azure-cli-core
- Refresh CVE-2025-24049.patch
azure-cli
- Add azure-storage-azcopy to Recommends (bsc#1245160, jsc#PED-13198)

- Drop CVE-2024-43591.patch, fixed upstream
- Fix testsuite evaluation logic
bind
- ensure file descriptors 0-2 are in use before using libuv (bsc#1230649)
  * bind-ensure-file-descriptors-0-2-are-in-use-before-using-.patch
boost
- CVE-2016-9840: fixed out-of-bounds pointer arithmetic in zlib in beast
  (bsc#1245936)
  - adds patch boost-zlib.patch
cloud-regionsrv-client
- Update version to 10.5.2 (bsc#1247539)
  + When an instance fails verification server side the default credentials
    were left behind requireing manual intervantion prior to the next
    registration attempt.
  + Fix issue triggered when using instance-billing-flavor-check due to
    IP address handling as object rather than string introduced 10.5.0

- Update version to 10.5.1
  + Fix issue with picking up configured server names from the
    regionsrv config file. Previously only IP addresses were collected
  + Update scriptlet for package uninstall to avoid issues in the
    build service

- Update version to 10.5.0
  + Use region server IP addresses to determine Internet access rather
    than a generic address. Region server IP addresses may not be blocked
    in the network construct. (bsc#1245305)
coreutils
- coreutils-9.7-sort-CVE-2025-5278.patch: Add upstream patch:
  sort with key character offsets of SIZE_MAX, could induce
  a read of 1 byte before an allocated heap buffer.
  (CVE-2025-5278, bsc#1243767)
crypto-policies
- Update the BSI policy [jsc#PED-12880]
  * BSI: switch to 3072 minimum RSA key size [322f0ba4]
  * BSI: Update BSI policy for new 2024 minimum [64b9dddd]
  * Add patches:
  - crypto-policies-BSI-Update-BSI-policy-for-new-2024-minimum-recommend.patch
  - crypto-policies-BSI-switch-to-3072-minimum-RSA-key-size.patch
curl
- tool_operate: fix return code when --retry is used but not
  triggered [bsc#1249367]
  * Add curl-tool_operate-fix-return-code-when-retry-is-used.patch

- Security fixes:
  * [bsc#1249191, CVE-2025-9086] Out of bounds read for cookie path
  * [bsc#1249348, CVE-2025-10148] Predictable WebSocket mask
  * Add patches:
  - curl-CVE-2025-9086.patch
  - curl-CVE-2025-10148.patch

- Fix the --ftp-pasv option in curl v8.14.1 [bsc#1246197]
  * tool_getparam: fix --ftp-pasv [5f805ee]
  * Add curl-fix--ftp-pasv.patch

- Update to 8.14.1: [jsc#PED-13055, jsc#PED-13056]
  * Add _multibuild
  * Remove patches fixed in the update:
  - curl-CVE-2024-11053.patch
  - curl-CVE-2024-2004.patch
  - curl-CVE-2024-2379.patch
  - curl-CVE-2024-2398.patch
  - curl-CVE-2024-2466.patch
  - curl-CVE-2024-6197.patch
  - curl-CVE-2024-7264.patch
  - curl-CVE-2024-8096.patch
  - curl-CVE-2024-9681.patch
  - curl-CVE-2025-0167.patch
  - curl-CVE-2025-0725.patch
  - curl-aws_sigv4-url-encode-the-canonical-path.patch
  - curl-mstp-starttls.patch

- Sync spec file with SLE codestreams: [jsc#PED-13055, jsc#PED-13056]
  * Add curl-mini.rpmlintrc to avoid rpmlint shlib-policy-name-error
    when building the curl-mini package in SLE.
  * Add libssh minimum version requirements.
  * Use ldconfig_scriptlets when available.
  * Remove unused option --disable-ntlm-wb.

- Update to 8.14.1:
  * Security fixes:
  - [bsc#1243933, CVE-2025-5399] libcurl can possibly get
    trapped in an endless busy-loop when processing specially
    crafted packets [d1145df2]
  * Bugfixes:
  - asyn-thrdd: fix cleanup when RR fails due to OOM
  - ftp: fix teardown of DATA connection in done
  - http: fail early when rewind of input failed when following redirects
  - multi: fix add_handle resizing
  - tls BIOs: handle BIO_CTRL_EOF correctly
  - tool_getparam: make --no-anyauth not be accepted
  - wolfssl: fix sending of early data
  - ws: handle blocked sends better
  - ws: tests and fixes

- Update to 8.14.0:
  * Security fixes:
  - [CVE-2025-4947, bsc#1243397] QUIC certificate check skip with wolfSSL
  - [CVE-2025-5025, bsc#1243706] No QUIC certificate pinning with wolfSSL
  * Changes:
  - mqtt: send ping at upkeep interval
  - schannel: handle pkcs12 client certificates containing CA certificates
  - TLS: add CURLOPT_SSL_SIGNATURE_ALGORITHMS and --sigalgs
  - vquic: ngtcp2 + openssl support
  - wcurl: import v2025.04.20 script + docs
  - websocket: add option to disable auto-pong reply
  * Bugfixes:
  - asny-thrdd: fix detach from running thread
  - async-threaded resolver: use ref counter
  - async: DoH improvements
  - build: enable gcc-12/13+, clang-10+ picky warnings
  - build: enable gcc-15 picky warnings
  - certs: drop unused `default_bits` from `.prm` files
  - cf-https-connect: use the passed in dns struct pointer
  - cf-socket: fix FTP accept connect
  - cfilters: remove assert
  - cmake: fix nghttp3 static linking with `USE_OPENSSL_QUIC=ON`
  - cmake: prefer `COMPILE_OPTIONS` over `CMAKE_C_FLAGS` for custom C options
  - cmake: revert `CURL_LTO` behavior for multi-config generators
  - configure: fix --disable-rt
  - CONTRIBUTE: add project guidelines for AI use
  - cpool/cshutdown: force close connections under pressure
  - curl: fix memory leak when -h is used in config file
  - curl_get_line: handle lines ending on the buffer boundary
  - headers: enforce a max number of response header to accept
  - http: fix HTTP/2 handling of TE request header using "trailers"
  - lib: include files using known path
  - lib: unify conversions to/from hex
  - libssh: add NULL check for Curl_meta_get()
  - libssh: fix memory leak
  - mqtt: use conn/easy meta hash
  - multi: do transfer book keeping using mid
  - multi: init_do(): check result
  - netrc: avoid NULL deref on weird input
  - netrc: avoid strdup NULL
  - netrc: deal with null token better
  - openssl-quic: avoid potential `-Wnull-dereference`, add assert
  - openssl-quic: fix shutdown when stream not open
  - openssl: enable builds for *both* engines and providers
  - openssl: set the cipher string before doing private cert
  - progress: avoid integer overflow when gathering total transfer size
  - rand: update comment on Curl_rand_bytes weak random
  - rustls: make max size of cert and key reasonable
  - smb: avoid integer overflow on weird input date
  - urlapi: redirecting to "" is considered fine
  * Remove curl-8.13.0-CloseSocket.patch upstream
  * Rebase libcurl-ocloexec.patch

- fix Leap build add curl-8.13.0-CloseSocket.patch

- Update to 8.13.0:
  * Changes:
  - curl: add write-out variable 'tls_earlydata'
  - curl: make --url support a file with URLs
  - gnutls: set priority via --ciphers
  - IMAP: add CURLOPT_UPLOAD_FLAGS and --upload-flags
  - lib: add CURLFOLLOW_OBEYCODE and CURLFOLLOW_FIRSTONLY
  - OpenSSL/quictls: add support for TLSv1.3 early data
  - rustls: add support for CERTINFO
  - rustls: add support for SSLKEYLOGFILE
  - rustls: support ECH w/ DoH lookup for config
  - rustls: support native platform verifier
  - var: add a '64dec' function that can base64 decode a string
  * Bugfixes:
  - conn: fix connection reuse when SSL is optional
  - hash: use single linked list for entries
  - http2: detect session being closed on ingress handling
  - http2: reset stream on response header error
  - http: remove a HTTP method size restriction
  - http: version negotiation
  - httpsrr: fix port detection
  - libssh: fix freeing of resources in disconnect
  - libssh: fix scp large file upload for 32-bit size_t systems
  - openssl-quic: do not iterate over multi handles
  - openssl: check return value of X509_get0_pubkey
  - openssl: drop support for old OpenSSL/LibreSSL versions
  - openssl: fix crash on missing cert password
  - openssl: fix pkcs11 URI checking for key files.
  - openssl: remove bad `goto`s into other scope
  - setopt: illegal CURLOPT_SOCKS5_AUTH should return error
  - setopt: setting PROXYUSERPWD after PROXYUSERNAME/PASSWORD is fine
  - sshserver.pl: adjust `AuthorizedKeysFile2` cutoff version
  - sshserver: fix excluding obsolete client config lines
  - SSLCERTS: list support for SSL_CERT_FILE and SSL_CERT_DIR
  - tftpd: prefix TFTP protocol error `E*` constants with `TFTP_`
  - tool_operate: fail SSH transfers without server auth
  - url: call protocol handler's disconnect in Curl_conn_free
  - urlapi: remove percent encoded dot sequences from the URL path
  - urldata: remove 'hostname' from struct Curl_async
  * Rebase patches:
  - libcurl-ocloexec.patch
  - curl-secure-getenv.patch

- Update to 8.12.1:
  * Bugfixes:
  - asyn-thread: fix build with 'CURL_DISABLE_SOCKETPAIR'
  - asyn-thread: fix HTTPS RR crash
  - asyn-thread: fix the returned bitmask from Curl_resolver_getsock
  - asyn-thread: survive a c-ares channel set to NULL
  - cmake: always reference OpenSSL and ZLIB via imported targets
  - cmake: respect 'GNUTLS_CFLAGS' when detected via 'pkg-config'
  - cmake: respect 'GNUTLS_LIBRARY_DIRS' in 'libcurl.pc' and 'curl-config'
  - content_encoding: #error on too old zlib
  - imap: TLS upgrade fix
  - ldap: drop support for legacy Novell LDAP SDK
  - libssh2: comparison is always true because rc <= -1
  - libssh2: raise lowest supported version to 1.2.8
  - libssh: drop support for libssh older than 0.9.0
  - openssl-quic: ignore ciphers for h3
  - pop3: TLS upgrade fix
  - runtests: fix the disabling of the memory tracking
  - runtests: quote commands to support paths with spaces
  - scache: add magic checks
  - smb: silence '-Warray-bounds' with gcc 13+
  - smtp: TLS upgrade fix
  - tool_cfgable: sort struct fields by size, use bitfields for booleans
  - tool_getparam: add "TLS required" flag for each such option
  - vtls: fix multissl-init
  - wakeup_write: make sure the eventfd write sends eight bytes

- Update to 8.12.0:
  * Security fixes:
  - [bsc#1234068, CVE-2024-11053] curl could leak the password used
    for the first host to the followed-to host under certain circumstances.
  - [bsc#1232528, CVE-2024-9681] HSTS subdomain overwrites parent cache entry
  - [bsc#1236589, CVE-2025-0665] eventfd double close
  * Changes:
  - curl: add byte range support to --variable reading from file
  - curl: make --etag-save acknowledge --create-dirs
  - getinfo: fix CURLINFO_QUEUE_TIME_T and add 'time_queue' var
  - getinfo: provide info which auth was used for HTTP and proxy
  - hyper: drop support
  - openssl: add support to use keys and certificates from PKCS#11 provider
  - QUIC: 0RTT for gnutls via CURLSSLOPT_EARLYDATA
  - vtls: feature ssls-export for SSL session im-/export
  * Bugfixes:
  - altsvc: avoid integer overflow in expire calculation
  - asyn-ares: acknowledge CURLOPT_DNS_SERVERS set to NULL
  - asyn-ares: fix memory leak
  - asyn-ares: initial HTTPS resolve support
  - asyn-thread: use c-ares to resolve HTTPS RR
  - async-thread: avoid closing eventfd twice
  - cd2nroff: do not insist on quoted <> within backticks
  - cd2nroff: support "none" as a TLS backend
  - conncache: count shutdowns against host and max limits
  - content_encoding: drop support for zlib before 1.2.0.4
  - content_encoding: namespace GZIP flag constants
  - content_encoding: put the decomp buffers into the writer structs
  - content_encoding: support use of custom libzstd memory functions
  - cookie: cap expire times to 400 days
  - cookie: parse only the exact expire date
  - curl: return error if etag options are used with multiple URLs
  - curl_multi_fdset: include the shutdown connections in the set
  - curl_sha512_256: rename symbols to the curl namespace
  - curl_url_set.md: adjust the added-in to 7.62.0
  - doh: send HTTPS RR requests for all HTTP(S) transfers
  - easy: allow connect-only handle reuse with easy_perform
  - easy: make curl_easy_perform() return error if connection still there
  - easy_lock: use Sleep(1) for thread yield on old Windows
  - ECH: update APIs to those agreed with OpenSSL maintainers
  - GnuTLS: fix 'time_appconnect' for early data
  - HTTP/2: strip TE request header
  - http2: fix data_pending check
  - http2: fix value stored to 'result' is never read
  - http: ignore invalid Retry-After times
  - http_aws_sigv4: Fix invalid compare function handling zero-length pairs
  - https-connect: start next immediately on failure
  - lib: redirect handling by protocol handler
  - multi: fix curl_multi_waitfds reporting of fd_count
  - netrc: 'default' with no credentials is not a match
  - netrc: fix password-only entries
  - netrc: restore _netrc fallback logic
  - ngtcp2: fix memory leak on connect failure
  - openssl: define `HAVE_KEYLOG_CALLBACK` before use
  - openssl: fix ECH logic
  - osslq: use SSL_poll to determine writeability of QUIC streams
  - sectransp: free certificate on error
  - select: avoid a NULL deref in cwfds_add_sock
  - src: omit hugehelp and ca-embed from libcurltool
  - ssl session cache: change cache dimensions
  - system.h: add 64-bit curl_off_t definitions for NonStop
  - telnet: handle single-byte input option
  - TLS: check connection for SSL use, not handler
  - tool_formparse.c: make curlx_uztoso a static in here
  - tool_formparse: accept digits in --form type= strings
  - tool_getparam: ECH param parsing refix
  - tool_getparam: fail --hostpubsha256 if libssh2 is not used
  - tool_getparam: fix "Ignored Return Value"
  - tool_getparam: fix memory leak on error in parse_ech
  - tool_getparam: fix the ECH parser
  - tool_operate: make --etag-compare always accept a non-existing file
  - transfer: fix CURLOPT_CURLU override logic
  - urlapi: fix redirect to a new fragment or query (only)
  - vquic: make vquic_send_packets not return without setting psent
  - vtls: fix default SSL backend as a fallback
  - vtls: only remember the expiry timestamp in session cache
  - websocket: fix message send corruption
  - x509asn1: add parse recursion limit
  * Rebase pathes:
  - libcurl-ocloexec.patch
  - dont-mess-with-rpmoptflags.patch
cyrus-sasl
- Add Channel Binding support for GSSAPI/GSS-SPNEGO; (bsc#1229655);
  (jsc#PED-12097); Add patch
  0009-Add-Channel-Binding-support-for-GSSAPI-GSS-SPNEGO.patch
- Add support for setting max ssf 0 to GSS-SPNEGO; (bsc#1229655);
  (jsc#PED-12097); Add patch
  0010-Add-support-for-setting-max-ssf-0-to-GSS-SPNEGO.patch
docker
- Update to Docker 28.3.3-ce. See upstream changelog online at
  <https://docs.docker.com/engine/release-notes/28/#2833>
  CVE-2025-54388 bsc#1247367

- Update to docker-buildx v0.26.1. Upstream changelog:
  <https://github.com/docker/buildx/releases/tag/v0.26.1>

- Update to docker-buildx v0.26.0. Upstream changelog:
  <https://github.com/docker/buildx/releases/tag/v0.26.0>

- Update to Go 1.24 for builds, to match upstream.

- Update to Docker 28.3.2-ce. See upstream changelog online at
  <https://docs.docker.com/engine/release-notes/28/#2832>

- Update to Docker 28.3.1-ce. See upstream changelog online at
  <https://docs.docker.com/engine/release-notes/28/#2831>

- Update to Docker 28.3.0-ce. See upstream changelog online at
  <https://docs.docker.com/engine/release-notes/28/#2830>
  bsc#1246556
- Rebase patches:
  * 0001-SECRETS-SUSE-always-clear-our-internal-secrets.patch
  * 0002-SECRETS-daemon-allow-directory-creation-in-run-secre.patch
  * 0003-SECRETS-SUSE-implement-SUSE-container-secrets.patch
  * 0004-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch
  * 0005-bsc1073877-apparmor-clobber-docker-default-profile-o.patch
  * 0006-SLE12-revert-apparmor-remove-version-conditionals-fr.patch

[ This update is a no-op, only needed to work around unfortunate automated
  packaging script behaviour on SLES. ]
- The following patches were removed in openSUSE in the Docker 28.1.1-ce
  update, but the patch names were later renamed in a SLES-only update before
  Docker 28.1.1-ce was submitted to SLES.
  This causes the SLES build scripts to refuse the update because the patches
  are not referenced in the changelog. There is no obvious place to put the
  patch removals (the 28.1.1-ce update removing the patches chronologically
  predates their renaming in SLES), so they are included here a dummy changelog
  entry to work around the issue.
  - 0007-CVE-2025-22868-vendor-jws-split-token-into-fixed-num.patch
  - 0008-CVE-2025-22869-vendor-ssh-limit-the-size-of-the-inte.patch

- Update to docker-buildx v0.25.0. Upstream changelog:
  <https://github.com/docker/buildx/releases/tag/v0.25.0>

- Do not try to inject SUSEConnect secrets when in Rootless Docker mode, as
  Docker does not have permission to access the host zypper credentials in this
  mode (and unprivileged users cannot disable the feature using
  /etc/docker/suse-secrets-enable.) bsc#1240150
  * 0003-SECRETS-SUSE-implement-SUSE-container-secrets.patch
- Rebase patches:
  * 0001-SECRETS-SUSE-always-clear-our-internal-secrets.patch
  * 0002-SECRETS-daemon-allow-directory-creation-in-run-secre.patch
  * 0004-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch
  * 0005-bsc1073877-apparmor-clobber-docker-default-profile-o.patch
  * 0006-SLE12-revert-apparmor-remove-version-conditionals-fr.patch

- Always clear SUSEConnect suse_* secrets when starting containers regardless
  of whether the daemon was built with SUSEConnect support. Not doing this
  causes containers from SUSEConnect-enabled daemons to fail to start when
  running with SUSEConnect-disabled (i.e. upstream) daemons.
  This was a long-standing issue with our secrets support but until recently
  this would've required migrating from SLE packages to openSUSE packages
  (which wasn't supported). However, as SLE Micro 6.x and SLES 16 will move
  away from in-built SUSEConnect support, this is now a practical issue users
  will run into. bsc#1244035
  + 0001-SECRETS-SUSE-always-clear-our-internal-secrets.patch
- Rearrange patches:
  - 0001-SECRETS-daemon-allow-directory-creation-in-run-secre.patch
  + 0002-SECRETS-daemon-allow-directory-creation-in-run-secre.patch
  - 0002-SECRETS-SUSE-implement-SUSE-container-secrets.patch
  + 0003-SECRETS-SUSE-implement-SUSE-container-secrets.patch
  - 0003-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch
  + 0004-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch
  - 0004-bsc1073877-apparmor-clobber-docker-default-profile-o.patch
  + 0005-bsc1073877-apparmor-clobber-docker-default-profile-o.patch
  - 0005-SLE12-revert-apparmor-remove-version-conditionals-fr.patch
  + 0006-SLE12-revert-apparmor-remove-version-conditionals-fr.patch

[NOTE: This update was only ever released in SLES and Leap.]
- Always clear SUSEConnect suse_* secrets when starting containers regardless
  of whether the daemon was built with SUSEConnect support. Not doing this
  causes containers from SUSEConnect-enabled daemons to fail to start when
  running with SUSEConnect-disabled (i.e. upstream) daemons.
  This was a long-standing issue with our secrets support but until recently
  this would've required migrating from SLE packages to openSUSE packages
  (which wasn't supported). However, as SLE Micro 6.x and SLES 16 will move
  away from in-built SUSEConnect support, this is now a practical issue users
  will run into. bsc#1244035
  + 0001-SECRETS-SUSE-always-clear-our-internal-secrets.patch
- Rearrange patches:
  - 0001-SECRETS-daemon-allow-directory-creation-in-run-secre.patch
  + 0002-SECRETS-daemon-allow-directory-creation-in-run-secre.patch
  - 0002-SECRETS-SUSE-implement-SUSE-container-secrets.patch
  + 0003-SECRETS-SUSE-implement-SUSE-container-secrets.patch
  - 0003-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch
  + 0004-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch
  - 0004-bsc1073877-apparmor-clobber-docker-default-profile-o.patch
  + 0005-bsc1073877-apparmor-clobber-docker-default-profile-o.patch
  - 0005-SLE12-revert-apparmor-remove-version-conditionals-fr.patch
  + 0006-SLE12-revert-apparmor-remove-version-conditionals-fr.patch
  - 0006-CVE-2025-22868-vendor-jws-split-token-into-fixed-num.patch
  + 0007-CVE-2025-22868-vendor-jws-split-token-into-fixed-num.patch
  - 0007-CVE-2025-22869-vendor-ssh-limit-the-size-of-the-inte.patch
  + 0008-CVE-2025-22869-vendor-ssh-limit-the-size-of-the-inte.patch

- Update to Docker 28.2.2-ce. See upstream changelog online at
  <https://docs.docker.com/engine/release-notes/28/#2822>
- Rebase patches:
  * 0001-SECRETS-daemon-allow-directory-creation-in-run-secre.patch
  * 0002-SECRETS-SUSE-implement-SUSE-container-secrets.patch
  * 0003-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch
  * 0004-bsc1073877-apparmor-clobber-docker-default-profile-o.patch
  * 0005-SLE12-revert-apparmor-remove-version-conditionals-fr.patch

- Update to Docker 28.2.1-ce. See upstream changelog online at
  <https://docs.docker.com/engine/release-notes/28/#2820> bsc#1243833
  <https://github.com/moby/moby/releases/tag/v28.2.1>
- Rebase patches:
  * 0001-SECRETS-daemon-allow-directory-creation-in-run-secre.patch
  * 0002-SECRETS-SUSE-implement-SUSE-container-secrets.patch
  * 0003-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch
  * 0004-bsc1073877-apparmor-clobber-docker-default-profile-o.patch
  * 0005-SLE12-revert-apparmor-remove-version-conditionals-fr.patch

- Update to docker-buildx v0.24.0. Upstream changelog:
  <https://github.com/docker/buildx/releases/tag/v0.24.0>

- Update to Docker 28.1.1-ce. See upstream changelog online at
  <https://docs.docker.com/engine/release-notes/28/#2811> bsc#1242114
  Includes upstream fixes:
  - CVE-2025-22872 bsc#1241830
- Remove long-outdated build handling for deprecated and unsupported
  devicemapper and AUFS storage drivers. AUFS was removed in v24, and
  devicemapper was removed in v25.
  <https://docs.docker.com/engine/deprecated/#aufs-storage-driver>
- Rebase patches:
  * 0001-SECRETS-daemon-allow-directory-creation-in-run-secre.patch
  * 0002-SECRETS-SUSE-implement-SUSE-container-secrets.patch
  * 0003-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch
  * 0004-bsc1073877-apparmor-clobber-docker-default-profile-o.patch
  * 0005-SLE12-revert-apparmor-remove-version-conditionals-fr.patch
- Remove upstreamed patches:
  - 0006-CVE-2025-22868-vendor-jws-split-token-into-fixed-num.patch
  - 0007-CVE-2025-22869-vendor-ssh-limit-the-size-of-the-inte.patch
  - cli-0001-docs-include-required-tools-in-source-tree.patch

- Update to docker-buildx v0.23.0. Upstream changelog:
  <https://github.com/docker/buildx/releases/tag/v0.23.0>

- Update to docker-buildx v0.22.0. Upstream changelog:
  <https://github.com/docker/buildx/releases/tag/v0.22.0>
  * Includes fixes for CVE-2025-0495. bsc#1239765

- Disable transparent SUSEConnect support for SLE-16. PED-12534
  When this patchset was first added in 2013 (and rewritten over the years),
  there was no upstream way to easily provide SLE customers with a way to build
  container images based on SLE using the host subscription. However, with
  docker-buildx you can now define secrets for builds (this is not entirely
  transparent, but we can easily document this new requirement for SLE-16).
  Users should use
    RUN --mount=type=secret,id=SCCcredentials zypper -n ...
  in their Dockerfiles, and
    docker buildx build --secret id=SCCcredentials,src=/etc/zypp/credentials.d/SCCcredentials,type=file .
  when doing their builds.
- Now that the only blocker for docker-buildx support was removed for SLE-16,
  enable docker-buildx for SLE-16 as well. PED-8905
dracut
- Update to version 059+suse.562.geca59f6b:
  * fix(dracut-util): crash if CMDLINE ends with quotation mark (bsc#1247819)
  * fix(rngd): adjust license to match the license of the whole project
  * fix(nfs): set correct ownership of rpc.statd state directories (bsc#1217885)
  * perf(nfs): remove references to old rpcbind state dir
  * fix(nfs): libnfsidmap plugins not added in some distributions
glibc
- regcomp-double-free.patch: posix: Fix double-free after allocation
  failure in regcomp (CVE-2025-8058, bsc#1246965, BZ #33185)

- nscd-gethst-race.patch: Reduce chance of crash when using nscd GETFDHST
  (bsc#1240058)
grub2
- Fix boot hangs in setting up serial console when ACPI SPCR table is present
  and redirection is disabled (bsc#1249088)
  * 0001-term-ns8250-spcr-Return-if-redirection-is-disabled.patch

- Skip mount point in grub_find_device function (bsc#1246231)
  * 0001-getroot-Skip-mount-points-in-grub_find_device.patch

- Fix CVE-2024-56738: side-channel attack due to not constant-time
  algorithm in grub_crypto_memcmp (bsc#1234959)
  * grub2-constant-time-grub_crypto_memcmp.patch

- Fix test -f and -s do not work properly over the network files served via
  tftp and http (bsc#1246157) (bsc#1246237)
  * 0001-test-Fix-f-test-on-files-over-network.patch
  * 0002-http-Return-HTTP-status-code-in-http_establish.patch
  * 0003-docs-Clarify-test-for-files-on-TFTP-and-HTTP.patch
  * 0004-tftp-Fix-hang-when-file-is-a-directory.patch
hwinfo
- merge gh#openSUSE/hwinfo#168
- fix usb network card detection (bsc#1245950)
- 21.89
hyper-v
- fcopy: Fix irregularities with size of ring buffer (a4131a50)
- fcopy: Fix incorrect file path conversion (0d86a8d6)

- Enable debug logs for hv_kvp_daemon (a9c0b33e) (bsc#1244154)

- update route parsing in kvp daemon (9bbb8a07)
- reduce resource usage in hv_kvp_daemon (175c71c2)
- reduce resouce usage in hv_get_dns_info helper (a4d024fe)
- hv_kvp_daemon: Pass NIC name to hv_get_dns_info as well (07dfa6e8)
- terminate fcopy daemon if read from uio fails (a9640fcd)
- change permissions of NetworkManager configuration file (91ae69c7)
- Fix a complier warning in the fcopy uio daemon (cb1b78f1)
- remove obsolete kvptest.ps1.txt which failed since a decade
- remove obsolete rpm postinstall code for SLE11SP2

- Add memory allocation check in hv_fcopy_start (94e86b17)
- suppress the invalid warning for packed member alignment (207e03b0)
- Add new fcopy application based on uio driver (82b0945c)
- Add vmbus_bufring (45bab4d7)
- kvp: Handle IPv4 and Ipv6 combination for keyfile format (f971f6dd)
- kvp: Some small fixes for handling NM keyfiles (c3803203)
- kvp: Support for keyfile based connection profile (42999c90)
- kvp: remove unnecessary (void*) conversions (22589542)
- Remove an extraneous "the" (f15f39fa)
- change http to https in hv_kvp_daemon.c (fa52a4b2)
- replace the copy of include/linux/hyperv.h with include/uapi/linux/hyperv.h (6de74d10)
- merge individual udev rules files into a single rules file
- package only files, not directories already owned by filesystem.rpm
- remove braces from rpm spec macros
- remove obsolete Group tag
- replace RPM_BUILD_ROOT with buildroot
- use a meaningful name for the UAPI include file
- use a meaningful variable name for ifcfg in hv_set_ifconfig.sh

- remove dependency on /usr/bin/python3 using
  %python3_fix_shebang macro, [bsc#1212476]

- Use %patch -P N instead of deprecated %patchN.
iproute2
- add post-6.4 follow-up fixes (bsc#1243005)
  * patches/bond-fix-stack-smash-in-xstats.patch
  * patches/tc-gred-fix-debug-print.patch

- sync UAPI header copies with SLE15-SP6 kernel
  * sync-UAPI-header-copies-with-SLE15-SP6.patch
- drop Update-kernel-headers.patch
  (no longer needed with full UAPI sync)

- devlink: support ipsec_crypto and ipsec_packet cap (bsc#1248660)
  * add Update-kernel-headers.patch
  * add devlink-Support-setting-port-function-ipsec_crypto-c.patch
  * add devlink-Support-setting-port-function-ipsec_packet-c.patch
  * refresh ss-Tone-down-cgroup-path-resolution.patch

- add post-6.4 follow-up fix (bsc#1243005)
  * ss-show-extra-info-when-processes-is-not-used.patch

- add post-6.4 follow-up fixes (bsc#1243005):
  * bpf-fix-warning-from-basename.patch
  * bridge-fdb-add-an-error-print-for-unknown-command.patch
  * bridge-vni-Accept-del-command.patch
  * bridge-vni-Fix-duplicate-group-and-remote-error-mess.patch
  * bridge-vni-Fix-vni-filter-help-strings.patch
  * bridge-vni-Remove-dead-code-in-group-argument-parsin.patch
  * bridge-vni-Report-duplicate-vni-argument-using-dupar.patch
  * f_flower-Treat-port-0-as-valid.patch
  * genl-ctrl.c-spelling-fix-in-error-message.patch
  * ip-Add-missing-echo-option-to-usage.patch
  * ip-Add-missing-stats-command-to-usage.patch
  * ip-ipmroute-use-preferred_family-to-get-prefix.patch
  * ip-remove-non-existent-amt-subcommand-from-usage.patch
  * iplink-fix-fd-leak-when-playing-with-netns.patch
  * iplink_bridge-fix-incorrect-root-id-dump.patch
  * iplink_xstats-spelling-fix-in-error-message.patch
  * iproute2-fix-type-incompatibility-in-ifstat.c.patch
  * iproute2-prevent-memory-leak.patch
  * libnetlink-validate-nlmsg-header-length-first.patch
  * man-devlink-resource-add-missing-words-in-the-exampl.patch
  * mnl_utils-sanitize-incoming-netlink-payload-size-in-.patch
  * rdma-Fix-help-information-of-rdma-resource.patch
  * rdma-Fix-the-error-of-accessing-string-variable-outs.patch
  * rdma-use-print_XXX-instead-of-COLOR_NONE.patch
  * ss-Fix-socket-type-check-in-packet_show_line.patch
  * ss-fix-directory-leak-when-T-option-is-used.patch
  * ss-mptcp-display-info-counters-as-unsigned.patch
  * ss-prevent-Process-column-from-being-printed-unless-.patch
  * tc-taprio-don-t-print-netlink-attributes-which-weren.patch
  * tc-taprio-fix-JSON-output-when-TCA_TAPRIO_ATTR_ADMIN.patch
  * tc-taprio-fix-parsing-of-fp-option-when-it-doesn-t-a.patch
  * vdpa-consume-device_features-parameter.patch
- add to blacklist:
  * af0ea2cd0b9e (duplicate of 92eac7e4bf14)
- refresh:
  * ss-Add-support-for-dumping-TCP-bound-inactive-socket.patch
  * add-explicit-typecast-to-avoid-gcc-warning.patch
  * use-sysconf-_SC_CLK_TCK-if-HZ-undefined.patch
iputils
- Security fix [bsc#1243772, CVE-2025-48964]
  * Fix  integer overflow in ping statistics via zero timestamp
  * Add iputils-CVE-2025-48964_01.patch
  * Add iputils-CVE-2025-48964_02.patch
  * Add iputils-CVE-2025-48964_03.patch
  * Add iputils-CVE-2025-48964_04.patch
  * Add iputils-CVE-2025-48964_regression.patch
kernel-azure
- sunrpc: fix handling of server side tls alerts (git-fixes).
- commit 40fb7b3

- cifs: Fix buffer overflow when parsing NFS reparse points
  (CVE-2024-49996 bsc#1232089).
- commit 50adb2e

- smb: client: fix parsing of device numbers (git-fixes).
- commit 45992a6

- smb3: move server check earlier when setting channel sequence
  number (git-fixes).
- commit df2adca

- ring-buffer: Do not allow events in NMI with generic atomic64
  cmpxchg() (git-fixes).
- commit 890fc59

- module: Restore the moduleparam prefix length check (git-fixes).
- commit ad2fc48

- module: Remove unnecessary +1 from last_unloaded_module::name
  size (git-fixes).
- commit 3efc8ab

- audit,module: restore audit logging in load failure case
  (git-fixes).
- kABI: Fix the module::name type in audit_context (git-fixes).
- commit 7e23359

- module: Fix memory deallocation on error path in move_module()
  (git-fixes).
- commit bb37d39

- SMB3: rename macro CIFS_SERVER_IS_CHAN to avoid confusion
  (git-fixes).
- Refresh
  patches.suse/smb-client-fix-use-after-free-of-signing-key.patch.
- commit ee8ada8

- smb: client: fix potential deadlock when reconnecting channels
  (bsc#1246183, CVE-2025-38244).
- commit fcf601a

- cifs: reconnect helper should set reconnect for the right
  channel (git-fixes).
- commit ae3173e

- [SMB3] send channel sequence number in SMB3 requests after
  reconnects (git-fixes).
- commit baa81e9

- net: mana: Add debug logs in MANA network driver (bsc#1246212).
- Refresh
  patches.suse/msft-hv-3280-net-mana-Add-support-for-Multi-Vports-on-Bare-metal.patch.
- commit 1b4ad82

- netlink: avoid infinite retry looping in netlink_unicast()
  (CVE-2025-38465 bsc#1247118).
- net: mana: Set tx_packets to post gso processing packet count
  (bsc#1245731).
- net: mana: Allocate MSI-X vectors dynamically (bsc#1245457).
- net: mana: Allow irq_setup() to skip cpus for affinity
  (bsc#1245457).
- net: mana: explain irq_setup() algorithm (bsc#1245457).
- PCI: hv: Allow dynamic MSI-X vector allocation (bsc#1245457).
- PCI/MSI: Export pci_msix_prepare_desc() for dynamic MSI-X
  allocations (bsc#1245457).
- net: mana: Add handler for hardware servicing events
  (bsc#1245730).
- net: mana: Expose additional hardware counters for drop and
  TC via ethtool (bsc#1245729).
- hv_netvsc: Use VF's tso_max_size value when data path is VF
  (bsc#1246203).
- net: mana: Allow tso_max_size to go up-to GSO_MAX_SIZE
  (bsc#1246203).
- commit bdd7f41

- NFS: Fix wakeup of __nfs_lookup_revalidate() in
  unblock_revalidate() (git-fixes).
- commit 80e576f

- sched: Add test_and_clear_wake_up_bit() and
  atomic_dec_and_wake_up() (git-fixes).
- commit 3754627

- drm/amdgpu: Add basic validation for RAS header (bsc#1247252 CVE-2025-38426)
- commit 5d23e74

- NFS: Fix the setting of capabilities when automounting a new
  filesystem (git-fixes).
- commit fabe208

- sunrpc: fix client side handling of tls alerts (git-fixes).
- commit 4c093f3

- NFS: Fixup allocation flags for nfsiod's __GFP_NORETRY
  (git-fixes).
- commit fd58755

- NFSv4.2: another fix for listxattr (git-fixes).
- commit 5a2e576

- NFS: Fix filehandle bounds checking in nfs_fh_to_dentry()
  (git-fixes).
- commit 094541e

- pNFS/flexfiles: don't attempt pnfs on fatal DS errors
  (git-fixes).
- commit ec1d884

- gpio: mlxbf2: use platform_get_irq_optional() (git-fixes).
- ALSA: hda/ca0132: Fix missing error handling in
  ca0132_alt_select_out() (git-fixes).
- ALSA: intel_hdmi: Fix off-by-one error in
  __hdmi_lpe_audio_probe() (git-fixes).
- commit 1750f05

- posix-cpu-timers: fix race between handle_posix_cpu_timers()
  and posix_cpu_timer_del() (bsc#1246911 CVE-2025-38352).
- commit ab7e2c1

- tls: always refresh the queue when reading sock (CVE-2025-38471
  bsc#1247450).
- ext4: only dirty folios when data journaling regular files
  (CVE-2025-38220 bsc#1245966).
- commit 4468ab0

- net/sched: mqprio: fix stack out-of-bounds write in tc entry
  parsing (git-fixes).
- commit 87e34c3

- net/packet: fix a race in packet_set_ring() and
  packet_notifier() (git-fixes).
- commit caa5d02

- net/sched: taprio: enforce minimum value for picos_per_byte
  (git-fixes).
- commit d33d37f

- ipv6: reject malicious packets in ipv6_gso_segment()
  (git-fixes).
- commit e120573

- netpoll: prevent hanging NAPI when netcons gets enabled
  (git-fixes).
- commit d8e3fe4

- tracing/kprobes: Fix to free objects when failed to copy a
  symbol (git-fixes).
- commit a2d3373

- tracing/kprobe: Make trace_kprobe's module callback called
  after jump_label update (git-fixes).
- commit 34ee7ea

- kABI fix for net: vlan: fix VLAN 0 refcount imbalance of
  toggling (CVE-2025-38470 bsc#1247288).
- commit 00f8e79

- net: vlan: fix VLAN 0 refcount imbalance of toggling filtering
  during runtime (CVE-2025-38470 bsc#1247288).
- net/sched: Abort __tc_modify_qdisc if parent class does not
  exist (CVE-2025-38457 bsc#1247098).
- atm: clip: Fix potential null-ptr-deref in to_atmarpd()
  (CVE-2025-38460 bsc#1247143).
- idpf: convert control queue mutex to a spinlock (CVE-2025-38392
  bsc#1247169).
- commit 4f53008

- drm/amd/display: Don't overwrite dce60_clk_mgr (git-fixes).
- Revert "vgacon: Add check for vc_origin address range in
  vgacon_scroll()" (stable-fixes).
- commit 6cc69eb

- exfat: fdatasync flag should be same like generic_write_sync()
  (git-fixes).
- commit ec3f01f

- do_change_type(): refuse to operate on unmounted/not ours mounts (CVE-2025-38498 bsc#1247374)
- commit 545afad

- vfio/mlx5: Fix an unwind issue in mlx5vf_add_migration_pages() (CVE-2024-56742 bsc#1235613)
- commit ff30550

- scsi: target: Fix NULL pointer dereference in
  core_scsi3_decode_spec_i_port() (CVE-2025-38399 bsc#1247097).
- commit e689eaa

- RDMA/siw: Fix the sendmsg byte count in siw_tcp_sendpages (git-fixes)
- commit 39fb4df

- drm/v3d: Disable interrupts before resetting the GPU
  (CVE-2025-38371 bsc#1247178).
- commit 4160ac6

- btrfs: fix log tree replay failure due to file with 0 links
  and extents (git-fixes).
- commit fd0c9dd

- netlink: make sure we allow at least one dump skb
  (CVE-2025-38465 bsc#1247118).
- netlink: Fix rmem check in netlink_broadcast_deliver()
  (CVE-2025-38465 bsc#1247118).
- netlink: Fix wraparounds of sk->sk_rmem_alloc (CVE-2025-38465
  bsc#1247118).
- commit b3ac9f0

- Refresh
  patches.kabi/xsk-Fix-race-condition-in-AF_XDP-generic-RX-path.patch.
  Drop the static_assert() kABI checks temporarily until we have a proper
  solution to signal kABI verification.
- commit d4817c8

- af_unix: Add a prompt to CONFIG_AF_UNIX_OOB (bsc#1246093).
- commit 9dcc611

- net: usbnet: Fix the wrong netif_carrier_on() call (git-fixes).
- commit 3ed80f8

- kABI: restore layout of struct msi_desc (CVE-2025-38062
  bsc#1245216).
- genirq/msi: Store the IOMMU IOVA directly in msi_desc instead
  of iommu_cookie (CVE-2025-38062 bsc#1245216).
- commit 19502f4

- Delete
  patches.suse/af_unix-Disable-MSG_OOB-for-unprivileged-users.patch.
- commit e99b1bb

- Update config files. (CVE-2025-38236 bsc#1246093)
  Disable CONFIG_AF_UNIX_OOB as the implementation is ridden with security
  bugs whose fixes would be hard to backport and the feature has no known
  users.
- commit f8cd607

- Refresh patches.suse/x86-its-Enumerate-Indirect-Target-Selection-ITS-bug.patch.
- Refresh
  patches.suse/x86-its-Add-vmexit-option-to-skip-mitigation-on-some-CPUs.patch.
  Fix affected model steppings.
- commit 115d04b

- KVM: x86: Reset IRTE to host control if *new* route isn't
  postable (bsc#1242960 CVE-2025-37885).
- commit b463fcd

- enabled CONFIG_X86_INTEL_TSX_MODE_AUTO
  This is a response to bsc#1246695. As result of TAA vulnerability
  (CVE-2019-11135) we have aimed to follow the upstream default for TSX
  but due to a mistake we have ended up using CONFIG_X86_INTEL_TSX_MODE_ON
  rather than CONFIG_X86_INTEL_TSX_MODE_OFF. This has been noticed later
  on and fixed to align with upstream. Which has made some users unhappy
  because they have lost a default TSX functionality even on HW that is
  not susceptible to CVE-2019-11135.
  We have discussed different ways to deal with that but the likely most
  straightforward turned out to be to go with CONFIG_X86_INTEL_TSX_MODE_AUTO
  which disables TSX only on CVE-2019-11135 affected HW. We are still
  diverging from the upstream here but there are some positive indications
  that no new TSX based side channels have been discovered since.
- commit 395c9dd

- tcp: call tcp_measure_rcv_mss() for ooo packets (git-fixes).
- commit 54261d2

- net/sched: sch_qfq: Avoid triggering might_sleep in atomic
  context in qfq_delete_class (git-fixes).
- commit cdfb027

- Refresh
  patches.suse/af_unix-Disable-MSG_OOB-for-unprivileged-users.patch.
  Print message upon disabled use.
- commit 31d5690

- Refresh
  patches.suse/virtio-blk-scsi-use-block-layer-helpers-to-calculate.patch.
- commit 773f5a0

- Rename to
  patches.suse/scsi-use-block-layer-helpers-to-calculate-num-of-que.patch.
- commit dd839b8

- Refresh
  patches.suse/nvme-pci-use-block-layer-helpers-to-calculate-num-of.patch.
- commit e114e47

- Refresh
  patches.suse/blk-mq-add-number-of-queue-calc-helper.patch.
- commit db4fa45

- Rename to
  patches.suse/lib-group_cpus-Let-group_cpu_evenly-return-the-numbe.patch.
  Refresh:
  - patches.kabi/kabi-fix-group-cpus-evenly.patch
  - patches.suse/lib-group_cpus-honor-housekeeping-config-when-grouping.patch
- commit ca07a82

- btrfs: tests: fix chunk map leak after failure to add it to
  the tree (git-fixes).
- commit 4c3fd9d

- lib/group_cpus: fix NULL pointer dereference from
  group_cpus_evenly() (bsc#1236897).
- lib/group_cpus.c: avoid acquiring cpu hotplug lock in
  group_cpus_evenly (bsc#1236897).
- commit 749ceff

- btrfs: fix ssd_spread overallocation (git-fixes).
- commit 760f402

- btrfs: use btrfs_record_snapshot_destroy() during rmdir
  (git-fixes).
- commit 05219d1

- btrfs: propagate last_unlink_trans earlier when doing a rmdir
  (git-fixes).
- btrfs: rename err to ret in btrfs_rmdir() (git-fixes).
- commit 6fea6c3

- btrfs: don't skip remaining extrefs if dir not found during
  log replay (git-fixes).
- commit ae66e11

- btrfs: don't ignore inode missing when replaying log tree
  (git-fixes).
- commit 87671c8

- btrfs: fix inode lookup error handling during log replay
  (git-fixes).
- commit a89d2a6

- nvmet-tcp: fix callback lock for TLS handshake (git-fixes).
- nvme: fix misaccounting of nvme-mpath inflight I/O (git-fixes).
- nvme: fix endianness of command word prints in
  nvme_log_err_passthru() (git-fixes).
- nvme: fix inconsistent RCU list manipulation in
  nvme_ns_add_to_ctrl_list() (git-fixes).
- commit bbf2481

- RDMA/core: Rate limit GID cache warning messages (git-fixes)
- commit fd0e41a

- kernel-syms.spec: Drop old rpm release number hack (bsc#1247172).
- commit b4fa2d1

- rtc: rv3028: fix incorrect maximum clock rate handling
  (git-fixes).
- rtc: pcf8563: fix incorrect maximum clock rate handling
  (git-fixes).
- rtc: pcf85063: fix incorrect maximum clock rate handling
  (git-fixes).
- rtc: nct3018y: fix incorrect maximum clock rate handling
  (git-fixes).
- rtc: hym8563: fix incorrect maximum clock rate handling
  (git-fixes).
- rtc: ds1307: fix incorrect maximum clock rate handling
  (git-fixes).
- ucount: fix atomic_long_inc_below() argument type (git-fixes).
- i3c: fix module_i3c_i2c_driver() with I3C=n (git-fixes).
- commit e466472

- pinmux: fix race causing mux_owner NULL with active mux_usecount
  (git-fixes).
- pinctrl: sunxi: Fix memory leak on krealloc failure (git-fixes).
- fbdev: imxfb: Check fb_add_videomode to prevent null-ptr-deref
  (git-fixes).
- firewire: ohci: correct code comments about bus_reset tasklet
  (git-fixes).
- commit fd1a6ae

- PCI: rockchip-host: Fix "Unexpected Completion" log message
  (git-fixes).
- PCI: endpoint: pci-epf-vntb: Fix the incorrect usage of __iomem
  attribute (git-fixes).
- PCI: endpoint: pci-epf-vntb: Return -ENOENT if
  pci_epc_get_next_free_bar() fails (git-fixes).
- PCI: endpoint: Fix configfs group removal on driver teardown
  (git-fixes).
- PCI: endpoint: Fix configfs group list head handling
  (git-fixes).
- watchdog: ziirave_wdt: check record length in
  ziirave_firm_verify() (git-fixes).
- dmaengine: nbpfaxi: Add missing check after DMA map (git-fixes).
- dmaengine: mv_xor: Fix missing check after DMA map and missing
  unmap (git-fixes).
- dmaengine: qcom: gpi: Drop unused gpi_write_reg_field()
  (git-fixes).
- dmaengine: dw-edma: Drop unused dchan2dev() and chan2dev()
  (git-fixes).
- ASoC: fsl_xcvr: get channel status data when PHY is not exists
  (git-fixes).
- soundwire: stream: restore params when prepare ports fail
  (git-fixes).
- power: supply: max14577: Handle NULL pdata when CONFIG_OF is
  not set (git-fixes).
- power: supply: cpcap-charger: Fix null check for
  power_supply_get_by_name (git-fixes).
- ALSA: hda/realtek - Add mute LED support for HP Pavilion
  15-eg0xxx (stable-fixes).
- can: netlink: can_changelink(): fix NULL pointer deref of
  struct can_priv::do_set_mode (git-fixes).
- ALSA: hda: Add missing NVIDIA HDA codec IDs (stable-fixes).
- usb: typec: tcpm: apply vbus before data bringup in
  tcpm_src_attach (git-fixes).
- usb: typec: tcpm: allow switching to mode accessory to mux
  properly (stable-fixes).
- usb: typec: tcpm: allow to use sink in accessory mode
  (stable-fixes).
- ALSA: hda/tegra: Add Tegra264 support (stable-fixes).
- can: dev: can_restart(): move debug message and stats after
  successful restart (stable-fixes).
- can: dev: can_restart(): reverse logic to remove need for goto
  (stable-fixes).
- commit 0f0c0d9

- btrfs: don't silently ignore unexpected extent type when
  replaying log (git-fixes).
- commit e423498

- btrfs: fix invalid inode pointer dereferences during log replay
  (git-fixes).
- commit 78cbba9

- btrfs: return a btrfs_inode from read_one_inode() (git-fixes).
- commit b3a9472

- iommu/arm-smmu-qcom: Add SM6115 MDSS compatible (git-fixes).
- iommu/amd: Fix geometry.aperture_end for V2 tables (git-fixes).
- commit f8c05a9

- btrfs: return a btrfs_inode from btrfs_iget_logging()
  (git-fixes).
- commit 88ed97b

- btrfs: use NOFS context when getting inodes during logging
  and log replay (git-fixes).
- commit 88eb1d5

- virtio-net: ensure the received length does not exceed allocated
  size (CVE-2025-38375 bsc#1247177).
- commit 2adf745

- btrfs: update superblock's device bytes_used when dropping chunk
  (git-fixes).
- commit e33076b

- Update
  patches.suse/0001-mm-hugetlb-fix-huge_pmd_unshare-vs-GUP-fast-race.patch
  (bsc#1245431 CVE-2025-38085 bsc#1245499).
- Update
  patches.suse/0001-mm-hugetlb-unshare-page-tables-during-VMA-split-not-.patch
  (bsc#1245431 CVE-2025-38084 bsc#1245498).
- Update
  patches.suse/ACPI-CPPC-Fix-NULL-pointer-dereference-when-nosmp-is.patch
  (git-fixes CVE-2025-38113 bsc#1245683).
- Update
  patches.suse/ACPICA-Refuse-to-evaluate-a-method-if-arguments-are-.patch
  (stable-fixes CVE-2025-38386 bsc#1247138).
- Update
  patches.suse/ACPICA-fix-acpi-operand-cache-leak-in-dswstate.c.patch
  (stable-fixes CVE-2025-38345 bsc#1246337).
- Update
  patches.suse/ACPICA-fix-acpi-parse-and-parseext-cache-leaks.patch
  (stable-fixes CVE-2025-38344 bsc#1246334).
- Update
  patches.suse/ALSA-usb-audio-Fix-out-of-bounds-read-in-snd_usb_get.patch
  (git-fixes CVE-2025-38249 bsc#1246171).
- Update
  patches.suse/ASoC-Intel-avs-Verify-content-returned-by-parse_int_.patch
  (git-fixes CVE-2025-38307 bsc#1246364).
- Update
  patches.suse/ASoC-codecs-wcd9335-Fix-missing-free-of-regulator-su.patch
  (git-fixes CVE-2025-38259 bsc#1246220).
- Update
  patches.suse/Bluetooth-Fix-NULL-pointer-deference-on-eir_get_serv.patch
  (git-fixes CVE-2025-38304 bsc#1246240).
- Update
  patches.suse/Bluetooth-Fix-null-ptr-deref-in-l2cap_sock_resume_cb.patch
  (git-fixes CVE-2025-38473 bsc#1247289).
- Update
  patches.suse/Bluetooth-MGMT-Fix-UAF-on-mgmt_remove_adv_monitor_co.patch
  (git-fixes CVE-2025-38118 bsc#1245670).
- Update
  patches.suse/HID-core-do-not-bypass-hid_hw_raw_request.patch
  (stable-fixes CVE-2025-38494 bsc#1247349).
- Update
  patches.suse/HID-core-ensure-the-allocated-report-buffer-can-cont.patch
  (stable-fixes CVE-2025-38495 bsc#1247348).
- Update
  patches.suse/IB-mlx5-Fix-potential-deadlock-in-MR-deregistration.patch
  (git-fixes CVE-2025-38373 bsc#1247033).
- Update
  patches.suse/Input-ims-pcu-check-record-size-in-ims_pcu_flash_fir.patch
  (git-fixes CVE-2025-38428 bsc#1247150).
- Update
  patches.suse/NFC-nci-uart-Set-tty-disc_data-only-in-success-path.patch
  (git-fixes CVE-2025-38416 bsc#1247151).
- Update
  patches.suse/NFSv4-pNFS-Fix-a-race-to-wake-on-NFS_LAYOUT_DRAIN.patch
  (git-fixes CVE-2025-38393 bsc#1247170).
- Update
  patches.suse/RDMA-cma-Fix-hang-when-cma_netevent_callback-fails-t.patch
  (git-fixes CVE-2025-38151 bsc#1245745).
- Update
  patches.suse/RDMA-iwcm-Fix-use-after-free-of-work-objects-after-c.patch
  (git-fixes CVE-2025-38211 bsc#1246008).
- Update
  patches.suse/RDMA-mlx5-Fix-error-flow-upon-firmware-failure-for-R.patch
  (git-fixes CVE-2025-38161 bsc#1245777).
- Update
  patches.suse/RDMA-mlx5-Initialize-obj_event-obj_sub_list-before-x.patch
  (git-fixes CVE-2025-38387 bsc#1247154).
- Update
  patches.suse/Squashfs-check-return-result-of-sb_min_blocksize.patch
  (git-fixes CVE-2025-38415 bsc#1247147).
- Update
  patches.suse/VMCI-fix-race-between-vmci_host_setup_notify-and-vmc.patch
  (git-fixes CVE-2025-38102 bsc#1245669).
- Update
  patches.suse/aoe-clean-device-rq_list-in-aoedev_downdev.patch
  (git-fixes CVE-2025-38326 bsc#1246490).
- Update
  patches.suse/ata-pata_via-Force-PIO-for-ATAPI-devices-on-VT6415-V.patch
  (stable-fixes CVE-2025-38336 bsc#1246370).
- Update
  patches.suse/backlight-pm8941-Add-NULL-check-in-wled_configure.patch
  (git-fixes CVE-2025-38143 bsc#1245714).
- Update patches.suse/bnxt-properly-flush-XDP-redirect-lists.patch
  (git-fixes CVE-2025-38246 bsc#1246195).
- Update
  patches.suse/bpf-sockmap-Fix-panic-when-calling-skb_linearize.patch
  (bsc#1245749 CVE-2025-38154 CVE-2025-38165 bsc#1245757).
- Update patches.suse/bus-fsl-mc-fix-double-free-on-mc_dev.patch
  (git-fixes CVE-2025-38313 bsc#1246342).
- Update
  patches.suse/calipso-Fix-null-ptr-deref-in-calipso_req_-set-del-a.patch
  (git-fixes CVE-2025-38181 bsc#1246000).
- Update
  patches.suse/comedi-Fail-COMEDI_INSNLIST-ioctl-if-n_insns-is-too-.patch
  (git-fixes CVE-2025-38481 bsc#1247276).
- Update
  patches.suse/comedi-Fix-initialization-of-data-for-instructions-t.patch
  (git-fixes CVE-2025-38478 bsc#1247273).
- Update
  patches.suse/comedi-Fix-use-of-uninitialized-data-in-insn_rw_emul.patch
  (git-fixes CVE-2025-38480 bsc#1247274).
- Update
  patches.suse/comedi-das16m1-Fix-bit-shift-out-of-bounds.patch
  (git-fixes CVE-2025-38483 bsc#1247278).
- Update
  patches.suse/comedi-das6402-Fix-bit-shift-out-of-bounds.patch
  (git-fixes CVE-2025-38482 bsc#1247277).
- Update
  patches.suse/crypto-marvell-cesa-Handle-zero-length-skcipher-requ.patch
  (git-fixes CVE-2025-38173 bsc#1245769).
- Update
  patches.suse/crypto-sun8i-ce-cipher-fix-error-handling-in-sun8i_c.patch
  (git-fixes CVE-2025-38300 bsc#1246349).
- Update patches.suse/dm-bufio-fix-sched-in-atomic-context.patch
  (git-fixes CVE-2025-38496 bsc#1247284).
- Update
  patches.suse/dma-buf-insert-memory-barrier-before-updating-num_fe.patch
  (git-fixes CVE-2025-38095 bsc#1245658).
- Update
  patches.suse/dmaengine-idxd-Check-availability-of-workqueue-alloc.patch
  (stable-fixes CVE-2025-38369 bsc#1247209).
- Update
  patches.suse/dmaengine-ti-Add-NULL-check-in-udma_probe.patch
  (git-fixes CVE-2025-38138 bsc#1245719).
- Update
  patches.suse/drivers-rapidio-rio_cm.c-prevent-possible-heap-overw.patch
  (stable-fixes CVE-2025-38090 bsc#1245510).
- Update
  patches.suse/drm-amd-display-Add-null-pointer-check-for-get_first.patch
  (git-fixes CVE-2025-38362 bsc#1247089).
- Update
  patches.suse/drm-amd-pp-Fix-potential-NULL-pointer-dereference-in.patch
  (git-fixes CVE-2025-38319 bsc#1246243).
- Update
  patches.suse/drm-exynos-exynos7_drm_decon-add-vblank-check-in-IRQ.patch
  (git-fixes CVE-2025-38467 bsc#1247146).
- Update
  patches.suse/drm-gem-Acquire-references-on-GEM-handles-for-frameb.patch
  (stable-fixes CVE-2025-38449 bsc#1247255).
- Update
  patches.suse/drm-i915-gt-Fix-timeline-left-held-on-VMA-alloc-erro.patch
  (git-fixes CVE-2025-38389 bsc#1247153).
- Update
  patches.suse/drm-msm-Fix-a-fence-leak-in-submit-error-path.patch
  (stable-fixes CVE-2025-38410 bsc#1247128).
- Update
  patches.suse/drm-msm-Fix-another-leak-in-the-submit-error-path.patch
  (stable-fixes CVE-2025-38409 bsc#1247285).
- Update
  patches.suse/drm-msm-gpu-Fix-crash-when-throttling-GPU-immediatel.patch
  (git-fixes CVE-2025-38354 bsc#1247061).
- Update
  patches.suse/drm-scheduler-signal-scheduled-fence-when-kill-job.patch
  (stable-fixes CVE-2025-38436 bsc#1247227).
- Update
  patches.suse/drm-tegra-Fix-a-possible-null-pointer-dereference.patch
  (git-fixes CVE-2025-38363 bsc#1247018).
- Update
  patches.suse/fbcon-Make-sure-modelist-not-set-on-unregistered-con.patch
  (stable-fixes CVE-2025-38198 bsc#1245952).
- Update
  patches.suse/fbdev-Fix-do_register_framebuffer-to-prevent-null-pt.patch
  (git-fixes CVE-2025-38215 bsc#1246109).
- Update
  patches.suse/fbdev-Fix-fb_set_var-to-prevent-null-ptr-deref-in-fb.patch
  (git-fixes CVE-2025-38214 bsc#1246042).
- Update
  patches.suse/fbdev-core-fbcvt-avoid-division-by-0-in-fb_cvt_hperi.patch
  (git-fixes CVE-2025-38312 bsc#1246386).
- Update
  patches.suse/fs-nfs-read-fix-double-unlock-bug-in-nfs_return_empty_folio.patch
  (git-fixes CVE-2025-38338 bsc#1246258).
- Update
  patches.suse/gve-add-missing-NULL-check-for-gve_alloc_pending_pac.patch
  (git-fixes CVE-2025-38122 bsc#1245746).
- Update
  patches.suse/hwmon-asus-ec-sensors-check-sensor-index-in-read_str.patch
  (git-fixes CVE-2025-38142 bsc#1245713).
- Update
  patches.suse/hwmon-ftsteutates-Fix-TOCTOU-race-in-fts_read.patch
  (git-fixes CVE-2025-38217 bsc#1246002).
- Update
  patches.suse/i2c-designware-Fix-an-initialization-issue.patch
  (git-fixes CVE-2025-38380 bsc#1247028).
- Update
  patches.suse/i2c-tegra-check-msg-length-in-SMBUS-block-read.patch
  (bsc#1242086 CVE-2025-38425 bsc#1247251).
- Update
  patches.suse/ice-fix-Tx-scheduler-error-handling-in-XDP-callback.patch
  (git-fixes CVE-2025-38127 bsc#1245705).
- Update
  patches.suse/iio-accel-fxls8962af-Fix-use-after-free-in-fxls8962a.patch
  (git-fixes CVE-2025-38485 bsc#1247236).
- Update
  patches.suse/jffs2-check-jffs2_prealloc_raw_node_refs-result-in-few-other-places.patch
  (git-fixes CVE-2025-38328 bsc#1246249).
- Update
  patches.suse/jffs2-check-that-raw-node-were-preallocated-before-writing-summary.patch
  (git-fixes CVE-2025-38194 bsc#1245957).
- Update
  patches.suse/media-cxusb-no-longer-judge-rbuf-when-the-write-fail.patch
  (git-fixes CVE-2025-38229 bsc#1246049).
- Update
  patches.suse/media-imx-jpeg-Cleanup-after-an-allocation-error.patch
  (git-fixes CVE-2025-38225 bsc#1246041).
- Update
  patches.suse/media-vidtv-Terminating-the-subsequent-process-of-in.patch
  (git-fixes CVE-2025-38227 bsc#1246031).
- Update
  patches.suse/media-vivid-Change-the-siize-of-the-composing.patch
  (git-fixes CVE-2025-38226 bsc#1246050).
- Update
  patches.suse/mtd-nand-ecc-mxic-Fix-use-of-uninitialized-variable-.patch
  (git-fixes CVE-2025-38277 bsc#1246246).
- Update
  patches.suse/mtd-spinand-fix-memory-leak-of-ECC-engine-conf.patch
  (stable-fixes CVE-2025-38384 bsc#1247035).
- Update
  patches.suse/mtk-sd-Prevent-memory-corruption-from-DMA-map-failur.patch
  (git-fixes CVE-2025-38401 bsc#1247125).
- Update
  patches.suse/nbd-fix-uaf-in-nbd_genl_connect-error-path.patch
  (git-fixes CVE-2025-38443 bsc#1247164).
- Update patches.suse/net-Fix-TOCTOU-issue-in-sk_is_readable.patch
  (git-fixes CVE-2025-38112 bsc#1245668).
- Update
  patches.suse/net-fix-udp-gso-skb_segment-after-pull-from-frag_lis.patch
  (git-fixes CVE-2025-38124 bsc#1245690).
- Update
  patches.suse/net-mdiobus-Fix-potential-out-of-bounds-clause-45-re.patch
  (git-fixes CVE-2025-38110 bsc#1245665).
- Update
  patches.suse/net-mdiobus-Fix-potential-out-of-bounds-read-write-a.patch
  (git-fixes CVE-2025-38111 bsc#1245666).
- Update
  patches.suse/net-mlx5-Fix-ECVF-vports-unload-on-shutdown-flow.patch
  (git-fixes CVE-2025-38109 bsc#1245684).
- Update
  patches.suse/net-phy-clear-phydev-devlink-when-the-link-is-delete.patch
  (git-fixes CVE-2025-38149 bsc#1245737).
- Update
  patches.suse/net-phy-mscc-Fix-memory-leak-when-using-one-step-tim.patch
  (git-fixes CVE-2025-38148 bsc#1245735).
- Update
  patches.suse/net-sched-Return-NULL-when-htb_lookup_leaf-encounter.patch
  (git-fixes CVE-2025-38468 bsc#1247437).
- Update
  patches.suse/net-sched-fix-use-after-free-in-taprio_dev_notifier.patch
  (git-fixes CVE-2025-38087 bsc#1245504).
- Update
  patches.suse/net-sched-sch_qfq-Fix-race-condition-on-qfq_aggregat.patch
  (git-fixes CVE-2025-38477 bsc#1247314).
- Update
  patches.suse/net-tipc-fix-refcount-warning-in-tipc_aead_encrypt.patch
  (CVE-2025-38052 bsc#1244749 CVE-2025-38273 bsc#1246266).
- Update
  patches.suse/net-usb-aqc111-fix-error-handling-of-usbnet-read-cal.patch
  (git-fixes CVE-2025-38153 bsc#1245744).
- Update
  patches.suse/net-usb-lan78xx-fix-WARN-in-__netif_napi_del_locked-.patch
  (git-fixes CVE-2025-38385 bsc#1247149).
- Update patches.suse/net-wwan-t7xx-Fix-napi-rx-poll-issue.patch
  (git-fixes CVE-2025-38123 bsc#1245688).
- Update
  patches.suse/net_sched-ets-fix-a-race-in-ets_qdisc_change.patch
  (git-fixes CVE-2025-38107 bsc#1245676).
- Update
  patches.suse/net_sched-red-fix-a-race-in-__red_change.patch
  (git-fixes CVE-2025-38108 bsc#1245675).
- Update
  patches.suse/net_sched-sch_sfq-reject-invalid-perturb-period.patch
  (git-fixes CVE-2025-38193 bsc#1245945).
- Update
  patches.suse/netfilter-nf_set_pipapo_avx2-fix-initial-map-fill.patch
  (git-fixes CVE-2024-57947 bsc#1236333 CVE-2025-38120
  bsc#1245711).
- Update
  patches.suse/nfs-Clean-up-proc-net-rpc-nfs-when-nfs_fs_proc_net_init-fails.patch
  (git-fixes CVE-2025-38400 bsc#1247123).
- Update
  patches.suse/nfsd-Initialize-ssc-before-laundromat_work-to-prevent-NULL-dereference.patch
  (git-fixes CVE-2025-38231 bsc#1246055).
- Update
  patches.suse/nfsd-nfsd4_spo_must_allow-must-check-this-is-a-v4-compound-request.patch
  (git-fixes CVE-2025-38430 bsc#1247160).
- Update
  patches.suse/page_pool-Fix-use-after-free-in-page_pool_recycle_in.patch
  (git-fixes CVE-2025-38129 bsc#1245723).
- Update patches.suse/perf-Fix-sample-vs-do_exit.patch
  (bsc#1246547 CVE-2025-38424 bsc#1247293).
- Update
  patches.suse/phy-qcom-qmp-usb-Fix-an-NULL-vs-IS_ERR-bug.patch
  (git-fixes CVE-2025-38275 bsc#1246236).
- Update
  patches.suse/pinctrl-at91-Fix-possible-out-of-boundary-access.patch
  (git-fixes CVE-2025-38286 bsc#1246283).
- Update
  patches.suse/platform-x86-dell-wmi-sysman-Fix-WMI-data-block-retr.patch
  (git-fixes CVE-2025-38412 bsc#1247132).
- Update patches.suse/platform-x86-dell_rbu-Fix-list-usage.patch
  (git-fixes CVE-2025-38197 bsc#1246047).
- Update
  patches.suse/powerpc-powernv-memtrace-Fix-out-of-bounds-issue-in-.patch
  (bsc#1244309 ltc#213790 CVE-2025-38088 bsc#1245506).
- Update
  patches.suse/ptp-remove-ptp-n_vclocks-check-logic-in-ptp_vclock_i.patch
  (git-fixes CVE-2025-38305 bsc#1246358).
- Update
  patches.suse/regulator-gpio-Fix-the-out-of-bounds-access-to-drvda.patch
  (git-fixes CVE-2025-38395 bsc#1247171).
- Update
  patches.suse/rose-fix-dangling-neighbour-pointers-in-rose_rt_devi.patch
  (git-fixes CVE-2025-38377 bsc#1247174).
- Update
  patches.suse/rpl-Fix-use-after-free-in-rpl_do_srh_inline.patch
  (git-fixes CVE-2025-38476 bsc#1247317).
- Update
  patches.suse/s390-bpf-Fix-bpf_arch_text_poke-with-new_addr-NULL-again.patch
  (git-fixes bsc#1246870 CVE-2025-38489 bsc#1247241).
- Update
  patches.suse/s390-pkey-Prevent-overflow-in-size-calculation-for-memdup_.patch
  (git-fixes bsc#1245598 CVE-2025-38257 bsc#1246186).
- Update
  patches.suse/sch_hfsc-make-hfsc_qlen_notify-idempotent.patch
  (CVE-2025-37798 bsc#1242414 CVE-2025-38177 bsc#1245986).
- Update
  patches.suse/scsi-lpfc-Avoid-potential-ndlp-use-after-free-in-dev.patch
  (bsc#1242993 CVE-2025-38289 bsc#1246287).
- Update patches.suse/scsi-lpfc-Use-memcpy-for-BIOS-version.patch
  (bsc#1240966 CVE-2025-38332 bsc#1246375).
- Update
  patches.suse/serial-Fix-potential-null-ptr-deref-in-mlb_usio_prob.patch
  (git-fixes CVE-2025-38135 bsc#1246023).
- Update
  patches.suse/soc-aspeed-Add-NULL-check-in-aspeed_lpc_enable_snoop.patch
  (git-fixes CVE-2025-38145 bsc#1245765).
- Update
  patches.suse/soc-aspeed-lpc-snoop-Don-t-disable-channels-that-are.patch
  (git-fixes CVE-2025-38487 bsc#1247238).
- Update
  patches.suse/software-node-Correct-a-OOB-check-in-software_node_g.patch
  (stable-fixes CVE-2025-38342 bsc#1246453).
- Update
  patches.suse/sunrpc-handle-SVC_GARBAGE-during-svc-auth-processing-as-auth-error.patch
  (git-fixes CVE-2025-38089 bsc#1245508).
- Update
  patches.suse/thunderbolt-Do-not-double-dequeue-a-configuration-re.patch
  (stable-fixes CVE-2025-38174 bsc#1245781).
- Update
  patches.suse/usb-chipidea-udc-disconnect-reconnect-from-host-when.patch
  (git-fixes CVE-2025-38376 bsc#1247176).
- Update
  patches.suse/usb-gadget-u_serial-Fix-race-condition-in-TTY-wakeup.patch
  (git-fixes CVE-2025-38448 bsc#1247233).
- Update
  patches.suse/usb-net-sierra-check-for-no-status-endpoint.patch
  (git-fixes CVE-2025-38474 bsc#1247311).
- Update
  patches.suse/usb-renesas_usbhs-Reorder-clock-handling-and-power-m.patch
  (git-fixes CVE-2025-38136 bsc#1245691).
- Update
  patches.suse/usb-typec-altmodes-displayport-do-not-index-invalid-.patch
  (git-fixes CVE-2025-38391 bsc#1247181).
- Update
  patches.suse/usb-typec-displayport-Fix-potential-deadlock.patch
  (git-fixes CVE-2025-38404 bsc#1247271).
- Update
  patches.suse/vgacon-Add-check-for-vc_origin-address-range-in-vgac.patch
  (git-fixes CVE-2025-38213 bsc#1246037).
- Update
  patches.suse/wifi-ath11k-fix-node-corruption-in-ar-arvifs-list.patch
  (git-fixes CVE-2025-38293 bsc#1246292).
- Update
  patches.suse/wifi-ath12k-fix-invalid-access-to-memory.patch
  (git-fixes CVE-2025-38292 bsc#1246295).
- Update
  patches.suse/wifi-ath12k-fix-node-corruption-in-ar-arvifs-list.patch
  (git-fixes CVE-2025-38290 bsc#1246293).
- Update
  patches.suse/wifi-ath6kl-remove-WARN-on-bad-firmware-input.patch
  (stable-fixes CVE-2025-38406 bsc#1247210).
- Update
  patches.suse/wifi-ath9k_htc-Abort-software-beacon-handling-if-dis.patch
  (git-fixes CVE-2025-38157 bsc#1245747).
- Update
  patches.suse/wifi-carl9170-do-not-ping-device-which-has-failed-to.patch
  (git-fixes CVE-2025-38420 bsc#1247279).
- Update
  patches.suse/wifi-mt76-mt7915-Fix-null-ptr-deref-in-mt7915_mmio_w.patch
  (git-fixes CVE-2025-38155 bsc#1245748).
- Update
  patches.suse/wifi-mt76-mt7996-drop-fragments-with-multicast-or-br.patch
  (stable-fixes CVE-2025-38343 bsc#1246438).
- Update
  patches.suse/wifi-p54-prevent-buffer-overflow-in-p54_rx_eeprom_re.patch
  (git-fixes CVE-2025-38348 bsc#1246262).
- Update
  patches.suse/wifi-rtw88-fix-the-para-buffer-size-to-avoid-reading.patch
  (git-fixes CVE-2025-38159 bsc#1245751).
- commit de345c9

- Revert "cgroup_freezer: cgroup_freezing: Check if not frozen"
  (bsc#1219338).
- sched,freezer: Remove unnecessary warning in __thaw_task
  (bsc#1219338).
- commit 108588a

- ipv6: fix possible infinite loop in fib6_info_uses_dev()
  (git-fixes).
- commit 16f1f6e

- ipv6: prevent infinite loop in rt6_nlmsg_size() (git-fixes).
- commit cb535e8

- net/sched: Restrict conditions for adding duplicating netems
  to qdisc tree (git-fixes).
- commit 6fae648

- Refresh
  patches.suse/af_unix-Disable-MSG_OOB-for-unprivileged-users.patch.
  Add cmdline override.
- commit 4b6e594

- af_unix: Disable MSG_OOB for unprivileged users (CVE-2025-38236
  bsc#1246093).
- commit 6110a63

- fs/orangefs: Allow 2 more characters in do_c_string()
  (git-fixes).
- commit 642fa26

- jfs: fix metapage reference count leak in dbAllocCtl
  (git-fixes).
- commit 58c926b

- x86/mce/amd: Fix threshold limit reset (git-fixes).
- commit 468e2ae

- bus: mhi: ep: Update read pointer only after buffer is written
  (CVE-2025-38429 bsc#1247253).
- commit 3341565

- x86/mce: Don't remove sysfs if thresholding sysfs init fails (git-fixes).
- commit 3d8385a

- x86/mce: Make sure CMCI banks are cleared during shutdown on Intel (git-fixes).
- commit fe9eb0f

- x86/mce/amd: Add default names for MCA banks and blocks (git-fixes).
- commit 27f7700

- x86/traps: Initialize DR6 by writing its architectural reset value (git-fixes).
- commit 80ddfd8

- media: venus: vdec: Clamp param smaller than 1fps and bigger
  than 240 (git-fixes).
- commit 1212a93

- x86/cpu/amd: Fix workaround for erratum 1054 (git-fixes).
- commit 2d80ddf

- mtd: rawnand: atmel: set pmecc data setup time (git-fixes).
- mtd: spinand: propagate spinand_wait() errors from
  spinand_write_page() (git-fixes).
- mtd: rawnand: fsmc: Add missing check after DMA map (git-fixes).
- mtd: rawnand: rockchip: Add missing check after DMA map
  (git-fixes).
- mtd: rawnand: atmel: Fix dma_mapping_error() address
  (git-fixes).
- mtd: rawnand: renesas: Add missing check after DMA map
  (git-fixes).
- mtd: spi-nor: Fix spi_nor_try_unlock_all() (git-fixes).
- mtd: fix possible integer overflow in erase_xfer() (git-fixes).
- clk: sunxi-ng: v3s: Fix de clock definition (git-fixes).
- clk: clk-axi-clkgen: fix fpfd_max frequency for zynq
  (git-fixes).
- clk: xilinx: vcu: unregister pll_post only if registered
  correctly (git-fixes).
- clk: davinci: Add NULL check in davinci_lpsc_clk_register()
  (git-fixes).
- hwmon: (gsc-hwmon) fix fan pwm setpoint show functions
  (git-fixes).
- pwm: imx-tpm: Reset counter if CMOD is 0 (git-fixes).
- media: uvcvideo: Do not mark valid metadata as invalid
  (git-fixes).
- media: ov2659: Fix memory leaks in ov2659_probe() (git-fixes).
- media: hi556: correct the test pattern configuration
  (git-fixes).
- media: vivid: fix wrong pixel_array control size (git-fixes).
- media: venus: hfi: explicitly release IRQ during teardown
  (git-fixes).
- media: venus: Add a check for packet size after reading from
  shared memory (git-fixes).
- media: venus: protect against spurious interrupts during probe
  (git-fixes).
- media: venus: venc: Clamp param smaller than 1fps and bigger
  than 240 (git-fixes).
- media: v4l2-ctrls: Don't reset handler's error in
  v4l2_ctrl_handler_free() (git-fixes).
- media: v4l2-ctrls: Fix H264 SEPARATE_COLOUR_PLANE check
  (git-fixes).
- media: imx: fix a potential memory leak in
  imx_media_csc_scaler_device_init() (git-fixes).
- media: rainshadow-cec: fix TOCTOU race condition in
  rain_interrupt() (git-fixes).
- media: gspca: Add bounds checking to firmware parser
  (git-fixes).
- media: usbtv: Lock resolution while streaming (git-fixes).
- media: uvcvideo: Fix 1-byte out-of-bounds read in
  uvc_parse_format() (git-fixes).
- crypto: qat - fix seq_file position update in adf_ring_next()
  (git-fixes).
- crypto: qat - fix DMA direction for compression on GEN2 devices
  (git-fixes).
- crypto: qat - flush misc workqueue during device shutdown
  (git-fixes).
- crypto: qat - disable ZUC-256 capability for QAT GEN5
  (git-fixes).
- crypto: img-hash - Fix dma_unmap_sg() nents value (git-fixes).
- crypto: keembay - Fix dma_unmap_sg() nents value (git-fixes).
- hwrng: mtk - handle devm_pm_runtime_enable errors (git-fixes).
- crypto: ccp - Fix crash when rebind ccp device for ccp.ko
  (git-fixes).
- crypto: inside-secure - Fix `dma_unmap_sg()` nents value
  (git-fixes).
- crypto: ccp - Fix locking on alloc failure handling (git-fixes).
- crypto: arm/aes-neonbs - work around gcc-15 warning (git-fixes).
- crypto: qat - fix state restore for banks with exceptions
  (git-fixes).
- crypto: qat - allow enabling VFs in the absence of IOMMU
  (git-fixes).
- crypto: marvell/cesa - Fix engine load inaccuracy (git-fixes).
- crypto: qat - use unmanaged allocation for dc_data (git-fixes).
- crypto: sun8i-ce - fix nents passed to dma_unmap_sg()
  (git-fixes).
- commit 8f3fb2a

- Move upstreamed SCSI and ACPI patches into sorted section
- commit 09d9d7c

- RDMA/uverbs: Add empty rdma_uattrs_has_raw_cap() declaration (git-fixes)
- commit ced3c6d

- Update config files.
  run_oldconfig, no functional change.
- commit 0b6044b

- RDMA/mlx5: Fix compilation warning when USER_ACCESS isn't set (git-fixes)
- commit dce79bd

- RDMA/hns: Fix -Wframe-larger-than issue (git-fixes)
- commit 90a067b

- RDMA/hns: Drop GFP_NOWARN (git-fixes)
- commit 927f6d6

- RDMA/hns: Fix accessing uninitialized resources (git-fixes)
- commit c1be2f8

- RDMA/hns: Get message length of ack_req from FW (git-fixes)
- commit 2e9a431

- RDMA/hns: Fix HW configurations not cleared in error flow (git-fixes)
- commit ba6e757

- RDMA/hns: Fix double destruction of rsv_qp (git-fixes)
- commit 0d7fee3

- Fix dma_unmap_sg() nents value (git-fixes)
- commit 89d1cb0

- RDMA/counter: Check CAP_NET_RAW check in user namespace for RDMA counters (git-fixes)
- commit c5238e7

- RDMA/nldev: Check CAP_NET_RAW in user namespace for QP modify (git-fixes)
- commit 0d7ab5b

- RDMA/mlx5: Check CAP_NET_RAW in user namespace for devx create (git-fixes)
- commit c162c8c

- RDMA/uverbs: Check CAP_NET_RAW in user namespace for RAW QP create (git-fixes)
- commit 3292115

- RDMA/uverbs: Check CAP_NET_RAW in user namespace for QP create (git-fixes)
- commit 90f88d3

- RDMA/mlx5: Check CAP_NET_RAW in user namespace for anchor create (git-fixes)
- commit a812e80

- RDMA/mlx5: Check CAP_NET_RAW in user namespace for flow create (git-fixes)
- commit 9dcd5e1

- RDMA/uverbs: Check CAP_NET_RAW in user namespace for flow create (git-fixes)
- commit eaff4b0

- vsock: Fix transport_{g2h,h2g} TOCTOU (CVE-2025-38462
  bsc#1247104).
- commit f5da768

- tcp: Correct signedness in skb remaining space calculation
  (CVE-2025-38463 bsc#1247113).
- net/sched: Always pass notifications when child class becomes
  empty (CVE-2025-38350 bsc#1246781).
- maple_tree: fix MA_STATE_PREALLOC flag in mas_preallocate()
  (CVE-2025-38364 bsc#1247091).
- commit 7390872

- x86: UV RTC: Add parameter to disable RTC clocksource
  (bsc#1241345).
- commit 79ccdce

- clocksource: Set cs_watchdog_read() checks based on
  .uncertainty_margin (bsc#1241345 bsc#1244457).
- commit 09911af

- clocksource: Scale the watchdog read retries automatically
  (bsc#1241345 bsc#1244457).
- Refresh
  patches.suse/clocksource-Fix-brown-bag-boolean-thinko-in-cs_watch.patch.
- Refresh
  patches.suse/clocksource-Make-watchdog-and-suspend-timing-multipl.patch.
- commit fdf040b

- wifi: iwlwifi: Fix error code in iwl_op_mode_dvm_start()
  (git-fixes).
- wifi: iwlwifi: return ERR_PTR from opmode start()
  (stable-fixes).
- commit bb4c593

- drm/amd/pm/powerplay/hwmgr/smu_helper: fix order of mask and
  value (git-fixes).
- fbcon: Fix outdated registered_fb reference in comment
  (git-fixes).
- drm/msm/dpu: Fill in min_prefill_lines for SC8180X (git-fixes).
- drm/vmwgfx: Fix Host-Backed userspace on Guest-Backed kernel
  (git-fixes).
- drm/panfrost: Fix panfrost device variable name in devfreq
  (git-fixes).
- drm/rockchip: cleanup fb when drm_gem_fb_afbc_init failed
  (git-fixes).
- can: peak_usb: fix USB FD devices potential malfunction
  (git-fixes).
- net: phy: micrel: fix KSZ8081/KSZ8091 cable test (git-fixes).
- net: usbnet: Avoid potential RCU stall on LINK_CHANGE event
  (git-fixes).
- can: kvaser_usb: Assign netdev.dev_port based on device channel
  index (git-fixes).
- can: kvaser_pciefd: Store device channel index (git-fixes).
- Bluetooth: hci_event: Mask data status from LE ext adv reports
  (git-fixes).
- wifi: ath12k: fix endianness handling while accessing wmi
  service bit (git-fixes).
- wifi: ath11k: fix sleeping-in-atomic in
  ath11k_mac_op_set_bitrate_mask() (git-fixes).
- wifi: ath12k: fix dest ring-buffer corruption when ring is full
  (git-fixes).
- wifi: ath12k: fix source ring-buffer corruption (git-fixes).
- wifi: ath12k: fix dest ring-buffer corruption (git-fixes).
- wifi: ath11k: fix dest ring-buffer corruption when ring is full
  (git-fixes).
- wifi: ath11k: fix source ring-buffer corruption (git-fixes).
- wifi: ath11k: fix dest ring-buffer corruption (git-fixes).
- wifi: ath11k: fix suspend use-after-free after probe failure
  (git-fixes).
- wifi: ath11k: clear initialized flag for deinit-ed srng lists
  (git-fixes).
- wifi: brcmfmac: fix P2P discovery failure in P2P peer due to
  missing P2P IE (git-fixes).
- Reapply "wifi: mac80211: Update skb's control block key in
  ieee80211_tx_dequeue()" (git-fixes).
- wifi: mac80211: Check 802.11 encaps offloading in
  ieee80211_tx_h_select_key() (git-fixes).
- wifi: mac80211: Don't call fq_flow_idx() for management frames
  (git-fixes).
- wifi: mac80211: Do not schedule stopped TXQs (git-fixes).
- wifi: plfxlc: Fix error handling in usb driver probe
  (git-fixes).
- wifi: mac80211: reject TDLS operations when station is not
  associated (git-fixes).
- wifi: brcmsmac: Remove const from tbl_ptr parameter in
  wlc_lcnphy_common_read_table() (git-fixes).
- mwl8k: Add missing check after DMA map (git-fixes).
- iwlwifi: Add missing check for alloc_ordered_workqueue
  (git-fixes).
- wifi: iwlwifi: Fix memory leak in iwl_mvm_init() (git-fixes).
- wifi: rtl818x: Kill URBs before clearing tx status queue
  (git-fixes).
- wifi: rtw89: avoid NULL dereference when RX problematic packet
  on unsupported 6 GHz band (git-fixes).
- commit 338f129

- usb: gadget: configfs: Fix OOB read on empty string write
  (CVE-2025-38497 bsc#1247347).
- commit 96c22e3

- fs: export anon_inode_make_secure_inode() and fix secretmem
  LSM bypass (CVE-2025-38396 bsc#1247156).
- commit 281f5f1

- wifi: ath12k: fix GCC_GCC_PCIE_HOT_RST definition for WCN7850
  (CVE-2025-38414 bsc#1247145).
- commit be37365

- Docs/ABI: Fix sysfs-kernel-address_bits path (git-fixes).
- soc: qcom: pmic_glink: fix OF node leak (git-fixes).
- soc: qcom: fix endianness for QMI header (git-fixes).
- soc: qcom: QMI encoding/decoding for big endian (git-fixes).
- soc/tegra: cbb: Clear ERR_FORCE register with ERR_STATUS
  (git-fixes).
- usb: musb: omap2430: fix device leak at unbind (git-fixes).
- usb: gadget: udc: renesas_usb3: fix device leak at unbind
  (git-fixes).
- usb: dwc3: meson-g12a: fix device leaks at unbind (git-fixes).
- usb: atm: cxacru: Merge cxacru_upload_firmware() into
  cxacru_heavy_init() (git-fixes).
- thunderbolt: Fix copy+paste error in match_service_id()
  (git-fixes).
- usb: typec: ucsi: Update power_supply on power role change
  (git-fixes).
- usb: gadget : fix use-after-free in composite_dev_cleanup()
  (git-fixes).
- cdc-acm: fix race between initial clearing halt and open
  (git-fixes).
- usb: early: xhci-dbc: Fix early_ioremap leak (git-fixes).
- usb: misc: apple-mfi-fastcharge: Make power supply names unique
  (git-fixes).
- Documentation: usb: gadget: Wrap remaining usage snippets in
  literal code block (git-fixes).
- usb: host: xhci-plat: fix incorrect type for of_match variable
  in xhci_plat_probe() (git-fixes).
- vt: defkeymap: Map keycodes above 127 to K_HOLE (git-fixes).
- vt: keyboard: Don't process Unicode characters in K_OFF mode
  (git-fixes).
- staging: axis-fifo: remove sysfs interface (git-fixes).
- staging: nvec: Fix incorrect null termination of battery
  manufacturer (git-fixes).
- staging: fbtft: fix potential memory leak in
  fbtft_framebuffer_alloc() (git-fixes).
- iio: adc: ad_sigma_delta: change to buffer predisable
  (git-fixes).
- iio: imu: bno055: fix OOB access of hw_xlate array (git-fixes).
- bus: mhi: host: Detect events pointing to unexpected TREs
  (git-fixes).
- misc: rtsx: usb: Ensure mmc child device is active when card
  is present (git-fixes).
- vmci: Prevent the dispatching of uninitialized payloads
  (git-fixes).
- samples: mei: Fix building on musl libc (git-fixes).
- platform/chrome: cros_ec: Unregister notifier in
  cros_ec_unregister() (git-fixes).
- gpio: virtio: Fix config space reading (git-fixes).
- ASoC: ops: dynamically allocate struct snd_ctl_elem_value
  (git-fixes).
- ASoC: soc-dai: tidyup return value of
  snd_soc_xlate_tdm_slot_mask() (git-fixes).
- Documentation: ACPI: Fix parent device references (git-fixes).
- ACPI: LPSS: Remove AudioDSP related ID (git-fixes).
- ACPI: processor: perflib: Fix initial _PPC limit application
  (git-fixes).
- powercap: dtpm_cpu: Fix NULL pointer dereference in
  get_pd_power_uw() (git-fixes).
- PM / devfreq: Check governor before using governor->name
  (git-fixes).
- commit fbd21ae

- apple-mfi-fastcharge: protect first device name (git-fixes).
- commit 903dc58

- vsock/vmci: Clear the vmci transport packet properly when
  initializing it (CVE-2025-38403 bsc#1247141).
- commit 6379963

- KVM: SVM: Reject SEV{-ES} intra host migration if vCPU creation
  is in-flight (CVE-2025-38455 bsc#1247101).
- commit ca76701

- vsock: Fix transport_* TOCTOU (CVE-2025-38461 bsc#1247103).
- commit 916fdd6

- eventpoll: don't decrement ep refcount while still holding
  the ep mutex (bsc#1246777 CVE-2025-38349).
- commit 6c5e857

- jbd2: fix data-race and null-ptr-deref in
  jbd2_journal_dirty_metadata() (bsc#1246253 CVE-2025-38337).
- commit 4cfb834

- ext4: inline: fix len overflow in ext4_prepare_inline_data
  (bsc#1245976 CVE-2025-38222).
- commit bdddb2f

- ublk: santizize the arguments from userspace when adding a
  device (bsc#1245937 CVE-2025-38182).
- commit c70260e

- __legitimize_mnt(): check for MNT_SYNC_UMOUNT should be under
  mount_lock (bsc#1245151 CVE-2025-38058).
- commit 5d79b46

- xfs: remove unused trace event xfs_reflink_cow_enospc
  (git-fixes).
- commit 43f2e3c

- xfs: only create event xfs_file_compat_ioctl when CONFIG_COMPAT
  is configure (git-fixes).
- commit 90cf0ff

- xfs: remove usused xfs_end_io_direct events (git-fixes).
- commit 973d0e0

- xfs: remove unused event xfs_pagecache_inval (git-fixes).
- commit 92f5436

- xfs: remove unused event xfs_alloc_near_nominleft (git-fixes).
- commit cce777b

- xfs: remove unused event xfs_alloc_near_error (git-fixes).
- commit 5b572bf

- xfs: remove unused event xfs_attr_node_removename (git-fixes).
- commit 4753b23

- xfs: remove unused xfs_attr events (git-fixes).
- commit 1b0cc0c

- xfs: remove unused trace event xfs_attr_rmtval_set (git-fixes).
- commit d855e56

- xfs: remove unused xfs_reflink_compare_extents events
  (git-fixes).
- commit a7afc4b

- xfs: remove unused event xfs_ioctl_clone (git-fixes).
- commit b5dfc1b

- xfs: remove unused event xlog_iclog_want_sync (git-fixes).
- commit 217c9f9

- xfs: remove unused trace event xfs_attr_remove_iter_return
  (git-fixes).
- commit 70b1bc5

- NFSD: detect mismatch of file handle and delegation stateid
  in OPEN op (git-fixes).
- commit 00b51c6

- nfsd: handle get_client_locked() failure in
  nfsd4_setclientid_confirm() (git-fixes).
- commit b0cf612

- hfsplus: remove mutex_lock check in hfsplus_free_extents
  (git-fixes).
- commit e14f374

- s390/entry: Fix last breaking event handling in case of stack
  corruption (git-fixes bsc#1243806).
- commit d31e65a

- hfs: make splice write available again (git-fixes).
- commit 96498bf

- hfsplus: make splice write available again (git-fixes).
- commit 5121068

- Refresh
  patches.suse/btrfs-always-fallback-to-buffered-write-if-the-inode.patch.
  To remove an incorrectly generated file which is not utilized at all.
- commit 8e57a15

- btrfs: fix non-empty delayed iputs list on unmount due to
  async workers (git-fixes).
- commit 285c1f5

- btrfs: fix assertion when building free space tree (git-fixes).
- commit a3fd65f

- btrfs: fix iteration of extrefs during log replay (bsc#1247031
  CVE-2025-38382).
- commit 5e64fe6

- btrfs: fix missing error handling when searching for inode
  refs during log replay (git-fixes).
- commit a8205e6

- i2c: qup: jump out of the loop in case of timeout (git-fixes).
- i2c: virtio: Avoid hang by using interruptible completion wait
  (git-fixes).
- i2c: tegra: Fix reset error handling with ACPI (git-fixes).
- commit 5a2e6c7

- btrfs: fix a race between renames and directory logging
  (bsc#1247023 CVE-2025-38365).
- commit 322c28e

- supported.conf: move nvme-apple to optional again
- commit a3e3a0c

- llist: add interface to check if a node is on a list
  (CVE-2025-38264 bsc#1246387).
- commit f06e99c

- nvme-tcp: sanitize request list handling (CVE-2025-38264
  bsc#1246387).
- commit 33933f9

- supported.conf: sort entries again
- commit 2db834f

- supported.conf: add missing entries for armv7hl
- commit 3fcf489

- nilfs2: reject invalid file types when reading inodes
  (git-fixes).
- commit b094111

- resource: fix false warning in __request_region() (git-fixes).
- bus: fsl-mc: Fix potential double device reference in
  fsl_mc_get_endpoint() (git-fixes).
- USB: serial: option: add Telit Cinterion FE910C04 (ECM)
  composition (stable-fixes).
- USB: serial: ftdi_sio: add support for NDI EMGUIDE GEMINI
  (stable-fixes).
- USB: serial: option: add Foxconn T99W640 (stable-fixes).
- iio: adc: max1363: Reorder mode_list[] entries (stable-fixes).
- iio: adc: max1363: Fix MAX1363_4X_CHANS/MAX1363_8X_CHANS[]
  (stable-fixes).
- ALSA: hda/realtek: Add quirk for ASUS ROG Strix G712LWS
  (stable-fixes).
- HID: core: do not bypass hid_hw_raw_request (stable-fixes).
- HID: core: ensure the allocated report buffer can contain the
  reserved report ID (stable-fixes).
- regulator: pwm-regulator: Calculate the output voltage for
  disabled PWMs (stable-fixes).
- commit 829a426

- rpm/kernel-subpackage-spec: Skip brp-strip-debug to avoid file truncation (bsc#1246879)
  Put the same workaround to avoid file truncation of vmlinux and co in
  kernel-default-base package, too.
- commit 2329734

- iommu/vt-d: Fix possible circular locking dependency
  (git-fixes).
- commit 0774c7d

- drm/bridge: ti-sn65dsi86: Remove extra semicolon in
  ti_sn_bridge_probe() (git-fixes).
- drm/sched: Remove optimization that causes hang when killing
  dependent jobs (git-fixes).
- platform/x86: ideapad-laptop: Fix kbd backlight not remembered
  among boots (git-fixes).
- commit 0083a37

- iommu/vt-d: Fix system hang on reboot -f (git-fixes).
- commit 034e69f

- rpm/kernel-binary.spec.in: Ignore return code from ksymtypes compare
  When using suse-kabi-tools, the RPM build invokes 'ksymvers compare' to
  compare the resulting symbol CRCs with the reference data. If the values
  differ, it then invokes 'ksymtypes compare' to provide a detailed report
  explaining why the symbols differ. The build expects the latter
  'ksymtypes compare' command to always return zero, even if the two
  compared kABI corpuses are different.
  This is currently the case for 'ksymtypes compare'. However, I plan to
  update the command to return a non-zero code when the comparison detects
  any differences. This should ensure consistent behavior with 'ksymvers
  compare'.
  Since the build uses 'ksymtypes compare' only for more detailed
  diagnostics, ignore its return code.
- commit 5ac1381

- net: atm: fix /proc/net/atm/lec handling (CVE-2025-38180
  bsc#1245970).
- net: atm: add lec_mutex (CVE-2025-38323 bsc#1246473).
- commit 1698a7c

- KVM: x86: Load DR6 with guest value only before entering .vcpu_run() loop (bsc#1239061 CVE-2025-21839).
- commit fe1f630

- net: dsa: b53: do not enable EEE on bcm63xx (CVE-2025-38272
  bsc#1246268).
- commit ee16b59

- Refresh
  patches.suse/selftests-bpf-Clean-up-open-coded-gettid-syscall-inv.patch.
  Fix following BPF selftests compilation error due to missing dependency.
  /home/runner/work/libbpf/libbpf/.kernel/tools/testing/selftests/bpf/prog_tests/ns_current_pid_tgid.c: In function ‘test_current_pid_tgid’:
  /home/runner/work/libbpf/libbpf/.kernel/tools/testing/selftests/bpf/prog_tests/ns_current_pid_tgid.c:31:9: error: invalid type argument of unary ‘*’ (have ‘pid_t’ {aka ‘int’})
    31 |         *pid = sys_gettid();
    |         ^~~~
- commit d85d5ff

- Delete
  patches.suse/selftests-bpf-Add-tests-for-sdiv-smod-overflow-cases.patch.
  The __arch_x86_64 macro is not yet supported in BPF selftests (depends
  on c64d2f72bf2e "selftests/bpf: *_arch** macro to limit test cases to
  specific archs"), so drop tests that uses it.
- commit 55e800e

- Bluetooth: hci_sync: Fix UAF on create_le_conn_complete
  (git-fixes).
- commit 7a089da

- hci_dev centralize extra lock (CVE-2025-38117 bsc#1245695).
- commit 892de21

- Bluetooth: MGMT: Protect mgmt_pending list with its own lock
  (CVE-2025-38117 bsc#1245695).
- commit e0d8b29

- Bluetooth: hci_sync: Introduce
  hci_cmd_sync_run/hci_cmd_sync_run_once (CVE-2025-38117
  bsc#1245695).
- commit c86dd9a

- Bluetooth: hci_core: Make hci_is_le_conn_scanning public
  (CVE-2025-38117 bsc#1245695).
- Refresh
  patches.suse/Bluetooth-hci_sync-Use-QoS-to-determine-which-PHY-to.patch.
- commit 566b348

- Bluetooth: hci_sync: Fix handling of HCI_OP_CREATE_CONN_CANCEL
  (git-fixes).
- commit 79fc3de

- gpiolib: of: Add polarity quirk for s5m8767 (stable-fixes).
- gpio: vf610: add locking to gpio direction functions
  (git-fixes).
- gpio: pca953x: log an error when failing to get the reset GPIO
  (git-fixes).
- gpiolib: cdev: Ignore reconfiguration without direction
  (git-fixes).
- gpiolib: acpi: Fix failed in acpi_gpiochip_find() by adding
  parent node match (bsc#1233300).
- gpiolib: Fix debug messaging in gpiod_find_and_request()
  (git-fixes).
- gpiolib: Handle no pin_ranges in gpiochip_generic_config()
  (git-fixes).
- gpio: sim: include a missing header (git-fixes).
- gpiolib: acpi: Don't use GPIO chip fwnode in
  acpi_gpiochip_find() (bsc#1233300).
- commit 75afc01

- Bluetooth: MGMT: convert timeouts to secs_to_jiffies()
  (CVE-2025-38117 bsc#1245695).
- commit 3e2758a

- bluetooth: mgmt: convert timeouts to secs_to_jiffies()
  (CVE-2025-38117 bsc#1245695).
- commit b8976eb

- s390/bpf: Fix bpf_arch_text_poke() with new_addr == NULL again
  (git-fixes bsc#1246870).
- commit 8e4fb25

- Fix build warning
  Refresh
  patches.suse/mm-hugetlb-fix-DEBUG_LOCKS_WARN_ON-1-when-dissolve_f.patch.
- commit ccb6e90

- Bluetooth: MGMT: Fix not generating command complete for
  MGMT_OP_DISCONNECT (git-fixes).
- Refresh
  patches.suse/Bluetooth-hci_event-Fix-not-using-key-encryption-siz.patch.
- commit 6f743e7

- Bluetooth: hci_sync: Attempt to dequeue connection attempt
  (git-fixes).
- Refresh
  patches.suse/Bluetooth-L2CAP-Fix-slab-use-after-free-Read-in-l2ca.patch.
- Refresh
  patches.suse/Bluetooth-hci_event-Fix-not-using-key-encryption-siz.patch.
- Refresh
  patches.suse/Bluetooth-hci_sync-Fix-UAF-in-hci_acl_create_conn_sy.patch.
- commit 22a7d25

- Bluetooth: hci_conn: Fix sending
  BT_HCI_CMD_LE_CREATE_CONN_CANCEL (git-fixes).
- commit defb49e

- Bluetooth: mgmt: remove NULL check in
  add_ext_adv_params_complete() (CVE-2025-38117 bsc#1245695).
- Bluetooth: mgmt: remove NULL check in
  mgmt_set_connectable_complete() (CVE-2025-38117 bsc#1245695).
- commit 3217653

- bluetooth: restore le_scan_restart in struct hci_dev
  (CVE-2025-38117 bsc#1245695).
- commit 7e7eb69

- Bluetooth: hci_core: Remove le_restart_scan work (CVE-2025-38117
  bsc#1245695).
- commit 9530108

- Input: gpio-keys - fix a sleep while atomic with PREEMPT_RT
  (CVE-2025-38335 bsc#1246250).
- commit 4b421f0

- Correctly put RDMA kabi patch into patches.kabi instead of patches.suse
- commit 0433d1f

- kABI workaround for bluetooth hci_dev changes (CVE-2025-38250
  bsc#1246182).
- commit 2bfeee5

- Bluetooth: hci_core: Fix use-after-free in vhci_flush()
  (CVE-2025-38250 bsc#1246182).
- commit 45dea35

- selftests/bpf: Support more socket types in create_pair()
  (bsc#1239470 CVE-2025-21854).
- selftests/bpf: Refactor out helper functions for a few tests
  (bsc#1239470 CVE-2025-21854).
- commit 21d7fea

- mm/hugetlb: fix DEBUG_LOCKS_WARN_ON(1) when
  dissolve_free_hugetlb_folio() (bsc#1225707 CVE-2024-36028).
- commit ce47e5b

- Delete
  patches.suse/selftest-bpf-Add-test-for-af_vsock-poll.patch.
  It requires the "bpf_program__attach_sockmap" API in libbpf, which isn't
  backported.
- Refresh patches.suse/selftest-bpf-Add-vsock-test-for-sockmap-rejecting-un.patch
- commit a7dddad

- i2c: stm32: fix the device used for the DMA map (git-fixes).
- usb: hub: Don't try to recover devices lost during warm reset
  (git-fixes).
- usb: musb: fix gadget state on disconnect (git-fixes).
- thunderbolt: Fix bit masking in tb_dp_port_set_hops()
  (git-fixes).
- thunderbolt: Fix wake on connect at runtime (git-fixes).
- pch_uart: Fix dma_sync_sg_for_device() nents value (git-fixes).
- comedi: Fix initialization of data for instructions that write
  to subdevice (git-fixes).
- comedi: Fix use of uninitialized data in insn_rw_emulate_bits()
  (git-fixes).
- comedi: das6402: Fix bit shift out of bounds (git-fixes).
- comedi: aio_iiro_16: Fix bit shift out of bounds (git-fixes).
- comedi: pcl812: Fix bit shift out of bounds (git-fixes).
- comedi: das16m1: Fix bit shift out of bounds (git-fixes).
- comedi: Fix some signed shift left operations (git-fixes).
- comedi: Fail COMEDI_INSNLIST ioctl if n_insns is too large
  (git-fixes).
- iio: adc: ad7949: use spi_is_bpw_supported() (git-fixes).
- iio: accel: fxls8962af: Fix use after free in
  fxls8962af_fifo_flush (git-fixes).
- iio: adc: stm32-adc: Fix race in installing chained IRQ handler
  (git-fixes).
- regmap: fix potential memory leak of regmap_bus (git-fixes).
- Input: xpad - set correct controller type for Acer NGR200
  (git-fixes).
- commit 08dfa63

- jfs: Fix null-ptr-deref in jfs_ioc_trim (bsc#1246044
  CVE-2025-38203).
- commit e88ea13

- hwmon: (corsair-cpro) Validate the size of the received input
  buffer (git-fixes).
- drm/amdgpu/gfx8: reset compute ring wptr on the GPU on resume
  (git-fixes).
- soundwire: amd: fix for clearing command status register
  (git-fixes).
- dmaengine: nbpfaxi: Fix memory corruption in probe()
  (git-fixes).
- phy: tegra: xusb: Fix unbalanced regulator disable in UTMI
  PHY mode (git-fixes).
- memstick: core: Zero initialize id_reg in
  h_memstick_read_dev_id() (git-fixes).
- mmc: bcm2835: Fix dma_unmap_sg() nents value (git-fixes).
- mmc: sdhci_am654: Workaround for Errata i2312 (git-fixes).
- mmc: sdhci-pci: Quirk for broken command queuing on Intel
  GLK-based Positivo models (git-fixes).
- commit 0d9aae2

- net/sched: Return NULL when htb_lookup_leaf encounters an
  empty rbtree (git-fixes).
- commit fb42307

- ipv6: mcast: Delay put pmc->idev in mld_del_delrec()
  (git-fixes).
- commit 505c14c

- rpl: Fix use-after-free in rpl_do_srh_inline() (git-fixes).
- commit 3342938

- af_packet: fix the SO_SNDTIMEO constraint not effective on
  tpacked_snd() (git-fixes).
- commit 877c186

- net/sched: sch_qfq: Fix race condition on qfq_aggregate
  (git-fixes).
- commit 2e8a829

- kABI workaround for struct drm_framebuffer changes (git-fixes).
- commit 7b3cefa

- drm/framebuffer: Acquire internal references on GEM handles
  (git-fixes).
- commit 736ff8d

- Bluetooth: L2CAP: Fix attempting to adjust outgoing MTU
  (git-fixes).
- Bluetooth: btusb: QCA: Fix downloading wrong NVM for WCN6855
  GF variant without board ID (git-fixes).
- Bluetooth: SMP: Fix using HCI_ERROR_REMOTE_USER_TERM on timeout
  (git-fixes).
- Bluetooth: SMP: If an unallowed command is received consider
  it a failure (git-fixes).
- Bluetooth: hci_sync: fix connectable extended advertising when
  using static random address (git-fixes).
- Bluetooth: Fix null-ptr-deref in l2cap_sock_resume_cb()
  (git-fixes).
- usb: net: sierra: check for no status endpoint (git-fixes).
- net: phy: Don't register LEDs for genphy (git-fixes).
- drm/gem: Fix race in drm_gem_handle_create_tail()
  (stable-fixes).
- wifi: prevent A-MSDU attacks in mesh networks (stable-fixes).
- Revert "ACPI: battery: negate current when discharging"
  (stable-fixes).
- usb: cdnsp: Fix issue with CV Bad Descriptor test (git-fixes).
- drm/gem: Acquire references on GEM handles for framebuffers
  (stable-fixes).
- vt: add missing notification when switching back to text mode
  (stable-fixes).
- ASoC: amd: yc: add quirk for Acer Nitro ANV15-41 internal mic
  (stable-fixes).
- ALSA: hda/realtek - Enable mute LED on HP Pavilion Laptop
  15-eg100 (stable-fixes).
- HID: lenovo: Add support for ThinkPad X1 Tablet Thin Keyboard
  Gen2 (stable-fixes).
- HID: Add IGNORE quirk for SMARTLINKTECHNOLOGY (stable-fixes).
- HID: quirks: Add quirk for 2 Chicony Electronics HP 5MP Cameras
  (stable-fixes).
- net: usb: qmi_wwan: add SIMCom 8230C composition (stable-fixes).
- usb: cdnsp: Replace snprintf() with the safer scnprintf()
  variant (stable-fixes).
- usb:cdnsp: remove TRB_FLUSH_ENDPOINT command (stable-fixes).
- commit b8ce602

- Refresh
  patches.suse/selftests-bpf-Add-tests-for-iter-next-method-returni.patch.
  Fix BPF selftests build failure in progs/iters_testmod.c due to missing
  definition of 'struct bpf_iter_task_vma' and 'bpf_iter_task_vma()'.
- commit ca03a47

- ptp: fix breakage after ptp_vclock_in_use() rework
  (bsc#1246506).
- commit 001cddf

- x86/virt/tdx: Avoid indirect calls to TDX assembly functions (git-fixes).
- commit 9c296c1

- soc: aspeed: lpc-snoop: Don't disable channels that aren't
  enabled (git-fixes).
- soc: aspeed: lpc-snoop: Cleanup resources in stack-order
  (git-fixes).
- HID: core: ensure __hid_request reserves the report ID as the
  first byte (git-fixes).
- commit 5cd5cd3

- drm/msm/a7xx: Call CP_RESET_CONTEXT_STATE (CVE-2025-38188
  bsc#1246098).
- drm/msm/a6xx+: Insert a fence wait before SMMU table update
  (CVE-2025-38188 bsc#1246098).
- commit e22ddaf

- x86/iopl: Cure TIF_IO_BITMAP inconsistencies (CVE-2025-38100
  bsc#1245650).
- commit 143bbc6

- Bluetooth: eir: Fix possible crashes on eir_create_adv_data
  (CVE-2025-38303 bsc#1246354).
- commit 89447f6

- btrfs: explicitly ref count block_group on new_bgs list (bsc#1243068)
- commit 8647d2c

- btrfs: make btrfs_discard_workfn() block_group ref explicit (bsc#1243068)
- commit 32e19f5

- btrfs: harden block_group::bg_list against list_del() races (CVE-2025-37856 bsc#1243068)
- commit 3333359

- btrfs: correct the order of prelim_ref arguments in btrfs__prelim_ref (CVE-2025-38034 bsc#1244792)
- commit 55c0ec4

- btrfs: do not BUG_ON() when freeing tree block after error (CVE-2024-44963 1230216)
- commit d292416

- scsi: megaraid_sas: Fix invalid node index (CVE-2025-38239
  bsc#1246178).
- seg6: Fix validation of nexthop addresses (CVE-2025-38310
  bsc#1246361).
- x86/sgx: Prevent attempts to reclaim poisoned pages
  (CVE-2025-38334 bsc#1246384).
- commit 740f6c2

- selftests/bpf: Add tests with stack ptr register in conditional
  jmp (bsc#1246264 CVE-2025-38279).
- bpf: Do not include stack ptr register in precision backtracking
  bookkeeping (bsc#1246264 CVE-2025-38279).
- Refresh patches.kabi/bpf-verifier-kABI-workarounds.patch
- commit ccc2c5b

- bridge: mcast: Fix use-after-free during router port
  configuration (CVE-2025-38248 bsc#1246173).
- net: stmmac: make sure that ptp_rate is not 0 before configuring
  timestamping (CVE-2025-38126 bsc#1245708).
- bpf: fix ktls panic with sockmap (CVE-2025-38166 bsc#1245758).
- commit 01133bb

- iommu/amd: Set the pgsize_bitmap correctly (git-fixes).
- commit 8746ec5

- scsi: core: Enforce unlimited max_segment_size when
  virt_boundary_mask is set (git-fixes).
- scsi: qla4xxx: Fix missing DMA mapping error in
  qla4xxx_alloc_pdu() (git-fixes).
- scsi: qla2xxx: Fix DMA mapping test in
  qla24xx_get_port_database() (git-fixes).
- scsi: megaraid_sas: Fix invalid node index (git-fixes).
- aoe: clean device rq_list in aoedev_downdev() (git-fixes).
- md/md-bitmap: fix dm-raid max_write_behind setting (git-fixes).
- commit 2e07501

- dm-bufio: fix sched in atomic context (git-fixes).
- commit c664ddf

- Update
  patches.suse/nvme-pci-fix-queue-unquiesce-check-on-slot_reset.patch
  (git-fixes bsc#1240885).
- commit 08c0025

- perf: Fix sample vs do_exit() (bsc#1246547).
- commit 5327721

- nvme-pci: refresh visible attrs after being checked (git-fixes).
- nvme: Fix incorrect cdw15 value in passthru error logging
  (git-fixes).
- commit c5d3460

- scsi: lpfc: Copyright updates for 14.4.0.10 patches (bsc#1245260
  bsc#1243100 bsc#1246125).
- commit 58f7c6e

- scsi: lpfc: Update lpfc version to 14.4.0.10 (bsc#1245260
  bsc#1243100 bsc#1246125).
- scsi: lpfc: Modify end-of-life adapters' model descriptions
  (bsc#1245260 bsc#1243100 bsc#1246125 bsc#1204142).
- scsi: lpfc: Revise CQ_CREATE_SET mailbox bitfield definitions
  (bsc#1245260 bsc#1243100 bsc#1246125).
- scsi: lpfc: Move clearing of HBA_SETUP flag to before
  lpfc_sli4_queue_unset (bsc#1245260 bsc#1243100 bsc#1246125).
- scsi: lpfc: Ensure HBA_SETUP flag is used only for SLI4 in
  dev_loss_tmo_callbk (bsc#1245260 bsc#1243100 bsc#1246125).
- scsi: lpfc: Relocate clearing initial phba flags from link up
  to link down hdlr (bsc#1245260 bsc#1243100 bsc#1246125).
- scsi: lpfc: Simplify error handling for failed
  lpfc_get_sli4_parameters cmd (bsc#1245260 bsc#1243100
  bsc#1246125).
- scsi: lpfc: Early return out of FDMI cmpl for locally rejected
  statuses (bsc#1245260 bsc#1243100 bsc#1246125).
- scsi: lpfc: Skip RSCN processing when FC_UNLOADING flag is set
  (bsc#1245260 bsc#1243100 bsc#1246125).
- scsi: lpfc: Check for hdwq null ptr when cleaning up lpfc_vport
  structure (bsc#1245260 bsc#1243100 bsc#1246125).
- scsi: lpfc: Update debugfs trace ring initialization messages
  (bsc#1245260 bsc#1243100 bsc#1246125).
- scsi: lpfc: Revise logging format for failed CT MIB requests
  (bsc#1245260 bsc#1243100 bsc#1246125).
- commit 14dcfed

- Update
  patches.suse/net-clear-the-dst-when-changing-skb-protocol.patch
  (bsc#1245954 CVE-2025-38192).
  Fix incorrect CVE reference.
- commit 288e8f6

- drm/nouveau: fix a use-after-free in r535_gsp_rpc_push() (bsc#1245951 CVE-2025-38187)
- commit 62c6956

- bpf: Check rcu_read_lock_trace_held() in
  bpf_map_lookup_percpu_elem() (bsc#1245980 CVE-2025-38202).
- commit 630834e

- selftest/bpf/benchs: Add benchmark for sockmap usage
  (bsc#1245749 CVE-2025-38154).
- commit ac96089

- bpf, sockmap: Avoid using sk_socket after free when sending
  (bsc#1245749 CVE-2025-38154).
- bpf, sockmap: Fix panic when calling skb_linearize (bsc#1245749
  CVE-2025-38154).
- bpf, sockmap: fix duplicated data transmission (bsc#1245749
  CVE-2025-38154).
- bpf, sockmap: Fix data lost during EAGAIN retries (bsc#1245749
  CVE-2025-38154).
- commit bc1361f

- bpf: Fix memory leak in bpf_core_apply (git-fixes).
- commit 44b4ba3

- bpf/selftests: Check errno when percpu map value size exceeds
  (git-fixes).
- bpf: Check percpu map value size first (git-fixes).
- commit 81feacb

- bpftool: Fix undefined behavior caused by shifting into the
  sign bit (git-fixes).
- commit 9363920

- ipc: fix to protect IPCS lookups using RCU (CVE-2025-38212
  bsc#1246029).
- commit 9ff5b2e

- calipso: unlock rcu before returning -EAFNOSUPPORT
  (CVE-2025-38147 bsc#1245768).
- calipso: Don't call calipso functions for AF_INET sk
  (CVE-2025-38147 bsc#1245768).
- commit 74ee184

- ucsi_operations: add stubs for all operations (git-fixes).
- commit 1e9baf6

- drm/amd/display: Don't treat wb connector as physical in (bsc#1245654 CVE-2025-38098)
- commit 277f764

- selftests/bpf: Add tests for iter next method returning valid
  pointer (git-fixes).
- bpf: Make the pointer returned by iter next method valid
  (git-fixes).
- commit fcdc4ee

- hisi_acc_vfio_pci: bugfix live migration function without VF
  device driver (CVE-2025-38283 bsc#1246273).
- configfs-tsm-report: Fix NULL dereference of tsm_ops
  (CVE-2025-38210 bsc#1246020).
- commit eef28a4

- kasan: remove kasan_find_vm_area() to prevent possible deadlock
  (git-fixes).
- maple_tree: fix mt_destroy_walk() on root leaf node (git-fixes).
- commit aaacc92

- drm/tegra: nvdec: Fix dma_alloc_coherent error check
  (git-fixes).
- nbd: fix uaf in nbd_genl_connect() error path (git-fixes).
- can: m_can: m_can_handle_lost_msg(): downgrade msg lost in rx
  message to debug level (git-fixes).
- net: phy: microchip: limit 100M workaround to link-down events
  on LAN88xx (git-fixes).
- wifi: mt76: mt7925: Fix null-ptr-deref in mt7925_thermal_init()
  (git-fixes).
- wifi: mt76: mt7925: fix invalid array index in ssid assignment
  during hw scan (git-fixes).
- wifi: mt76: mt7925: fix the wrong config for tx interrupt
  (git-fixes).
- wifi: zd1211rw: Fix potential NULL pointer dereference in
  zd_mac_tx_to_dev() (git-fixes).
- commit 067b949

- xfs: fix off-by-one error in fsmap's end_daddr usage
  (bsc#1235837).
- commit 919d943

- hisi_acc_vfio_pci: fix XQE dma address error (CVE-2025-38158
  bsc#1245750).
- commit 373ef61

- i40e: fix MMIO write access to an invalid page in i40e_clear_hw
  (CVE-2025-38200 bsc#1246045).
- net: cadence: macb: Fix a possible deadlock in macb_halt_tx
  (CVE-2025-38094 bsc#1245649).
- commit 45301b8

- platform/x86: think-lmi: Create ksets consecutively
  (stable-fixes).
- Refresh
  patches.suse/platform-x86-think-lmi-Fix-kobject-cleanup.patch.
- commit 5072bed

- net: phy: smsc: Fix link failure in forced mode with Auto-MDIX
  (git-fixes).
- net: phy: smsc: Fix Auto-MDIX configuration when disabled by
  strap (git-fixes).
- Bluetooth: hci_event: Fix not marking Broadcast Sink BIS as
  connected (git-fixes).
- Bluetooth: hci_sync: Fix not disabling advertising instance
  (git-fixes).
- usb: xhci: quirk for data loss in ISOC transfers (stable-fixes).
- Logitech C-270 even more broken (stable-fixes).
- Input: xpad - support Acer NGR 200 Controller (stable-fixes).
- dma-buf: fix timeout handling in dma_resv_wait_timeout v2
  (stable-fixes).
- mmc: sdhci: Add a helper function for dump register in dynamic
  debug mode (stable-fixes).
- ACPICA: Refuse to evaluate a method if arguments are missing
  (stable-fixes).
- mtd: spinand: fix memory leak of ECC engine conf (stable-fixes).
- ASoC: amd: yc: update quirk data for HP Victus (stable-fixes).
- ASoC: amd: yc: Add quirk for MSI Bravo 17 D7VF internal mic
  (stable-fixes).
- ALSA: sb: Force to disable DMAs once when DMA mode is changed
  (stable-fixes).
- ALSA: sb: Don't allow changing the DMA mode during operations
  (stable-fixes).
- drm/msm: Fix another leak in the submit error path
  (stable-fixes).
- drm/msm: Fix a fence leak in submit error path (stable-fixes).
- regulator: fan53555: add enable_time support and soft-start
  times (stable-fixes).
- wifi: ath6kl: remove WARN on bad firmware input (stable-fixes).
- wifi: mac80211: drop invalid source address OCB frames
  (stable-fixes).
- ata: pata_cs5536: fix build on 32-bit UML (stable-fixes).
- platform/x86/amd/pmc: Add PCSpecialist Lafite Pro V 14M to
  8042 quirks list (stable-fixes).
- Revert "drm/i915/gem: Allow EXEC_CAPTURE on recoverable contexts
  on DG1" (stable-fixes).
- wifi: mac80211: Add link iteration macro for link data
  (stable-fixes).
- wifi: mac80211: chan: chandef is non-NULL for reserved
  (stable-fixes).
- commit 66a4a55

- net: clear the dst when changing skb protocol (bsc#1245954
  CVE-2024-49861).
- commit eed1284

- usb: typec: ucsi: Set orientation as none when connector is
  unplugged (git-fixes).
- commit 9b64a84

- usb: typec: ucsi: glink: fix off-by-one in connector_status
  (git-fixes).
- commit 63d64a6

- coresight: prevent deactivate active config while enabling
  the config (CVE-2025-38131 bsc#1245677).
- coresight: holding cscfg_csdev_lock while removing cscfg from
  csdev (CVE-2025-38132 bsc#1245679).
- commit f8db328

- ACPI: PRM: Reduce unnecessary printing to avoid user confusion
  (bsc#1246122).
- commit f060328

- usb: typec: ucsi: Fix busy loop on ASUS VivoBooks (git-fixes).
- usb: typec: ucsi: Fix the partner PD revision (git-fixes).
- commit cb5cfe6

- restore UCSI_CONNECTOR_RESET_HARD definition (git-fixes).
- commit 3a50af7

- usb: typec: ucsi: Add DATA_RESET option of Connector Reset
  command (git-fixes).
- commit ebc917a

- pinctrl: amd: Clear GPIO debounce for suspend (git-fixes).
- pinctrl: qcom: msm: mark certain pins as invalid for interrupts
  (git-fixes).
- commit 7a0a421

- efi/mokvar-table: Avoid repeated map/unmap of the same page
  (bsc#1240323 CVE-2025-21872).
- commit a16e799

- usb: typec: ucsi: move ucsi_acknowledge() from ucsi_read_error()
  (git-fixes).
- commit 9793505

- kabi: restore encap_sk in struct xfrm_state (CVE-2025-38097
  bsc#1245660).
- espintcp: remove encap socket caching to avoid reference leak
  (CVE-2025-38097 bsc#1245660).
- commit 94f2735

- net: lan743x: fix potential out-of-bounds write in
  lan743x_ptp_io_event_clock_get() (CVE-2025-38183 bsc#1246006).
- commit 0eb12cd

- net_sched: sch_sfq: fix a potential crash on gso_skb handling
  (CVE-2025-38115 bsc#1245689).
- commit 6a4ffd3

- usb: typec: ucsi_acpi: Add LG Gram quirk (git-fixes).
- commit da7fb49

- usb: typec: ucsi: don't retrieve PDOs if not supported
  (git-fixes).
- commit d303a5e

- usb: typec: ucsi: Delay alternate mode discovery (git-fixes).
- commit b7ba22d

- usb: typec: Update sysfs when setting ops (git-fixes).
- commit b336d78

- usb: typec: ucsi: glink: increase max ports for x1e80100
  (git-fixes).
- commit 31de9c9

- ucsi_ops: adapt update_connector to kABI consistency
  (git-fixes).
- usb: typec: ucsi: add update_connector callback (git-fixes).
- blacklist.conf: needed for infrastructure. kABI fix added
- Refresh
  patches.kabi/struct-ucsi_operations-use-padding-for-new-operation.patch.
- Refresh patches.suse/paddings-add-paddings-to-TypeC-stuff.patch.
- commit a70b9ee

- ALSA: usb-audio: Kill timer properly at removal (CVE-2025-38105
  bsc#1245682).
- commit 2bf6099

- x86/process: Move the buffer clearing before MONITOR (bsc#1238896 CVE-2024-36350 CVE-2024-36357 CVE-2024-36348 CVE-2024-36349).
- commit 9303368

- usb: typec: ucsi: glink: use typec_set_orientation (git-fixes).
- Refresh
  patches.suse/soc-qcom-pmic_glink-Fix-race-during-initialization.patch.
- Refresh
  patches.suse/usb-typec-ucsi-glink-fix-child-node-release-in-probe.patch.
- commit b105e3e

- KVM: SVM: Advertise TSA CPUID bits to guests (bsc#1238896 CVE-2024-36350 CVE-2024-36357 CVE-2024-36348 CVE-2024-36349).
- commit 67b316f

- Bluetooth: btusb: Fix regression in the initialization of fake
  Bluetooth controllers (CVE-2025-38099 bsc#1245671).
- Bluetooth: Disable SCO support if READ_VOICE_SETTING is
  unsupported/broken (CVE-2025-38099 bsc#1245671).
- Bluetooth: Add quirk for broken READ_PAGE_SCAN_TYPE
  (CVE-2025-38099 bsc#1245671).
- Bluetooth: Add quirk for broken READ_VOICE_SETTING
  (CVE-2025-38099 bsc#1245671).
- commit 254e65a

- jfs: fix array-index-out-of-bounds read in add_missing_indices
  (bsc#1245983 CVE-2025-38204).
- commit 65d9d7f

- usb: typec: ucsi_glink: drop NO_PARTNER_PDOS quirk for sm8550 /
  sm8650 (git-fixes).
- commit 380eca4

- usb: typec: ucsi_glink: enable the UCSI_DELAY_DEVICE_PDOS
  quirk on qcm6490 (git-fixes).
- commit 3de42d7

- usb: typec: ucsi_glink: enable the UCSI_DELAY_DEVICE_PDOS quirk
  (git-fixes).
- commit 2a3ce34

- usb: typec: ucsi_glink: rework quirks implementation
  (git-fixes).
- commit b78f907

- usb: typec: ucsi: support delaying GET_PDOS for device
  (git-fixes).
- Refresh patches.kabi/struct-usci-hide-additional-member.patch.
- commit 95f3b03

- rpm/mkspec: Fix missing kernel-syms-rt creation (bsc#1244337)
- commit 630f139

- usb: typec: ucsi: extract code to read PD caps (git-fixes).
- commit ebc6c46

- usb: typec: ucsi: properly register partner's PD device
  (git-fixes).
- commit 7b95fc1

- usb: typec: ucsi: fix UCSI on SM8550 & SM8650 Qualcomm devices
  (git-fixes).
- commit c40444f

- usb: typec: ucsi: Add qcm6490-pmic-glink as needing PDOS quirk
  (git-fixes).
- commit 46f5c2a

- ucsi_ccg: Refine the UCSI Interrupt handling (git-fixes).
- commit e97f436

- exfat: fix double free in delayed_free (bsc#1246073
  CVE-2025-38206).
- commit 38c1950

- usb: typec: ucsi: Get PD revision for partner (git-fixes).
- commit a80ec70

- x86/bugs: Add a Transient Scheduler Attacks mitigation (bsc#1238896 CVE-2024-36350 CVE-2024-36357 CVE-2024-36348 CVE-2024-36349).
- Update config files.
- commit 45d6a14

- pwm: mediatek: Ensure to disable clocks in error path
  (git-fixes).
- ASoC: cs35l56: probe() should fail if the device ID is not
  recognized (git-fixes).
- ASoC: fsl_asrc: use internal measured ratio for non-ideal
  ratio mode (git-fixes).
- commit 5b2c070

- dm-raid: fix variable in journal device check (git-fixes).
- commit 7e51a3f

- dm-verity: fix a memory leak if some arguments are specified
  multiple times (git-fixes).
- commit 18c3347

- dm-mirror: fix a tiny race condition (git-fixes).
- commit 6d6aef6

- dm-flakey: make corrupting read bios work (git-fixes).
- commit bbf383a

- dm-flakey: error all IOs when num_features is absent
  (git-fixes).
- commit d4d758e

- dm: free table mempools if not used in __bind (git-fixes).
- commit 6abd700

- dm: don't change md if dm_table_set_restrictions() fails
  (git-fixes).
- commit 0d534aa

- dm: restrict dm device size to 2^63-512 bytes (git-fixes).
- commit 240dadc

- virtgpu: don't reset on shutdown (git-fixes).
- commit 82f42df

- kernel/fork: only call untrack_pfn_clear() on VMAs duplicated
  for fork() (git-fix for CVE-2025-22090 bsc#1241537).
- commit 852f7f4

- netfilter: nft_set_pipapo: prevent overflow in lookup table
  allocation (CVE-2025-38162 bsc#1245752).
- commit c7520cc

- efi: Don't map the entire mokvar table to determine its size
  (bsc#1240323 CVE-2025-21872).
- commit aefffb0

- ucsi-glink: adapt to kABI consistency (git-fixes).
- usb: typec: ucsi: glink: move GPIO reading into connector_status
  callback (git-fixes).
- Refresh
  patches.suse/usb-typec-ucsi-Move-unregister-out-of-atomic-section.patch.
- commit 8ae6c79

- vhost-scsi: protect vq->log_used with vq->mutex (CVE-2025-38074
  bsc#1244735).
- commit 29ecfb7

- struct ucsi_operations: use padding for new operation
  (git-fixes).
- commit 5fe6bda

- crypto: ecdsa - Harden against integer overflows in
  DIV_ROUND_UP() (CVE-2025-37984 bsc#1243669).
- commit 4115893

- virtio: break and reset virtio devices on device_shutdown()
  (CVE-2025-38064 bsc#1245201).
- commit 1ef712f

- usb: typec: ucsi: add callback for connector status updates
  (git-fixes).
- blacklist.conf: needed as infrastructure. kABI workaround following
- Refresh patches.suse/paddings-add-paddings-to-TypeC-stuff.patch.
- Refresh
  patches.suse/usb-typec-ucsi-displayport-Fix-deadlock.patch.
- commit de5a5b0

- struct cdns: move new member to the end (git-fixes).
- commit 4384b08

- usb: cdnsp: Fix issue with resuming from L1 (git-fixes).
- commit c8b7c96

- net: dsa: clean up FDB, MDB, VLAN entries on unbind
  (CVE-2025-37864 bsc#1242965).
- commit d1f463e

- NFSv4: Always set NLINK even if the server doesn't support it
  (git-fixes).
- commit 84005c5

- NFSv4.2: fix listxattr to return selinux security label
  (git-fixes).
- commit 0319baa

- NFSv4: xattr handlers should check for absent nfs filehandles
  (git-fixes).
- commit 80ac5a3

- sunrpc: don't immediately retransmit on seqno miss (git-fixes).
- commit ceebf6f

- fs/jfs: consolidate sanity checking in dbMount (git-fixes).
- commit 5c4bc1b

- objtool: Ignore end-of-section jumps for KCOV/GCOV (git-fixes).
- commit e383ffb

- objtool: Silence more KCOV warnings, part 2 (git-fixes).
- commit ddae9d6

- netfilter: nf_set_pipapo_avx2: fix initial map fill (git-fixes
  CVE-2024-57947 bsc#1236333).
- commit cedcb24

- usb: typec: displayport: Fix potential deadlock (git-fixes).
- commit a45e2f9

- drm/bridge: ti-sn65dsi86: Add HPD for DisplayPort connector type
  (git-fixes).
- ASoC: amd: yc: Add DMI quirk for Lenovo IdeaPad Slim 5 15
  (stable-fixes).
- Bluetooth: L2CAP: Fix L2CAP MTU negotiation (stable-fixes).
- drm/amdkfd: Fix race in GWS queue scheduling (stable-fixes).
- ASoC: codecs: wcd9335: Fix missing free of regulator supplies
  (git-fixes).
- ALSA: hda: Ignore unsol events for cards being shut down
  (stable-fixes).
- ALSA: hda: Add new pci id for AMD GPU display HD audio
  controller (stable-fixes).
- usb: dwc2: also exit clock_gating when stopping udc while
  suspended (stable-fixes).
- usb: potential integer overflow in usbg_make_tpg()
  (stable-fixes).
- usb: common: usb-conn-gpio: use a unique name for usb connector
  device (stable-fixes).
- usb: Add checks for snprintf() calls in usb_alloc_dev()
  (stable-fixes).
- usb: cdc-wdm: avoid setting WDM_READ for ZLP-s (stable-fixes).
- usb: typec: displayport: Receive DP Status Update NAK request
  exit dp altmode (stable-fixes).
- usb: typec: mux: do not return on EOPNOTSUPP in {mux,
  switch}_set (stable-fixes).
- iio: pressure: zpa2326: Use aligned_s64 for the timestamp
  (stable-fixes).
- iio: adc: ad_sigma_delta: Fix use of uninitialized status_pos
  (stable-fixes).
- drm/scheduler: signal scheduled fence when kill job
  (stable-fixes).
- amd/amdkfd: fix a kfd_process ref leak (stable-fixes).
- drm/amdgpu: amdgpu_vram_mgr_new(): Clamp lpfn to total vram
  (stable-fixes).
- dmaengine: idxd: Check availability of workqueue allocated by
  idxd wq driver before using (stable-fixes).
- dmaengine: xilinx_dma: Set dma_device directions (stable-fixes).
- PCI: dwc: Make link training more robust by setting
  PORT_LOGIC_LINK_WIDTH to one lane (stable-fixes).
- leds: multicolor: Fix intensity setting while SW blinking
  (stable-fixes).
- mfd: max14577: Fix wakeup source leaks on device unbind
  (stable-fixes).
- hwmon: (pmbus/max34440) Fix support for max34451 (stable-fixes).
- drm/bridge: ti-sn65dsi86: make use of debugfs_init callback
  (stable-fixes).
- ASoC: codec: wcd9335: Convert to GPIO descriptors
  (stable-fixes).
- types: Complement the aligned types with signed 64-bit one
  (stable-fixes).
- ASoC: codecs: wcd9335: Handle nicer probe deferral and simplify
  with dev_err_probe() (stable-fixes).
- commit 9aa1e05

- i2c/designware: Fix an initialization issue (git-fixes).
- commit d80f186

- powercap: intel_rapl: Do not change CLAMPING bit if ENABLE
  bit cannot be changed (git-fixes).
- regulator: gpio: Fix the out-of-bounds access to drvdata::gpiods
  (git-fixes).
- spi: spi-fsl-dspi: Clear completion counter before initiating
  transfer (git-fixes).
- platform/x86: think-lmi: Fix sysfs group cleanup (git-fixes).
- platform/x86: think-lmi: Fix kobject cleanup (git-fixes).
- platform/mellanox: mlxreg-lc: Fix logic error in power state
  check (git-fixes).
- platform/x86: dell-wmi-sysman: Fix WMI data block retrieval
  in sysfs callbacks (git-fixes).
- platform/mellanox: nvsw-sn2201: Fix bus number in adapter
  error message (git-fixes).
- platform/mellanox: mlxbf-pmc: Fix duplicate event ID for
  CACHE_DATA1 (git-fixes).
- platform/mellanox: mlxbf-tmfifo: fix vring_desc.len assignment
  (git-fixes).
- xhci: dbc: Flush queued requests before stopping dbc
  (git-fixes).
- xhci: dbctty: disable ECHO flag by default (git-fixes).
- xhci: Disable stream for xHC controller with XHCI_BROKEN_STREAMS
  (git-fixes).
- usb: typec: altmodes/displayport: do not index invalid
  pin_assignments (git-fixes).
- Revert "usb: xhci: Implement xhci_handshake_check_state()
  helper" (git-fixes).
- usb: xhci: Skip xhci_reset in xhci_resume if xhci is being
  removed (git-fixes).
- usb: gadget: u_serial: Fix race condition in TTY wakeup
  (git-fixes).
- usb: chipidea: udc: disconnect/reconnect from host when do
  suspend/resume (git-fixes).
- usb: cdnsp: do not disable slot for disabled slot (git-fixes).
- Input: iqs7222 - explicitly define number of external channels
  (git-fixes).
- Input: xpad - adjust error handling for disconnect (git-fixes).
- drm/exynos: fimd: Guard display clock control with runtime PM
  calls (git-fixes).
- drm/exynos: exynos7_drm_decon: add vblank check in IRQ handling
  (git-fixes).
- drm/i915/gsc: mei interrupt top half should be in irq disabled
  context (git-fixes).
- drm/i915/gt: Fix timeline left held on VMA alloc error
  (git-fixes).
- drm/i915/selftests: Change mock_request() to return error
  pointers (git-fixes).
- drm/sched: Increment job count before swapping tail spsc queue
  (git-fixes).
- drm/bridge: panel: move prepare_prev_first handling to
  drm_panel_bridge_add_typed (git-fixes).
- drm/ttm: fix error handling in ttm_buffer_object_transfer
  (git-fixes).
- powercap: call put_device() on an error path in
  powercap_register_control_type() (stable-fixes).
- commit d0cb71b

- dm: fix unconditional IO throttle caused by REQ_PREFLUSH
  (CVE-2025-38063 bsc#1245202).
- commit 65fa7b7

- smb: client: Fix use-after-free in cifs_fill_dirent
  (CVE-2025-38051 bsc#1244750).
- commit 0f203bf

- cgroup,freezer: fix incomplete freezing when attaching tasks
  (bsc#1245789).
- commit 1970df7

- cgroup/cpuset: Extend kthread_is_per_cpu() check to all
  PF_NO_SETAFFINITY tasks (bsc#1241166).
- commit 86012b8

- objtool: Stop UNRET validation on UD2 (git-fixes).
- commit 0be0bc6

- objtool: Fix INSN_CONTEXT_SWITCH handling in validate_unret()
  (git-fixes).
- commit f1073e2

- objtool: Properly disable uaccess validation (git-fixes).
- commit b170301

- mm/memory-failure: fix handling of dissolved but not taken
  off from buddy pages (CVE-2024-39298 bsc#1227082).
  Refreshed:
  blacklist.conf: De-blacklist 8cf360b9d6a840700e06864236a01a883b34bbad
- commit 1d1f80f

- rose: fix dangling neighbour pointers in rose_rt_device_down()
  (git-fixes).
- Bluetooth: MGMT: mesh_send: check instances prior disabling
  advertising (git-fixes).
- Bluetooth: MGMT: set_mesh: update LE scan interval and window
  (git-fixes).
- Bluetooth: hci_sync: revert some mesh modifications (git-fixes).
- Bluetooth: Prevent unintended pause by checking if advertising
  is active (git-fixes).
- net: usb: lan78xx: fix WARN in __netif_napi_del_locked on
  disconnect (git-fixes).
- commit 9d01c7e

- objtool: Silence more KCOV warnings (git-fixes).
- commit 246e013

- objtool: Fix error handling inconsistencies in check()
  (git-fixes).
- commit 2b123dd

- objtool: Ignore dangling jump table entries (git-fixes).
- commit 694bcb3

- objtool: Fix UNWIND_HINT_{SAVE,RESTORE} across basic blocks
  (git-fixes).
- commit 24df4fe

- x86/tdx: Fix __noreturn build warning around
  __tdx_hypercall_failed() (git-fixes).
- Refresh
  patches.suse/x86-virt-tdx-Define-TDX-supported-page-sizes-as-macros.patch.
- commit 741a25e

- objtool: Fix _THIS_IP_ detection for cold functions (git-fixes).
- commit b2539b9

- nvmet-tcp: don't restore null sk_state_change (bsc#1244801
  CVE-2025-38035).
- commit a1cc55e

- s390/pci: Fix stale function handles in error handling
  (git-fixes bsc#1245647).
- commit 1f0ecfd

- s390/pci: Do not try re-enabling load/store if device is
  disabled (git-fixes bsc#1245646).
- commit a7a5884

- NFSv4/pNFS: Fix a race to wake on NFS_LAYOUT_DRAIN (git-fixes).
- commit cbe692c

- nfs: Clean up /proc/net/rpc/nfs when nfs_fs_proc_net_init()
  fails (git-fixes).
- commit 29c2a95

- IB/mlx5: Fix potential deadlock in MR deregistration (git-fixes)
- commit a31c762

- RDMA/mlx5: Fix vport loopback for MPV device (git-fixes)
- commit 50aa3ad

- RDMA/mlx5: Fix CC counters query for MPV (git-fixes)
- commit 6fac6aa

- RDMA/mlx5: Fix HW counters query for non-representor devices (git-fixes)
- commit f645a5e

- RDMA/mlx5: Initialize obj_event->obj_sub_list before xa_insert (git-fixes)
- commit 9bf32eb

- mtk-sd: reset host->mrq on prepare_data() error (git-fixes).
- commit 85b8654

- Revert "mmc: sdhci: Disable SD card clock before changing
  parameters" (git-fixes).
- mtk-sd: Prevent memory corruption from DMA map failure
  (git-fixes).
- mtk-sd: Fix a pagefault in dma_unmap_sg() for not prepared data
  (git-fixes).
- mmc: core: sd: Apply BROKEN_SD_DISCARD quirk earlier
  (git-fixes).
- commit 4977a9e

- kABI workaround for xsk: Fix race condition in AF_XDP generic
  RX path (CVE-2025-37920 bsc#1243479).
- commit 2cbaa5f

- xsk: Fix race condition in AF_XDP generic RX path
  (CVE-2025-37920 bsc#1243479).
- commit b0fed9b

- bpf, sockmap: Fix sk_msg_reset_curr (git-fixes).
- commit 3936762

- scsi: s390: zfcp: Ensure synchronous unit_add (git-fixes
  bsc#1245599).
- commit 4cb28a8

- s390/pkey: Prevent overflow in size calculation for
  memdup_user() (git-fixes bsc#1245598).
- commit 458c9d8

- s390: Add z17 elf platform (LTC#214086 bsc#1245540).
- commit a338278

- net: pktgen: fix access outside of user given buffer in
  pktgen_thread_write() (CVE-2025-38061 bsc#1245440).
- commit 386f111

- net: tipc: fix refcount warning in tipc_aead_encrypt
  (CVE-2025-38052 bsc#1244749).
- net/tipc: fix slab-use-after-free Read in tipc_aead_encrypt_done
  (CVE-2025-38052 bsc#1244749).
- commit 39309cf
gcc14
- Exclude shared objects present for link editing in the GCC specific
  subdirectory from provides processing via __provides_exclude_from.
  [bsc#1244050][bsc#1243991]

- Make cross-*-gcc14-bootstrap package conflict with the non-bootstrap
  variant conflict with the unversioned cross-*-gcc package.

- Disable build of glibc cross to loongarch64 and hppa in SLFO
  and SLE15.

- Update to GCC 14.3 release, bb24b4c804f3d95b0ba95b7496, git11799
- Remove gcc14-pr120061.patch which is now included upstream.

- Add gcc14-pr120061.patch to fix the PR108900 fix instead of
  reverting it.
- Remove gcc14-pr108900.patch

- Add gcc14-pr108900.patch to revert it, fixing libqt6webengine build.

- Update to gcc-14 branch head, 3418d740b344e0ba38022f3be, git11702
  * Remove gcc14-pr118780.patch now on the upstream branch
- Fix build on s390x [bsc#1241549]

- Make sure link editing is done against our own shared library
  copy rather than the installed system runtime.  [bsc#1240788]
- Add gcc14-pr119680.patch to fix cross-compiler builds with
  - -enable-host-pie.
avahi
- Add avahi-CVE-2024-52615.patch:
  Backport 4e2e1ea from upstream, Resolve fixed source ports for
  wide-area DNS queries cause DNS responses be injected.
  (CVE-2024-52615, bsc#1233421)
libevent
- Disable the select backend, this can be easily done by lying
  to configure. This is done due to:
  * using fd number > 1024 on an fd_set results in a runtime
    fortify source assertion, preventing further doom.
  * select will not be changed to handle fd > 1024.
  * this limit is unreasonable low for this century.

- Drop insserv_prereq and fillup_prereq macros: there are no
  pre-scripts that would justify these dependencies.

- Update to 2.1.12 stable
  * buffer: do not pass NULL to memcpy() from evbuffer_pullup()
  * http: fix undefined-shift in EVUTIL_IS*_ helpers
  * Check error code of evhttp_add_header_internal() in
    evhttp_parse_query_impl()
  * http: fix EVHTTP_CON_AUTOFREE in case of timeout
  * evdns: Add additional validation for values of dns options
  * Fix memory corruption in EV_CLOSURE_EVENT_FINALIZE with debug enabled
  * increase segment refcnt only if evbuffer_add_file_segment() succeeds
  * evdns: fix a crash when evdns_base with waiting requests is freed
  * event_base_once: fix potential null pointer threat
  * http: do not assume body for CONNECT
  * evbuffer_add_file: fix freeing of segment in the error path
  * Fix checking return value of the evdns_base_resolv_conf_parse()
  * Support EV_CLOSED on linux for poll(2)
  * Parse IPv6 scope IDs.
  * evutil_time: detect and use _gmtime64_s()/_gmtime64()
  * bufferevent: allow setting priority on socket and openssl type
  * Fix EV_CLOSED detection/reporting
  * Revert "Warn if forked from the event loop during event_reinit()"

- Add upstream patches with the feature of "prepare" and "check"
  watchers. That feature is needed by envoy-proxy:
  * 0001-evwatch-Add-prepare-and-check-watchers.patch
  * 0002-evwatch-fix-race-condition.patch

- Update to 2.1.11 stable
  * Fix ABI breakage that had been introduced in 2.1.10. Strictly speaking
    this release breaks ABI again to make it compatible with <= 2.1.9.
    + See git commit 18104973 for more details
  * evdns: add new options -- so-rcvbuf/so-sndbuf
  * various autotools and cmake build changes
  * buffer: fix possible NULL dereference in evbuffer_setcb() on ENOMEM
  * Warn if forked from the event loop during event_reinit()
  * evutil: set the have_checked_interfaces in evutil_check_interfaces()
  * https-client: correction error checking

- Use FAT LTO objects in order to provide proper static library.

- Fix name of library package (bsc#1138369)

- Update to 2.1.10 stable
  * evdns: add DNS_OPTION_NAMESERVERS_NO_DEFAULT /
    EVDNS_BASE_NAMESERVERS_NO_DEFAULT
  * Add support for EV_TIMEOUT to event_base_active_by_fd
  * kqueue: Avoid undefined behaviour.
  * Prevent integer overflow in kq_build_changes_list.
  * evdns: fix lock/unlock mismatch in evdns_close_server_port()
  * Protect min_heap_push_ against integer overflow.
  * le-proxy: initiate use of the Winsock DLL
  * Fix leaks in error path of the bufferevent_init_common_()
  * buffer: make evbuffer_prepend() of zero-length array no-op
  * Don't loose top error in SSL
  * Remove needless check for arc4_seeded_ok
  * Cleanup __func__ detection
  * Add convenience macros for user-triggered events
  * Notify event base if there are no more events, so it can exit without
    delay
  * Fix base unlocking in event_del() if event_base_set() runned in another
    thread
  * If precise_time is false, we should not set EVENT_BASE_FLAG_PRECISE_TIMER
  * Fix race in access to ev_res from event loop with event_active()
  * Return from event_del() after the last event callback termination
  * Preserve socket error from listen across closesocket cleanup
  * fix connection retries when there more then one request for connection
  * improve error path for bufferevent_{setfd,enable,disable}()
  * Fix conceivable UAF of the bufferevent in evhttp_connection_free()
  * Fix evhttp_connection_get_addr() fox incomming http connections
  * fix leaks in evhttp_uriencode()
  * CONNECT method only takes an authority
  * Allow bodies for GET/DELETE/OPTIONS/CONNECT
  * Do not crash when evhttp_send_reply_start() is called after a timeout.
  * Fix crashing http server when callback do not reply in place
  * fix handling of close_notify (ssl) in http with openssl bufferevents
  * use *_new_with_arg() to match function prototype
  * avoid NULL dereference on request is not EVHTTP_REQ_POST
  * bufferevent_socket_connect{,_hostname}() missing event callback and use
    ret code
  * don't fail be_null_filter if bytes are copied
  * Call underlying bev ctrl GET_FD on filtered bufferevents
  * be_openssl: avoid leaking of SSL structure
  * Add missing includes into openssl-compat.h
  * Explicitly call SSL_clear when reseting the fd.
  * sample/https-client: use host SSL certificate store by default
  * ipv6only socket bind support
  * evdns: handle NULL filename explicitly
  * Fix assert() condition in evbuffer_drain() for IOCP
  * fix incorrect unlock of the buffer mutex (for deferred callbacks)
  * Fix wrong assert in evbuffer_drain()
  * Port `event_rpcgen.py` and `test/check-dumpevents.py` to Python 3.
- rename python2-shebang.patch -> python3-shebang.patch following port

- Make use of %license macro

- Add devel-static package, which is needed for building Envoy
  (https://www.envoyproxy.io/) and Cilium with Envoy integration
- Fix an error about /usr/bin/env shebang in event_rpcgen.py
  * python2-shebang.patch
libgcrypt
- Security fix [bsc#1221107, CVE-2024-2236]
  * Add --enable-marvin-workaround to spec to enable workaround
  * Fix  timing based side-channel in RSA implementation ( Marvin attack )
  * Add libgcrypt-CVE-2024-2236_01.patch
  * Add libgcrypt-CVE-2024-2236_02.patch
gnutls
- Fix heap buffer overread when handling the CT SCT extension during X.509
  certificate parsing [bsc#1246233, CVE-2025-32989]
  * Add patch gnutls-CVE-2025-32989.patch
- Fix double-free due to incorrect ownership handling in the export logic of
  SAN entries containing an otherName [bsc#1246232, CVE-2025-32988]
  * Add patch gnutls-CVE-2025-32988.patch
- Fix 1-byte heap buffer overflow when parsing templates with certtool
  [bsc#1246267, CVE-2025-32990]
  * Add patch gnutls-CVE-2025-32990.patch
- Fix NULL pointer dereference when 2nd Client Hello omits PSK
  [bsc#1246299, CVE-2025-6395]
  * Add patch gnutls-CVE-2025-6395.patch
openssl-1_1
- Security fix: [bsc#1250232 CVE-2025-9230]
  * Fix out-of-bounds read & write in RFC 3211 KEK unwrap
  * Add patch openssl3-CVE-2025-9230.patch

- FIPS: Use the NID_X9_62_prime256v1 curve in ECDSA KAT test
  instead of NID_secp256k1. [bsc#1246697]
  * Add openssl-fips-ECDSA-KAT.patch
openssl-3
- Security fix: [bsc#1250232 CVE-2025-9230]
  * Fix out-of-bounds read & write in RFC 3211 KEK unwrap
  * Add patch openssl3-CVE-2025-9230.patch

- Increase limit for CRL download [bsc#1247148, bsc#1247144]
  * Add openssl-3-large-CRLs.patch
polkit
- CVE-2025-7519: Fixed that a XML policy file with a large number of
  nested elements may lead to out-of-bounds write (bsc#1246472)
  added 0001-Nested-.policy-files-cause-xml-parsing-overflow-lead.patch
libpsm2
- Add libpsm2-disable-AVX.patch to completely disable AVX support
  and use only up to SSE4.2. (bsc#1245739)

- Use %autosetup macro. Allows to eliminate the usage of deprecated
  %patchN
python311
- Add CVE-2025-8194-tarfile-no-neg-offsets.patch which now
  validates archives to ensure member offsets are non-negative
  (gh#python/cpython#130577, CVE-2025-8194, bsc#1247249).

- Add CVE-2025-6069-quad-complex-HTMLParser.patch to avoid worst
  case quadratic complexity when processing certain crafted
  malformed inputs with HTMLParser (CVE-2025-6069, bsc#1244705).

- Use one core to build doc. This will make sphinx doc build
  reproducible.
  bsc#1243155
python3
- Add CVE-2025-8194-tarfile-no-neg-offsets.patch which now
  validates archives to ensure member offsets are non-negative
  (gh#python/cpython#130577, CVE-2025-8194, bsc#1247249).

- Add CVE-2025-4435-normalize-lnk-trgts-tarfile.patch
  Security fixes for CVE-2025-4517, CVE-2025-4330, CVE-2025-4138,
  CVE-2024-12718, CVE-2025-4435 on tarfile (bsc#1244032,
  bsc#1244061, bsc#1244059, bsc#1244060, bsc#1244056).
  The backported fixes do not contain changes for ntpath.py and
  related tests, because the support for symlinks and junctions
  were added later in Python 3.9, and it does not make sense to
  backport them to 3.6 here.
  The patch is contains the following changes:
  - python@42deeab fixes symlink handling for tarfile.data_filter
  - python@9d2c2a8 fixes handling of existing files/symlinks in tarfile
  - python@00af979 adds a new "strict" argument to realpath()
  - python@dd8f187 fixes mulriple CVE fixes in the tarfile module
  - downstream only fixes that makes the changes work and
    compatible with Python 3.6
- Add CVE-2025-6069-quad-complex-HTMLParser.patch to avoid worst
  case quadratic complexity when processing certain crafted
  malformed inputs with HTMLParser (CVE-2025-6069, bsc#1244705).

- Add python36-* provides/obsoletes to enable SLE-12 -> SLE-15
  migration, bsc#1233012

- Add ipaddress-update-pr60.patch from gh#phihag/ipaddress!60 to
  update vendored ipaddress module to 3.8 equivalent
- Add gh-128840_parse-IPv6-with-emb-IPv4.patch to limit buffer
  size for IPv6 address parsing (gh#python/cpython#128840,
  bsc#1244401).
- Update CVE-2025-4516-DecodeError-handler.patch not to break
  _PyBytes_DecodeEscape signature.

- Add CVE-2025-4516-DecodeError-handler.patch fixing
  CVE-2025-4516 (bsc#1243273) blocking DecodeError handling
  vulnerability, which could lead to DoS.
ruby2.5
- update suse.patch to 3f3682bf07fcd4f2fa875958853d3843ee7dcdb9
  - fix remote DoS via YAML manifest
    bsc#1225905 CVE-2024-35221

- update suse.patch to c76fb820676cfded16c697a62281a3bfeb8e4bb1
  - fix webrick: Ruby WEBrick read_header HTTP Request Smuggling Vulnerability
    bsc#1245254 CVE-2025-6442

- update suse.patch to 5d79fc609c5761864aec47e1ae4796b93db99104
  - fix ruby: userinfo leakage in URI#join, URI#merge and URI#+
    bsc#1237805 CVE-2025-27221
libsolv
- add support for product-obsoletes() provides in the product
  autopackage generation code
- bump version to 0.7.34

- improve transaction ordering by allowing more uninst->uninst
  edges [bsc#1243457]
- implement color filtering when adding update targets
- support orderwithrequires dependencies in susedata.xml
- bump version to 0.7.33
sqlite3
- Backpatch the URLs in sqlite3.n from https to http to avoid a
  file conflict with the tcl package on SLE-15-GA up to SP2. In
  SP3 and onwards the Tcl package does not contain the sqlite
  extension anymore.

- Sync version 3.50.2 from Factory:
  * CVE-2025-6965, bsc#1246597:
    Raise an error early if the number of aggregate terms in a
    query exceeds the maximum number of columns, to avoid
    downstream assertion faults.
  * Add subpackage for the lemon parser generator.
    + sqlite-3.49.0-fix-lemon-missing-cflags.patch
    + sqlite-3.6.23-lemon-system-template.patch
libssh
- Security fix: [CVE-2025-8277, bsc#1249375]
  * Memory Exhaustion via Repeated Key Exchange
  * Add patches:
  - libssh-CVE-2025-8277-packet-Adjust-packet-filter-to-work-wh.patch
  - libssh-CVE-2025-8277-Fix-memory-leak-of-unused-ephemeral-ke.patch
  - libssh-CVE-2025-8277-ecdh-Free-previously-allocated-pubkeys.patch

- Security fix: [CVE-2025-8114, bsc#1246974]
  * NULL pointer dereference when calculating session ID during KEX
  * Add libssh-CVE-2025-8114.patch
systemd
- triggers.systemd: skip update of hwdb, journal-catalog if executed during
  an offline update.

- systemd-repart is no more considered as experimental (jsc#PED-13213)

- Import commit 130293e510ceb4d121d11823e6ebd4b1e8332ea0 (merge of v254.27)
  For a complete list of changes, visit:
  https://github.com/openSUSE/systemd/compare/278fb676146e35a7b4057f52f34a7bbaf1b82369...130293e510ceb4d121d11823e6ebd4b1e8332ea0
libxml2
- security update
- added patches
  CVE-2025-7425 [bsc#1246296], Heap Use-After-Free in libxslt caused by atype corruption in xmlAttrPtr
  + libxml2-CVE-2025-7425.patch

- security update
- added patches
  CVE-2025-49794 [bsc#1244554], heap use after free (UAF) can lead to Denial of service (DoS)
  CVE-2025-49796 [bsc#1244557], type confusion may lead to Denial of service (DoS)
  + libxml2-CVE-2025-49794,49796.patch
  CVE-2025-49795 [bsc#1244555], null pointer dereference may lead to Denial of service (DoS)
  + libxml2-CVE-2025-49795.patch

- security update
- added patches
  CVE-2025-6170 [bsc#1244700], stack buffer overflow may lead to a crash
  CVE-2025-6021 [bsc#1244580], Integer Overflow in xmlBuildQName() Leads to Stack Buffer Overflow in libxml2
  + libxml2-CVE-2025-6170,6021.patch
libzypp
- Fix evaluation of libproxy results (bsc#1247690)
- Replace URL variables inside mirrorlist/metalink files
  (fixes #667)
- version 17.37.16 (35)

- Append RepoInfo::path() to the mirror URLs in Preloader
  (bsc#1247054)
- version 17.37.15 (35)

- During installation indicate the backend being used (bsc#1246038)
  If some package actually needs to know, it should test for
  ZYPP_CLASSIC_RPMTRANS being set in the environment.
  Otherwise the transaction is driven by librpm.
- version 17.37.14 (35)

- Workaround 'rpm -vv' leaving scriptlets /var/tmp (bsc#1218459)
- Verbose log libproxy results if PX_DEBUG=1 is set.
- BuildRequires:  cmake >= 3.17.
- version 17.37.13 (35)

- Allow explicit request to probe an added repo's URL
  (bsc#1246466)
- Fix tests with -DISABLE_MEDIABACKEND_TESTS=1 (fixes #661)
- version 17.37.12 (35)

- Add runtime check for a broken rpm-4.18.0 --runpostrans
  (bsc#1246149)
- Add regression test for bsc#1245220 and some other filesize
  related tests.
- version 17.37.11 (35)

- BuildRequires: %{libsolv_devel_package} >= 0.7.34 (bsc#1243486)
  Newer rpm versions no longer allow a ':' in rpm package names or
  obsoletes. So injecting an
    Obsoletes: product:oldproductname < oldproductversion
  into the -release package to indicate a product rename is no longer
  possible.
  Since libsolv-0.7.34 you can and should use:
    Provides: product-obsoletes(oldproductname) < oldproductversion
  in the -release package. libsolv will then inject the appropriate
  Obsoletes into the Product.
- version 17.37.10 (35)

- Ignore DeltaRpm download errors (bsc#1245672)
  DeltaRpms are in fact optional resources. In case of a failure
  the full rpm is downloaded.
- Improve fix for incorrect filesize handling (bsc#1245220)
- version 17.37.9 (35)

- Do not trigger download data exceeded errors on HTTP non data
  responses (bsc#1245220)
  In some cases a HTTP 401 or 407 did trigger a "filesize exceeded"
  error, because the response payload size was compared against the
  expected filesize. This patch adds some checks if the response
  code is in the success range and only then takes expected
  filesize into account. Otherwise the response content-length is
  used or a fallback of 2Mb if no content-length is known.
- version 17.37.8 (35)

- Fix SEGV in MediaDISK handler (bsc#1245452)
- Explicitly selecting DownloadAsNeeded also selects the
  classic_rpmtrans backend.
  DownloadAsNeeded can not be combined with the rpm singletrans
  installer backend because a rpm transaction requires all package
  headers to be available the the beginning of the transaction. So
  explicitly selecting this mode also turns on the classic_rpmtrans
  backend.
- Fix evaluation of libproxy results (bsc#1244710)
- version 17.37.7 (35)

- Enhancements regarding mirror handling during repo refresh.
  Added  means to disable the use of mirrors when downloading
  security relevant files. Requires updaing zypper to 1.14.91.
- Fix autotestcase writer if ZYPP_FULLLOG=1 (bsc#1244042)
  If ZYPP_FULLLOG=1 a solver testcase to
  "/var/log/YaST2/autoTestcase" should be written for each solver
  run. There was no testcase written for the very first solver run.
  This is now fixed.
- Pass $1==2 to %posttrans script if it's an update (bsc#1243279)
- version 17.37.6 (35)
mozilla-nspr
- update to version 4.36
  * remove support for OS/2
  * remove support for Unixware, Bsdi, old AIX, old HPUX9 & scoos
  * remove support for Windows 16 bit
  * renamed the prwin16.h header to prwin.h
  * configure was updated from 2.69 to 2.71
  * various build, test and automation script fixes
  * major parts of the source code were reformatted
mozilla-nss
- update to NSS 3.112
  * bmo#1963792 - Fix alias for mac workers on try
  * bmo#1966786 - ensure all options can be configured with SSL_OptionSet and SSL_OptionSetDefault
  * bmo#1931930 - ABI/API break in ssl certificate processing
  * bmo#1955971 - remove unnecessary assertion in sec_asn1d_init_state_based_on_template
  * bmo#1965754 - update taskgraph to v14.2.1
  * bmo#1964358 - Workflow for automation of the release on GitHub when pushing a tag
  * bmo#1952860 - fix faulty assertions in SEC_ASN1DecoderUpdate
  * bmo#1934877 - Renegotiations should use a fresh ECH GREASE buffer
  * bmo#1951396 - update taskgraph to v14.1.1
  * bmo#1962503 - Partial fix for ACVP build CI job
  * bmo#1961827 - Initialize find in sftk_searchDatabase
  * bmo#1963121 - Add clang-18 to extra builds
  * bmo#1963044 - Fault tolerant git fetch for fuzzing
  * bmo#1962556 - Tolerate intermittent failures in ssl_policy_pkix_ocsp
  * bmo#1962770 - fix compiler warnings when DEBUG_ASN1D_STATES or CMSDEBUG are set
  * bmo#1961835 - fix content type tag check in NSS_CMSMessage_ContainsCertsOrCrls
  * bmo#1963102 - Remove Cryptofuzz CI version check

- update to NSS 3.111
  * bmo#1930806 - FIPS changes need to be upstreamed: force ems policy
  * bmo#1957685 - Turn off Websites Trust Bit from CAs
  * bmo#1937338 - Update nssckbi version following April 2025 Batch of Changes
  * bmo#1943135 - Disable SMIME ‘trust bit’ for GoDaddy CAs
  * bmo#1874383 - Replaced deprecated sprintf function with snprintf in dbtool.c
  * bmo#1954612 - Need up update NSS for PKCS 3.1
  * bmo#1773374 - avoid leaking localCert if it is already set in ssl3_FillInCachedSID
  * bmo#1953097 - Decrease ASAN quarantine size for Cryptofuzz in CI
  * bmo#1943962 - selfserv: Add support for zlib certificate compression

- update to NSS 3.110
  * bmo#1930806 - FIPS changes need to be upstreamed: force ems policy
  * bmo#1954724 - Prevent excess allocations in sslBuffer_Grow
  * bmo#1953429 - Remove Crl templates from ASN1 fuzz target
  * bmo#1953429 - Remove CERT_CrlTemplate from ASN1 fuzz target
  * bmo#1952855 - Fix memory leak in NSS_CMSMessage_IsSigned
  * bmo#1930807 - NSS policy updates
  * bmo#1951161 - Improve locking in nssPKIObject_GetInstances
  * bmo#1951394 - Fix race in sdb_GetMetaData
  * bmo#1951800 - Fix member access within null pointer
  * bmo#1950077 - Increase smime fuzzer memory limit
  * bmo#1949677 - Enable resumption when using custom extensions
  * bmo#1952568 - change CN of server12 test certificate
  * bmo#1949118 - Part 2: Add missing check in
    NSS_CMSDigestContext_FinishSingle
  * bmo#1949118 - Part 1: Fix smime UBSan errors
  * bmo#1930806 - FIPS changes need to be upstreamed: updated key checks
  * bmo#1951491 - Don't build libpkix in static builds
  * bmo#1951395 - handle `-p all` in try syntax
  * bmo#1951346 - fix opt-make builds to actually be opt
  * bmo#1951346 - fix opt-static builds to actually be opt
  * bmo#1916439 - Remove extraneous assert
- Removed upstreamed nss-fips-stricter-dh.patch
- Added bmo1962556.patch to fix test failures
- Rebased nss-fips-approved-crypto-non-ec.patch nss-fips-combined-hash-sign-dsa-ecdsa.patch
- update to NSS 3.109
  * bmo#1939512 - Call BL_Init before RNG_RNGInit() so that special
    SHA instructions can be used if available
  * bmo#1930807 - NSS policy updates - fix inaccurate key policy issues
  * bmo#1945883 - SMIME fuzz target
  * bmo#1914256 - ASN1 decoder fuzz target
  * bmo#1936001 - Part 2: Revert “Extract testcases from ssl gtests
    for fuzzing”
  * bmo#1915155 - Add fuzz/README.md
  * bmo#1936001 - Part 4: Fix tstclnt arguments script
  * bmo#1944545 - Extend pkcs7 fuzz target
  * bmo#1912320 - Extend certDN fuzz target
  * bmo#1944300 - revert changes to HACL* files from bug 1866841
  * bmo#1936001 - Part 3: Package frida corpus script
- update to NSS 3.108
  * bmo#1923285 - libclang-16 -> libclang-19
  * bmo#1939086 - Turn off Secure Email Trust Bit for Security
    Communication ECC RootCA1
  * bmo#1937332 - Turn off Secure Email Trust Bit for BJCA Global Root
    CA1 and BJCA Global Root CA2
  * bmo#1915902 - Remove SwissSign Silver CA – G2
  * bmo#1938245 - Add D-Trust 2023 TLS Roots to NSS
  * bmo#1942301 - fix fips test failure on windows
  * bmo#1935925 - change default sensitivity of KEM keys
  * bmo#1936001 - Part 1: Introduce frida hooks and script
  * bmo#1942350 - add missing arm_neon.h include to gcm.c
  * bmo#1831552 - ci: update windows workers to win2022
  * bmo#1831552 - strip trailing carriage returns in tools tests
  * bmo#1880256 - work around unix/windows path translation issues
    in cert test script
  * bmo#1831552 - ci: let the windows setup script work without $m
  * bmo#1880255 - detect msys
  * bmo#1936680 - add a specialized CTR_Update variant for AES-GCM
  * bmo#1930807 - NSS policy updates
  * bmo#1930806 - FIPS changes need to be upstreamed: FIPS 140-3 RNG
  * bmo#1930806 - FIPS changes need to be upstreamed: Add SafeZero
  * bmo#1930806 - FIPS changes need to be upstreamed - updated POST
  * bmo#1933031 - Segmentation fault in SECITEM_Hash during pkcs12 processing
  * bmo#1929922 - Extending NSS with LoadModuleFromFunction functionality
  * bmo#1935984 - Ensure zero-initialization of collectArgs.cert
  * bmo#1934526 - pkcs7 fuzz target use CERT_DestroyCertificate
  * bmo#1915898 - Fix actual underlying ODR violations issue
  * bmo#1184059 - mozilla::pkix: allow reference ID labels to begin
    and/or end with hyphens
  * bmo#1927953 - don't look for secmod.db in nssutil_ReadSecmodDB if
    NSS_DISABLE_DBM is set
  * bmo#1934526 - Fix memory leak in pkcs7 fuzz target
  * bmo#1934529 - Set -O2 for ASan builds in CI
  * bmo#1934543 - Change branch of tlsfuzzer dependency
  * bmo#1915898 - Run tests in CI for ASan builds with detect_odr_violation=1
  * bmo#1934241 - Fix coverage failure in CI
  * bmo#1934213 - Add fuzzing for delegated credentials, DTLS short
    header and Tls13BackendEch
  * bmo#1927142 - Add fuzzing for SSL_EnableTls13GreaseEch and
    SSL_SetDtls13VersionWorkaround
  * bmo#1913677 - Part 3: Restructure fuzz/
  * bmo#1931925 - Extract testcases from ssl gtests for fuzzing
  * bmo#1923037 - Force Cryptofuzz to use NSS in CI
  * bmo#1923037 - Fix Cryptofuzz on 32 bit in CI
  * bmo#1933154 - Update Cryptofuzz repository link
  * bmo#1926256 - fix build error from 9505f79d
  * bmo#1926256 - simplify error handling in get_token_objects_for_cache
  * bmo#1931973 - nss doc: fix a warning
  * bmo#1930797 - pkcs12 fixes from RHEL need to be picked up
- remove obsolete patches
  * nss-fips-safe-memset.patch
  * nss-bmo1930797.patch
- update to NSS 3.107
  * bmo#1923038 - Remove MPI fuzz targets.
  * bmo#1925512 - Remove globals `lockStatus` and `locksEverDisabled`.
  * bmo#1919015 - Enable PKCS8 fuzz target.
  * bmo#1923037 - Integrate Cryptofuzz in CI.
  * bmo#1913677 - Part 2: Set tls server target socket options in config class
  * bmo#1913677 - Part 1: Set tls client target socket options in config class
  * bmo#1913680 - Support building with thread sanitizer.
  * bmo#1922392 - set nssckbi version number to 2.72.
  * bmo#1919913 - remove Websites Trust Bit from Entrust Root
    Certification Authority - G4.
  * bmo#1920641 - remove Security Communication RootCA3 root cert.
  * bmo#1918559 - remove SecureSign RootCA11 root cert.
  * bmo#1922387 - Add distrust-after for TLS to Entrust Roots.
  * bmo#1927096 - update expected error code in pk12util pbmac1 tests.
  * bmo#1929041 - Use random tstclnt args with handshake collection script
  * bmo#1920466 - Remove extraneous assert in ssl3gthr.c.
  * bmo#1928402 - Adding missing release notes for NSS_3_105.
  * bmo#1874451 - Enable the disabled mlkem tests for dtls.
  * bmo#1874451 - NSS gtests filter cleans up the constucted buffer
    before the use.
  * bmo#1925505 - Make ssl_SetDefaultsFromEnvironment thread-safe.
  * bmo#1925503 - Remove short circuit test from ssl_Init.
- fix build on loongarch64 (setting it as 64bit arch)
- Remove upstreamed bmo-1400603.patch
- Added nss-bmo1930797.patch to fix failing tests in testsuite
- update to NSS 3.106
  * bmo#1925975 - NSS 3.106 should be distributed with NSPR 4.36.
  * bmo#1923767 - pk12util: improve error handling in p12U_ReadPKCS12File.
  * bmo#1899402 - Correctly destroy bulkkey in error scenario.
  * bmo#1919997 - PKCS7 fuzz target, r=djackson,nss-reviewers.
  * bmo#1923002 - Extract certificates with handshake collection script.
  * bmo#1923006 - Specify len_control for fuzz targets.
  * bmo#1923280 - Fix memory leak in dumpCertificatePEM.
  * bmo#1102981 - Fix UBSan errors for SECU_PrintCertificate and
    SECU_PrintCertificateBasicInfo.
  * bmo#1921528 - add new error codes to mozilla::pkix for Firefox to use.
  * bmo#1921768 - allow null phKey in NSC_DeriveKey.
  * bmo#1921801 - Only create seed corpus zip from existing corpus.
  * bmo#1826035 - Use explicit allowlist for for KDF PRFS.
  * bmo#1920138 - Increase optimization level for fuzz builds.
  * bmo#1920470 - Remove incorrect assert.
  * bmo#1914870 - Use libFuzzer options from fuzz/options/\*.options in CI.
  * bmo#1920945 - Polish corpus collection for automation.
  * bmo#1917572 - Detect new and unfuzzed SSL options.
  * bmo#1804646 - PKCS12 fuzzing target.
- requires NSPR 4.36
- update to NSS 3.105
  * bmo#1915792 - Allow importing PKCS#8 private EC keys missing public key
  * bmo#1909768 - UBSAN fix: applying zero offset to null pointer in sslsnce.c
  * bmo#1919577 - set KRML_MUSTINLINE=inline in makefile builds
  * bmo#1918965 - Don't set CKA_SIGN for CKK_EC_MONTGOMERY private keys
  * bmo#1918767 - override default definition of KRML_MUSTINLINE
  * bmo#1916525 - libssl support for mlkem768x25519
  * bmo#1916524 - support for ML-KEM-768 in softoken and pk11wrap
  * bmo#1866841 - Add Libcrux implementation of ML-KEM 768 to FreeBL
  * bmo#1911912 - Avoid misuse of ctype(3) functions
  * bmo#1917311 - part 2: run clang-format
  * bmo#1917311 - part 1: upgrade to clang-format 13
  * bmo#1916953 - clang-format fuzz
  * bmo#1910370 - DTLS client message buffer may not empty be on retransmit
  * bmo#1916413 - Optionally print config for TLS client and server
    fuzz target
  * bmo#1916059 - Fix some simple documentation issues in NSS.
  * bmo#1915439 - improve performance of NSC_FindObjectsInit when
    template has CKA_TOKEN attr
  * bmo#1912828 - define CKM_NSS_ECDHE_NO_PAIRWISE_CHECK_KEY_PAIR_GEN
- Fix build error under Leap by rebasing nss-fips-safe-memset.patch.
- update to NSS 3.104
  * bmo#1910071 - Copy original corpus to heap-allocated buffer
  * bmo#1910079 - Fix min ssl version for DTLS client fuzzer
  * bmo#1908990 - Remove OS2 support just like we did on NSPR
  * bmo#1910605 - clang-format NSS improvements
  * bmo#1902078 - Adding basicutil.h to use HexString2SECItem function
  * bmo#1908990 - removing dirent.c from build
  * bmo#1902078 - Allow handing in keymaterial to shlibsign to make
    the output reproducible
  * bmo#1908990 - remove nec4.3, sunos4, riscos and SNI references
  * bmo#1908990 - remove other old OS (BSDI, old HP UX, NCR,
    openunix, sco, unixware or reliantUnix
  * bmo#1908990 - remove mentions of WIN95
  * bmo#1908990 - remove mentions of WIN16
  * bmo#1913750 - More explicit directory naming
  * bmo#1913755 - Add more options to TLS server fuzz target
  * bmo#1913675 - Add more options to TLS client fuzz target
  * bmo#1835240 - Use OSS-Fuzz corpus in NSS CI
  * bmo#1908012 - set nssckbi version number to 2.70.
  * bmo#1914499 - Remove Email Trust bit from ACCVRAIZ1 root cert.
  * bmo#1908009 - Remove Email Trust bit from certSIGN ROOT CA.
  * bmo#1908006 - Add Cybertrust Japan Roots to NSS.
  * bmo#1908004 - Add Taiwan CA Roots to NSS.
  * bmo#1911354 - remove search by decoded serial in
    nssToken_FindCertificateByIssuerAndSerialNumber
  * bmo#1913132 - Fix tstclnt CI build failure
  * bmo#1913047 - vfyserv: ensure peer cert chain is in db for
    CERT_VerifyCertificateNow
  * bmo#1912427 - Enable all supported protocol versions for UDP
  * bmo#1910361 - Actually use random PSK hash type
  * bmo#1911576 - Initialize NSS DB once
  * bmo#1910361 - Additional ECH cipher suites and PSK hash types
  * bmo#1903604 - Automate corpus file generation for TLS client Fuzzer
  * bmo#1910364 - Fix crash with UNSAFE_FUZZER_MODE
  * bmo#1910605 - clang-format shlibsign.c
- remove obsolete nss-reproducible-builds.patch
- update to NSS 3.103
  * bmo#1908623 - move list size check after lock acquisition in sftk_PutObjectToList.
  * bmo#1899542 - Add fuzzing support for SSL_ENABLE_POST_HANDSHAKE_AUTH,
  * bmo#1909638 - Follow-up to fix test for presence of file nspr.patch.
  * bmo#1903783 - Adjust libFuzzer size limits
  * bmo#1899542 - Add fuzzing support for SSL_SetCertificateCompressionAlgorithm,
    SSL_SetClientEchConfigs, SSL_VersionRangeSet and SSL_AddExternalPsk
  * bmo#1899542 - Add fuzzing support for SSL_ENABLE_GREASE and
    SSL_ENABLE_CH_EXTENSION_PERMUTATION
- Add nss-reproducible-builds.patch to make the rpms reproducible,
  by using a hardcoded, static key to generate the checksums (*.chk-files)
- Updated nss-fips-approved-crypto-non-ec.patch to enforce
  approved curves with the CKK_EC_MONTGOMERY key type (bsc#1224113).
- update to NSS 3.102.1
  * bmo#1905691 - ChaChaXor to return after the function
- update to NSS 3.102
  * bmo#1880351 - Add Valgrind annotations to freebl Chacha20-Poly1305.
  * bmo#1901932 - missing sqlite header.
  * bmo#1901080 - GLOBALTRUST 2020: Set Distrust After for TLS and S/MIME.
  * bmo#1615298 - improve certutil keyUsage, extKeyUsage, and nsCertType keyword handling.
  * bmo#1660676 - correct length of raw SPKI data before printing in pp utility.

- Add nss-reproducible-chksums.patch to make NSS-build reproducible
  Use key from openssl (bsc#1081723)

- Updated nss-fips-approved-crypto-non-ec.patch to exclude the
  SHA-1 hash from SLI approval.
net-tools
- Drop 0002-Do-not-warn-about-interface-socket-not-binded.patch. It
  worked around a net-tools-1.60 specific problem, that does not
  happen in net-tools-2.10. It is more harmful than useful, as it
  can hide real problems. (bsc#430864#c15,
  https://github.com/ecki/net-tools/issues/32#issuecomment-3265471116).

- Drop 0004-By-default-do-not-fopen-anything-in-netrom_gr.patch. It
  was net-tools-1.60 specific leak fix and breaks netrom in
  net-tools-2.10 (bnc#544339#c2).

- Drop old Fedora patch 0006-Allow-interface-stacking.patch. It
  provided a fix for CVE-2025-46836 (bsc#142461), but it was fixes
  by the upstream in 2025 in a different way. Revert interferring
  net-tools-CVE-2025-46836.patch back to the upstream version.
- Fix stack buffer overflow in parse_hex (bsc#1248687,
  GHSA-h667-qrp8-gj58, net-tools-parse_hex-stack-overflow.patch).
- Fix stack-based buffer overflow in proc_gen_fmt (bsc#1248687,
  GHSA-w7jq-cmw2-cq59,
  net-tools-proc_gen_fmt-buffer-overflow.patch).
- Avoid unsafe memcpy in ifconfig (bsc#1248687,
  net-tools-ifconfig-avoid-unsafe-memcpy.patch).
- Prevent overflow in ax25 and netrom (bsc#1248687,
  net-tools-ax25+netrom-overflow-1.patch,
  net-tools-ax25+netrom-overflow-2.patch).
- Keep possibility to enter long interface names, even if they are
  not accepted by the kernel, because it was always possible up to
  CVE-2025-46836 fix. But issue a warning about an interface name
  concatenation (bsc#1248410,
  net-tools-ifconfig-long-name-warning.patch).

- Provide more readable error for interface name size checking
  introduced by net-tools-CVE-2025-46836.patch
  (bsc#1243581, net-tools-CVE-2025-46836-error-reporting.patch).

- Fix a regression in net-tools-CVE-2025-46836.patch (bsc#1246608).

- Perform bound checks when parsing interface labels in
  /proc/net/dev (bsc#1243581, CVE-2025-46836, GHSA-pfwf-h6m3-63wf,
  net-tools-CVE-2025-46836.patch,
  net-tools-CVE-2025-46836-regression.patch).
pam
- Make sure that the buffer containing encrypted passwords get's erased
  bedore free.
- Replace to previous CVE fix which led to CPU performance issues.
  [bsc#1246221, CVE-2024-10041,
  + libpam-introduce-secure-memory-erasure-helpers.patch
  + pam_modutil_get-overwrite-password-at-free.patch
  - passverify-always-run-the-helper-to-obtain-shadow_pwd.patch]
python-azure-agent
- Set AutoUpdate.UpdateToLatestVersion=n in /etc/waagent.conf
  (bsc#1244933)

- Fix %suse_version conditional in spec file so package is built
  using python2 in SLE 12 (bsc#1240385)
python-appdirs
- Add python36-appdirs provides/obsoletes to enable SLE-12 ->
  SLE-15 migration, bsc#1233012
python-asn1crypto
- Add python36-asn1crypto provides/obsoletes to enable SLE-12 ->
  SLE-15 migration, bsc#1233012
python-certifi
- Add python36-certifi provides/obsoletes to enable SLE-12 ->
  SLE-15 migration, bsc#1233012
python3-cryptography
- Add python36-cryptography provides/obsoletes to enable SLE-12 ->
  SLE-15 migration, bsc#1233012
- Skipping failing test
python-idna
- Add python36-idna provides/obsoletes to enable SLE-12 ->
  SLE-15 migration, bsc#1233012
python-importlib-metadata
- Add python36-importlib-metadata provides/obsoletes to enable SLE-12 ->
  SLE-15 migration, bsc#1233012
python3-more-itertools
- Add python36-more-itertools provides/obsoletes to enable SLE-12 ->
  SLE-15 migration, bsc#1233012
python-packaging
- Add python36-packaging provides/obsoletes to enable SLE-12 ->
  SLE-15 migration, bsc#1233012
python3-pyOpenSSL
- Add python36-pyOpenSSL provides/obsoletes to enable SLE-12 ->
  SLE-15 migration, bsc#1233012
python-pyasn1
- Add python36-pyasn1 provides/obsoletes to enable SLE-12 ->
  SLE-15 migration, bsc#1233012
python-pycparser
- Add python36-pycparser provides/obsoletes to enable SLE-12 ->
  SLE-15 migration, bsc#1233012
python-pyparsing
- Add python36-pyparsing provides/obsoletes to enable SLE-12 ->
  SLE-15 migration, bsc#1233012
python-pytz
- Add python36-pytz provides/obsoletes to enable SLE-12 ->
  SLE-15 migration, bsc#1233012
python-py
- Add python36-py provides/obsoletes to enable SLE-12 ->
  SLE-15 migration, bsc#1233012
python-requests
- Add python36- provides/obsoletes to enable SLE-12 ->
  SLE-15 migration, bsc#1233012
python3-setuptools
- Add python36-setuptools provides/obsoletes to enable SLE-12 ->
  SLE-15 migration, bsc#1233012
python-six
- Add python36-six provides/obsoletes to enable SLE-12 ->
  SLE-15 migration, bsc#1233012
python-urllib3
- Add patch CVE-2025-50181-poolmanager-redirects.patch:
  * Pool managers now properly control redirects when retries is passed
    (CVE-2025-50181, GHSA-pq67-6m6q-mj2v, bsc#1244925)

- Add python36-urllib3 provides/obsoletes to enable SLE-12 ->
  SLE-15 migration, bsc#1233012
python-aiohttp
- Add CVE-2025-53643.patch to fix CVE-2025-53643 (bsc#1246517)
python-azure-appconfiguration
- New upstream release
  + Version 1.7.1
  + For detailed information about changes see the
    CHANGELOG.md file provided with this package

- New upstream release
  + Version 1.7.0
  + For detailed information about changes see the
    CHANGELOG.md file provided with this package
- Drop extra LICENSE.txt as upstream now ships its own
- Rename LICENSE.txt to LICENSE in %files section

- New upstream release
  + Version 1.6.0
  + For detailed information about changes see the
    CHANGELOG.md file provided with this package
python-azure-batch
- New upstream release
  + Version 14.2.0
  + For detailed information about changes see the
    CHANGELOG.md file provided with this package
python-azure-mgmt-batch
- New upstream release
  + Version 17.3.0
  + For detailed information about changes see the
    CHANGELOG.md file provided with this package
python-azure-mgmt-compute
- New upstream release
  + Version 33.1.0
  + For detailed information about changes see the
    CHANGELOG.md file provided with this package
- Adjust upstream source name in spec file

- New upstream release
  + Version 33.0.0
  + For detailed information about changes see the
    CHANGELOG.md file provided with this package

- New upstream release
  + Version 32.0.0
  + For detailed information about changes see the
    CHANGELOG.md file provided with this package
- Drop extra LICENSE.txt as upstream now ships its own
- Rename LICENSE.txt to LICENSE in %files section
- Update Requires from setup.py

- New upstream release
  + Version 31.0.0
  + For detailed information about changes see the
    CHANGELOG.md file provided with this package

- New upstream release
  + Version 30.6.0
  + For detailed information about changes see the
    CHANGELOG.md file provided with this package
- Update Requires from setup.py
python-azure-mgmt-containerservice
- New upstream release
  + Version 32.1.0
  + For detailed information about changes see the
    CHANGELOG.md file provided with this package

- New upstream release
  + Version 32.0.0
  + For detailed information about changes see the
    CHANGELOG.md file provided with this package
- Adjust upstream source name in spec file

- New upstream release
  + Version 31.0.0
  + For detailed information about changes see the
    CHANGELOG.md file provided with this package
- Drop extra LICENSE.txt as upstream now ships its own
- Rename LICENSE.txt to LICENSE in %files section
- Update Requires from setup.py

- New upstream release
  + Version 30.0.0
  + For detailed information about changes see the
    CHANGELOG.md file provided with this package
python-azure-mgmt-cosmosdb
- New upstream release
  + Version 9.6.0
  + For detailed information about changes see the
    CHANGELOG.md file provided with this package
- Adjust upstream source name in spec file
- Drop extra LICENSE.txt as upstream now ships its own
- Rename LICENSE.txt to LICENSE in %files section
- Update Requires from setup.py

- New upstream release
  + Version 9.5.1
  + For detailed information about changes see the
    CHANGELOG.md file provided with this package

- New upstream release
  + Version 9.5.0
  + For detailed information about changes see the
    CHANGELOG.md file provided with this package
- Update Requires from setup.py
python-azure-mgmt-rdbms
- New upstream release
  + Version 10.2.0b17
  + For detailed information about changes see the
    CHANGELOG.md file provided with this package

- New upstream release
  + Version 10.2.0b16
  + For detailed information about changes see the
    CHANGELOG.md file provided with this package

- New upstream release
  + Version 10.2.0b14
  + For detailed information about changes see the
    CHANGELOG.md file provided with this package
- Update Requires from setup.py
python-azure-mgmt-recoveryservicesbackup
- New upstream release
  + Version 9.2.0
  + For detailed information about changes see the
    CHANGELOG.md file provided with this package
- Adjust upstream source name in spec file
- Drop extra LICENSE.txt as upstream now ships its own
- Rename LICENSE.txt to LICENSE in %files section

- New upstream release
  + Version 9.1.0
  + For detailed information about changes see the
    CHANGELOG.md file provided with this package
python-azure-mgmt-recoveryservices
- New upstream release
  + Version 3.0.0
  + For detailed information about changes see the
    CHANGELOG.md file provided with this package
- Update Requires from setup.py
python-azure-mgmt-redhatopenshift
- New upstream release
  + Version 1.5.0
  + For detailed information about changes see the
    CHANGELOG.md file provided with this package
- Update Requires from setup.py
python-azure-mgmt-redis
- New upstream release
  + Version 14.5.0
  + For detailed information about changes see the
    CHANGELOG.md file provided with this package
- Adjust upstream source name in spec file
- Drop extra LICENSE.txt as upstream now ships its own
- Rename LICENSE.txt to LICENSE in %files section
- Update Requires from setup.py

- New upstream release
  + Version 14.4.0
  + For detailed information about changes see the
    CHANGELOG.md file provided with this package
- Update Requires from setup.py
python-azure-mgmt-resource
- New upstream release
  + Version 23.3.0
  + For detailed information about changes see the
    CHANGELOG.md file provided with this package

- New upstream release
  + Version 23.2.0
  + For detailed information about changes see the
    CHANGELOG.md file provided with this package
- Adjust upstream source name in spec file
- Drop extra LICENSE.txt as upstream now ships its own
- Rename LICENSE.txt to LICENSE in %files section
- Update Requires from setup.py

- New upstream release
  + Version 23.1.1
  + For detailed information about changes see the
    CHANGELOG.md file provided with this package
- Remove temporary version override
- Remove unzip package from BuildRequires
- Switch source archive format to TAR.GZ
- Update Requires from setup.py
python-azure-mgmt-servicefabricmanagedclusters
- New upstream release
  + Version 2.0.0
  + For detailed information about changes see the
    CHANGELOG.md file provided with this package
- Drop extra LICENSE.txt as upstream now ships its own
- Remove temporary version override
- Rename LICENSE.txt to LICENSE in %files section
python-azure-mgmt-servicelinker
- New upstream release
  + Version 1.2.0b3
  + For detailed information about changes see the
    CHANGELOG.md file provided with this package
- Adjust upstream source name in spec file
- Drop extra LICENSE.txt as upstream now ships its own
- Rename LICENSE.txt to LICENSE in %files section

- New upstream release
  + Version 1.2.0b2
  + For detailed information about changes see the
    CHANGELOG.md file provided with this package
- Remove unzip package from BuildRequires
- Switch source archive format to TAR.GZ
- Update Requires from setup.py
python-azure-mgmt-signalr
- New upstream release
  + Version 2.0.0b2
  + For detailed information about changes see the
    CHANGELOG.md file provided with this package
- Adjust upstream source name in spec file
- Drop extra LICENSE.txt as upstream now ships its own
- Rename LICENSE.txt to LICENSE in %files section
python-azure-mgmt-sql
- New upstream release
  + Version 4.0.0b21
  + For detailed information about changes see the
    CHANGELOG.md file provided with this package

- New upstream release
  + Version 4.0.0b20
  + For detailed information about changes see the
    CHANGELOG.md file provided with this package

- New upstream release
  + Version 4.0.0b19
  + For detailed information about changes see the
    CHANGELOG.md file provided with this package
- Adjust upstream source name in spec file
- Drop extra LICENSE.txt as upstream now ships its own
- Rename LICENSE.txt to LICENSE in %files section
- Update Requires from setup.py

- New upstream release
  + Version 4.0.0b18
  + For detailed information about changes see the
    CHANGELOG.md file provided with this package

- New upstream release
  + Version 4.0.0b17
  + For detailed information about changes see the
    CHANGELOG.md file provided with this package

- New upstream release
  + Version 4.0.0b16
  + For detailed information about changes see the
    CHANGELOG.md file provided with this package
- Update Requires from setup.py
python-azure-mgmt-storage
- New upstream release
  + Version 21.2.1
  + For detailed information about changes see the
    CHANGELOG.md file provided with this package

- New upstream release
  + Version 21.2.0
  + For detailed information about changes see the
    CHANGELOG.md file provided with this package
- Update Requires from setup.py
python-azure-multiapi-storage
- Downgrade upstream version to 1.3.0 to address compatibility
  issues with azure-cli 2.66.0 in SLE-15-SP4 (bsc#1247261)
- Override upstream version with 1.4.0.really.1.3.0

- New upstream release
  + Version 1.4.0
  + For detailed information about changes see the
    README.rst file provided with this package

- New upstream release
  + Version 1.3.0
  + For detailed information about changes see the
    README.rst file provided with this package
- Drop extra LICENSE.txt as upstream now ships its own
- Rename LICENSE.txt to LICENSE in %files section
python-azure-synapse-artifacts
- New upstream release
  + Version 0.19.0
  + For detailed information about changes see the
    CHANGELOG.md file provided with this package
python-msal-extensions
- Update to version 1.3.1
  * Do not install tests in site-packages by @musicinmybrain in (#139)
  * Also dropped Python 3.7 and 3.8 since this release
- from version 1.3.0
  * Fix a typo in README.md (persistance/persistence)
    by @musicinmybrain in (#133)
  * Maintenance by @rayluo in (#137)
  * Allow portalocker version 3 by @musicinmybrain in (#136)
  * Make portalocker optional (opt in by pip install
    msal-extensions[portalocker]) by @rayluo in (#117)
- Drop me_relax-portalocker.patch, fixed upstream

- Add patch to relax python-portalocker version dependency in setup.py
  + me_relax-portalocker.patch
- Relax python-portalocker version dependency in BuildRequires and Requires

- Update to version 1.2.0
  + Remove mentions of Travis CI by @akx in (#126)
  + Set proper lower bound for portalocker dependency,
    drop packaging dependency by @akx in (#125)
  + Switch to MSAL 1.29+'s TokenCache.search()
    by @rayluo in (#131)
- Remove temporary version override
- Update BuildRequires and Requires from setup.py

- Update to version 1.2.0b1
  + MSAL Extensions has been updated to work with
    MSAL Python 1.27.* and 1.28.* (#127, #128)
- Adjust upstream source name in spec file
- Override upstream version with 1.2.0~b1
- Update Requires from setup.py
python-msal
- Update to version 1.32.3
  * Fix a regression on Azure Arc / on-prem servers (#814, #815)
- from version 1.32.2
  * Bugfix for Authentication Failed: MsalResponse object has no
    attribute 'headers' (#812)
- from version 1.32.1
  * Optimization on cache

- Update to version 1.32.0
  * Refactor to allow adding new field into cache key
    and/or content by @rayluo in (#751)
  * Warning when obsolete msal-extensions is detected
    by @rayluo in (#752)
  * Add msal_cache.bin to .gitignore by @DharshanBJ in (#753)
  * MSAL will use env var MSAL_FORCE_REGION by default
    by @rayluo in (#756)
  * Allow MI endpoint changing through environment variable
    by @jimdigriz in (#754)
  * Revert "allow MI endpoint changing through environment
    variable" by @rayluo in (#769)
  * Fix document for using SystemAssigned managed identity
    by @jiasli in (#764)
  * Suppress a false positive CodeQL alarm by @rayluo in (#783)
  * Pass Sku and Ver to MsalRuntime by @Ugonnaak1 in (#786)
  * Try to suppress another verify=False by @rayluo in (#788)
  * Supports dSTS by ClientApplication(..., authority=
    "https://...example.com/dstsv2/...") by @rayluo in (#772)
  * Add test case to show that OBO supports SP by @rayluo in (#481)
  * Enable Issue-Sentinel to scan for similar issues by @DharshanBJ in (#790)
  * Support pod identity by @rayluo in (#795)
  * Scope to resource by @rayluo in (#785)

- Update to version 1.31.2b1
  * acquire_token_interactive(...) supports scope with the shape of
    "GUID/.default" when running inside Cloud Shell (#784, #785)
- Override upstream version with 1.31.2~b1

- Update to version 1.31.1
  * Bugfix: The Managed Identity detection logic on Arc (#731)
    had a bug (#762), now fixed in PR (#763)

- Update to version 1.31.0
  * Integration with Broker-on-Mac in (#596)
  * Change Managed Identity detection logic on Arc in (#731)
  * Managed Identity supports CAE in (#730)
  * Support Managed Identity on Azure Container
    Instance (ACI) with Resource id in (#741)
  * Other refactoring in (#740)

- Update to version 1.30.0
  * New feature: Support Subject Name/Issuer authentication when using
    .pfx certificate file. Documentation available in one of the recent
    purple boxes here. (#718)
  * New feature: Automatically use SHA256 and PSS padding when using
    .pfx certificate on non-ADFS, non-OIDC authorities. (#722)
  * New feature: Expose refresh_on (if any) to fresh or cached response,
    so that caller may choose to proactively call acquire_token_silent()
    early. (#723)
  * Bugfix for token cache search. MSAL 1.27+ customers please upgrade
    to MSAL 1.30+. (#717)

- Update to version 1.29.0
  * New feature: Supports Managed Identity for Azure VM, App Service
    (including Azure Functions, Azure Automation), Service Fabric,
    Azure Machine Learning, Arc, etc.. Comes with a sample, its
    configuration via ENV VAR, and its API documentation.
    (#58, #480, #634, #674)
  * New feature: Support reading ConfidentialClientApplication's
    cert from a pfx file (#684, #699)
  * New feature: TokenCache class has a new search() method which will
    return a generator of tokens. The old find() method still exists and
    returns a list, but MSAL 1.27+ will not call find() anymore. (#693, #644)
  * Change: Re-enable the username password flow to go through broker,
    if available. (#712)
- from version 1.28.1
  * Change: pip install msal[broker] will now pick up the latest PyMsalRuntime
    0.16.x which contains a bugfix for being run as administrator. This release
    fixes #707.

- Update to version 1.28.0
  * New feature: PublicClientApplication and ConfidentialClientApplication
    have a new oidc_authority parameter that can be used to specify authority
    of any generic OpenID Connect authority, typically the customized domain
    for CIAM. (#676, #678)
  * Dropping Python 2.7
- from version 1.27.0
  * New feature: remove_tokens_for_client() will remove tokens acquired
    by acquire_token_for_client() (#640, #650, #666)
  * Performance: Throughput of token-cache-hit happy path is roughly 2x faster (#644)
  * Adjustment: MSAL no longer attempts to validate an ID token's time (#656, #657)
  * Adjustment: Bump upstream broker dependency to 0.14.x
  * Improvement: Better chance to remove accounts from broker (#651)
  * Improvement: Cleaner console output when the http local server
    is visited in https protocol (#546)
  * Improvement: Reduce a bare except clause (#667)
protobuf
- Add CVE-2025-4565.patch to fix parsing of untrusted Protocol Buffers
  data containing an arbitrary number of recursive groups or messages
  can lead to crash due to RecursionError (bsc#1244663, CVE-2025-4565)
python-xmltodict
- Cherry-pick security-fix-prereqs.patch to allow backport of CVE fix
- Cherry-pick CVE-2025-9375.patch to fix multiple XML Injection
  vulnerabilities in XML parser (bsc#1249036, CVE-2025-9375)
regionServiceClientConfigAzure
- Update to version 3.0.0 (bsc#1246995)
  + SLE 16 python-requests requiers SSL v3 certificates. Update 2
    region server certs to support SLE 16 when it gets released.

- Update dependency name for metadata package, name change in SLE 16
  (bsc#1243419)
samba
- Windows security hardening locks out schannel'ed netlogon dc
  calls like netr_DsRGetDCName; (bsc#1246431); (bso#15876).
suse-build-key
- adjust UID (name + email) of SLES16 signing key with official
  names. (bsc#1245223)
suse-module-tools
- Update to version 15.6.11:
  * spec file: add missing util-linux requirement (bsc#1241038)
  * regenerate-initrd-posttrans: Fix SKIP_REGENERATE_INITRD_ALL
  (bsc#1228929)
sysconfig
- version 0.85.10
  * codespell run for all repository files and changes file
  * spec: define permissions for ghost file attrs to avoid
    rpm --restore resets them to 0 (bsc#1237595).
  * spec: fix name-repeated-in-summary rpmlint warning
systemd-presets-branding-SLE
- enable sysstat_collect.timer and sysstat_summary.timer [bsc#1244553]
  and [bsc#1246835]
- modified sources
  % default-SLE.preset
systemd-rpm-macros
- Bump version to 16

- Introduce %udev_trigger_with_reload() for packages that need to trigger events
  in theirs scriplets. The new macro automatically triggers a reload of the udev
  rule files as this step is often overlooked by packages (bsc#1237143).
vim
- Fix the following CVEs and bugs:
  * bsc#1246602 (CVE-2025-53906)
  * bsc#1246604 (CVE-2025-53905)
  * bsc#1247939 (CVE-2025-55158)
  * bsc#1247938 (CVE-2025-55157)
- Update to 9.1.1629:
  9.1.1629: Vim9: Not able to use more than 10 type arguments in a generic function
  9.1.1628: fuzzy.c has a few issues
  9.1.1627: fuzzy matching can be improved
  9.1.1626: cindent: does not handle compound literals
  9.1.1625: Autocompletion slow with include- and tag-completion
  9.1.1624: Cscope not enabled on MacOS
  9.1.1623: Buffer menu does not handle unicode names correctly
  9.1.1622: Patch v9.1.1432 causes performance regressions
  9.1.1621: flicker in popup menu during cmdline autocompletion
  9.1.1620: filetype: composer.lock and symfony.lock files not recognized
  9.1.1619: Incorrect E535 error message
  9.1.1618: completion: incorrect selected index returned from complete_info()
  9.1.1617: Vim9: some error messages can be improved
  9.1.1616: xxd: possible buffer overflow with bitwise output
  9.1.1615: diff format erroneously detected
  9.1.1614: Vim9: possible variable type change
  9.1.1613: tests: test_search leaves a few swapfiles behind
  9.1.1612: Ctrl-G/Ctrl-T do not ignore the end search delimiter
  9.1.1611: possible undefined behaviour in mb_decompose()
  9.1.1610: completion: hang or E684 when 'tagfunc' calls complete()
  9.1.1609: complete: Heap-buffer overflow with complete function
  9.1.1608: No command-line completion for :unsilent {command}
  9.1.1607: :apple command detected as :append
  9.1.1606: filetype: a few more files are not recognized
  9.1.1605: cannot specify scope for chdir()
  9.1.1604: completion: incsearch highlight might be lost
  9.1.1603: completion: cannot use autoloaded funcs in 'complete' F{func}
  9.1.1602: filetype: requirements-*.txt files are not recognized
  9.1.1601: Patch v8.1.0425 was wrong
  9.1.1600: using diff anchors with hidden buffers fails silently
  9.1.1599: :bnext doesn't go to unlisted help buffers
  9.1.1598: filetype: waybar config file is not recognized
  9.1.1597: CI reports leaks in libgtk3 library
  9.1.1596: tests: Test_search_wildmenu_iminsert() depends on help file
  9.1.1595: Wayland: non-portable use of select()
  9.1.1594: completion: search completion throws errors
  9.1.1593: Confusing error when compiling incomplete try block
  9.1.1592: Vim9: crash with classes and garbage collection
  9.1.1591: VMS support can be improved
  9.1.1590: cannot perform autocompletion
  9.1.1589: Cannot disable cscope interface using configure
  9.1.1588: Vim9: cannot split dict inside command block
  9.1.1587: Wayland: timeout not updated before select()
  9.1.1586: Vim9: can define an enum/interface in a function
  9.1.1585: Wayland: gvim still needs GVIM_ENABLE_WAYLAND
  9.1.1584: using ints as boolean type
  9.1.1583: gvim window lost its icons
  9.1.1582: style issue in vim9type.c and vim9generics.c
  9.1.1581: possible memory leak in vim9generics.c
  9.1.1580: possible memory leak in vim9type.c
  9.1.1579: Coverity complains about unchecked return value
  9.1.1578: configure: comment still mentions autoconf 2.71
  9.1.1577: Vim9: no generic support yet
  9.1.1576: cannot easily trigger wildcard expansion
  9.1.1575: tabpanel not drawn correctly with wrapped lines
  9.1.1574: Dead code in mbyte.c
  9.1.1573: Memory leak when pressing Ctrl-D in cmdline mode
  9.1.1572: expanding $var does not escape whitespace for 'path'
  9.1.1571: CmdlineChanged triggered to often
  9.1.1570: Copilot suggested some improvements in cmdexpand.c
  9.1.1569: tests: Vim9 tests can be improved
  9.1.1568: need a few more default highlight groups
  9.1.1567: crash when using inline diff mode
  9.1.1566: self-referenced enum may not get freed
  9.1.1565: configure: does not consider tiny version for wayland
  9.1.1564: crash when opening popup to closing buffer
  9.1.1563: completion: ruler may disappear
  9.1.1562: close button always visible in the 'tabline'
  9.1.1561: configure: wayland test can be improved
  9.1.1560: configure: uses $PKG_CONFIG before it is defined
  9.1.1559: tests: Test_popup_complete_info_01() fails when run alone
  9.1.1558: str2blob() treats NULL string and empty string differently
  9.1.1557: not possible to anchor specific lines in difff mode
  9.1.1556: string handling in cmdexpand.c can be improved
  9.1.1555: completion: repeated insertion of leader
  9.1.1554: crash when omni-completion opens command-line window
  9.1.1553: Vim9: crash when accessing a variable in if condition
  9.1.1552: [security]: path traversal issue in tar.vim
  9.1.1551: [security]: path traversal issue in zip.vim
  9.1.1550: defaults: 'showcmd' is not enabled in non-compatible mode on Unix
  9.1.1549: filetype: pkl files are not recognized
  9.1.1548: filetype: OpenFGA files are not recognized
  9.1.1547: Wayland: missing ifdef
  9.1.1546: Vim9: error with has() and short circuit evaluation
  9.1.1545: typo in os_unix.c
  9.1.1544: :retab cannot be limited to indentation only
  9.1.1543: Wayland: clipboard appears to not be working
  9.1.1542: Coverity complains about uninitialized variable
  9.1.1541: Vim9: error when last enum value ends with a comma
  9.1.1540: completion: menu state wrong on interruption
  9.1.1539: completion: messages don't respect 'shm' setting
  9.1.1537: helptoc: still some issues when markdown code blocks
  9.1.1536: tests: test_plugin_comment uses wrong :Check command
  9.1.1535: the maximum search count uses hard-coded value 99
  9.1.1534: unnecessary code in tabpanel.c
  9.1.1533: helptoc: does not handle code sections in markdown well
  9.1.1532: termdebug: not enough ways to configure breakpoints
  9.1.1531: confusing error with nested legacy function
  9.1.1530: Missing version change in v9.1.1529
  9.1.1529: Win32: the toolbar in the GUI is old and dated
  9.1.1528: completion: crash with getcompletion()
  9.1.1527: Vim9: Crash with string compound assignment
  9.1.1526: completion: search completion match may differ in case
  9.1.1525: tests: testdir/ is a bit messy
  9.1.1524: tests: too many imports in the test suite
  9.1.1523: tests: test_clipmethod fails in non X11 environment
  9.1.1522: tests: still some ANSI escape sequences in test output
  9.1.1521: completion: pum does not reset scroll pos on reopen with 'noselect'
  9.1.1520: completion: search completion doesn't handle 'smartcase' well
  9.1.1519: tests: Test_termdebug_decimal_breakpoints() may fail
  9.1.1518: getcompletiontype() may crash
  9.1.1517: filetype: autopkgtest files are not recognized
  9.1.1516: tests: no test that 'incsearch' is updated after search completion
  9.1.1515: Coverity complains about potential unterminated strings
  9.1.1514: Coverity complains about the use of tmpfile()
  9.1.1513: resizing Vim window causes unexpected internal window width
  9.1.1512: completion: can only complete from keyword characters
  9.1.1511: tests: two edit tests change v:testing from 1 to 0
  9.1.1510: Search completion may use invalid memory
  9.1.1509: patch 9.1.1505 was not good
  9.1.1508: string manipulation can be improved in cmdexpand.c
  9.1.1507: symlinks are resolved on :cd commands
  9.1.1506: tests: missing cleanup in Test_search_cmdline_incsearch_highlight()
  9.1.1505: not possible to return completion type for :ex command
  9.1.1504: filetype: numbat files are not recognized
  9.1.1503: filetype: haxe files are not recognized
  9.1.1502: filetype: quickbms files are not recognized
  9.1.1501: filetype: flix files are not recognized
  9.1.1500: if_python: typo in python error variable
  9.1.1499: MS-Windows: no indication of ARM64 architecture
  9.1.1498: completion: 'complete' funcs behave different to 'omnifunc'
  9.1.1497: Link error with shm_open()
  9.1.1496: terminal: still not highlighting empty cells correctly
  9.1.1495: Wayland: uses $XDG_SEAT to determine seat
  9.1.1494: runtime(tutor): no French translation for Chapter 2
  9.1.1493: manually comparing positions on buffer
  9.1.1492: tests: failure when Wayland compositor fails to start
  9.1.1491: missing out-of-memory checks in cmdexpand.c
  9.1.1490: 'wildchar' does not work in search contexts
  9.1.1489: terminal: no visual highlight of empty cols with empty 'listchars'
  9.1.1488: configure: using obsolete macro AC_PROG_GCC_TRADITIONAL
  9.1.1487: :cl doesn't invoke :clist
  9.1.1486: documentation issues with Wayland
  9.1.1485: missing Wayland clipboard support
  9.1.1484: tests: Turkish locale tests fails on Mac
  9.1.1483: not possible to translation position in buffer
  9.1.1482: scrolling with 'splitkeep' and line()
  9.1.1481: gcc complains about uninitialized variable
  9.1.1480: Turkish translation outdated
  9.1.1479: regression when displaying localized percentage position
  9.1.1478: Unused assignment in ex_uniq()
  9.1.1476: no easy way to deduplicate text
  9.1.1476: missing out-of-memory checks in cmdexpand.c
  9.1.1475: completion: regression when "nearest" in 'completeopt'
  9.1.1474: missing out-of-memory check in mark.c
  9.1.1473: inconsistent range arg for :diffget/diffput
  9.1.1472: if_python: PySequence_Fast_{GET_SIZE,GET_ITEM} removed
  9.1.1471: completion: inconsistent ordering with CTRL-P
  9.1.1470: use-after-free with popup callback on error
  9.1.1469: potential buffer-underflow with invalid hl_id
  9.1.1468: filetype: bright(er)script files are not recognized
  9.1.1467: too many strlen() calls
  9.1.1466: filetype: not all lex files are recognized
  9.1.1465: tabpanel: not correctly drawn with 'equalalways'
  9.1.1464: gv does not work in operator-pending mode
  9.1.1463: Integer overflow in getmarklist() after linewise operation
  9.1.1462: missing change from patch v9.1.1461
  9.1.1461: tabpanel: tabpanel vanishes with popup menu
  9.1.1460: MS-Windows: too many strlen() calls in os_win32.c
  9.1.1459: xxd: coloring output is inefficient
  9.1.1458: tabpanel: tabs not properly updated with 'stpl'
  9.1.1457: compile warning with tabpanelopt
  9.1.1456: comment plugin fails toggling if 'cms' contains \
  9.1.1455: Haiku: dailog objects created with no reference
  9.1.1454: tests: no test for pum at line break position
  9.1.1453: tests: Test_geometry() may fail
  9.1.1452: completion: redundant check for completion flags
  9.1.1451: tabpanel rendering artifacts when scrolling
  9.1.1450: Session has wrong arglist with :tcd and :arglocal
  9.1.1449: typo in pum_display()
  9.1.1448: tabpanel is not displayed correctly when msg_scrolled
  9.1.1447: completion: crash when backspacing with fuzzy completion
  9.1.1446: filetype: cuda-gdb config files are not recognized
  9.1.1445: negative matchfuzzy scores although there is a match
  9.1.1444: Unused assignment in set_fuzzy_score()
  9.1.1443: potential buffer underflow in insertchar()
  9.1.1442: tests: Test_diff_fold_redraw() is insufficient
  9.1.1441: completion: code can be improved
  9.1.1440: too many strlen() calls in os_win32.c
  9.1.1439: Last diff folds not merged
  9.1.1438: tests: Test_breakindent_list_split() fails
  9.1.1437: MS-Windows: internal compile error in uc_list()
  9.1.1436: GUI control code is displayed on the console on startup
  9.1.1435: completion: various flaws in fuzzy completion
  9.1.1434: MS-Windows: missing out-of-memory checks in os_win32.c
  9.1.1433: Unnecessary :if when writing session
  9.1.1432: GTK GUI: Buffer menu does not handle unicode correctly
  9.1.1431: Hit-Enter Prompt when loading session files
  9.1.1430: tabpanel may flicker in the GUI
  9.1.1429: dragging outside the tabpanel changes tabpagenr
  9.1.1428: completion: register completion needs cleanup
  9.1.1427: rendering artifacts with the tabpanel
  9.1.1426: completion: register contents not completed
  9.1.1425: tabpanel: there are still some problems with the tabpanel
  9.1.1424: PMenu selection broken with multi-line selection and limits
  9.1.1423: :tag command not working correctly using Vim9 Script
  9.1.1422: scheduling of complete function can be improved
  9.1.1421: tests: need a test for the new-style tutor.tutor
  9.1.1420: tests: could need some more tests for shebang lines
  9.1.1419: It is difficult to ignore all but some events
  9.1.1418: configures GUI auto detection favors GTK2
  9.1.1417: missing info about register completion in complete_info()
  9.1.1416: completion limits not respected for fuzzy completions
  9.1.1415: potential use-after free when there is an error in 'tabpanel'
  9.1.1414: MS-Windows: compile warnings in os_win32.c
  9.1.1413: spurious CursorHold triggered in GUI on startup
  9.1.1412: tests: Test_tabpanel_tabonly() fails on larger screens
  9.1.1411: crash when calling non-existing function for tabpanel
  9.1.1410: out-of-bounds access with 'completefunc'
  9.1.1409: using f-flag in 'complete' conflicts with Neovim
  9.1.1408: not easily possible to complete from register content
  9.1.1407: Can't use getpos('v') in OptionSet when using setbufvar()
xen
- bsc#1246112, bsc#1238896 - VUL-0: xen: More AMD transient
  execution attack (CVE-2024-36350, CVE-2024-36357, XSA-471)
  66f28b47-x86-cpufeature-reposition-ext-leaf-21-EAX.patch
  685c29cf-x86-idle-Move-monitor-mwait-wrappers.patch
  685c29d0-x86-idle-remove-MFENCEs-for-CLFLUSH_MONITOR.patch
  685c29d1-revert-part-of-mwait-idle-disable-IBRS-.patch
  686277ed-x86-cpu-policy-simplify-logic-in-gcdfa.patch
  68656b6f-x86-cpu-policy-leaf-80000021-handling.patch
  68681770-x86-idle-remove-broken-MWAIT-implementation.patch
  68681771-x86-idle-drop-incorrect-smp_mb-in-.patch
  68681772-x86-idle-convert-force_mwait_ipi_wakeup-to-.patch
  68681773-rework-arch_skip_send_event_check-into-.patch
  68681774-x86-new-MWAIT-IPI-elision-algorithm.patch
  68681775-x86-idle-fix-IRQ-enable-before-C1-on-Xeons.patch
  xsa471-13.patch
  686d2646-x86-cpu-policy-rearrange-gc_fa.patch
  686d2647-x86-cpu-policy-CPUID-leaf-0x80000021-ecx.patch
  686d2648-x86-AMD-ucode-digests-for-TSA.patch
  686d2649-x86-idle-rearrange-VERW-and-MONITOR-in-.patch
  686d264a-x86-spec-ctrl-mitigate-Transitive-Scheduler-Attacks.patch
- bsc#1244644 - VUL-0: CVE-2025-27465: xen: x86: Incorrect stubs
  exception handling for flags recovery (XSA-470)
  6863cd0b-x86emul-extable-registration-in-invoke_stub.patch
  Replaces xsa470.patch
- Upstream bug fixes (bsc#1027519)
  6835a042-VMX-VMEntry-failure-on-ADL-SPR-with-shadow.patch
  6835a043-x86-PV-breakpoint-reporting.patch

- bsc#1244644 - VUL-0: CVE-2025-27465: xen: x86: Incorrect stubs
  exception handling for flags recovery (XSA-470)
  xsa470.patch
yast2-packager
- Fix Internal Error: Encoding::CompatibilityError when
  adding SLE-HA as add-on product (bsc#1245555)
- 4.6.10
zypper
- Fix addrepo to handle explicit --check and --no-check requests
  (bsc#1246466)
- Accept "show" as alias for "info" (bsc#1245985)
- version 1.14.93

- sh: Reset solver options after command (bsc#1245496)
- Explicitly selecting DownloadAsNeeded also selects the
  classic_rpmtrans backend.
- version 1.14.92

- BuildRequires:  libzypp-devel >= 17.37.6.
  Enhancements regarding mirror handling during repo refresh. Adapt
  to libzypp API changes. (bsc#1230267)
- version 1.14.91