Packages changed: MicroOS-release (20260912 -> 20260914) kbd (2.9.0 -> 2.10.0) kernel-source (7.2.4 -> 7.2.5) qt6-declarative zchunk (1.5.3 -> 1.5.4) === Details === ==== MicroOS-release ==== Version update (20260912 -> 20260914) Subpackages: MicroOS-release-appliance MicroOS-release-dvd - automatically generated by openSUSE-release-tools/pkglistgen ==== kbd ==== Version update (2.9.0 -> 2.10.0) Subpackages: libkbdfile1 libkeymap1 libkfont0 - Require xkeyboard-config to be able to load XKB based keymaps. Its data is required to compile these keymaps, and its %posttrans creates /var/lib/xkb/compiled in a way compatible with immutable updates. - Update to version 2.9.0 (boo#1268148): * keymaps: + Add Backtab keysym and update keymaps to use it for Shift+Tab. + Add keymap for Norwegian Apple ISO keyboard. + Adjust Swiss German keyboard mappings. * libkeymap: + Add API to validate keysyms. + Add XKB-aware symbol aliases through the normal synonym tables. + Fix compose table upload limit handling. * utils: + loadkeys: Add support for generating console keymaps from XKB. + loadkeys: Add XKB compose import support. + loadkeys: Add support for XKB group switching, modifier handling, virtual console switching and keypad/editing remaps. + loadkeys: Add diagnostics for XKB keysym coverage. + openvt: make -u process matching more conservative. + setfont: Add setfont --check that checks for setfont availability without logging errors (boo#1212970, obsoletes kbd-setfont-check.patch). * contrib: + Add an XKB keysym coverage diagnostic tool. + Add a VT layout indicator using keyboard LED lock triggers. - Refresh kbd-1.15.5-loadkeys-search-path.patch. - Enable compressed file loading introduced by the upstream in version 2.9.0. - Remove xz from BuildRequires, as it is not needed. ==== kernel-source ==== Version update (7.2.4 -> 7.2.5) - Update patches.kernel.org/7.2.1-001-PCI-host-generic-Fix-NULL-pointer-dereference-o.patch (bsc#1012628 CVE-2026-80917 bsc#1280009). - Update patches.kernel.org/7.2.1-002-Bluetooth-RFCOMM-take-rfcomm_mutex-for-the-defe.patch (bsc#1012628 CVE-2026-80819 bsc#1279607). - Update patches.kernel.org/7.2.1-003-iommu-tegra241-cmdqv-Fix-CMD_SYNC-use-after-fre.patch (bsc#1012628 CVE-2026-80818 bsc#1279695). - Update patches.kernel.org/7.2.1-004-iommu-iommufd-Fix-NULL-pointer-deref-in-iommufd.patch (bsc#1012628 CVE-2026-80817 bsc#1279465). - Update patches.kernel.org/7.2.1-005-ALSA-FCP-Use-a-private-URB-for-the-notification.patch (bsc#1012628 CVE-2026-80816 bsc#1279703). - Update patches.kernel.org/7.2.1-006-ALSA-scarlett2-Use-a-private-URB-for-the-notifi.patch (bsc#1012628 CVE-2026-80815 bsc#1279700). - Update patches.kernel.org/7.2.1-007-rndis_host-add-overflow-check-in-rndis_rx_fixup.patch (bsc#1012628 CVE-2026-80814 bsc#1279705). - Update patches.kernel.org/7.2.1-008-nvmet-fix-NULL-pointer-dereference-in-nvmet_exe.patch (bsc#1012628 CVE-2026-80813 bsc#1279537). - Update patches.kernel.org/7.2.1-009-futex-pi-Reject-cross-mm-private-futex-owners.patch (bsc#1012628 CVE-2026-80778 bsc#1279587). - Update patches.kernel.org/7.2.1-011-futex-pi-Plug-private-futex-exec-race.patch (bsc#1012628 CVE-2026-80777 bsc#1279586). - Update patches.kernel.org/7.2.1-012-futex-Avoid-private-hash-use-after-free-on-fina.patch (bsc#1012628 CVE-2026-80758 bsc#1279469). - Update patches.kernel.org/7.2.1-013-futex-Fix-race-on-the-initial-mm-futex.phash.re.patch (bsc#1012628 CVE-2026-80775 bsc#1279583). - Update patches.kernel.org/7.2.1-016-ALSA-dummy-Check-card-index-validity-at-probe.patch (bsc#1012628 CVE-2026-80812 bsc#1279777). - Update patches.kernel.org/7.2.1-017-io_uring-cmd-fix-iovec-leak-when-the-async-cmd-.patch (bsc#1012628 CVE-2026-80811 bsc#1279712). - Update patches.kernel.org/7.2.1-019-io_uring-rsrc-fix-folio-size-overflow-in-io_vec.patch (bsc#1012628 CVE-2026-80810 bsc#1279789). - Update patches.kernel.org/7.2.1-021-io_uring-defer-eventfd-signaling-when-queued-fr.patch (bsc#1012628 CVE-2026-80920 bsc#1279928). - Update patches.kernel.org/7.2.1-022-ocfs2-fix-missing-metadata-reservation-for-larg.patch (bsc#1012628 CVE-2026-80809 bsc#1279606). - Update patches.kernel.org/7.2.1-024-kcov-fix-data-corruption-and-race-conditions-on.patch (bsc#1012628 CVE-2026-80916 bsc#1279972). - Update patches.kernel.org/7.2.1-025-ext4-stop-retrying-saturated-xattr-cache-entrie.patch (bsc#1012628 CVE-2026-80808 bsc#1279795). - Update patches.kernel.org/7.2.1-026-nilfs2-reject-invalid-block-index-in-GC-ioctl.patch (bsc#1012628 CVE-2026-80807 bsc#1279591). - Update patches.kernel.org/7.2.1-030-ext4-don-t-enable-DAX-on-new-encrypted-files.patch (bsc#1012628 CVE-2026-80806 bsc#1279589). - Update patches.kernel.org/7.2.1-032-xfs-validate-attr-entry-pointer-before-field-ac.patch (bsc#1012628 CVE-2026-80805 bsc#1279580). - Update patches.kernel.org/7.2.1-033-xfs-restore-nofs-context-unconditionally-in-xfs.patch (bsc#1012628 CVE-2026-80804 bsc#1279579). - Update patches.kernel.org/7.2.1-034-nfc-digital-clamp-SENSF_RES-length-to-the-desti.patch (bsc#1012628 CVE-2026-80803 bsc#1279798). - Update patches.kernel.org/7.2.1-035-nfc-fdp-bound-the-device-reported-read-length-a.patch (bsc#1012628 CVE-2026-80802 bsc#1279814). - Update patches.kernel.org/7.2.1-036-nfc-microread-validate-target-discovery-payload.patch (bsc#1012628 CVE-2026-80801 bsc#1279815). - Update patches.kernel.org/7.2.1-037-nfc-llcp-bound-the-connect_sn-TLV-walk-to-the-s.patch (bsc#1012628 CVE-2026-80800 bsc#1279812). - Update patches.kernel.org/7.2.1-038-nfc-llcp-fix-OOB-read-and-u8-offset-wrap-in-TLV.patch (bsc#1012628 CVE-2026-80799 bsc#1279811). - Update patches.kernel.org/7.2.1-039-nfc-llcp-reject-PDUs-shorter-than-the-LLCP-head.patch (bsc#1012628 CVE-2026-80798 bsc#1279809). - Update patches.kernel.org/7.2.1-040-nfc-pn533-purge-fragmented-skbs-during-cleanup.patch (bsc#1012628 CVE-2026-80797 bsc#1279808). - Update patches.kernel.org/7.2.1-041-nfc-st21nfca-validate-ATR_REQ-length-against-th.patch (bsc#1012628 CVE-2026-80823 bsc#1279608). - Update patches.kernel.org/7.2.1-042-nfc-nci-add-data_len-bound-checks-to-activation.patch (bsc#1012628 CVE-2026-80796 bsc#1279807). - Update patches.kernel.org/7.2.1-043-nfc-nci-fix-out-of-bounds-write-in-nci_target_a.patch (bsc#1012628 CVE-2026-80795 bsc#1279805). ... changelog too long, skipping 1291 lines ... - commit e841c45 ==== qt6-declarative ==== Subpackages: libQt6LabsAnimation6 libQt6LabsFolderListModel6 libQt6LabsPlatform6 libQt6LabsQmlModels6 libQt6LabsSettings6 libQt6LabsSharedImage6 libQt6LabsStyleKit6 libQt6LabsSynchronizer6 libQt6LabsWavefrontMesh6 libQt6Qml6 libQt6QmlCore6 libQt6QmlLocalStorage6 libQt6QmlMeta6 libQt6QmlModels6 libQt6QmlNetwork6 libQt6QmlWorkerScript6 libQt6QmlXmlListModel6 libQt6Quick6 libQt6QuickControls2-6 libQt6QuickControls2Impl6 libQt6QuickDialogs2-6 libQt6QuickDialogs2QuickImpl6 libQt6QuickDialogs2Utils6 libQt6QuickEffects6 libQt6QuickLayouts6 libQt6QuickParticles6 libQt6QuickShapes6 libQt6QuickTemplates2-6 libQt6QuickTest6 libQt6QuickVectorImage6 libQt6QuickWidgets6 qt6-declarative-imports - Add upstream change (kde#508377) * 0001-QML-engine-Correctly-compare-composites-when-multipl.patch ==== zchunk ==== Version update (1.5.3 -> 1.5.4) - update to 1.5.4: * memory leak and use-after-free fixes in compression, download range, header and index handling * raise meson BuildRequires floor to 0.54.0 per upstream - drop Group: tags, modernize suse_version conditional (spec-cleaner)