1271053). - CVE-2026-60001: sshd: minimum authentication delay is not honored (bsc#1271054). - CVE-2026-60002: ssh: client-side use-after-free when a server changes its host key during a key reexchange (bsc#1271055). openssh-askpass-gnome-9.6p1-150600.6.49.1.src.rpm openssh-askpass-gnome-9.6p1-150600.6.49.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3485 Security update for spice-vdagent important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for spice-vdagent fixes the following issues: - CVE-2026-57965: integer overflow in `udscs_write()` can lead to heap buffer overflow (bsc#1269553). - CVE-2026-57966: improper sanitization allows a compromised SPICE host to write arbitrary files to any location on the guest operating system (bsc#1269554). spice-vdagent-0.22.1-150500.4.3.1.src.rpm spice-vdagent-0.22.1-150500.4.3.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3501 Security update for wireshark important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for wireshark fixes the following issues: Update to version 4.6.7: - CVE-2026-5299: ICMPv6 dissector crash (bsc#1263757). - CVE-2026-5401: AFP dissector crash (bsc#1263756). - CVE-2026-5402: TLS dissector crash and possible code execution (bsc#1263755). - CVE-2026-5403: SBC audio codec crash (bsc#1263765). - CVE-2026-5404: K12 RF5 file parser crash (bsc#1263766). - CVE-2026-5405: RDP dissector crash (bsc#1263767). - CVE-2026-5406: FC-SWILS dissector crash (bsc#1263754). - CVE-2026-5407: SMB2 dissector infinite loop (bsc#1263753). - CVE-2026-5408: BT-DHT dissector crash (bsc#1263752). - CVE-2026-5409: Monero dissector crash (bsc#1263751). - CVE-2026-5653: DCP-ETSI dissector crash (bsc#1263750). - CVE-2026-5654: AMR-NB audio codec crash (bsc#1263749). - CVE-2026-5655: SDP dissector crash (bsc#1263748). - CVE-2026-5656: Profile import crash and possible code execution (bsc#1263809). - CVE-2026-5657: iLBC audio codec crash (bsc#1263747). - CVE-2026-6519: MBIM protocol dissector infinite loop (bsc#1263746). - CVE-2026-6520: OpenFlow v6 protocol dissector infinite loop (bsc#1263745). - CVE-2026-6521: OpenFlow v5 protocol dissector infinite loops (bsc#1263744). - CVE-2026-6522: RPKI-Router protocol dissector infinite loop (bsc#1263743). - CVE-2026-6523: GNW protocol dissector infinite loop (bsc#1263742). - CVE-2026-6524: MySQL protocol dissector crash (bsc#1263741). - CVE-2026-6525: IEEE 802.11 protocol dissector crash (bsc#1263810). - CVE-2026-6526: RTSP protocol dissector crash (bsc#1263740). - CVE-2026-6527: ASN.1 PER dissector crash (bsc#1263739). - CVE-2026-6528: TLS protocol dissector infinite loop (bsc#1263738). - CVE-2026-6529: iLBC audio codec crash (bsc#1263737). - CVE-2026-6530: DCP-ETSI protocol dissector crash (bsc#1263736). - CVE-2026-6531: SANE protocol dissector infinite loop (bsc#1263735). - CVE-2026-6532: Kismet protocol dissector crash (bsc#1263734). - CVE-2026-6533: Dissection engine LZ77 decompression crash (bsc#1263733). - CVE-2026-6534: USB HID dissector infinite loop (bsc#1263732). - CVE-2026-6535: Dissection engine zlib decompression crash (bsc#1263731). - CVE-2026-6536: DLMS/COSEM dissector infinite loop (bsc#1263730). - CVE-2026-6537: ZigBee dissector crash (bsc#1263729). - CVE-2026-6538: BEEP dissector crash (bsc#1263728). - CVE-2026-6867: SMB2 protocol dissector crash (bsc#1263727). - CVE-2026-6868: HTTP protocol dissector crash (bsc#1263762). - CVE-2026-6869: WebSocket protocol dissector crash (bsc#1263726). - CVE-2026-6870: GSM RP protocol dissector crash (bsc#1263725). - CVE-2026-7375: UDS protocol dissector infinite loop (bsc#1263761). - CVE-2026-7376: Sharkd utility crash (bsc#1263760). - CVE-2026-7378: Sharkd utility crash (bsc#1263759). - CVE-2026-7379: Sharkd utility memory leak (bsc#1263758). - CVE-2026-9759: ROHC protocol dissector crash (bsc#1266670). - CVE-2026-15163: Denial of Service via multiple protocol dissector infinite loops (bsc#1271133). - CVE-2026-15164: Denial of Service vulnerability in ciscodump (bsc#1271134). - CVE-2026-15165: Denial of Service via TLS ECH decryptor crash (bsc#1271135). - CVE-2026-15166: Denial of Service via IEEE 802.11 protocol dissector crash (bsc#1271136). - CVE-2026-15167: Denial of Service via DBS Etherwatch file parser crash (bsc#1271137). - CVE-2026-15168: BLF file parser allows possible information disclosure (bsc#1271138). - CVE-2026-15169: Denial of Service via UMTS FP protocol dissector crash (bsc#1271139). - CVE-2026-15170: Denial of service via Z39.50 protocol dissector crash (bsc#1271140). - CVE-2026-15171: Denial of service via SSH protocol dissector crash (bsc#1271141). - CVE-2026-15172: Denial of service via FMP/NOTIFY protocol dissector crash (bsc#1271142). - CVE-2026-15173: Denial of Service via pcapng file parser crash (bsc#1271143). - CVE-2026-15174: Denial of Service via Catapult DCT2000 protocol dissector crash (bsc#1271144). wireshark-4.6.7-150700.21.11.1.src.rpm wireshark-devel-4.6.7-150700.21.11.1.x86_64.rpm wireshark-ui-qt-4.6.7-150700.21.11.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3512 Security update for evince moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for evince fixes the following issue: - CVE-2026-63729: texlive: heap use-after-free in `synctex_parser.c` via a malformed `.synctex` or `.synctex.gz` file (bsc#1272433). evince-45.0-150600.3.6.1.src.rpm evince-45.0-150600.3.6.1.x86_64.rpm evince-devel-45.0-150600.3.6.1.x86_64.rpm evince-lang-45.0-150600.3.6.1.noarch.rpm evince-plugin-djvudocument-45.0-150600.3.6.1.x86_64.rpm evince-plugin-dvidocument-45.0-150600.3.6.1.x86_64.rpm evince-plugin-pdfdocument-45.0-150600.3.6.1.x86_64.rpm evince-plugin-psdocument-45.0-150600.3.6.1.x86_64.rpm evince-plugin-tiffdocument-45.0-150600.3.6.1.x86_64.rpm evince-plugin-xpsdocument-45.0-150600.3.6.1.x86_64.rpm libevdocument3-4-45.0-150600.3.6.1.x86_64.rpm libevview3-3-45.0-150600.3.6.1.x86_64.rpm typelib-1_0-EvinceDocument-3_0-45.0-150600.3.6.1.x86_64.rpm typelib-1_0-EvinceView-3_0-45.0-150600.3.6.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3553 Security update for gd important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for gd fixes the following issue: - CVE-2026-9672: security issues in `libgd` (bsc#1273101). gd-2.2.5-150200.11.8.1.src.rpm gd-2.2.5-150200.11.8.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3586 Security update for ImageMagick moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for ImageMagick fixes the following issue: - CVE-2026-64685: heap buffer over-read in BGR decoder due to missing end-of-file check (bsc#1272953). ImageMagick-7.1.1.43-150700.3.79.1.src.rpm ImageMagick-7.1.1.43-150700.3.79.1.x86_64.rpm ImageMagick-config-7-SUSE-7.1.1.43-150700.3.79.1.x86_64.rpm ImageMagick-config-7-upstream-limited-7.1.1.43-150700.3.79.1.x86_64.rpm ImageMagick-config-7-upstream-open-7.1.1.43-150700.3.79.1.x86_64.rpm ImageMagick-config-7-upstream-secure-7.1.1.43-150700.3.79.1.x86_64.rpm ImageMagick-config-7-upstream-websafe-7.1.1.43-150700.3.79.1.x86_64.rpm ImageMagick-devel-7.1.1.43-150700.3.79.1.x86_64.rpm libMagick++-7_Q16HDRI5-7.1.1.43-150700.3.79.1.x86_64.rpm libMagick++-devel-7.1.1.43-150700.3.79.1.x86_64.rpm libMagickCore-7_Q16HDRI10-7.1.1.43-150700.3.79.1.x86_64.rpm libMagickWand-7_Q16HDRI10-7.1.1.43-150700.3.79.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3571 Security update for ImageMagick moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for ImageMagick fixes the following issue: - CVE-2026-64685: heap buffer overread in BGR decoder due to missing end-of-file check (bsc#1272953). ImageMagick-7.1.0.9-150400.6.110.1.src.rpm ImageMagick-config-7-upstream-7.1.0.9-150400.6.110.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3552 Security update for ffmpeg important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for ffmpeg fixes the following issues: - CVE-2026-64830: Heap Buffer Overflow via VobSub Subtitle Demuxer (bsc#1272752). - CVE-2026-66039: MACE6 Audio Decoder Heap Out-of-Bounds Write via CAF File (bsc#1272765). ffmpeg-3.4.2-150200.11.73.1.src.rpm libavcodec57-3.4.2-150200.11.73.1.x86_64.rpm libavutil-devel-3.4.2-150200.11.73.1.x86_64.rpm libavutil55-3.4.2-150200.11.73.1.x86_64.rpm libpostproc-devel-3.4.2-150200.11.73.1.x86_64.rpm libpostproc54-3.4.2-150200.11.73.1.x86_64.rpm libswresample-devel-3.4.2-150200.11.73.1.x86_64.rpm libswresample2-3.4.2-150200.11.73.1.x86_64.rpm libswscale-devel-3.4.2-150200.11.73.1.x86_64.rpm libswscale4-3.4.2-150200.11.73.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3597 Security update for libheif moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for libheif fixes the following issues: Update to version 1.23.1 (jsc#PED-16355). Security issues fixed: - CVE-2026-62289: integer underflow in Fraction constructor via double clap transform application (bsc#1273079). - CVE-2026-62291: heap out-of-bounds write in the uncompressed encoder when writing images with mismatched auxiliary alpha dimensions (bsc#1273080). - CVE-2026-62292: out-of-bounds read in uncompressed unci tile range slicing (bsc#1273081). - CVE-2026-62377: reachable assertion in `HeifContext::get_track()` aborts on a valid-but-empty HEIF sequence file (bsc#1273082). - Heap out-of-bounds write in the uncompressed encoder for RRGGBB images with interleaved bit-depth `<= 8` (bsc#1273083). Changes for libheif: - Version 1.23.1 + FFmpeg decoder plugin gains AV1, VVC, JPEG, and JPEG 2000/HTJ2K decoding. + SVT-AV1 encoder: new `tune=iq` and `ms-ssim` tune parameters. + C++ API: added getters/setters for the CLLI and MDCV HDR metadata boxes. + Sequence decoder now scales the alpha auxiliary track to the main image size. + Fixed pixi box writing for multi-channel images. + Corrected the placement of the TAI `clock_type` field into the top 2 bits. + Empty/unset plugin directory is no longer scanned. libheif-1.23.1-150700.3.18.1.src.rpm libheif-aom-1.23.1-150700.3.18.1.x86_64.rpm libheif-dav1d-1.23.1-150700.3.18.1.x86_64.rpm libheif-jpeg-1.23.1-150700.3.18.1.x86_64.rpm libheif-rav1e-1.23.1-150700.3.18.1.x86_64.rpm libheif1-1.23.1-150700.3.18.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3628 Security update for texlive moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for texlive fixes the following issues: - CVE-2023-46048: NULL pointer dereference in texk/web2c/pdftexdir/writet1.c (bsc#1222126). - CVE-2023-46051: NULL pointer dereference in texk/web2c/pdftexdir/tounicode.c (bsc#1222127). - CVE-2026-63729: use-after-free in synctex_parser.c in TeX Live (bsc#1272432). libkpathsea6-6.3.3-150600.38.3.1.x86_64.rpm libptexenc1-1.3.9-150600.38.3.1.x86_64.rpm libsynctex2-1.21-150600.38.3.1.x86_64.rpm libtexlua53-5-5.3.6-150600.38.3.1.x86_64.rpm libtexluajit2-2.1.0beta3-150600.38.3.1.x86_64.rpm texlive-2021.20210325-150600.38.3.1.src.rpm texlive-2021.20210325-150600.38.3.1.x86_64.rpm texlive-a2ping-bin-2021.20210325.svn27321-150600.38.3.1.x86_64.rpm texlive-accfonts-bin-2021.20210325.svn12688-150600.38.3.1.x86_64.rpm texlive-adhocfilelist-bin-2021.20210325.svn28038-150600.38.3.1.x86_64.rpm texlive-afm2pl-bin-2021.20210325.svn57878-150600.38.3.1.x86_64.rpm texlive-albatross-bin-2021.20210325.svn57089-150600.38.3.1.x86_64.rpm texlive-aleph-bin-2021.20210325.svn58378-150600.38.3.1.x86_64.rpm texlive-amstex-bin-2021.20210325.svn3006-150600.38.3.1.x86_64.rpm texlive-arara-bin-2021.20210325.svn29036-150600.38.3.1.x86_64.rpm texlive-asymptote-bin-2021.20210325.svn57890-150600.38.3.1.x86_64.rpm texlive-attachfile2-bin-2021.20210325.svn52909-150600.38.3.1.x86_64.rpm texlive-authorindex-bin-2021.20210325.svn18790-150600.38.3.1.x86_64.rpm texlive-autosp-bin-2021.20210325.svn57878-150600.38.3.1.x86_64.rpm texlive-axodraw2-bin-2021.20210325.svn58378-150600.38.3.1.x86_64.rpm texlive-bib2gls-bin-2021.20210325.svn45266-150600.38.3.1.x86_64.rpm texlive-biber-bin-2021.20210325.svn57273-150600.38.3.1.noarch.rpm texlive-bibexport-bin-2021.20210325.svn16219-150600.38.3.1.x86_64.rpm texlive-bibtex-bin-2021.20210325.svn57878-150600.38.3.1.x86_64.rpm texlive-bibtex8-bin-2021.20210325.svn57878-150600.38.3.1.x86_64.rpm texlive-bibtexu-bin-2021.20210325.svn57878-150600.38.3.1.x86_64.rpm texlive-bin-devel-2021.20210325-150600.38.3.1.x86_64.rpm texlive-bundledoc-bin-2021.20210325.svn17794-150600.38.3.1.x86_64.rpm texlive-cachepic-bin-2021.20210325.svn15543-150600.38.3.1.x86_64.rpm texlive-checkcites-bin-2021.20210325.svn25623-150600.38.3.1.x86_64.rpm texlive-checklistings-bin-2021.20210325.svn38300-150600.38.3.1.x86_64.rpm texlive-chklref-bin-2021.20210325.svn52631-150600.38.3.1.x86_64.rpm texlive-chktex-bin-2021.20210325.svn57878-150600.38.3.1.x86_64.rpm texlive-cjk-gs-integrate-bin-2021.20210325.svn37223-150600.38.3.1.x86_64.rpm texlive-cjkutils-bin-2021.20210325.svn57878-150600.38.3.1.x86_64.rpm texlive-clojure-pamphlet-bin-2021.20210325.svn51944-150600.38.3.1.x86_64.rpm texlive-cluttex-bin-2021.20210325.svn48871-150600.38.3.1.x86_64.rpm texlive-context-bin-2021.20210325.svn34112-150600.38.3.1.x86_64.rpm texlive-convbkmk-bin-2021.20210325.svn30408-150600.38.3.1.x86_64.rpm texlive-crossrefware-bin-2021.20210325.svn45927-150600.38.3.1.x86_64.rpm texlive-cslatex-bin-2021.20210325.svn3006-150600.38.3.1.x86_64.rpm texlive-csplain-bin-2021.20210325.svn50528-150600.38.3.1.x86_64.rpm texlive-ctan-o-mat-bin-2021.20210325.svn46996-150600.38.3.1.x86_64.rpm texlive-ctanbib-bin-2021.20210325.svn48478-150600.38.3.1.x86_64.rpm texlive-ctanify-bin-2021.20210325.svn24061-150600.38.3.1.x86_64.rpm texlive-ctanupload-bin-2021.20210325.svn23866-150600.38.3.1.x86_64.rpm texlive-ctie-bin-2021.20210325.svn57878-150600.38.3.1.x86_64.rpm texlive-cweb-bin-2021.20210325.svn58136-150600.38.3.1.x86_64.rpm texlive-cyrillic-bin-bin-2021.20210325.svn53554-150600.38.3.1.x86_64.rpm texlive-de-macro-bin-2021.20210325.svn17399-150600.38.3.1.x86_64.rpm texlive-detex-bin-2021.20210325.svn57878-150600.38.3.1.x86_64.rpm texlive-diadia-bin-2021.20210325.svn37645-150600.38.3.1.noarch.rpm texlive-dosepsbin-bin-2021.20210325.svn24759-150600.38.3.1.x86_64.rpm texlive-dtl-bin-2021.20210325.svn57878-150600.38.3.1.x86_64.rpm texlive-dtxgen-bin-2021.20210325.svn29031-150600.38.3.1.x86_64.rpm texlive-dviasm-bin-2021.20210325.svn8329-150600.38.3.1.x86_64.rpm texlive-dvicopy-bin-2021.20210325.svn57878-150600.38.3.1.x86_64.rpm texlive-dvidvi-bin-2021.20210325.svn57878-150600.38.3.1.x86_64.rpm texlive-dviinfox-bin-2021.20210325.svn44515-150600.38.3.1.x86_64.rpm texlive-dviljk-bin-2021.20210325.svn57878-150600.38.3.1.x86_64.rpm texlive-dviout-util-bin-2021.20210325.svn57878-150600.38.3.1.x86_64.rpm texlive-dvipdfmx-bin-2021.20210325.svn58535-150600.38.3.1.x86_64.rpm texlive-dvipng-bin-2021.20210325.svn57878-150600.38.3.1.x86_64.rpm texlive-dvipos-bin-2021.20210325.svn57878-150600.38.3.1.x86_64.rpm texlive-dvips-bin-2021.20210325.svn57878-150600.38.3.1.x86_64.rpm texlive-dvisvgm-bin-2021.20210325.svn57878-150600.38.3.1.x86_64.rpm texlive-eplain-bin-2021.20210325.svn3006-150600.38.3.1.x86_64.rpm texlive-epspdf-bin-2021.20210325.svn29050-150600.38.3.1.x86_64.rpm texlive-epstopdf-bin-2021.20210325.svn18336-150600.38.3.1.x86_64.rpm texlive-exceltex-bin-2021.20210325.svn25860-150600.38.3.1.x86_64.rpm texlive-fig4latex-bin-2021.20210325.svn14752-150600.38.3.1.x86_64.rpm texlive-findhyph-bin-2021.20210325.svn14758-150600.38.3.1.x86_64.rpm texlive-fontinst-bin-2021.20210325.svn53554-150600.38.3.1.x86_64.rpm texlive-fontools-bin-2021.20210325.svn25997-150600.38.3.1.x86_64.rpm texlive-fontware-bin-2021.20210325.svn57878-150600.38.3.1.x86_64.rpm texlive-fragmaster-bin-2021.20210325.svn13663-150600.38.3.1.x86_64.rpm texlive-getmap-bin-2021.20210325.svn34971-150600.38.3.1.x86_64.rpm texlive-git-latexdiff-bin-2021.20210325.svn54732-150600.38.3.1.x86_64.rpm texlive-glossaries-bin-2021.20210325.svn37813-150600.38.3.1.x86_64.rpm texlive-gregoriotex-bin-2021.20210325.svn58378-150600.38.3.1.x86_64.rpm texlive-gsftopk-bin-2021.20210325.svn57878-150600.38.3.1.x86_64.rpm texlive-hyperxmp-bin-2021.20210325.svn56984-150600.38.3.1.x86_64.rpm texlive-jadetex-bin-2021.20210325.svn3006-150600.38.3.1.x86_64.rpm texlive-jfmutil-bin-2021.20210325.svn44835-150600.38.3.1.x86_64.rpm texlive-ketcindy-bin-2021.20210325.svn49033-150600.38.3.1.x86_64.rpm texlive-kotex-utils-bin-2021.20210325.svn32101-150600.38.3.1.x86_64.rpm texlive-kpathsea-bin-2021.20210325.svn57878-150600.38.3.1.x86_64.rpm texlive-kpathsea-devel-6.3.3-150600.38.3.1.x86_64.rpm texlive-l3build-bin-2021.20210325.svn46894-150600.38.3.1.x86_64.rpm texlive-lacheck-bin-2021.20210325.svn53999-150600.38.3.1.x86_64.rpm texlive-latex-bin-bin-2021.20210325.svn54358-150600.38.3.1.x86_64.rpm texlive-latex-bin-dev-bin-2021.20210325.svn53999-150600.38.3.1.x86_64.rpm texlive-latex-git-log-bin-2021.20210325.svn30983-150600.38.3.1.x86_64.rpm texlive-latex-papersize-bin-2021.20210325.svn42296-150600.38.3.1.x86_64.rpm texlive-latex2man-bin-2021.20210325.svn13663-150600.38.3.1.x86_64.rpm texlive-latex2nemeth-bin-2021.20210325.svn42300-150600.38.3.1.x86_64.rpm texlive-latexdiff-bin-2021.20210325.svn16420-150600.38.3.1.x86_64.rpm texlive-latexfileversion-bin-2021.20210325.svn25012-150600.38.3.1.x86_64.rpm texlive-latexindent-bin-2021.20210325.svn32150-150600.38.3.1.x86_64.rpm texlive-latexmk-bin-2021.20210325.svn10937-150600.38.3.1.x86_64.rpm texlive-latexpand-bin-2021.20210325.svn27025-150600.38.3.1.x86_64.rpm texlive-lcdftypetools-bin-2021.20210325.svn57878-150600.38.3.1.x86_64.rpm texlive-light-latex-make-bin-2021.20210325.svn56352-150600.38.3.1.x86_64.rpm texlive-lilyglyphs-bin-2021.20210325.svn31696-150600.38.3.1.x86_64.rpm texlive-listbib-bin-2021.20210325.svn26126-150600.38.3.1.x86_64.rpm texlive-listings-ext-bin-2021.20210325.svn15093-150600.38.3.1.x86_64.rpm texlive-lollipop-bin-2021.20210325.svn41465-150600.38.3.1.x86_64.rpm texlive-ltxfileinfo-bin-2021.20210325.svn29005-150600.38.3.1.x86_64.rpm texlive-ltximg-bin-2021.20210325.svn32346-150600.38.3.1.x86_64.rpm texlive-luahbtex-bin-2021.20210325.svn58535-150600.38.3.1.x86_64.rpm texlive-luajittex-bin-2021.20210325.svn58535-150600.38.3.1.x86_64.rpm texlive-luaotfload-bin-2021.20210325.svn34647-150600.38.3.1.x86_64.rpm texlive-luatex-bin-2021.20210325.svn58535-150600.38.3.1.x86_64.rpm texlive-lwarp-bin-2021.20210325.svn43292-150600.38.3.1.x86_64.rpm texlive-m-tx-bin-2021.20210325.svn50281-150600.38.3.1.x86_64.rpm texlive-make4ht-bin-2021.20210325.svn37750-150600.38.3.1.x86_64.rpm texlive-makedtx-bin-2021.20210325.svn38769-150600.38.3.1.x86_64.rpm texlive-makeindex-bin-2021.20210325.svn57878-150600.38.3.1.x86_64.rpm texlive-match_parens-bin-2021.20210325.svn23500-150600.38.3.1.x86_64.rpm texlive-mathspic-bin-2021.20210325.svn23661-150600.38.3.1.x86_64.rpm texlive-metafont-bin-2021.20210325.svn58378-150600.38.3.1.x86_64.rpm texlive-metapost-bin-2021.20210325.svn57878-150600.38.3.1.x86_64.rpm texlive-mex-bin-2021.20210325.svn3006-150600.38.3.1.x86_64.rpm texlive-mf2pt1-bin-2021.20210325.svn23406-150600.38.3.1.x86_64.rpm texlive-mflua-bin-2021.20210325.svn58535-150600.38.3.1.x86_64.rpm texlive-mfware-bin-2021.20210325.svn57878-150600.38.3.1.x86_64.rpm texlive-mkgrkindex-bin-2021.20210325.svn14428-150600.38.3.1.x86_64.rpm texlive-mkjobtexmf-bin-2021.20210325.svn8457-150600.38.3.1.x86_64.rpm texlive-mkpic-bin-2021.20210325.svn33688-150600.38.3.1.x86_64.rpm texlive-mltex-bin-2021.20210325.svn3006-150600.38.3.1.x86_64.rpm texlive-mptopdf-bin-2021.20210325.svn18674-150600.38.3.1.x86_64.rpm texlive-multibibliography-bin-2021.20210325.svn30534-150600.38.3.1.x86_64.rpm texlive-musixtex-bin-2021.20210325.svn37026-150600.38.3.1.x86_64.rpm texlive-musixtnt-bin-2021.20210325.svn50281-150600.38.3.1.x86_64.rpm texlive-omegaware-bin-2021.20210325.svn57878-150600.38.3.1.x86_64.rpm texlive-optex-bin-2021.20210325.svn53804-150600.38.3.1.x86_64.rpm texlive-patgen-bin-2021.20210325.svn57878-150600.38.3.1.x86_64.rpm texlive-pax-bin-2021.20210325.svn10843-150600.38.3.1.x86_64.rpm texlive-pdfbook2-bin-2021.20210325.svn37537-150600.38.3.1.x86_64.rpm texlive-pdfcrop-bin-2021.20210325.svn14387-150600.38.3.1.x86_64.rpm texlive-pdfjam-bin-2021.20210325.svn52858-150600.38.3.1.x86_64.rpm texlive-pdflatexpicscale-bin-2021.20210325.svn41779-150600.38.3.1.x86_64.rpm texlive-pdftex-bin-2021.20210325.svn58535-150600.38.3.1.x86_64.rpm texlive-pdftex-quiet-bin-2021.20210325.svn49140-150600.38.3.1.x86_64.rpm texlive-pdftosrc-bin-2021.20210325.svn57878-150600.38.3.1.x86_64.rpm texlive-pdfxup-bin-2021.20210325.svn40690-150600.38.3.1.x86_64.rpm texlive-pedigree-perl-bin-2021.20210325.svn25962-150600.38.3.1.x86_64.rpm texlive-perltex-bin-2021.20210325.svn16181-150600.38.3.1.x86_64.rpm texlive-petri-nets-bin-2021.20210325.svn39165-150600.38.3.1.x86_64.rpm texlive-pfarrei-bin-2021.20210325.svn29348-150600.38.3.1.x86_64.rpm texlive-pkfix-bin-2021.20210325.svn13364-150600.38.3.1.x86_64.rpm texlive-pkfix-helper-bin-2021.20210325.svn13663-150600.38.3.1.x86_64.rpm texlive-platex-bin-2021.20210325.svn52800-150600.38.3.1.x86_64.rpm texlive-pmx-bin-2021.20210325.svn57878-150600.38.3.1.x86_64.rpm texlive-pmxchords-bin-2021.20210325.svn32405-150600.38.3.1.x86_64.rpm texlive-ps2eps-bin-2021.20210325.svn50281-150600.38.3.1.x86_64.rpm texlive-ps2pk-bin-2021.20210325.svn57878-150600.38.3.1.x86_64.rpm texlive-pst-pdf-bin-2021.20210325.svn7838-150600.38.3.1.x86_64.rpm texlive-pst2pdf-bin-2021.20210325.svn29333-150600.38.3.1.x86_64.rpm texlive-ptex-bin-2021.20210325.svn58378-150600.38.3.1.x86_64.rpm texlive-ptex-fontmaps-bin-2021.20210325.svn44206-150600.38.3.1.x86_64.rpm texlive-ptex2pdf-bin-2021.20210325.svn29335-150600.38.3.1.x86_64.rpm texlive-ptexenc-devel-1.3.9-150600.38.3.1.x86_64.rpm texlive-purifyeps-bin-2021.20210325.svn13663-150600.38.3.1.x86_64.rpm texlive-pygmentex-bin-2021.20210325.svn34996-150600.38.3.1.x86_64.rpm texlive-pythontex-bin-2021.20210325.svn31638-150600.38.3.1.x86_64.rpm texlive-rubik-bin-2021.20210325.svn32919-150600.38.3.1.x86_64.rpm texlive-scripts-bin-2021.20210325.svn55172-150600.38.3.1.x86_64.rpm texlive-scripts-extra-bin-2021.20210325.svn53577-150600.38.3.1.x86_64.rpm texlive-seetexk-bin-2021.20210325.svn57878-150600.38.3.1.x86_64.rpm texlive-spix-bin-2021.20210325.svn55933-150600.38.3.1.x86_64.rpm texlive-splitindex-bin-2021.20210325.svn29688-150600.38.3.1.x86_64.rpm texlive-srcredact-bin-2021.20210325.svn38710-150600.38.3.1.x86_64.rpm texlive-sty2dtx-bin-2021.20210325.svn21215-150600.38.3.1.x86_64.rpm texlive-svn-multi-bin-2021.20210325.svn13663-150600.38.3.1.x86_64.rpm texlive-synctex-bin-2021.20210325.svn58136-150600.38.3.1.x86_64.rpm texlive-synctex-devel-1.21-150600.38.3.1.x86_64.rpm texlive-tex-bin-2021.20210325.svn58378-150600.38.3.1.x86_64.rpm texlive-tex4ebook-bin-2021.20210325.svn37771-150600.38.3.1.x86_64.rpm texlive-tex4ht-bin-2021.20210325.svn57878-150600.38.3.1.x86_64.rpm texlive-texcount-bin-2021.20210325.svn13013-150600.38.3.1.x86_64.rpm texlive-texdef-bin-2021.20210325.svn45011-150600.38.3.1.x86_64.rpm texlive-texdiff-bin-2021.20210325.svn15506-150600.38.3.1.x86_64.rpm texlive-texdirflatten-bin-2021.20210325.svn12782-150600.38.3.1.x86_64.rpm texlive-texdoc-bin-2021.20210325.svn47948-150600.38.3.1.x86_64.rpm texlive-texdoctk-bin-2021.20210325.svn29741-150600.38.3.1.x86_64.rpm texlive-texfot-bin-2021.20210325.svn33155-150600.38.3.1.x86_64.rpm texlive-texliveonfly-bin-2021.20210325.svn24062-150600.38.3.1.x86_64.rpm texlive-texloganalyser-bin-2021.20210325.svn13663-150600.38.3.1.x86_64.rpm texlive-texlua-devel-5.3.6-150600.38.3.1.x86_64.rpm texlive-texluajit-devel-2.1.0beta3-150600.38.3.1.x86_64.rpm texlive-texosquery-bin-2021.20210325.svn43596-150600.38.3.1.x86_64.rpm texlive-texplate-bin-2021.20210325.svn53444-150600.38.3.1.x86_64.rpm texlive-texsis-bin-2021.20210325.svn3006-150600.38.3.1.x86_64.rpm texlive-texware-bin-2021.20210325.svn57878-150600.38.3.1.x86_64.rpm texlive-thumbpdf-bin-2021.20210325.svn6898-150600.38.3.1.x86_64.rpm texlive-tie-bin-2021.20210325.svn57878-150600.38.3.1.x86_64.rpm texlive-tikztosvg-bin-2021.20210325.svn55132-150600.38.3.1.x86_64.rpm texlive-tpic2pdftex-bin-2021.20210325.svn50281-150600.38.3.1.x86_64.rpm texlive-ttfutils-bin-2021.20210325.svn57878-150600.38.3.1.x86_64.rpm texlive-typeoutfileinfo-bin-2021.20210325.svn25648-150600.38.3.1.x86_64.rpm texlive-ulqda-bin-2021.20210325.svn13663-150600.38.3.1.x86_64.rpm texlive-uplatex-bin-2021.20210325.svn52800-150600.38.3.1.x86_64.rpm texlive-uptex-bin-2021.20210325.svn58378-150600.38.3.1.x86_64.rpm texlive-urlbst-bin-2021.20210325.svn23262-150600.38.3.1.x86_64.rpm texlive-velthuis-bin-2021.20210325.svn50281-150600.38.3.1.x86_64.rpm texlive-vlna-bin-2021.20210325.svn50281-150600.38.3.1.x86_64.rpm texlive-vpe-bin-2021.20210325.svn6897-150600.38.3.1.x86_64.rpm texlive-web-bin-2021.20210325.svn57878-150600.38.3.1.x86_64.rpm texlive-webquiz-bin-2021.20210325.svn50419-150600.38.3.1.x86_64.rpm texlive-wordcount-bin-2021.20210325.svn46165-150600.38.3.1.x86_64.rpm texlive-xdvi-bin-2021.20210325.svn58378-150600.38.3.1.x86_64.rpm texlive-xelatex-dev-bin-2021.20210325.svn53999-150600.38.3.1.x86_64.rpm texlive-xetex-bin-2021.20210325.svn58378-150600.38.3.1.x86_64.rpm texlive-xindex-bin-2021.20210325.svn49312-150600.38.3.1.x86_64.rpm texlive-xml2pmx-bin-2021.20210325.svn57878-150600.38.3.1.x86_64.rpm texlive-xmltex-bin-2021.20210325.svn3006-150600.38.3.1.x86_64.rpm texlive-xpdfopen-bin-2021.20210325.svn52917-150600.38.3.1.x86_64.rpm texlive-yplan-bin-2021.20210325.svn34398-150600.38.3.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3632 Security update for ffmpeg important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for ffmpeg fixes the following issue: - CVE-2026-8461: out-of-bounds write in the MagicYUV decoder can lead to denial of service or remote code execution (bsc#1269490). ffmpeg-3.4.2-150200.11.76.1.src.rpm libavcodec57-3.4.2-150200.11.76.1.x86_64.rpm libavutil-devel-3.4.2-150200.11.76.1.x86_64.rpm libavutil55-3.4.2-150200.11.76.1.x86_64.rpm libpostproc-devel-3.4.2-150200.11.76.1.x86_64.rpm libpostproc54-3.4.2-150200.11.76.1.x86_64.rpm libswresample-devel-3.4.2-150200.11.76.1.x86_64.rpm libswresample2-3.4.2-150200.11.76.1.x86_64.rpm libswscale-devel-3.4.2-150200.11.76.1.x86_64.rpm libswscale4-3.4.2-150200.11.76.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3658 Security update for MozillaFirefox important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for MozillaFirefox fixes the following issues: Update to Firefox Extended Support Release 140.14.0 ESR. - MFSA 2026-74 (bsc#1274867) - CVE-2026-74934: Site isolation issue in the Graphics: CanvasWebGL component. - CVE-2026-74935: Privilege escalation in the DOM: Networking component. - CVE-2026-74936: Use-after-free in the JavaScript: WebAssembly component. - CVE-2026-74937: Use-after-free in the JavaScript: GC component. - CVE-2026-74938: Mitigation bypass in the JavaScript: GC component. - CVE-2026-74939: Privilege escalation in the DOM: Navigation component. - CVE-2026-74940: Use-after-free in the Graphics: Text component. - CVE-2026-74941: Privilege escalation in the Graphics: CanvasWebGL component. - CVE-2026-74942: Privilege escalation in the Remote Settings Client component. - CVE-2026-74943: Use-after-free in the Graphics: ImageLib component. - CVE-2026-74944: Use-after-free in the DOM: Core & HTML component. - CVE-2026-74945: Information disclosure in the Graphics: Text component. - CVE-2026-74946: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. - CVE-2026-74947: Privilege escalation due to invalid pointer in the Graphics component. - CVE-2026-74948: Information disclosure in the Graphics component. - CVE-2026-74949: Privilege escalation due to use-after-free in the Graphics: Canvas2D component. - CVE-2026-74950: Privilege escalation in the Downloads API component. - CVE-2026-74951: Clickjacking issue in Firefox for Android. - CVE-2026-74952: Privilege escalation in the Application Update component. - CVE-2026-74953: Privilege escalation in the Networking: Cookies component. - CVE-2026-74954: Information disclosure due to side-channel in the Storage: Cache API component. - CVE-2026-74955: Privilege escalation in the Request Handling component. - CVE-2026-74956: Same-origin policy bypass in the DOM: Service Workers component. - CVE-2026-74957: Mitigation bypass in the Safe Browsing component. - CVE-2026-74958: Information disclosure in the WebRTC component. - CVE-2026-74959: Mitigation bypass in the Storage: Cache API component. - CVE-2026-74960: Site isolation issue in the WebExtensions component. - CVE-2026-74961: Side-channel in the Web Audio component. - CVE-2026-74962: Site isolation issue in the Networking: Cookies component. - CVE-2026-74963: Same-origin policy bypass in the Networking: Cookies component. - CVE-2026-74964: Integer overflow in the Graphics component. - CVE-2026-74965: Privilege escalation in the Shell Integration component. - CVE-2026-74966: Information disclosure in the Form Autofill component. - CVE-2026-74967: Same-origin policy bypass in the Audio/Video: Playback component. - CVE-2026-74968: Site isolation issue in the Graphics: WebRender component. - CVE-2026-74969: Use-after-free in the Layout: Text and Fonts component. - CVE-2026-74970: Site isolation issue in the Graphics component. - CVE-2026-74971: Information disclosure in the DOM: UI Events & Focus Handling component. - CVE-2026-74972: Information disclosure in the DOM: Push Subscriptions component. - CVE-2026-74973: Race condition, use-after-free in the Graphics component. - CVE-2026-74974: Same-origin policy bypass in the Graphics: ImageLib component. - CVE-2026-74975: Spoofing issue in the Downloads component in Firefox for Android. - CVE-2026-74976: JIT miscompilation in the JavaScript Engine: JIT component. - CVE-2026-74977: Integer overflow in the Graphics component. - CVE-2026-74978: Clickjacking issue in the Widget component. - CVE-2026-74979: Mitigation bypass in the Add-ons Manager component. - CVE-2026-74980: Clickjacking issue in the Downloads component in Firefox for Android. - CVE-2026-74981: Site isolation issue in the Audio/Video: Web Codecs component. - CVE-2026-74982: Denial-of-service in the Widget component. - CVE-2026-74983: Mitigation bypass in the Data Loss Prevention component. - CVE-2026-74984: Race condition in the JavaScript Engine component. - CVE-2026-74985: Privilege escalation in the Enterprise Policies component. - CVE-2026-74986: Site isolation issue in the CSS Parsing and Computation component. - CVE-2026-74987: Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154. - CVE-2026-74988: Internally found bugs fixed in Firefox ESR 153.1 and Firefox 154. - CVE-2026-74989: Internally found bugs fixed in Firefox 154. - CVE-2026-74990: Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154. - CVE-2026-75874: Sandbox escape in the Remote Settings Client component. MozillaFirefox-140.14.0-150200.152.251.1.src.rpm MozillaFirefox-140.14.0-150200.152.251.1.x86_64.rpm MozillaFirefox-devel-140.14.0-150200.152.251.1.noarch.rpm MozillaFirefox-translations-common-140.14.0-150200.152.251.1.x86_64.rpm MozillaFirefox-translations-other-140.14.0-150200.152.251.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3795 Security update for librest moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for librest fixes the following issue: - CVE-2026-16615: PKCE implementation for OAuth authorization uses a cryptographically insecure pseudo-random number generator (bsc#1272399). librest-0.9.1-150600.3.3.1.src.rpm librest-1_0-0-0.9.1-150600.3.3.1.x86_64.rpm librest-devel-0.9.1-150600.3.3.1.x86_64.rpm typelib-1_0-Rest-1_0-0.9.1-150600.3.3.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3789 Recommended update for gdm moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for gdm fixes the following issues: - Fix: During system startup, tty1 is left in an invalid state, preventing it from being switched away from. (bsc#1274029) gdm-45.0.1-150700.12.8.1.src.rpm gdm-45.0.1-150700.12.8.1.x86_64.rpm gdm-devel-45.0.1-150700.12.8.1.x86_64.rpm gdm-lang-45.0.1-150700.12.8.1.noarch.rpm gdm-schema-45.0.1-150700.12.8.1.noarch.rpm gdm-systemd-45.0.1-150700.12.8.1.noarch.rpm gdmflexiserver-45.0.1-150700.12.8.1.noarch.rpm libgdm1-45.0.1-150700.12.8.1.x86_64.rpm typelib-1_0-Gdm-1_0-45.0.1-150700.12.8.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3680 Security update for vim important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for vim fixes the following issues: - CVE-2026-73070: stack buffer overflow in the socket server can lead to denial of service (bsc#1275018). - CVE-2026-73071: use-after-free in JSON decoding can lead to process crash (bsc#1275017). - CVE-2026-73072: heap buffer overflow when loading a spell file can lead to crash or potential code execution (bsc#1275016). - CVE-2026-73074: heap buffer overflow in text property handling can lead to a crash or potential code execution (bsc#1275015). - CVE-2026-73075: out-of-bounds access in popup opacity handling can lead to a conditional memory write (bsc#1275014). - CVE-2026-73076: arbitrary command execution via the vimball record file (bsc#1275013). - CVE-2026-73077: arbitrary code execution due to insecure shell command handling (bsc#1275012). - CVE-2026-73078: arbitrary code execution via crafted netrw menu entries (bsc#1275011). Changes for vim: - Updated to version 9.2.0957. * tests: Test_fuzzy_completion_bufname_fullpath() creates unnecessary dir (9.2.0781). * tests: missing cleanup in test_mksession.vim (9.2.0782). * tests: personal spell files leak into later tests (9.2.0783). * crash when borrowing statusline highlight in silent Ex mode (9.2.0784). * WinResized not triggered when the whole Vim is resized (9.2.0785). * filetype: containerfile is not recognized (9.2.0786). * regexp: code 0x1ecb duplicated for equivalence class (9.2.0787). * filetype: hip files are not recognized (9.2.0788). * 'statuslineopt' status line too high after a window is minimized (9.2.0789). * 'completeslash' breaks :find completion with 'findfunc' (9.2.0790). * wincol() counts from right side for 'rightleft' (9.2.0791). * runtime(netrw): explore without optional dir broken (9.2.0792). * if session restored a tiny window, restore fails (9.2.0793). * extend() and extendnew() don't handle NULL expr2 properly (9.2.0794). * popup menu shadow is not cleared when the menu shrinks (9.2.0795). * Visual block reselection wrong with 'virtualedit' (9.2.0796). * memory leak in get_qfline_items() on alloc failure (9.2.0797). * memory leak in compile_expr6() on alloc failure (9.2.0798). * memory leak in compile_def_function_body() on alloc failure (9.2.0799). * memory leak in call_func() on alloc failure (9.2.0800). * memory leak in f_getreginfo() on alloc failure (9.2.0801). * memory leak with list_append_dict/dict_add_list on alloc failure (9.2.0802). * memory leak on alloc failure with taglist/gettagstack() (9.2.0803). * wincol() is wrong for a double-wide character with 'rightleft' (9.2.0804). * screenpos() "curscol" is wrong with 'rightleft' (9.2.0805). * 'showcmd' may show internal command keys (9.2.0806). * MS-Windows: ellipsis character is garbled (9.2.0807). * getregionpos: double-free on alloc failure (9.2.0808). * getframelayout() uses wrong function to free lists (9.2.0809). * add_llist_tags() uses wrong function to free dict (9.2.0810). * mksession writes terminal command unquoted (9.2.0811). * :argdelete with pattern leads to wrong argidx() (9.2.0812). * dict_add_func() may corrupt funcref count on failure (9.2.0813). * Vim9: E1041 when reloading an autoload script with exported variables (9.2.0814). * deeply nested regexp patterns may cause stack overflow (9.2.0815). * GTK4: memory leak in gui_gtk_set_dnd_targets() (9.2.0816). * crash when building a stacktrace during an autocommand (9.2.0817). * tests: client-server test fails without X11 server (9.2.0818). * MS-Windows: sixel image shown as raw text in the console (9.2.0819). * GUI: hidden popup image is displayed and not erased (9.2.0820). * filetype: msmtp system-wide rc file not detected (9.2.0821). * GTK4: crash menu id is null in gui_mch_destroy_menu() (9.2.0822). * tests: Test_clientserver_servlist_list may fail (9.2.0823). * Makefile: make tags depends on configure (9.2.0824). * regexp: submatch in a look-behind is empty with the NFA engine (9.2.0825). * highlighting for broken terminals can be improved (9.2.0826). * :startinsert enters Insert mode in a non-modifiable buffer (9.2.0827). * GTK4: hardware rendering can be improved (9.2.0828). * sessions do not preserve script version for expression options (9.2.0829). * the completion menu is not used on terminals without colors (9.2.0830). * diff highlighting hard to read with syntax enabled (9.2.0831). * socketserver: remote commands can be processed in reverse order (9.2.0832). * GTK4: menu mnemonics do not work properly (9.2.0833). * cleared last search pattern is restored from viminfo (9.2.0834). * features in version.c are not sorted (9.2.0835). * filetype: .git-blame-ignore-revs file is not recognized (9.2.0836). * using wrong colors in hl_blend_attr() (9.2.0837). * searchcount() returns wrong cached maxcount (9.2.0838). * [security]: arbitrary code execution via keyword lookup (9.2.0839). * [security]: code injection in netrw via bookmarks (9.2.0840). * [security]: heap overflow when adding > 65535 text properties (9.2.0841). * [security]: stack buffer overflow in socket server (9.2.0842). * [security]: popup: opacity mask indexed out of bounds (9.2.0843). * [security]: use-after-free on json decode error (9.2.0844). * [security]: arbitrary Ex command execution during C omni-completion (9.2.0845). * [security]: heap buffer overflow in set_sofo() (9.2.0846). * [security]: vimball: code execution via .VimballRecord file (9.2.0847). * tagfunc "cmd" with a generic Ex command corrupts the tag entry (9.2.0848). * filetype: osquery config files are not recognized (9.2.0849). * MS-Windows: commands from a client can be lost (9.2.0850). * focus autocommands triggered inconsistently (9.2.0851). * GTK: ligatures not correctly displayed (9.2.0852). * popup: popup images do not support scaling (9.2.0853). * memory leak when reading a spell file with SN_SAL and SN_SOFO (9.2.0854). * 'showcmd' not redrawn with empty mapping triggered on timeout (9.2.0855). * GTK4: undercurl rendering is inefficient (9.2.0856). * popup: opacity popup over a terminal is not cleared when closed (9.2.0857). * MS-Windows GUI: white flash when VimEnter is slow (9.2.0858). * GTK2: link error (9.2.0859). * filetype: xilinx design constraint files are not recognized (9.2.0860). * GTK4: bleed region updates in jumps (9.2.0861). * missing test change from v9.2.0857 (9.2.0862). * MS-Windows GUI: window contents can be missing when VimEnter is slow (9.2.0863). * using some dead code in Wayland feature (9.2.0864). * GTK4: non-hardware accelerated UI is too slow (9.2.0865). * MS-Windows: ":language messages" only works once (9.2.0866). * MS-Windows: messages are not in the display language (9.2.0867). * GTK: window Manager hint prevents giving focus to dialog (9.2.0868). * buf_copy_options() can lose the P_INSECURE flag (9.2.0869). * filetype: marko files are not recognized (9.2.0870). * screen line is lost when splitting a 'winfixheight' window (9.2.0871). * popup with opacity does not use the font of the highlight group (9.2.0872). * :redrawstatus does not update the ruler of the last window (9.2.0873). * fold size is compared against 'foldminlines' of the wrong window (9.2.0874). * GTK4: GUI does not support command-line arguments (9.2.0875). * GTK4: compile error with disabled netbeans feat (9.2.0876). * Vim9: crash when a closure assigns to a variable declared in a loop (9.2.0877). * Vim9: cannot use a script variable of an enclosing block in a lambda (9.2.0878). * popup: "maxwidth" is not respected when 'wrap' is off (9.2.0879). * scroll: window scrolls when using the autocommand window (9.2.0880). * 'smoothscroll' position is lost when the window height changes (9.2.0881). * :bwipe crashes if WinLeave wipes all other buffers (9.2.0882). * scroll: 'smoothscroll' position is lost when using "|" (9.2.0883). * scroll: unreachable 'smoothscroll' code in cursor_correct() (9.2.0884). * scroll: 'smoothscroll' position is lost when the window is squeezed (9.2.0885). * :set completion works for an invalid sub-option name (9.2.0886). * scroll: jump-scrolling when moving the cursor onto a wrapping line (9.2.0887). * mapping: modifier is not recognized after a partial mapping (9.2.0888). * VMS: spurious "INVALID DECC FEATURE VALUE" message at every startup (9.2.0889). * test: test for patch v9.2.0888 can be clarified (9.2.0890). * MS-Windows: filename-modifier ":8:t" causes underflow (9.2.0891). * highlight: wrong column highlighted with 'cursorcolumn' (9.2.0892). * MS-Windows: "*.vim" also matches files with a longer extension (9.2.0893). * filetype: ed script files not recognised (9.2.0894). * test: Test_aucmd_win_scroll_multibyte() is flaky in the GUI (9.2.0895). * scroll: 'smoothscroll' position is lost when splitting a window (9.2.0896). * GTK3 X11 redraws are not coalesced (9.2.0897). * printing support is lacking (9.2.0898). * command output temporary files may collide (9.2.0899). * FocusGained still triggered when closing dialog (9.2.0900). * textprop: wrong cursor line with truncated virtual text (9.2.0901). * Vim9: iterating over a tuple leaks memory (9.2.0902). * Vim9: cannot use an exported function of an autoload import (9.2.0903). * "zb" scrolls incorrectly with cursor just above fold (9.2.0904). * MS-Windows: ghost cursor with ligatures (9.2.0905). * slow transstr() with long strings (9.2.0906). * popup: virtual text is not redrawn when a text property changes (9.2.0907). * cannot use a {} block in a nested :autocmd (9.2.0908). * insert completion is slow to collect many matches (9.2.0909). * runtime(vim): update syntax, contain Ex commands (9.2.0910). * makefiles do not build hardcopy_postscript.c (9.2.0911). * hardcopy: prototypes are hand-written instead of generated (9.2.0912). * statusline: cell below the vertical separator keeps the old highlight (9.2.0913). * diff: undo after :diffget into an empty buffer leaves a line behind (9.2.0914). * tests: two terminal tests in test_popupwin fail on FreeBSD (9.2.0915). * configure: honor `--disable-hardcopy-pango` with GTK UI (9.2.0916). * :quitall not allowed in the command-line window (9.2.0917). * screen: fill char with a zero low byte is stored as a NUL cell (9.2.0918). * screen: the wrong array is copied into ScreenCols on a resize (9.2.0919). * filetype: json-ld files are not recognized (9.2.0920). * test: terminal tests fail on FreeBSD (9.2.0921). * Wayland: modeless selection not redrawn (9.2.0922). * tabpage: closing a tab page loses the alternate tab page (9.2.0923). * tests: Test_termwinscroll() fails on FreeBSD (9.2.0924). * crash when getcompletiontype() gets a NULL string (9.2.0925). * filetype: business Central files are not recognized (9.2.0926). * curswant not set on 8g8 (9.2.0927). * MinGW: tests hang when Vim is built with coverage enabled (9.2.0928). * incorrect completion for 'pumopt' and 'pumborder' (9.2.0929). * floating point exception when displaying pum (9.2.0930). * the GTK4 GUI is still experimental and untested by CI (9.2.0931). * NFA engine fallback can double free the compiled program (9.2.0932). * u_read_undo() leaks the file name when the undo file owner differs (9.2.0933). * filetype: hlsl files are not recognized (9.2.0934). * reading an undo file is slow with many undo headers (9.2.0935). * stringifying a list or dict can free the item being iterated (9.2.0936). * sort() with a numeric option converts each item on every comparison (9.2.0937). * cursorbind: cursor in the other window is not updated after undo (9.2.0938). * mbyte: wrong cell count for an overlong UTF-8 sequence (9.2.0939). * GTK4: columns are lost when a scrollbar appears (9.2.0940). * tests: clipboard tests fail in the GUI when the terminal has no clipboard (9.2.0941). * test: test_mksession_winpos() fails on GTK4 UI (9.2.0942). * test: test_hardcopy fails on GTK4 UI (9.2.0943). * test: tests fail when checking for GTK4 feature (9.2.0944). * sort() with a numeric option can be improved (9.2.0945). * GTK2/3: mouse move starts Visual selection after a dialog (9.2.0946). * GTK4: screen is cleared when moving the mouse after startup (9.2.0947). * GTK4: mouse move starts Visual selection after a dialog (9.2.0948). * GDK_KEY_VoidSymbol might be undefined (9.2.0949). * transstr() can be improved (after 9.2.0906) (9.2.0950). * GTK3: cursor does no longer blink (9.2.0951). * locking a container while stringifying can be improved (9.2.0952). * insert completion code can be improved (9.2.0953). * u_read_undo() can be improved (after 9.2.0935) (9.2.0954). * tests: terminal tests are flaky (9.2.0955). * GTK4: crash when the window is resized while redrawing (9.2.0956). * filetype: ArgoCD config file is not recognized (9.2.0957). gvim-9.2.0957-150500.20.64.1.x86_64.rpm vim-9.2.0957-150500.20.64.1.src.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-4020 Security update for webkit2gtk3 important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for webkit2gtk3 fixes the following issues: - CVE-2026-28984,CVE-2026-43804,CVE-2026-64713,CVE-2026-64719,CVE-2026-64728, CVE-2026-64730,CVE-2026-64757,CVE-2026-64783,CVE-2026-64787: WebKitGTK and WPE WebKit Security Advisory WSA-2026-0005 (bsc#1275791). Changes for webkit2gtk3: - Update to version 2.52.6 WebKitGTK-4.1-lang-2.52.6-150600.12.74.1.noarch.rpm libjavascriptcoregtk-4_1-0-2.52.6-150600.12.74.1.x86_64.rpm libwebkit2gtk-4_1-0-2.52.6-150600.12.74.1.x86_64.rpm typelib-1_0-JavaScriptCore-4_1-2.52.6-150600.12.74.1.x86_64.rpm typelib-1_0-WebKit2-4_1-2.52.6-150600.12.74.1.x86_64.rpm typelib-1_0-WebKit2WebExtension-4_1-2.52.6-150600.12.74.1.x86_64.rpm webkit2gtk-4_1-injected-bundles-2.52.6-150600.12.74.1.x86_64.rpm webkit2gtk3-2.52.6-150600.12.74.1.src.rpm webkit2gtk3-devel-2.52.6-150600.12.74.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-4007 Security update for file-roller moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for file-roller fixes the following issue: - CVE-2026-78322: stack buffer overflow in parse_progress_line for 7z and RAR handlers (bsc#1276442). file-roller-43.1-150600.3.3.1.src.rpm file-roller-43.1-150600.3.3.1.x86_64.rpm file-roller-lang-43.1-150600.3.3.1.noarch.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-4003 Security update for openexr important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for openexr fixes the following issues: - CVE-2026-59184: invalid heap pointer, causing out-of-bounds or use-after-free writes (bsc#1276849). - CVE-2026-59186: On ILP32, the Array2D<Rgba> tile-conversion buffer size calculation overflows, allocates a much smaller heap buffer, and tile decode writes past that allocation (bsc#1276850). - CVE-2026-59189: API can return an out-of-bounds pointer when a deep image has a non-zero dataWindow origin, resulting in a heap out-of-bounds read and crash, with potential information disclosure under a controlled heap layout (bsc#1276855). - CVE-2026-59981: an attacker-controlled deep EXR file can access sample counts through row() performs an out-of-bounds read, which can crash the process or, under a controlled heap layout, return adjacent heap memory as sample-count values (bsc#1276862). - CVE-2026-59982: an out-of-bounds pointer from TypedDeepImageChannel::row() when a crafted deep EXR has a nonzero dataWindow origin (bsc#1276853). - CVE-2026-61555: crashing occurs when Imf::GetChannelsInMultiPartFile() processes a crafted EXR with an empty multiView header attribute and Imf::viewFromChannelName() indexes the empty vector for a dotless channel name (bsc#1276859). - CVE-2026-68515: The utility allocates sampled channel storage using a truncated union_width / xSampling, then reads the sampled input through a Slice based on the misaligned union window, producing a heap out-of-bounds write (bsc#1276848). libIlmImf-2_2-23-2.2.1-150000.3.55.1.x86_64.rpm libIlmImfUtil-2_2-23-2.2.1-150000.3.55.1.x86_64.rpm openexr-2.2.1-150000.3.55.1.src.rpm openexr-devel-2.2.1-150000.3.55.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3934 Security update for ffmpeg important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for ffmpeg fixes the following issues: - CVE-2026-64833: out-of-bounds read in the S/PDIF muxer via a crafted DTS stream with a `core_size` value larger than the actual packet length (bsc#1272755). - CVE-2026-64834: infinite loop in the RTP/ASF demuxer via a crafted RTP/ASF stream (bsc#1272757). - CVE-2026-65703: out-of-bounds write in the TDSC video decoder via a crafted AVI file that changes frame dimensions across TDSF frames(bsc#1272759). - CVE-2026-65705: out-of-bounds write in the `vf_floodfill` video filter via a dynamically sized video stream with filtergraph reinitialization disabled via `-reinit_filter 0` (bsc#1272761). - CVE-2026-65706: out-of-bounds write in the `vf_swaprect` video filter via a crafted NV12 video frame with odd width dimensions(bsc#1272762). - CVE-2026-66036: out-of-bounds write in the `vf_hqdn3d` filter via a crafted video whose frame resolution increases between frames when filtergraph reinitialization is disabled via the `-reinit_filter 0` option (bsc#1272763). ffmpeg-3.4.2-150200.11.79.1.src.rpm libavcodec57-3.4.2-150200.11.79.1.x86_64.rpm libavutil-devel-3.4.2-150200.11.79.1.x86_64.rpm libavutil55-3.4.2-150200.11.79.1.x86_64.rpm libpostproc-devel-3.4.2-150200.11.79.1.x86_64.rpm libpostproc54-3.4.2-150200.11.79.1.x86_64.rpm libswresample-devel-3.4.2-150200.11.79.1.x86_64.rpm libswresample2-3.4.2-150200.11.79.1.x86_64.rpm libswscale-devel-3.4.2-150200.11.79.1.x86_64.rpm libswscale4-3.4.2-150200.11.79.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-4083 Security update for emacs important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for emacs fixes the following issues: - Arbitrary code execution when opening a specially crafted file (bsc#1275941). - CVE-2026-77219: integer overflow in the PBM/PPM/PGM image loader leads to heap memory content leaks when a crafted image with large dimensions and an elevated max color index is processed (bsc#1276264). - CVE-2026-79992: improper argument sanitization in TRAMP leads to arbitrary code execution via crafted filenames (bsc#1275927). emacs-27.2-150400.3.31.2.src.rpm emacs-x11-27.2-150400.3.31.2.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-4156 Security update for MozillaFirefox, MozillaFirefox-branding-SLE, mozilla-nspr, mozilla-nss, rust-cbindgen important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for MozillaFirefox, MozillaFirefox-branding-SLE, mozilla-nspr, mozilla-nss, rust-cbindgen fixes the following issues: Changes in MozillaFirefox: Firefox Extended Support Release 153.2.0 ESR * Fixed: Various security fixes. MFSA 2026-85 (bsc#1278001): * CVE-2026-75874: Sandbox escape in the Remote Settings Client component * CVE-2026-84118: Use-after-free in the JavaScript: GC component * CVE-2026-84119: Sandbox escape due to use-after-free in the DOM: Navigation component * CVE-2026-84120: Use-after-free in the Audio/Video component * CVE-2026-84121: Sandbox escape due to use-after-free in the DOM: Security component * CVE-2026-84122: Use-after-free in the Audio/Video component * CVE-2026-84123: Privilege escalation due to use-after-free in the Graphics: WebGPU component * CVE-2026-84124: Use-after-free in the DOM: Core & HTML component * CVE-2026-84125: Use-after-free in the DOM: Core & HTML component * CVE-2026-74952: Privilege escalation in the Application Update component * CVE-2026-84129: Site isolation issue in the DOM: Navigation component * CVE-2026-84130: Information disclosure in the Graphics: WebGPU component * CVE-2026-84131: Privilege escalation due to invalid pointer in the Graphics component * CVE-2026-84132: Information disclosure in the Networking: HTTP component * CVE-2026-84133: Site isolation issue in the DOM: Push Subscriptions component * CVE-2026-84134: Other issue in the Profile Backup component * CVE-2026-84136: Other issue in the DOM: Navigation component * CVE-2026-84137: Spoofing issue in the DOM: Core & HTML component * CVE-2026-84139: Clickjacking issue in the DOM: Events component * CVE-2026-84140: Site isolation issue in the DOM: Navigation component * CVE-2026-84141: Integer overflow in the Graphics: ImageLib component * CVE-2026-84143: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2 and Firefox ESR 140.15 * CVE-2026-84144: Internally found bugs fixed in Firefox 155 and Firefox ESR 153.2 * CVE-2026-84145: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox ESR 140.15 and Firefox ESR 115.40 * Fixed: Various security fixes. MFSA 2026-77 (bsc#1274867): * CVE-2026-74934: Site isolation issue in the Graphics: CanvasWebGL component * CVE-2026-74935: Privilege escalation in the DOM: Networking component * CVE-2026-74936: Use-after-free in the JavaScript: WebAssembly component * CVE-2026-74937: Use-after-free in the JavaScript: GC component * CVE-2026-74938: Mitigation bypass in the JavaScript: GC component * CVE-2026-74939: Privilege escalation in the DOM: Navigation component * CVE-2026-74940: Use-after-free in the Graphics: Text component * CVE-2026-74941: Privilege escalation in the Graphics: CanvasWebGL component * CVE-2026-74942: Privilege escalation in the Remote Settings Client component * CVE-2026-74943: Use-after-free in the Graphics: ImageLib component * CVE-2026-74944: Use-after-free in the DOM: Core & HTML component * CVE-2026-74945: Information disclosure in the Graphics: Text component * CVE-2026-74946: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component * CVE-2026-74947: Privilege escalation due to invalid pointer in the Graphics component * CVE-2026-74948: Information disclosure in the Graphics component * CVE-2026-74949: Privilege escalation due to use-after-free in the Graphics: Canvas2D component * CVE-2026-74950: Privilege escalation in the Downloads API component * CVE-2026-74953: Privilege escalation in the Networking: Cookies component * CVE-2026-74954: Information disclosure due to side-channel in the Storage: Cache API component * CVE-2026-74955: Privilege escalation in the Request Handling component * CVE-2026-74956: Same-origin policy bypass in the DOM: Service Workers component * CVE-2026-74957: Mitigation bypass in the Safe Browsing component * CVE-2026-74958: Information disclosure in the WebRTC component * CVE-2026-74959: Mitigation bypass in the Storage: Cache API component * CVE-2026-74960: Site isolation issue in the WebExtensions component * CVE-2026-74961: Side-channel in the Web Audio component * CVE-2026-74962: Site isolation issue in the Networking: Cookies component * CVE-2026-74963: Same-origin policy bypass in the Networking: Cookies component * CVE-2026-74964: Integer overflow in the Graphics component * CVE-2026-74965: Privilege escalation in the Shell Integration component * CVE-2026-74966: Information disclosure in the Form Autofill component * CVE-2026-74967: Same-origin policy bypass in the Audio/Video: Playback component * CVE-2026-74968: Site isolation issue in the Graphics: WebRender component * CVE-2026-74969: Use-after-free in the Layout: Text and Fonts component * CVE-2026-74970: Site isolation issue in the Graphics component * CVE-2026-74971: Information disclosure in the DOM: UI Events & Focus Handling component * CVE-2026-74972: Information disclosure in the DOM: Push Subscriptions component * CVE-2026-74973: Race condition, use-after-free in the Graphics component * CVE-2026-74974: Same-origin policy bypass in the Graphics: ImageLib component * CVE-2026-74976: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-74977: Integer overflow in the Graphics component * CVE-2026-74978: Clickjacking issue in the Widget component * CVE-2026-74979: Mitigation bypass in the Add-ons Manager component * CVE-2026-74981: Site isolation issue in the Audio/Video: Web Codecs component * CVE-2026-74982: Denial-of-service in the Widget component * CVE-2026-74983: Mitigation bypass in the Data Loss Prevention component * CVE-2026-74984: Race condition in the JavaScript Engine component * CVE-2026-74985: Privilege escalation in the Enterprise Policies component * CVE-2026-74986: Site isolation issue in the CSS Parsing and Computation component * CVE-2026-74987: Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 * CVE-2026-74988: Internally found bugs fixed in Firefox ESR 153.1 and Firefox 154 * CVE-2026-74990: Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 - Firefox Extended Support Release 153.0esr ESR * New: ## General - Firefox now includes a new profile management system that helps you separate your online life into distinct profiles for work, school, vacation planning, or whatever you choose. Profiles can be customized with names, avatars, and color themes while keeping tabs, bookmarks, passwords, and browsing history separate. Built-in profile backup and restore also makes it easier to migrate to a new device or recover your browsing data. - Split View lets you view two webpages side-by-side in a single browser window, with additional options to quickly open links in Split View, rearrange pages, and search open tabs. - The Firefox address bar has gained several new capabilities, including built-in unit and time zone conversion, quick actions such as muting all browser audio, and direct search results as you type. - Firefox now supports copying links directly to highlighted text on a webpage for easier sharing. - Firefox Settings has been redesigned with improved organization and navigation, making it easier to find and customize browser preferences. * New: ## AI Firefox introduced several new AI-powered features, including on-device tab organization, AI-assisted link previews, integrated AI search, and centralized controls for managing AI features. Whenever possible, these features perform processing locally to help protect user privacy. * New: ## Sidebar and Tabs - Firefox continues to improve tab management with enhancements to vertical tabs, tab groups, and the sidebar. - Tab groups have gained numerous usability improvements, including better support for collapsed groups, previews of grouped tabs, and additional organization options. - Passwords can now be accessed directly from the Firefox sidebar without opening a separate tab. - Firefox now supports copying links from one or multiple background tabs directly from the tab context menu, and multiple tabs can be copied or shared in a single action. - A Send Tab toolbar button is now available through Customize Toolbar. * New: ## Security & Privacy - Firefox has significantly expanded Fingerprinting Protection, making it harder for websites to uniquely identify users in both Standard and Strict Enhanced Tracking Protection modes. - Enhanced Tracking Protection includes stronger protections against bounce tracking and additional safeguards that restrict websites from accessing local network resources without user permission. - Firefox now uses Safe Browsing V5 for phishing and malware protection. - Firefox Password Manager now uses stronger AES-256 encryption to protect stored logins on disk. - Private Browsing has been enhanced with new controls, including the ability to instantly end a private browsing session and temporarily relax tracker blocking for individual sites when needed for compatibility. * New: ## Translations - Firefox has expanded on-device translation support with many additional languages and continued improvements to translation quality. - A dedicated translations page now provides an easy way to perform real-time translations directly within Firefox. * New: ## Accessibility - Firefox continues to improve accessibility with enhanced support for assistive technologies, including Windows UI Automation, improved keyboard navigation, more accessible date and time controls, and better support for mathematical content in PDFs. * New: ## Windows - Firefox now supports installing websites as standalone web apps pinned to the Windows taskbar. - Firefox web apps are also available for Microsoft Store installations. - Firefox now better integrates with Windows location permissions when websites request geolocation access. * New: ## macOS - Firefox now uses a dedicated GPU process by default, improving stability by allowing graphics failures to recover without restarting the browser. - WebGPU is now enabled by default on Apple Silicon Macs. * New: ## Linux - Firefox now supports native fractional scaling on Wayland, improving rendering on high-DPI displays. - Firefox no longer requires a restart after package manager updates and uses less memory on Linux. - Firefox now supports the XDG Base Directory Specification and ships with RPM packages for Red Hat, Fedora, openSUSE, and other RPM-based distributions. * HTML5: - Firefox now supports the View Transitions API for creating smooth animated transitions between application views. - WebGPU support has expanded across supported platforms, including Windows and Apple Silicon Macs. - Added support for several modern web platform APIs, improving compatibility with modern web applications. Notable additions include the Navigation API, URLPattern, Trusted Types, Sanitizer API, and Prioritized Task Scheduling. * Enterprise: - Enterprise administrators can now centrally manage Firefox's Generative AI features through enterprise policy. - Fixed a performance regression affecting native messaging, improving responsiveness for enterprise extensions that communicate with external applications. - Enterprise policy documentation has moved to https://firefox-admin-docs.mozilla.org/. * Fixed: Various security fixes. MFSA 2026-68 (bsc#1271649): * CVE-2026-16349: Same-origin policy bypass in the DOM: Navigation component * CVE-2026-16350: Incorrect boundary conditions in the Audio/Video: cubeb component * CVE-2026-16362: Use-after-free in the WebRTC: Audio/Video component * CVE-2026-16351: Sandbox escape due to use-after-free in the DOM: Navigation component * CVE-2026-16352: Sandbox escape due to use-after-free in the Disability Access APIs component * CVE-2026-16363: JIT miscompilation in the JavaScript: WebAssembly component * CVE-2026-16364: Incorrect boundary conditions in the Audio/Video: Playback component * CVE-2026-16365: Privilege escalation in the DOM: Workers component * CVE-2026-16366: Privilege escalation in the DOM: Navigation component * CVE-2026-16353: Invalid pointer in the DOM: Bindings (WebIDL) component * CVE-2026-16354: Information disclosure in the Graphics: ImageLib component * CVE-2026-16367: Sandbox escape due to invalid pointer in the Disability Access APIs component * CVE-2026-16368: Incorrect boundary conditions in the JavaScript: WebAssembly component * CVE-2026-16369: Integer overflow in the JavaScript: WebAssembly component * CVE-2026-16355: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16356: Sandbox escape due to use-after-free in the Disability Access APIs component * CVE-2026-16357: Incorrect boundary conditions in the Graphics component * CVE-2026-16370: Mitigation bypass in the DOM: Networking component * CVE-2026-16371: Privilege escalation in the DOM: Navigation component * CVE-2026-16372: Privilege escalation in the DOM: Content Processes component * CVE-2026-16373: Information disclosure in the Privacy component in Firefox for Android * CVE-2026-16374: Information disclosure in the Framework component in DevTools * CVE-2026-16375: Site isolation issue in the Networking: HTTP component * CVE-2026-16376: Denial-of-service in the Graphics: WebGPU component * CVE-2026-16377: Mitigation bypass in the PDF Viewer component * CVE-2026-16378: Other issue in the DOM: Copy & Paste and Drag & Drop component * CVE-2026-16379: Privilege escalation in the DOM: Content Processes component * CVE-2026-16358: Site isolation issue in the Graphics: WebRender component * CVE-2026-16380: Mitigation bypass in the Networking component * CVE-2026-16381: Same-origin policy bypass in the Networking: DNS component * CVE-2026-16382: Mitigation bypass in the DOM: Service Workers component * CVE-2026-16383: Mitigation bypass in the DOM: Networking component * CVE-2026-16384: Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16385: Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16386: Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16387: Site isolation issue in the Networking component * CVE-2026-16388: Sandbox escape in the DOM: Networking component * CVE-2026-16389: Incorrect boundary conditions, integer overflow in the Libraries component in NSS * CVE-2026-16390: Mitigation bypass in the Enterprise Policies component * CVE-2026-16391: Information disclosure in the Storage: IndexedDB component * CVE-2026-16392: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16393: Incorrect boundary conditions in the Graphics: WebGPU component * CVE-2026-16359: Incorrect boundary conditions in the Audio/Video: GMP component * CVE-2026-16394: Mitigation bypass in the DOM: Security component * CVE-2026-16395: Integer overflow in the Audio/Video component * CVE-2026-16396: Privilege escalation in WebExtensions * CVE-2026-16397: Clickjacking issue in the WebExtensions component in Firefox for Android * CVE-2026-16398: Site isolation issue in the Graphics component * CVE-2026-16399: Site isolation issue in the DOM: Navigation component * CVE-2026-16400: Information disclosure in the DOM: Security component * CVE-2026-16401: Privilege escalation in the Data Loss Prevention component * CVE-2026-16402: Integer overflow in the Graphics: ImageLib component * CVE-2026-16403: Spoofing issue in the Address Bar component * CVE-2026-16404: Spoofing issue in Firefox for Android * CVE-2026-16405: Information disclosure in the Networking: WebSockets component * CVE-2026-16406: Mitigation bypass in the Networking component * CVE-2026-16407: Mitigation bypass in the DOM: Service Workers component * CVE-2026-16408: Integer overflow in the Audio/Video: Playback component * CVE-2026-16409: Invalid pointer in the Security: PSM component * CVE-2026-16410: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16411: Memory safety bugs fixed in Firefox 153 * CVE-2026-16412: Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153 * CVE-2026-16360: Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153 * Fixed: Various security fixes. MFSA 2026-76 (bsc#1274867): * CVE-2026-74934: Site isolation issue in the Graphics: CanvasWebGL component * CVE-2026-74935: Privilege escalation in the DOM: Networking component * CVE-2026-74936: Use-after-free in the JavaScript: WebAssembly component * CVE-2026-74939: Privilege escalation in the DOM: Navigation component * CVE-2026-74940: Use-after-free in the Graphics: Text component * CVE-2026-74941: Privilege escalation in the Graphics: CanvasWebGL component * CVE-2026-74942: Privilege escalation in the Remote Settings Client component * CVE-2026-74943: Use-after-free in the Graphics: ImageLib component * CVE-2026-74944: Use-after-free in the DOM: Core & HTML component * CVE-2026-74945: Information disclosure in the Graphics: Text component * CVE-2026-74946: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component * CVE-2026-74948: Information disclosure in the Graphics component * CVE-2026-74949: Privilege escalation due to use-after-free in the Graphics: Canvas2D component * CVE-2026-74953: Privilege escalation in the Networking: Cookies component * CVE-2026-74957: Mitigation bypass in the Safe Browsing component * CVE-2026-74959: Mitigation bypass in the Storage: Cache API component * CVE-2026-74960: Site isolation issue in the WebExtensions component * CVE-2026-74962: Site isolation issue in the Networking: Cookies component * CVE-2026-74963: Same-origin policy bypass in the Networking: Cookies component * CVE-2026-74964: Integer overflow in the Graphics component * CVE-2026-74965: Privilege escalation in the Shell Integration component * CVE-2026-74967: Same-origin policy bypass in the Audio/Video: Playback component * CVE-2026-74969: Use-after-free in the Layout: Text and Fonts component * CVE-2026-74971: Information disclosure in the DOM: UI Events & Focus Handling component * CVE-2026-74972: Information disclosure in the DOM: Push Subscriptions component * CVE-2026-74973: Race condition, use-after-free in the Graphics component * CVE-2026-74974: Same-origin policy bypass in the Graphics: ImageLib component * CVE-2026-74976: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-74983: Mitigation bypass in the Data Loss Prevention component * CVE-2026-74987: Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 * CVE-2026-74990: Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 Changes in rust-cbindgen: - Update to version v0.29.4+git0: * Bump version. * tests: Add some tests for constant enums. * ir: Add support for arrays. * ir: Allow constant literals with enum variants. * ir: Use Path for ConstExprs. * Bump version to 0.29.3 and update CHANGES doc * tests: Fix tests with modern gcc. * Use C++ fixed-type enumeration syntax under C23 (or higher) as well * Allow `pub` access to `ReprType` fields - Update to version 0.29.2+git0: * ci: Add a meta job to block the merge queue on it. * Check for CMSE ABI's as well * Fix doc attribute parsing to properly handle block comments * Expose the line_endings config option to use with the builder * fix env in workflow file * use env to pass output parameters * Explicitly request serde's std features to avoid issues with newer toml versions. * Account for master -> main rename. * Update changelog and bump version. * enum: Track dependencies properly in enumerations. - Update to version 0.29.2+git0: * Explicitly request serde's std features to avoid issues with newer toml versions. * Account for master -> main rename. * Update changelog and bump version. * enum: Track dependencies properly in enumerations. * Allow must_use if a reason is specified * constant: Handle cfg in associated constants. * tests: Add a test for bitflags + disjoint cfg. * Remove "display" feature from the toml crate * DOC: Add metatensor * Fix #1085 - Incorrect detection of duplicated constants * chore: More clippy fixes. * docs: Correct after_include type in example config * cargo update * cfg: Remove another clippy warning. * Fix `clippy::uninlined_format_args` * Update toml to 0.9 * Release 0.29.0 * Support no-export annotation for statics and functions. * conditional fields of constexpr literal structs * Add LiteralStructField * Github action: Add aarch64 to deploy * Add rename rule for generated associated constant * Upgrade heck to 0.5 * Add support for an optional nullable attribute * docs.md: Fix deprecated_with_note and deprecated_variant_with_note being spelled as 'notes' * Fix generic with "void" default * The return of Cast is simplified * Added tests for as keyword inside array into structs * Fixed error generation of structures using the keyword of as inside arrays * Added test for unsafe(no_mangle) attribute * Added tests for unsafe methotd's atributs * Fixed handling of trait methods containing the unsafe attribute * Rename -Zparse-only * Release 0.28.0 * tests: Fix symbol file and tests. * Appease clippy. * tests: Run rustfmt. Changes in mozilla-nspr: - update to NSPR 4.39 * Improved error handling in PR_CreateThread on Windows * Cleanup and Type-cast fixes for prtime * Remove unused prstreams C++ wrapper from NSPR * Memory poisoning and Arena redzone fixes * Removed emacs/vim modelines and .cvsignore files * Added .editorconfig - update to version 4.38.2 * Fixed a syntax error in test file parsetm.c, which was introduced in 4.38.1 - update to version 4.38.1 * Incorrect time value produced by PR_ParseTimeString and PR_ParseTimeStringToExplodedTime if input string doesn't specify seconds. - update to version 4.38 * Removed support for HPUX and _PR_POLL_WITH_SELECT * Fixed a bug in pt_TCP_SendTo on macOS * Ensure parameter passed to isalpha() is unsigned char - update to version 4.37 * PR_GetUniqueIdentity asserts on the 32767th call * error LNK2019: unresolved external symbol _InterlockedCompareExchange * initclk deadline elapsed macOS * Remove prwin.h (formerly known as prwin16.h) * Use builtin atomic functions on RISC-V32/64 * PR_FormatTimeUSEnglish() doesn't support "%e" format specifier Changes in MozillaFirefox-branding-SLE: - use suse_version for SLE16 (bsc#1273243) - chage version to 153 - Switch to using xdg-desktop-portal file picker everywhere for SLE-16 and later (bsc#1226112) Changes in mozilla-nss: - Fix potential crash in FIPS checks on PBKDF2 password checking (boo#1279863) - Fix upper bound to allow FIPS approval for P-521. - Approve HKDF and key concatenation in the context of TLS. This enables approved TLS 1.3 channels with PQC (bsc#1262698). - Don't consider unapproved algorithms for TLS 1.3 in FIPS mode. - Mark TLS 1.2 KDF without extended master secret non-approved for FIPS (bsc#1266262). - Add patch to prefer any hybrid PQC and send at most one hybrid key share (bsc#1262698). - Add a notice to the module ID when it's in non-FIPS mode (bsc#1266263). - Import ML-DSA implementation and related PQC fixes from upstream (bsc#1262698, bsc#1272772). - Add power-on self-tests (KATs) for ML-KEM and ML-DSA (bsc#1272773). - Add zeroization for ML-KEM, ported from upstream (bsc#1272774). - Add zeroization for ML-DSA (bsc#1272774). - nss-ml-dsa-test-fixes.patch: Add ML-DSA robustness and test fixes. - Add PQC algorithms to approved list. Increase approved symmetric keygen floor to 112 bits (bsc#1262698). Approve non-NSS-aliased TLS 1.2 mechanisms (bsc#1266262). - Apply jitter enablement unconditionally (bsc#1262701). - update to NSS 3.125 * Set nssckbi version to 2.88. * Add Cybertrust Japan SecureSign Root CA16. * Remove Email Trust bit from TrustAsia Global Root CA G3 and G4. * Remove Entrust Root Certification Authority. * Remove SecureSign Root CA12. * Initialize ssl3.hs.echOuterExtensions in ssl_NewSocket. * replace references to nss-dev/nss with mozilla/nss. * limit recursion depth in CMS decoder. * clamp input.len to testString size in pk11_mergeSecretKey. * NULL pointer dereference in CERT_MergeExtensions. * CERT_DecodeAVAValue — Integer Overflow in Output Buffer Sizing. * fix two integer overflows on LLP64 systems. * Modify an assertion in ssl3_ClientSendAppProtoXtn. * Import RSA-PSS PKCS#8 private keys. * Add EC Derive fuzz target. * Update fuzz/config/tstclnt_arguments.py. * Add DSAU fuzz target. * Update ASN1 mutators for fuzzing. * Update TLS mutators for fuzzing. * Update TLS certs for fuzzing. * Update TLS config for fuzzing. * Extend QuickDER fuzz target. * Extend PKCS12 fuzz target. * Extend PKCS8 fuzz target. * Extend certDN fuzz target. * Update ASN1 fuzz target. * Extend PKCS7 fuzz target. * Bounds-check wrap index in PK11_GetWrapKey to match PK11_SetWrapKey. * Adding a guard against integer overflow in AESKeyWrap_EncryptKWP. * Add an integer overflow guard in UpdateBase64Decoder. * Void out the fd.release in reconfig tests. * make sftk_FindAttribute return a copy. * Converted nss parameter schema from voluptuous to msgspec. * bmo#311577 - drop slot monitor in PK11_ResetToken before calling PK11_InitToken. * adjust the code to use nspr from github. * avoid deadlock when PK11_IsLoggedIn is called from PK11_DoPassword. * test pk11auth.c functions with a non-threadsafe module. * bmo#311577 - PK11_InitPin sets slot->lastLoginCheck without holding the slot monitor. * reject empty nickname in PK11_TraverseCertsForNicknameInSlot. * validate encoded EC params length and tag in SECKEY_ECParamsToKeySize/BasePointOrderLen. * guard space subtraction in ssl_CallCustomExtensionSenders. * rewrite labelLen bound in tls13_HkdfExpandLabelGeneral to avoid unsigned overflow. * bound usageCount in PK11_UnwrapPrivKey to keyTemplate capacity. * Set tail pointer to null in static slot lists when deallocating. * avoid leaving a dangling ss->sec.ci.sid on allocation failure. * guard against integer overflow in CERT_Hexify. * Reject empty SECItem inputs in sftk_IsSafePrime before indexing data[len-1]. * NUL-terminate within filename field in jar_listtar to bound the filename scan. * Widen CERT_FormatName length accumulator from unsigned to size_t. * Bound IKE PRF nonce lengths to prevent CK_ULONG to unsigned int truncation. * Drop companion arrays on length mismatch in NSS_CMSArray_Sort instead of asserting. * Operate on a NUL-terminated copy in jar_parse_any to keep manifest scans bounded. * Reject MD2 contexts with unusedBuffer > MD2_BUFSIZE in Update and End. * Reserve NUL terminator for CKA_NSS_URL in nssCKObject_GetAttributes. * Guard padding read against empty output in SEC_PKCS7DecryptContents. * Guard against keySize overflow in IKE PRF/PRF+ output sizing. * Allocate values array when overwriting an empty CMS attribute. * Validate CKA_TOKEN attribute size in nssCKFWObject_SetAttribute. * Validate CKA_CERTIFICATE_TYPE ulValueLen in nss_cert_type_from_ck_attrib. * Handle zero-length input in PrepareBitStringForEncoding. * Length-check raw_manifest before PORT_Strncasecmp prefix dispatch in JAR_parse_manifest. * Reject CKA_NSS_MODULE_SPEC values that aren’t NUL-terminated within ulValueLen. * Reject negative PR_Read returns in JAR_digest_file and jar_create_pk7. * Update Bogo tests to 3fff7111b0eca817466e121059cb4e8b67ade35b. * doc: import NSS:TryServer wiki page in the tree. * improve PK11 URI tests. * avoid nested attributeLock acquisition in sftk_CopyObject. * doc: fix a typo in “Community — Network Security Services (NSS)”. * acquire RWLock before key copies in ssl_SetSelfEncryptKeyPair. * Reject empty nickname in PK11_TraverseCertsForNicknameInSlot. * require non-null session pointer in sftk_GetContext. * set session->lastOpWasFIPS while holding session reference. * atomically claim object removal in sftk_DeleteObject. * atomically swap session search in NSC_FindObjects*. * atomically install session contexts in C_*Init. * hold session reference for context lifetime in C_*Update. * align softoken session lock with head-bucket hash. * restore reference counting for SFTKSession. - update to NSS 3.124 * Add test for PKCS7 digest array alignment * Add test for rejection of excessively large ASN.1 SEQUENCE OF in quickder * Add test for CMS content size validation * Add regression tests for DSAU signature decoding * Add test for S/MIME profile lookup on temp certs * Test case for post-handshake auth and many certificate requests * Add test for intra-arena ASan redzones * update nss_status flags one at a time * add defensive info->len check in PK11_HPKE_SetupS and PK11_HPKE_SetupR * avoid PORT_Strdup in ssl_DecodeResumptionToken * add runtime check on decoded resumption token session id * improve mach try error handling * clang format * add comprehensive SECItem and SECItemArray tests * add bugzilla_cf_status_nss.py script * regenerate some recent release notes * fix bug list output by release note and email scripts * test removal from trust domain email cache * fix "testing if key corruption is detected in attribute" failures with sqlite-3.53.0 * build sqlite3 shell for Windows CI runners * avoid race with module unloading in NSSTrustDomain_FindTokensByURI * add ImportEd25519WithNonEmptyAlgorithmParams test * add CLAUDE.md and .mcp.json * add a mach try command * remove dead condition in sec_asn1d_check_and_subtract_length * avoid integer truncation in nssCKObject_GetAttributes * add defensive input validation to sftk_compute_ANSI_X9_63_kdf * avoid refcount over-release in nssTokenObjectCache error path [@ nssToken_Destroy] * sdb: enforce that metaData's id key is unique when reading * improve handling of escape sequences in pk11uri_ParseAttributes * use correct data for ID comparison in transfer_uri_certs_to_collection * fix truncation of ulValueLen in sdb_FindObjectsInit * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max * set previous-nss-release for abicheck * Skip `PR_Sleep` yield for non-blocking sockets in `ssl3_SendApplicationData` * consistently protect PK11SlotInfo::maxKeyCount with freeListLock * Remove CRMF from testing and manifests * Remove unused RSA blind signature implementation from freebl - update to NSS 3.123.1 * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max - update to NSS 3.123 * https://groups.google.com/a/mozilla.org/g/dev-tech-crypto/c/AW6VHkn6E0o - update to NSS 3.122.2: * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max - update to NSS 3.122.1 * improve error handling in PK11_ImportPrivateKeyInfoAndReturnKey. * Improving the allocation of S/MIME DecryptSymKey. * store email on subject cache_entry in NSS trust domain. * Heap use-after-free in cert_VerifyCertChainOld via dangling certsList[] entry on NameConstraints violation. * Improve size calculations in CMS content buffering. * avoid integer overflow while escaping RFC822 Names. * Reject excessively large ASN.1 SEQUENCE OF in quickder. * Deep copy profile data in CERT_FindSMimeProfile. * Improve input validation in DSAU signature decoding. * avoid integer overflow in RSA_EMSAEncodePSS. * Add a maximum cert uncompressed len and tests. * Clarify extension negotiation mechanism for TLS Handshakes. * make ss->ssl3.hs.cookie an owned-copy of the cookie. - update to NSS 3.122 * ensure permittedSubtrees don't match wildcards that could be outside the permitted tree. * run mach doc-lint from generate_release_doc.py. * Fix integer underflow in tls13_AEAD when ciphertext is shorter than tag. * tls13_CopyEchConfigs uses PR_LIST_TAIL instead of loop variable. * fix cipher spec count intermittent CI failures. * fix Mlkem768x25519ShareDamager intermittent CI failures. * lint the legacy documentation. * lint the NSS 3.112.3 release notes. * add a doc-lint CI job. * Add more useful coverage reports to CI and fail if new commit isn't tested. * wrong alert for malformed TLS 1.3 Finished. * Swap order of asserts and state check. * set correct value of unused curve parameters in tls13_HandleKeyShare. * GCM needs to check for various limits in FIPS mode. * Get Key Length not working from ED and Montgomery keys. * Not all ike modes are FIPS approved. Adjust the indicators when they aren't. * fix intermittent ssl.sh test failures on windows runners. * FIPS indicators on HKDF needs to be restricted to TLS usage. * Generate keys not getting indicators. * improve error handling in smime_init_once. * Detect CPU features on OpenBSD using elf_aux_info. * RSA_EMSAEncodePSS should validate the length of mHash. * more robustly distinguish SFTKSessionObject and SFTKTokenObjects. * fix missing .S file error in Solaris Makefile builds. * fix memory leak in NSC_GenerateKey error path. * Missing SECFailure return after FATAL_ERROR in tls13_HandleEncryptedExtensions. * release xmit buf lock on dtls13_MaybeSendKeyUpdate error paths. * release 1stHandshakeLock on SSL_ResetHandshake error path. * avoid null deref in mp_div_d sign normalization. * Temp private key lifecycle is broken. * protect rwSessionCount with slotLock. * Remove invalid PORT_Free(). * Fix intermittent ClientGreaseKeyShare test failure. * Fix kCtxStr len passed to tls_SignOrVerifyUpdate. * patch upstream acvp-rust during checkout to avoid build failures. * update acvp Dockerfile. * CKA_PARAM_SET missing from the CK_ULONG list in softoken. * CKA_SEED missing from isPrivate in the database. * update abicheck expectation for __nss_InitLock. * taskcluster: set NSS_DISABLE_LIBPKIX=1 in test env for static builds. * tests: fix setup_policy to use ROOTCERTSFILE for root cert module path. * tests: fix selfserv/httpserv PID handling and wait exit code for MSYS_NT. * tests: add native_path helper for cross-platform path conversion. * tstclnt, strsclnt: avoid DNS lookup for loopback addresses on Windows. * avoid platform GCM for x64 iOS emulator builds. * remove lock instrumentation feature. * Move FIPS indicator structures out of fips_algorithms.h. * all.sh is failing in FIPS SSL test in main tree. * fix memory leaks in crmf tests. * fix unsatisfiable condition in lg_getTrust. * allow selfserv makefile build to use system zlib. * Add allocation limit to pkcs12 decoding. * Add text/html single-line example emails to NSS S/SMIME CMS tests. - Rebase patches nss-fips-aes-gcm-restrict.patch and nss-fips-approved-crypto-non-ec.patch due to upstreamed FIPS patches - update to NSS 3.121 * update vendored zlib to v1.3.2. * Revert the unnecessary changes to intel-gcm-wrap.gyp. * Use C fallback for AES-GCM on MinGW builds. * fix ML-KEM PCT. * Extend NSS Fuzzing docs. * avoid integer overflow in platform-independent ghash. * Fix errant whitespace in OISTE Server Root RSA G1 nickname. * fix build with glibc-2.43 assignment discards 'const' qualifier from pointer. * add gcm.gyp dependency for Solaris SPARC builds. * Set nssckbi version to 2.84. * Add e-Szigno TLS Root CA 2023 to NSS. * allow manual selection of CPU_ARCH=x86_64 and ppc64 in coreconf/Darwin.mk. * Update cryptofuzz version. * Paranoia assert. * Darwin compatibility for intel-aes.S and intel-gcm.S. * rename intel-{aes,gcm}.s to .S. * rename C files for platform-specific ghash implementations. * simplify compilation of platform-specific GCM and GHASH. * FORWARD_NULL null deref of worker in p7decode.c (sec_pkcs7_decoder_abort_digests). * Out-of-Bounds Read in ML-DSA Private Key Parsing (zero-length privateKey). - update to NSS 3.120.1 * no upstream releasenotes - update to NSS 3.120 * Fix docs generation bug. * CID 1678226: Dereferencing null pointer plaintext.data(). * Run PKCS12 fuzz target with --fuzz=tls in CI. * Allowing RT be started several times. * move linux decision and build tasks to d2g worker pools. - Revert back to original naming scheme of tarballs - update to NSS 3.119.1 * restore coreconf/Darwin.mk behavior for intel archs - update to NSS 3.119 * Fix ml-dsa return value for SECKEY_PrivateKeyStrengthInBits. * Make sure we don't accept ECH if the HRR cookie is ill-formatted. * Add a pkcs12 fuzzer with crypto stubbed out. * handle errors while setting sanitizers cflags in build. * Ignore IVs for AES KW. * Update Cryptofuzz version. * Fix incorrect logic for SNI selection when ECH is available but disabled. * fix forwarding of sqlite_libs in sqlite.gyp. * fix CPU_ARCH setting for arm64 makefile builds. * remove unused calcThreads variable from cmd/rsaperf. * Solving the incorrect tests introduced by extending EKU. * Memory leaks in pkcs12 and pkcs7 decoders. * Extending parsing with Microsoft Document Signing EKU. * Extending parsing with Adobe Document Signing EKU. * Extending pkix parsing with document signing EKUs. * fix compilation failure on ia32. * use hardware x64 GCM in static builds. * separate ppc sha512 library from ppc gcm library. * simplify cross-compilation from build.sh. * use clang's integrated assembler. * remove unused MP_IS_LITTLE_ENDIAN defines. * fix logic for disabling altivec in gyp builds. * free digest objects in SEC_PKCS7DecoderFinish if they haven't already been freed. * Add TLS interoperability tests with openssl and gnutls. * Ensure we don't send a DTLS1.3 cookie after DTLS1.2 HelloVerifyRequest. * add failure checks to pk11_mergeTrust() . * pk11wrap selects incorrect slot for CKM_ML_KEM*. - Adjusted for changed naming scheme of tarballs for this release by upstream - update to NSS 3.118.1 * pk11wrap selects incorrect slot for CKM_ML_KEM* - update to NSS 3.118 * Remove four Commscope root certificates from NSS * fix try pushes with --nspr-patch to actually apply the patch * Support for NIST Curves compressed points * Destroy certificate on error paths * Move NSS DB password hash away from SHA-1 * support secp384r1mlkem1024 * vendor latest ML-KEM code from libcrux * add mlk-kem-1024 tests * use the correct directory for FStar_UInt_8_16_32_64.h in source consistency test * Move scripts to python3 * add mlkem1024 support in freebl * support secp256r1mlkem768 * Make mlkem768x25519 the default * ML-DSA SGN and VFY interfaces * Align FIPS interfaces count with array * Ensure CKK_ML_KEM has derive CK_FALSE * Add script for tagging an NSS release * Remove the globals from nss-release-helper.py * Add release helper command for generating the release index * Add release helper command for generating a release note * Add release helper command for freezing a branch - update to NSS 3.117 * fix memory leak in secasn1decode_unittest.cc * Add OISTE roots * Add runbook for certdata.txt changes * dbtool: close databases before shutdown * SEC_ASN1Decode* should ensure it has read as many bytes as each length field indicates * don’t flush base64 when buffer is null * Set use_pkcs5_pbkd2_params2_only=1 for fuzzing builds * mozilla::pkix: recognize the qcStatements extension for QWACs * Fix a big-endian-problematic cast in zlib calls * Revert removing out/ directory after ossfuzz build * Add Cryptofuzz to OSS-Fuzz build * Add PKCS#11 trust tests * final disable dsa patch cert.sh * ml-dsa: move tls 1.3 to use streaming signatures * ml-dsa: Prep Create a FindOidTagByString function * ml-dsa: softoken changes * ml-dsa: der key decode * ml-dsa: Prep colapse the overuse of keyType outside of pk11wrap and cryptohi * ml-dsa: Prep Create a CreateSignatureAlgorithmID function - update to NSS 3.116 * disable DSA in NSS script tests * Disabling of some algorithms: generic cert.sh * Need to update to new mechanisms * Add ML-DSA public key printing support in NSS command-line utilities * note embedded scts before revocation checks are performed * Add support for ML-DSA keys and mechanisms in PKCS#11 interface * Add support for ML-DSA key type and public key structure * Enable ML-DSA integration via OIDs support and SECMOD flag * disable kyber * Implement PKCS #11 v3.2 PQ functions (use verify signature) * Disable dsa - gtests * make group and scheme support in test tools generic * Create GH workflow to automatically close PRs * Disable dsa - base code * Disabling of some algorithms: remove dsa from pk11_mode * Disable seed and RC2 bug fixes * restore support for finding certificates by decoded serial number * avoid CKR_BUFFER_TO_SMALL error in trust lookups * lib/softtoken/{sdb.c,sftkdbti.h}: Align sftkdb_known_attributes_size type * Use PKCS #11 v3.2 KEM mechanisms and functions - update to NSS 3.115.1 * restore support for finding certificates by decoded serial number. * avoid CKR_BUFFER_TO_SMALL error in trust lookups. - update to NSS 3.115 * CID 1648399 - Resource leak in shlibsign.c * CKA_SEED needs to be marked as a private attribute * Fix bad syntax on Windows in softoken_gtest.cc * Key private/public/secret keys by key type in softoken keydb * add PK11_HPKE_GetSharedSecret to abi-check expected report * remove NetscapeStepUpMatchesServerAuth from mozpkix TrustDomain * Fixup ABI * add ECH_SECRET and ECH_CONFIG to SSLKEYLOG for both client and server * ECH fuzz target * Implement PKCS #11 v3.2 FIPS indicator and validation objects * remove expired explicitly distrusted DigiNotar lookalike root * Implement PKCS #11 v3.2 functions - update to NSS 3.114 * NSS 3.114 source distribution should include NSPR 4.37 * Prevent leaks during pkcs12 decoding * Remove redundant assert in p7local.c * Bump nssckbi version to 2.80 * Remove expired Baltimore CyberTrust Root * Add TrustAsia Dedicated Roots to NSS * Add SwissSign 2022 Roots to NSS * Add backwards compatibility for CK_PKCS5_PBKD2_PARAMS * Implement PKCS #11 v3.2 trust objects in softoken * Implement PKCS #11 v3.2 trust objects - nss proper * remove dead code in ssl3con.c * DTLS (excl DTLS1.3) Changing Holddown timer logic * Bump nssckbi version to 2.79 * remove unneccessary assertion * Update mechanisms for Softoken PCT * convert Chunghwa Telecom ePKI Root removal to a distrust after * Ensure ssl_HaveRecvBufLock and friends respect opt.noLocks * use -O2 for asan build * Fix leaking locks when toggling SSL_NO_LOCKS * remove out-of-function semicolon * Extend pkcs8 fuzz target * Extend pkcs7 fuzz target * Remove unused assignment to pageno * Remove unused assignment to nextChunk * don't run commands as part of shell `local` declarations * fix sanitizer setup * don't silence ssl_gtests output when running with coverage * Release docs and housekeeping * migrate to new linux tester pool - rebase FIPS patches to adjust for upstream FIPS work - update to NSS 3.113 * Fix alias for mac workers on try. * bmo#198090 - Part 1: Use AES in the SDR (NSS) r=simonf,nss-reviewers,rrelyea * Bump nssckbi version to 2.78. * Turn off Websites Trust Bit for Chunghwa Telecom ePKI Root in FF 141. * fix frame pointers in intel-gcm.s. * Typo in release notes for NSS 101.4. * Improve nss-release-helper.py. * shlibsign is broken in System FIPS mode. * Need up update NSS for PKCS 3.1: Move IPSEC to 3.1 * PKCS #11 v3.2 header files. MozillaFirefox-153.2.0-150400.157.5.1.src.rpm MozillaFirefox-153.2.0-150400.157.5.1.x86_64.rpm MozillaFirefox-branding-SLE-153-150400.14.3.1.src.rpm MozillaFirefox-branding-SLE-153-150400.14.3.1.x86_64.rpm MozillaFirefox-devel-153.2.0-150400.157.5.1.noarch.rpm MozillaFirefox-translations-common-153.2.0-150400.157.5.1.x86_64.rpm MozillaFirefox-translations-other-153.2.0-150400.157.5.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3985 Recommended update for libnvidia-egl-wayland moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for libnvidia-egl-wayland fixes the following issues: - egl-wayland: * Fix fd and mapping leaks in dmabuf feedback handlers * Destroy the default feedback proxy after initialization * Destroy the display registry after initialization * Make the registry a local variable * Unmap the format table with the proxy * Clear the feedback proxy pointer on destroy - Remove the unused queue parameter from wlEglSendDamageEvent libnvidia-egl-wayland-1.1.22-150700.3.12.1.src.rpm libnvidia-egl-wayland1-32bit-1.1.22-150700.3.12.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3983 Recommended update for libnvidia-egl-x11 moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for libnvidia-egl-x11 fixes the following issues: - Update to version 1.0.6: * Fix building on FreeBSD * Add some fixes for handling the attribute list in eglCreateWindow/PixmapSurface * Add a setting to tell egl-x11 to run on the normal NVIDIA Xorg driver. Requires DRI3 1.2 support, which was added in 595 and later drivers. * base: + Use an rwlock for the surface list + Use an rwlock for eglInitialize/eglTerminate + Add an explicit egl dependency + Add an optional hook for eglSwapInterval + Add basic support for EGL_KHR_partial_update + Add an EplImplFuncs function for EGL_BUFFER_AGE + Add an EplImplFuncs function for eglSetDamageRegionKHR + Replace EplImplFuncs::QueryBufferAge with QuerySurface + Fix eglSetDamageRegionKHR for non-postable surfaces + Fix eglSwapInterval to return correct error without current context * Replace eplGetCurrentDisplay with eplGetCurrentSurface * egl-wayland2: add FP16 DRM format * Update the X11 code to match the base library changes * x11: + Remove some unused function pointers + Implement EGL_BUFFER_AGE_KHR tracking for window surfaces * Poll for resize events in x11 SwapBuffers * Fix parameter validation libnvidia-egl-x11-1.0.6-150700.4.14.1.src.rpm libnvidia-egl-x11-devel-1.0.6-150700.4.14.1.x86_64.rpm libnvidia-egl-x111-1.0.6-150700.4.14.1.x86_64.rpm libnvidia-egl-x111-32bit-1.0.6-150700.4.14.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3984 Recommended update for libnvidia-egl-gbm moderate SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for libnvidia-egl-gbm fixes the following issues: - Update to version 1.1.3: * Add missing validation for EGL_NATIVE_RENDERABLE to eglChooseConfig. Fixes dEQP-EGL.functional.negative_api.* - Update to version 1.1.2.1: * egl-gbm: add FP16 DRM format libnvidia-egl-gbm-1.1.3-150700.3.3.1.src.rpm libnvidia-egl-gbm-devel-1.1.3-150700.3.3.1.x86_64.rpm libnvidia-egl-gbm1-1.1.3-150700.3.3.1.x86_64.rpm libnvidia-egl-gbm1-32bit-1.1.3-150700.3.3.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-4148 Security update for NetworkManager important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for NetworkManager fixes the following issues: - CVE-2026-10805: Local privilege escalation via malformed MUD URLs in dhclient backend (bsc#1267696). - CVE-2026-19685: missing user ownership checks for 802.1X directory properties can allow WPA-Enterprise server certificate validation bypass (bsc#1276764). NetworkManager-1.44.2-150600.3.10.1.src.rpm NetworkManager-1.44.2-150600.3.10.1.x86_64.rpm NetworkManager-wwan-1.44.2-150600.3.10.1.x86_64.rpm SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-4240 Security update for gvfs important SUSE Updates SLE-Module-Desktop-Applications 15-SP7 x86 64 This update for gvfs fixes the following issues: - CVE-2026-84267: `read_string()` allocates buffers withouth verifying that the buffer is completely filled when communicating with a malicious SFTP server, which can lead to uninitialized heap memory leaks (bsc#1278157). - CVE-2026-84268: `read_reply()` processes length that exceeds requested client size when communicating with a malicious SFTP server, which can lead to an OOB write (bsc#1278158). - CVE-2026-84269: DSI read path processes length that exceeds requested client size when communicating with a malicious AFP server, which can lead to an OOB memory access (bsc#1278159). - CVE-2026-84270: `do_read()` trusts the data length returned by a mounted MTP device and does not limit it to the original size requested by the client, which can lead to an OOB write (bsc#1278156). gvfs-1.52.2-150600.3.9.1.src.rpm gvfs-1.52.2-150600.3.9.1.x86_64.rpm gvfs-backend-afc-1.52.2-150600.3.9.1.x86_64.rpm gvfs-backend-samba-1.52.2-150600.3.9.1.x86_64.rpm gvfs-backends-1.52.2-150600.3.9.1.x86_64.rpm gvfs-devel-1.52.2-150600.3.9.1.noarch.rpm gvfs-fuse-1.52.2-150600.3.9.1.x86_64.rpm gvfs-lang-1.52.2-150600.3.9.1.noarch.rpm