bind
- Security Fixes:
  * Amplification vulnerabilities via self-pointed glue records.
    (CVE-2026-3592)
    [bsc#1265592, bind-9.16-CVE-2026-3592.patch]
  * Server memory exhaustion during GSS-API TKEY negotiation.
    (CVE-2026-3039)
    [bsc#1265591, bind-9.16-CVE-2026-3039.patch]
  * Invalid handling of CLASS != IN.
    (CVE-2026-5946)
    [bsc#1265594, bind-9.16-CVE-2026-5946.patch]
cifs-utils
- CVE-2026-12505: cifs.upcall: remove getpwuid() dependency
  (bsc#1267389)
  * add cifs.upcall-remove-getpwuid-dependency.patch
containerd
- Add patch for CVE-2026-34986 (bsc#1262948)
  * 0003-CVE-2026-34986-Bump-go-jose-to-v3.0.5.patch
- Add patch for CVE-2026-39821 (bsc#1266640)
  * 0004-CVE-2026-39821-idna-update-from-x-text-fix-ToUnicode.patch
- Add patch for CVE-2026-33814 (bsc#1265794)
  * 0005-CVE-2026-33814-http2-prevent-hanging-Transport-due-t.patch

- Add patch for CVE-2026-33186 (bsc#1260296):
  * 0002-CVE-2026-33186-containerd-google.golang.org-grpc-aut.patch
coreutils
- proc: Use affinity mask even on systems with more than 1024 CPUs (bsc#1259327)
  - add coreutils-gnulib-nproc-Use-affinity-mask-even-on-systems-with-more-th.patch
dracut
- Update to version 055+suse.365.g79144c5:
  * fix(network-legacy): sanitize DHCP values in dhclient-script.sh (bsc#1268322, CVE-2026-6893)
  * fix(network-legacy): add input validation to RFC 3442 route parser

- Update to version 055+suse.363.gea2753a:
  * fix(systemd): explicitly install /bin/bash (bsc#1263940)
glibc
- ungetwc-byte-stream.patch: libio: Fix ungetwc operating on byte stream
  (CVE-2026-5928, bsc#1262464, BZ #33998)
- scanf-mc-buffer-overflow.patch: stdio-common: Fix buffer overflow in
  scanf %mc (CVE-2026-5450, bsc#1262465, BZ #34008)

- gconv-spurious-nul-iso-2022-jp.patch: gconv: Do not emit spurious NUL
  character in ISO-2022-JP-3 (BZ #28524)
- ibm139x-pending-char-state.patch: Use pending character state in
  IBM1390, IBM1399 character sets (CVE-2026-4046, bsc#1261206, BZ #33980)
hwdata
- update to 0.406:
  * Update pci and vendor ids

- update to 0.405:
  * Update pci and vendor ids

- Update to version 0.397:
  * Update pci and vendor ids

- Update to version 0.395:
  * Update pci and vendor ids
iproute2
- add CVE fix (CVE-2024-58251 bsc#1254324)
  * ss-escape-characters-in-command-name.patch

- support display of bound but unconnected sockets (bsc#1204562)
  * ss-Add-support-for-dumping-TCP-bound-inactive-socket.patch
jq
- Add patch CVE-2026-33948.patch (CVE-2026-33948, bsc#1262043)
kernel-default
- drm/amdkfd: validate SVM ioctl nattr against buffer size (bsc#1267381 CVE-2026-46197)
- commit 51ead61

- crypto: ccp: Don't attempt to copy ID to userspace if PSP
  command failed (bsc#1264116 CVE-2026-31697).
- crypto: ccp: Don't attempt to copy PDH cert to userspace if
  PSP command failed (bsc#1263880 CVE-2026-31698).
- crypto: ccp: Don't attempt to copy CSR to userspace if PSP
  command failed (bsc#1263879 CVE-2026-31699).
- crypto: ccp: Don't attempt to copy ID to userspace if PSP
  command failed (bsc#1264116 CVE-2026-31697).
- crypto: ccp: Don't attempt to copy PDH cert to userspace if
  PSP command failed (bsc#1263880 CVE-2026-31698).
- crypto: ccp: Don't attempt to copy CSR to userspace if PSP
  command failed (bsc#1263879 CVE-2026-31699).
- commit 12add94

- xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (CVE-2026-46116 bsc#1267369)
- commit 2de5e93

- crypto: algif_aead - Fix minimum RX size check for decryption
  (CVE-2026-43077 bsc#1264470).
- commit 3c6f0bc

- netfilter: nf_tables: release flowtable after rcu grace period
  on error (CVE-2026-23392 bsc#1260531).
- commit a113750

- ip6_gre: Use cached t->net in ip6erspan_changelink() (CVE-2026-46120 bsc#1267640)
- commit 9355ea4

- sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (CVE-2026-46227 bsc#1267697)
- commit 9f23ae6

- Bluetooth: btintel: serialize btintel_hw_error() with
  hci_req_sync_lock (CVE-2026-31500 bsc#1262993).
- commit 3f9d46a

- kabi: revert kabi breaking changes from bsc#1264610 fix
  (CVE-2026-43198 bsc#1264610).
- tcp: fix potential race in tcp_v6_syn_recv_sock()
  (CVE-2026-43198 bsc#1264610).
- commit e76ef72

- Bluetooth: virtio_bt: clamp rx length before skb_put
  (CVE-2026-46123 bsc#1267621).
- commit cd81331

- media: mc, v4l2: serialize REINIT and REQBUFS with
  req_queue_mutex (CVE-2026-31473 bsc#1262663).
- commit 02e769f

- ipv4: icmp: validate reply type before using icmp_pointers
  (CVE-2026-46037 bsc#1267361).
- commit 1875083

- fanotify: fix false positive on permission events (bsc#1267387
  CVE-2026-46150).
- commit 06e4d33

- usb: ulpi: fix memory leak on ulpi_register() error paths
  (CVE-2026-31759 bsc#1264076).
- commit b80df76

- usb: ulpi: fix double free in ulpi_register_interface() error
  path (CVE-2026-31759 bsc#1264076).
- commit 45a646c

- arm64: errata: Mitigate TLBI errata on various Arm CPUs (bsc#1266290 CVE-2025-10263)
  Enable workaround for this CVE.
  Drop all new CPU models which where not existing at the time of v5.14.
- commit ec74444

- scsi: imm: Fix use-after-free bug caused by unfinished delayed
  work (CVE-2025-68324 bsc#1255416).
- commit 3b35bd6

- packaging: Add nvidia kernel description
- commit 5f2699f

- btrfs: fix btrfs_ioctl_space_info() slot_count TOCTOU which
  can lead  to info-leak (bsc#1267652,CVE-2026-46159).
- commit 5b52ada

- gfs2: Fix use-after-free in iomap inline data write path
  (CVE-2026-45984 bsc#1267214).
- gfs2: Add metapath_dibh helper (CVE-2026-45984 bsc#1267214).
- gfs2: Move the inode glock locking to gfs2_file_buffered_write
  (CVE-2026-45984 bsc#1267214).
- commit 329df60

- rpm/mkspec: Conditionally set Rust BuildReqs (bsc#1258538)
  This is a further optimization of kernel packaging rust-enablement.
  Add the check of CONFIG_RUST at creating the spec for each kernel
  flavor, and set BuildRequires conditionally only for archs that have
  CONFIG_RUST.  This avoids the unnecessary dependency chains due to
  unused rust.
  The main knob ENABLE_RUST is still needed because otherwise we can't
  know whether to pass the dummy-tools or not at processing
  run_oldconfig.
- commit ccf4b93

- rpm/check-for-config-changes: ignore Rust-related configs (bsc#1258538)
  Those configs may be dynamically changed at the build time
- commit 5251980

- rpm: Add BuildRequires for Rust enablement (bsc#1258538)
  Update mkspec and template to generate the spec files with
  BuildRequires of Rust-related packages when ENABLE_RUST=Yes is set in
  rpm/config.sh.
- commit d0f276f

- bonding: alb: fix UAF in rlb_arp_recv during bond up/down
  (CVE-2026-45970 bsc#1267205).
- commit 99e9810

- thermal: core: Fix thermal zone governor cleanup issues
  (CVE-2026-46021 bsc#1267220).
- commit 8a0a43b

- arm64: tlb: Optimize ARM64_WORKAROUND_REPEAT_TLBI (git-fixes)
- commit 5565461

- arm64: tlb: Allow XZR argument to TLBI ops (git-fixes)
- commit b280f12

- KVM: x86: Fix shadow paging use-after-free due to unexpected
  GFN (CVE-2026-46113 bsc#1266969).
- commit ed60983

- KVM: x86/mmu: Add helper to convert SPTE value to its shadow
  page (CVE-2026-46113 bsc#1266969).
- commit f4850cb

- media: dvb-net: fix OOB access in ULE extension header tables (CVE-2026-31405 bsc#1261700)
- commit c1417e1

- usb: usbtmc: Flush anchored URBs in usbtmc_release (CVE-2026-31758 bsc#1264093)
- commit c03e48d

- RDMA/rxe: Fix double free in rxe_srq_from_init (CVE-2026-45852 bsc#1266711)
- commit 5d9b762

- nfc: llcp: add missing return after LLCP_CLOSED checks (CVE-2026-31629 bsc#1263790)
- commit 2b38048

- RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv (CVE-2026-46043 bsc#1266901)
- commit af9ad17

- packaging: Replace compute-PATCHVERSION with python implementation
  This script is copied by kkspec to the package directory and called from
  there. That means that libraries from kernel-source cannot be loaded,
  and that's the reason why the script is appended to the library that is
  most useful for it. compute-PATCHVERSION and mkspec are no longer
  shipped in rpm packages which means compute-PATCHVERSION could be folded
  into mkspec, and that in turn into tar-up. However, these are all
  written in different languages.
- commit de458e0

- drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set()
  (CVE-2026-43206 bsc#1264551).
- commit 1d4097b

- rtmutex: Use waiter::task instead of current in remove_waiter()
  (bsc#1266001 CVE-2026-43499).
- commit a819149

- ipv6: rpl: reserve mac_len headroom when recompressed SRH grows
  (CVE-2026-43501 bsc#1266009).
- ip6_tunnel: clear skb2->cb in ip4ip6_err() (CVE-2026-43037
  bsc#1263995).
- commit 6011115

- Improve compatibility with awk 2.4.0 (bsc#1266214)
  This was meant to match the literal '+', so it needs to be backslashed
  not a repetition of the '^' symbol.
- commit fbbce3e

- smb: client: reject userspace cifs.spnego descriptions
  (bsc#1266238).
- commit 534122a

- compute-PATCHVERSION: Do not append .. to default patch directories
  All the callers are either using . or a specific patch directory.
  If a caller really needs to load patches from .. it should be passed as
  parameter.
- commit d383394

- compute-PATCHVERSION: Remove unpack logic
  This used to be needed when compute-PATCHVERSION was shipped as part of
  the rpm package where unpacked patches are not available.
  It is not done annymore, and the unpackinng is not needed.
- commit 9a8fa0e

- packaging: Rip out extra symbols support
  Extra symbols are not supported for a long time.
  The oldest branch we maintain is SLE 11 SP1 and it does not use patch
  guards to select patches.
- commit 7b3d5b0

- Refresh patches.suse/ALSA-pcm-fix-use-after-free-on-linked-stream-runtime.patch
  Fix the incorrect backport that overlooked the usage of runtime->rate.
- commit b830cb3
krb5
- Fix Fix two NegoEx parsing vulnerabilities:
  * CVE-2026-40355, bsc#1263366
  * CVE-2026-40356, bsc#1263367
- Add patch 0016-Fix-two-NegoEx-parsing-vulnerabilities.patch
avahi
- Add avahi-CVE-2026-34933.patch: refuse to accept publish flags
  where both wide_area and multicast are set.
  (CVE-2026-34933, bsc#1261546)

- Add avahi-CVE-2026-24401.patch: Fix unsolicited mDNS response
  containing a recursive CNAME record (bsc#1257235).
util-linux
- loopdev: Prevent unauthorized read access to symlinked filesystem
  images (bsc#1261606, CVE-2026-27456,
  util-linux-CVE-2026-27456.patch).
openssl-1_1
- Security fixes:
  * CVE-2026-42766: Possible NULL Dereference in Password-Based CMS
    Decryption (bsc#1266349)
  * CVE-2026-9076:  Out-of-Bounds Read in CMS Password-Based Decryption
    (bsc#1266341)
  * CVE-2026-7383:  Possible Heap Buffer Overflow in ASN.1 Multibyte String
    Conversion (bsc#1266340)
  * CVE-2026-34180: Heap Buffer Over-read in ASN.1 Content Parsing
    (bsc#1266342)
  * CVE-2026-45447: Heap Use-After-Free in OpenSSL PKCS7_verify() (bsc#1266357)
  * Add patches:
    openssl-CVE-2026-42766.patch openssl-CVE-2026-9076.patch
    openssl-CVE-2026-7383.patch openssl-CVE-2026-34180.patch
    openssl-CVE-2026-45447.patch
libsolv
- fix solv_chksum_free segfault when called with a NULL pointer
- bump version to 0.7.39

- made repo_add_solv more robust against corrupt files
  [bsc#1265935] [CVE-2026-9149]
- fix potential buffer overflow when verifying EdDSA signatures
  [bsc#1266039] [CVE-2026-48863]
- added limit checks in multiple places to catch overflows
- reduce the size of the language id cache
- fixed Debian canon selection
- fixed dbpath detection in repo_rpmdb_librpm
- reduced stack usage in repo page compression (needed for musl)
- bump version to 0.7.38

- fix parsing of sha512 checksums in debian repositories
  [bsc#1265938] [CVE-2026-9150]
- improve speed of dirpool_add_dir makeing parsing of filelists.xml
  twice as fast
- fix parsing of recommends in the old Mandriva synthesis format
- bump version to 0.7.37

- respect the "default" attribute in environment optionlist in
  the comps parser
- support suse namespace deps in boolean dependencies [bsc#1258193]
- support for the Elbrus2000 (e2k) architecture
- support language() suse namespace rewriting
- bump version to 0.7.36

- fixed rare crash in the handling of allowuninstall in combination
  with forcebest updates
- new pool_satisfieddep_map feature to test if a set of packages
  satisfies a dependency
- bump version to 0.7.35
sqlite3
- Sync version 3.53.2 from Factory:
  * bsc#1268013, CVE-2026-11824: heap-based buffer overflow
    vulnerability in the FTS5 full-text search extension.
  * bsc#1268012, CVE-2026-11822: memory corruption vulnerabilities
    in the FTS5 full-text search extension.
libzypp
- A .repo files "path=" entry must not refer to a location
  outside the repo (bsc#1267874, CVE-2026-44942)
  A "path=" entry may solely denote a sub-directory of the baseurl
  where the metadata are located. A relative path trying to access
  data outside the baseurl is reported and sanitized.
- version 17.38.13 (35)

- Repo "keyhint" must denote a filename, no path (bsc#1267426,
  CVE-2026-44941)
- version 17.38.12 (35)

- Fix potential crash on malformed or malicious repository
  metadata (fixes #740)
- version 17.38.11 (35)

- Repo metadata: discard entries referring to a location outside
  the repo (bsc#1259802, CVE-2026-25707)
  Mirroring those data locally would refer to a location outside
  the repo's local cache directory. Those data entries are reported
  and discarded.
- zypp.conf: Allow [env] section to add environment variables.
  This feature is designed to enable environment-specific settings
  or debugging options over an extended period. See zypp.conf(5).
- version 17.38.10 (35)

- Prevent configured scripts from escaping the sigcheck directory
  (bsc#1265223, CVE-2026-44933)
- StringV: guard hasPrefix/hasPrefixCI against reading past the
  view end (fixes #735)
- version 17.38.9 (35)

- Mandatory signature verification plugin support (PED#11922)
- version 17.38.8 (35)

- Fix purge-kernel -rc kernel handling (bsc#1239718)
- Explicitly_set_pool_DISTTYPE_RPM (fixes #726)
- version 17.38.7 (35)

- Check for trusted key updates when updating the general keyring
  (bsc#1259706)
- Support multiple MirroredOrigin authorities (bsc#1253193)
- Workaround doxygen bug: doxygen/doxygen#12057
- libzypp.spec: Add missing graphviz-gd BuildRequires (boo#1259842)
- version 17.38.6 (35)

- Fix preloader not caching packages from arch specific subrepos
  (bsc#1253740)
- Deprioritize invalid mirrors (fixes openSUSE/zypper#636)
- version 17.38.5 (35)

- Fix Product::referencePackage lookup (bsc#1259311)
  Use a provided autoproduct() as hint to the package name of the
  release package. It might be that not just multiple versions of
  the same release package provide the same product version, but
  also different release packages.
- version 17.38.4 (35)

- specfile: on fedora use %{_prefix}/share as zyppconfdir if
  %{_distconfdir} is undefined (fixes #693)
  This will set '-DZYPPCONFDIR=%{zyppconfdir}' for cmake.
- Fall back to a writable location when precaching packages
  without root (bsc#1247948)
- version 17.38.3 (35)

- Prepare a legacy /etc/zypp/zypp.conf to be installed on old distros.
  See the ZYPP.CONF(5) man page for details.
- Fix runtime check for broken rpm --runposttrans (bsc#1257068)
- version 17.38.2 (35)

- Avoid libcurl-mini4 when building as it does not support ftp
  protocol.
- Translation: updated .pot file.
- version 17.38.1 (35)

- zypp.conf: follow the UAPI configuration file specification
  (PED-14658)
  In short terms it means we will no longer ship an
  /etc/zypp/zypp.conf, but store our own defaults in
  /usr/etc/zypp/zypp.conf. The systems administrator may choose to
  keep a full copy in /etc/zypp/zypp.conf ignoring our config file
  settings completely, or - the preferred way - to overwrite
  specific settings via /etc/zypp/zypp.conf.d/*.conf overlay files.
  See the ZYPP.CONF(5) man page for details.
- cmake: correctly detect rpm6 (fixes #689)
- Use 'zypp.tmp' as temp directory component to ease setting up
  SELinux policies (bsc#1249435)
- zyppng: Update Provider to current MediaCurl2 download
  approach, drop Metalink ( fixes #682 )
- version 17.38.0 (35)
openssh
- Add patch rebased from upstream to add missing askpass check for
  proxy-mode multiplexing sessions (CVE-2026-35388, bsc#1261441):
  * openssh-cve-2026-35388-askpass-multiplexing.patch
- Update patch to fix a possible information disclosure or denial
  of service due to uninitialized variables in gssapi patches
  (CVE-2026-3497, bsc#1259642) :
  * openssh-8.0p1-gssapi-keyex.patch

- Add patch to fix a potential issue when validating mac or ciphers
  (bsc#1264568):
  * fix-mac-validation-strsep-logic-bug.patch

- Improve %prep LDAP regex to preserve subdirectories (e.g., ope-
  nbsd-compat/) and handle optional [ab]/ prefixes.
python-PyJWT
- CVE-2026-48526: JWK JSON accepted as HMAC secret (algorithm confusion)
  (bsc#1266802)
- CVE-2026-48523: Algorithm allow-list bypass with PyJWK / PyJWKClient
  (bsc#1266799)
- CVE-2026-48525: DoS via base64 decode of unused payload segment when b64=false
  (bsc#1266801)
- CVE-2026-48522: PyJWKClient accepts non-HTTP(S) URIs (bsc#1266798)
- CVE-2026-48524: PyJWKClient cache wiped on fetch error (bsc#1266800)
- added security-fixes.patch to fix above vulnerabilities
python-urllib3
- CVE-2026-44431: sensitive information disclosure due to sensitive
  headers being forwarded across origins in proxied low-level redirects
  (bsc#1265267)
  Add patch CVE-2026-44431.patch
000release-packages:sle-module-basesystem-release
n/a
000release-packages:sle-module-containers-release
n/a
000release-packages:sle-module-public-cloud-release
n/a
000release-packages:sle-module-server-applications-release
n/a
tar
- Fix CVE-2026-5704.patch causing errors when extracting certain archives
  generated by rpm2archive which contain hard links
- Refresh fix-dereference.patch

- Fix tar changing dir permissions temporarily even when using --no-overwrite-dir
  * no-overwrite-dir-fix.patch
- Fix CVE-2026-5704, crafted archives can be used to to hide file injection
  (bsc#1261900)
  * CVE-2026-5704.patch
- Fix --dereference/-h not working properly after CVE-2025-45582 fix (bsc#1265450)
  * fix-dereference.patch
- Fix extraction failure for paths like "a/./b" caused by the gnulib openat2
  implementation (bsc#1267189)
  * openat2-fix-dotlike-failure.patch
timezone
- Update to 2026b:
  * British Columbia moved to permanent -07 on 2026-03-09. (bsc#1264965)
  * Some more overflow bugs have been fixed in zic.
- Refresh revert-philippines-historical-data.patch
- Change SUSE-Public-Domain license to LicenseRef-SUSE-Public-Domain to
  fix rpmlint errors

- Update to 2026a:
  * Moldova has used EU transition times since 2022.
  * The "right" TZif files are no longer installed by default.
  * -DTZ_RUNTIME_LEAPS=0 disables runtime support for leap seconds.
  * TZif files are no longer limited to 50 bytes of abbreviations.
  * zic is no longer limited to 50 leap seconds.
  * Several integer overflow bugs have been fixed.
- Changes from 2025c:
  * update Baja California DST rules in 1953, 1961-1975
  * An unset TZ is no longer invalid when /etc/localtime is
    missing, and is abbreviated "UTC" not "-00".  This reverts to
    2024b behavior
  * tzset etc. are now more cautious about questionable TZ settings.
  * tzset etc. now treat ' ' like '_' in time zone abbreviations
  * tzfree now preserves errno, consistently with POSIX.1-2024 ‘free’.
  * zic has new options inspired by FreeBSD.  ‘-D’ skips creation of
    output ancestor directories, ‘-m MODE’ sets output files’ mode,
    and ‘-u OWNER[:GROUP]’ sets output files’ owner and group.
  * multiple changes visible to developers
- Use "REDO=posix_right" to keep installing "right" TZif files.
util-linux-systemd
- loopdev: Prevent unauthorized read access to symlinked filesystem
  images (bsc#1261606, CVE-2026-27456,
  util-linux-CVE-2026-27456.patch).
vim
- Update to v9.2.0530.
- Fix for SG#71948, bsc#1262395:
  * vim-9.1.1732-fix-inc-detection.patch: Fix for incorrectly detecting
    scientific parameter files as bitbake recipies.
- Upstream fixed the following bugs / CVEs:
  * bsc#1264706 CVE-2026-42307
  * bsc#1265360 CVE-2026-46483
  * bsc#1264708 CVE-2026-45130
  * bsc#1264707 CVE-2026-44656
  * bsc#1265349 CVE-2026-43961
- Changes:
  * 9.2.0530: WinBar row vertical separator not refreshed on window change
  * 9.2.0529: GTK4: clipboard returns empty after a foreign app takes the selection
  * 9.2.0528: possible overflow in XIM resource handling
  * 9.2.0527: Possible double free in fill_partial_and_closure()
  * 9.2.0526: missing out-of-memory check in ex_substitute()
  * 9.2.0525: spell: memory leak in spell_read_dic()
  * 9.2.0524: spell: buffer overflow with many affix or compound flags
  * 9.2.0523: tests: no test for using shellescape() in combination with :!
  * 9.2.0522: event_nr2name() in autocmd.c can be improved
  * 9.2.0521: GTK4: cannot resize shell after the window is shown
  * 9.2.0520: Reversed text opacity in popup when termguicolor is set
  * 9.2.0519: GTK4: GUI tabline is not displayed correctly
  * 9.2.0518: GTK4: input method cannot compose text
  * 9.2.0517: quickfix: can set quickfixtextfunc in restricted/sandbox mode
  * 9.2.0516: socketserver: spurious error when servername is taken
  * 9.2.0515: virtualedit=insert doesn't work during change operation
  * 9.2.0514: GTK4: build errors when socketserver is enabled
  * 9.2.0513: [security]: memory safety issues in spellfile.c
  * 9.2.0512: clientserver uses binary protocol
  * 9.2.0511: configure: when GTK4 is used also links in X11 libs
  * 9.2.0510: setline() mapping may trigger autoindent
  * 9.2.0509: term.c: compile error when LOG_TRN is enabled
  * 9.2.0508: completion: cannot complete user cmd :K with 'ignorecase'
  * 9.2.0507: Vim9 class: public/protected member name clash uses same error
  * 9.2.0506: home_replace() function can be improved
  * 9.2.0505: GTK4: text looks blurry on HiDPI displays
  * 9.2.0504: configure: requires X11 libraries for GTK4 build
  * 9.2.0503: Makefile: Missing dependencies for new GTK4 source files
  * 9.2.0502: runtime(netrw): bookmark handling can be improved
  * 9.2.0501: GTK4: there is no GTK4 UI available
  * 9.2.0500: filetype: some html files wrongly recognized as htmlangular
  * 9.2.0499: modeline: allow to disable modelines with modelinestrict
  * 9.2.0498: potential heap buffer overflow in if_xcmdsrv.c
  * 9.2.0497: Cannot jump to remote tags
  * 9.2.0496: [security]: Code Injection in cucumber filetype plugin
  * 9.2.0495: [security]: runtime(netrw): code injection via NetrwBookHistSave()
  * 9.2.0494: User commands cannot handle single args with spaces
  * 9.2.0493: popup: missing  Popup, PopupBorder and PopupTitle hi groups
  * 9.2.0492: popup: decoration wrongly drawn with clipping on border
  * 9.2.0491: VMS: various build issues
  * 9.2.0490: matchfuzzy() can crash on long multi-word patterns
  * 9.2.0489: filetype: some Objective-C files are not recognized
  * 9.2.0488: statusline: status line highlight blends into adjacent vsep cells
  * 9.2.0487: viminfo: possible signed int overflow in register array
  * 9.2.0486: out-of-bound read when recovering swap files
  * 9.2.0485: clipboard provider callback can be called recursively
  * 9.2.0484: TextPutPre triggers clipboard provider callback twice
  * 9.2.0483: popup: terminal embedded in an opacity popup freezes Vim on input
  * 9.2.0482: runtime(osc52): triggered twice with TextPutPoste autocmd
  * 9.2.0481: runtime(netrw): command injection possible via maps
  * 9.2.0480: [security]: runtime(netrw): code injection via mf command
  * 9.2.0479: [security]: runtime(tar): command injection in tar plugin
  * 9.2.0478: channel: redundant str/length assignments in channel_part_info()
  * 9.2.0477: popup: leftover content after popup_free under layout change
  * 9.2.0476: pattern completion leaks memory on alloc failures
  * 9.2.0475: runtime(netrw): bookmark paths not normalized
  * 9.2.0474: MS-Windows: hard to tell which Visual Studio version was selected with MSVC
  * 9.2.0473: Pasting ". register without autocommands breaks TextPut*
  * 9.2.0472: popup: column jitters when scrolled outside viewport
  * 9.2.0471: vimvars di_key initialized at runtime
  * 9.2.0470: No way to hook into put commands
  * 9.2.0469: popup: textprop-anchored popups bleed past host window edges
  * 9.2.0468: popups: not correctly updated from a CmdlineChanged autocommand
  * 9.2.0467: multi-line statusline loses highlighting attributes
  * 9.2.0466: popup: redraw can use stale blended cells
  * 9.2.0465: modeline: foldmarker cannot be set with modelinestrict
  * 9.2.0464: runtime(netrw): bookmarking directory uses current dir
  * 9.2.0463: Not able to use legacy expression evaluation in a vim9script maps
  * 9.2.0462: MS-Windows: workaround for assert error on GUI
  * 9.2.0461: Corrupted undofile causes use-after-free
  * 9.2.0460: did_set_shellpipe_redir() in wrong file
  * 9.2.0459: tests: test_termcodes fails (after v9.2.0456)
  * 9.2.0458: Crash with invalid shellredir/shellpipe value
  * 9.2.0457: Compile warning about unused variable
  * 9.2.0456: stray p character displayed on some terms
  * 9.2.0455: 'findfunc' only allows extra info for cmdline completion
  * 9.2.0454: tests: no test that "abbr" in customlist completion is shown
  * 9.2.0453: vertical separator of statusline blend into active statusline
  * 9.2.0452: screen.c popup opacity blend logic is duplicated
  * 9.2.0451: 'findfunc' can't return extra info for cmdline completion
  * 9.2.0450: [security]: heap buffer overflow in spellfile.c read_compound()
  * 9.2.0449: Make proto fails in non GTK builds
  * 9.2.0448: Vim9: dangling cmdline pointer after skip_expr_cctx()
  * 9.2.0447: cindent does not ignore comments
  * 9.2.0446: runtime(netrw): off-by-one bug in s:NetrwUnMarkFile()
  * 9.2.0445: win_fix_scroll() called before win_comp_pos() in command_height()
  * 9.2.0444: Cannot set 'path' option via modeline
  * 9.2.0443: GUI: cancelling save dialog overwrites or discards unnamed buffer
  * 9.2.0442: completion: i_CTRL-X_CTRL-V doesn't use dict from customlist
  * 9.2.0441: statusline: click handler not called on multi-line statusline
  * 9.2.0440: MS-Windows: cursor flicker during update_screen()
  * 9.2.0439: completion: info popup not removed in cmdline mode
  * 9.2.0438: tests: test_plugin_termdebug is flaky
  * 9.2.0437: MS-Windows: cursor flicker in vtp mode
  * 9.2.0436: Buffer overflow when parsing overlong errorformat lines
  * 9.2.0435: [security]: backticks in 'path' may cause shell execution on completion
  * 9.2.0434: cscope: filename interpreted by /bin/sh
  * 9.2.0433: customlist completion cannot supply pum metadata
  * 9.2.0432: blob to string conversion can be improved
  * 9.2.0431: blob encoding can be improved
  * 9.2.0430: tests: Test_shortmess_F3() is flaky on MS-Windows
  * 9.2.0429: tests: flaky screendump Test_smoothscroll_incsearch()
  * 9.2.0428: popup: no opacity support for completepopup/previewpopup
  * 9.2.0427: popup: opacity blend may leaks white bg color
  * 9.2.0426: tests: still some flaky screendump tests
  * 9.2.0425: Cannot silence undo/redo messages
  * 9.2.0424: popup: flicker when wildtrigger() refreshes the popup menu
  * 9.2.0423: popup: wrapped cmdline truncated with wildoptions=pum
  * 9.2.0422: popup: leave stray char when scrollbar changes
  * 9.2.0421: vimball: can smuggle Vimscript into VimballRecord file
  * 9.2.0420: channel: cannot handle binary data via channel callbacks
  * 9.2.0419: popup: rendering issues
  * 9.2.0418: wildcards in expanded env vars reinterpreted by glob
  * 9.2.0417: completion: no support for "noinsert" with 'wildmode'
  * 9.2.0416: Unix: filename completion splits at space for single-file Ex commands
  * 9.2.0415: Wrong behavior when executing register that ends in Insert mode
  * 9.2.0414: Flicker when drawing window separator and pum is shown
  * 9.2.0413: Scrolling wrong with 'splitkeep' when changing 'cmdheight'
  * 9.2.0412: channel: term_start() out_cb/err_cb no longer deliver raw chunks
  * 9.2.0411: tabpanel: no Vim script functions for the tabpanel
  * 9.2.0410: test suite races when run with parallel make
  * 9.2.0409: memory leaks in copy_substring_from_pos()
  * 9.2.0408: Insert-mode <Cmd> edits can corrupt undo
  * 9.2.0407: tabpanel: A few issues with the tabpanel
  * 9.2.0406: VisualNOS not used when Wayland selection ownership lost
  * 9.2.0405: when jumping to tags, will open URLs
  * 9.2.0404: redraw_listener_add() does not check secure flag
  * 9.2.0403: Vim9: def function sandbox bypass
  * 9.2.0402: pum: opacity not applied to wildmenu pum
  * 9.2.0401: tests: still a few flaky tests
  * 9.2.0400: sandbox callbacks selected through 'complete'
  * 9.2.0399: MS-Windows: compile warning in strptime.c

- Fix bsc#1261833 / CVE-2026-39881.
- Update to 9.2.0398.
- Changes:
  * 9.2.0398: MS-Windows: missing strptime() support
  * 9.2.0397: tabpanel: double-click opens a new tab
  * 9.2.0396: tests: Test_error_callback_terminal is flaky on macOS
  * 9.2.0395: tests: Test_backupskip() may read from $HOME
  * 9.2.0394: xxd: offsets greater than LONG_MAX print as negative
  * 9.2.0393: MS-Windows: link error with XPM support on UCRT64
  * 9.2.0392: tests: Some tests are flaky
  * 9.2.0391: tests: Comment in test_vim9_cmd breaks syntax highlighting
  * 9.2.0390: filetype: some Beancount files are not recognized
  * 9.2.0389: DECRQM still leaves stray "pp" on Apple Terminal.app
  * 9.2.0388: strange indent in update_topline()
  * 9.2.0387: DECRQM request may leave stray chars in terminal
  * 9.2.0386: No scroll/scrollbar support in the tabpanel
  * 9.2.0385: Integer overflow with "ze" and large 'sidescrolloff'
  * 9.2.0384: stale Insstart after <Cmd> cursor move breaks undo
  * 9.2.0383: [security]: runtime(netrw): shell-injection via sftp: and file: URLs
  * 9.2.0382: Wayland: focus-stealing is non-working
  * 9.2.0381: Vim9: Missing check_secure() in exec_instructions()
  * 9.2.0380: completion: a few issues in completion code
  * 9.2.0379: gui.color_approx is never used
  * 9.2.0378: Using int as bool type in win_T struct
  * 9.2.0377: Using int as bool type in gui_T struct
  * 9.2.0376: Vim9: elseif condition compiled in dead branch
  * 9.2.0375: prop_find() does not find a virt text in starting line
  * 9.2.0374: c_CTRL-{G,T} does not handle offset
  * 9.2.0373: Ctrl-R mapping not triggered during completion
  * 9.2.0372: pum: rendering issues with multibyte text and opacity
  * 9.2.0371: filetype: ghostty config files are not recognized
  * 9.2.0370: duplicate code with literal string_T assignment
  * 9.2.0369: multiple definitions of STRING_INIT macro
  * 9.2.0368: too many strlen() calls when adding strings to dicts
  * 9.2.0367: runtime(netrw): ~ note expanded on MS Windows
  * 9.2.0366: pum: flicker when updating pum in place
  * 9.2.0365: using int as bool
  * 9.2.0364: tests: test_smoothscroll_textoff_showbreak() fails
  * 9.2.0363: Vim9: variable shadowed by script-local function
  * 9.2.0362: division by zero with smoothscroll and small windows
  * 9.2.0361: tests: no tests for ch_listen() with IPs
  * 9.2.0360: Cannot handle mouse-clicks in the tabpanel
  * 9.2.0359: wrong VertSplitNC highlighting on winbar
  * 9.2.0358: runtime(vimball): still path traversal attacks possible
  * 9.2.0357: [security]: command injection via backticks in tag files
  * 9.2.0356: Cannot apply 'scrolloff' context lines at end of file
  * 9.2.0355: runtime(tar): missing path traversal checks in tar#Extract()
  * 9.2.0354: filetype: not all Bitbake include files are recognized
  * 9.2.0353: Missing out-of-memory check in register.c
  * 9.2.0352: 'winhighlight' of left window blends into right window
  * 9.2.0351: repeat_string() can be improved
  * 9.2.0350: Enabling modelines poses a risk
  * 9.2.0349: cannot style non-current window separator
  * 9.2.0348: potential buffer underrun when setting statusline like option
  * 9.2.0347: Vim9: script-local variable not found
  * 9.2.0346: Wrong cursor position when entering command line window
  * 9.2.0345: Wrong autoformatting with 'autocomplete'
  * 9.2.0344: channel: ch_listen() can bind to network interface
  * 9.2.0343: tests: test_clientserver may fail on slower systems
  * 9.2.0342: tests: test_excmd.vim leaves swapfiles behind
  * 9.2.0341: some functions can be run from the sandbox
  * 9.2.0340: pum_redraw() may cause flicker
  * 9.2.0339: regexp: nfa_regmatch() allocates and frees too often
  * 9.2.0338: Cannot handle mouseclicks in the tabline
  * 9.2.0337: list indexing broken on big-endian 32-bit platforms
  * 9.2.0336: libvterm: no terminal reflow support
  * 9.2.0335: json_encode() uses recursive algorithm
  * 9.2.0334: GTK: window geometry shrinks with with client-side decorations
  * 9.2.0333: filetype: PklProject files are not recognized
  * 9.2.0332: popup: still opacity rendering issues
  * 9.2.0331: spellfile: stack buffer overflows in spell file generation
  * 9.2.0330: tests: some patterns in tar and zip plugin tests not strict enough
  * 9.2.0329: tests: test_indent.vim leaves swapfiles behind
  * 9.2.0328: Cannot handle mouseclicks in the statusline
  * 9.2.0327: filetype: uv scripts are not detected
  * 9.2.0326: runtime(tar): but with dotted path
  * 9.2.0325: runtime(tar): bug in zstd handling
  * 9.2.0324: 0x9b byte not unescaped in <Cmd> mapping
  * 9.2.0323: filetype: buf.lock files are not recognized
  * 9.2.0322: tests: test_popupwin fails
  * 9.2.0321: MS-Windows: No OpenType font support
  * 9.2.0320: several bugs with text properties
  * 9.2.0319: popup: rendering issues with partially transparent popups
  * 9.2.0318: cannot configure opacity for popup menu
  * 9.2.0317: listener functions do not check secure flag
  * 9.2.0316: [security]: command injection in netbeans interface via defineAnnoType
  * 9.2.0315: missing bound-checks
  * 9.2.0314: channel: can bind to all network interfaces
  * 9.2.0313: Callback channel not registered in GUI
  * 9.2.0312: C-type names are marked as translatable
  * 9.2.0311: redrawing logic with text properties can be improved
  * 9.2.0310: unnecessary work in vim_strchr() and find_term_bykeys()
  * 9.2.0309: Missing out-of-memory check to may_get_cmd_block()
  * 9.2.0308: Error message E1547 is wrong
  * 9.2.0307: more mismatches between return types and documentation
  * 9.2.0306: runtime(tar): some issues with lz4 support
  * 9.2.0305: mismatch between return types and documentation
  * 9.2.0304: tests: test for 9.2.0285 doesn't always fail without the fix
  * 9.2.0303: tests: zip plugin tests don't check for warning message properly
  * 9.2.0302: runtime(netrw): RFC2396 decoding double escaping spaces
  * 9.2.0301: Vim9: void function return value inconsistent
  * 9.2.0300: The vimball plugin needs some love
  * 9.2.0299: runtime(zip): may write using absolute paths
  * 9.2.0298: Some internal variables are not modified
  * 9.2.0297: libvterm: can improve CSI overflow code
  * 9.2.0296: Redundant and incorrect integer pointer casts in drawline.c
  * 9.2.0295: 'showcmd' shows wrong Visual block size with 'linebreak'
  * 9.2.0294: if_lua: lua interface does not work with lua 5.5
  * 9.2.0293: :packadd may lead to heap-buffer-overflow
  * 9.2.0292: E340 internal error when using method call on void value
  * 9.2.0291: too many strlen() calls
  * 9.2.0290: Amiga: no support for AmigaOS 3.x
  * 9.2.0289: 'linebreak' may lead to wrong Visual block highlighting
  * 9.2.0288: libvterm: signed integer overflow parsing long CSI args
  * 9.2.0287: filetype: not all ObjectScript routines are recognized
  * 9.2.0286: still some unnecessary (int) casts in alloc()
  * 9.2.0285: :syn sync grouphere may go beyond end of line
  * 9.2.0284: tabpanel: crash when tabpanel expression returns variable line count
  * 9.2.0283: unnecessary (int) casts before alloc() calls
  * 9.2.0282: tests: Test_viminfo_len_overflow() fails
  * 9.2.0281: tests: Test_netrw_FileUrlEdit.. fails on Windows
wicked
- Update to version 0.6.79
  - Fix an indirect remote shell command injection via unsanitized
    dhcp strings and leaseinfo dump (bsc#1265221,CVE-2026-44932):
  - Fix to escape single-quotes in leaseinfo dump output used by the
    `wicked test dhcp4` and `wicked test dhcp6` and written to the
    /run/wicked/leaseinfo.* files, e.g. to pass them to netconfig.
    A netconfig modify filtered for strict key='value' lines without
    any escaped quotes and discarded these lines already before.
  - Fix posix-tz-dbname and tz-string option processing checks to
    permit only valid characters according to RFC4833.
  - Discard string values containing single-quotes in other options.
  - Trigger to regenerate initrd that may contain wicked binaries on
    updates from wicked versions <= 0.6.78.

- Update to version 0.6.78
  - man: small fixes in wireless manpage (gh#opensuse/wicked#1053)
  - rtnetlink: fix RTM_NEWLINK name resolution in debug (gh#opensuse/wicked#1052)
  - Add support for IPVLAN/IPVTAP (jsc#PED-1942, gh#opensuse/wicked#1050, gh#opensuse/wicked#1051)
  - fsm: remove children reference array from worker (gh#opensuse/wicked#1049)
  - ifxml: migrate and generate lower configs/policies (gh#opensuse/wicked#1048)
  - fsm: use refcount and array macros in worker and policy (gh#opensuse/wicked#1047)
  - route: use refcounted array and fix error leaks (gh#opensuse/wicked#1046)
  - utils: add support for refcounted objects in generic array (gh#openSUSE/wicked#1045)
zypper
- Transactional systems: Delegate rw-commands to
  transactional-wrapper if available (jsc#PED-13680, jsc#PED-15607)
  On a transactional system where the root filesystem is mounted
  read-only, zypper commands that modify the system cannot be
  executed directly.
  If the system provides a transactional-wrapper utility, zypper
  will automatically attempt to invoke it. The wrapper
  transparently executes the zypper command within a new, writable
  snapshot and manages the lifecycle of that snapshot based on the
  command's exit status.
  On transactional systems lacking a transactional-wrapper, users
  must manually invoke specialized tools -such as
  transactional-update- to install, update, or remove software.
- version 1.14.98

- Add --filter-version-change to zypper lu.
  Adds filtering by version change significance to reduce noise in
  update listings. Supports levels: rebuild (hides rebuild-only
  changes) and package (hides all release-only changes).
- version 1.14.97

- Autorefresh ris-services the way as plugin-services (bsc#1246504)
  It's actually wrong to treat service refreshes different
  depending on the service type. For the purpose of a service it
  makes no difference how the data about the repos to use are
  acquired.
- version 1.14.96

- Report download progress for command line rpms (fixes #613)
- Hint to '-vv ref' to see the mirrors used to download the
  metadata (bsc#1257882)
- Service: Allow "zypper ls SERVICE ..." to test whether a
  service with this alias is defined (bsc#1252744)
  The command prints an abstract of all services passed on the
  command line. It returns 3-ZYPPER_EXIT_ERR_INVALID_ARGS if some
  argument does not name an existing service.
- Keep repo data when updating the service settings (bsc#1252744)
- info: Enhance pattern content table (bsc#1158038)
  Alternatives (multiple packages providing the same requirement)
  are now listed as a single entry in the content table. The entry
  shows either the installed package which satisfies the
  requirement or the requirement itself as type 'Provides'.
  Listing all potential alternatives was miss leading, especially
  if the alternatives were mutual exclusive. It looked like an
  installed pattern had not-installed requirements and it was not
  possible to install all requirements at the same time.
- version 1.14.95