SUSE-CU-2026:9137-1: Security update of suse/multi-linux-manager/5.1/x86_64/server
sle-container-updates at lists.suse.com
sle-container-updates at lists.suse.com
Mon Aug 24 07:23:01 UTC 2026
SUSE Container Update Advisory: suse/multi-linux-manager/5.1/x86_64/server
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:9137-1
Container Tags : suse/multi-linux-manager/5.1/x86_64/server:5.1.5 , suse/multi-linux-manager/5.1/x86_64/server:5.1.5.8.25.2 , suse/multi-linux-manager/5.1/x86_64/server:latest
Container Release : 8.25.2
Severity : important
Type : security
References : 1183870 1240054 1243168 1244141 1245862 1245944 1247004 1247539
1250110 1252306 1253043 1253505 1253777 1254201 1254340 1254341
1254702 1254867 1254960 1254982 1254984 1255451 1256709 1257102
1257295 1257383 1257463 1258069 1258500 1258567 1259132 1259225
1259254 1259520 1259594 1259720 1259804 1260342 1260396 1260421
1260998 1261002 1261003 1261166 1261195 1261400 1261606 1261969
1261982 1261983 1262012 1262098 1262168 1262305 1262319 1262631
1262654 1262664 1262684 1263083 1263366 1263367 1263656 1263658
1263822 1263823 1263890 1264062 1264396 1264962 1264994 1265156
1265268 1265334 1265413 1265413 1265930 1266304 1266481 1267355
1267581 1267606 1267619 1267644 1267647 1267739 1267821 1267871
1268006 1268131 1268151 1268162 1268165 1268169 1268170 1268229
1268244 1268246 1268247 1268248 1268249 1268250 1268251 1268252
1268255 1268257 1268258 1268259 1268260 1268261 1268262 1268290
1268309 1268325 1268349 1268375 1268402 1268407 1268409 1268413
1268415 1268416 1268417 1268420 1268422 1268427 1268530 1268546
1268567 1268570 1268603 1268673 1268683 1268853 1268886 1268897
1268898 1268899 1268902 1268902 1268977 1269012 1269039 1269040
1269041 1269042 1269043 1269044 1269045 1269046 1269047 1269048
1269049 1269050 1269051 1269052 1269053 1269054 1269055 1269056
1269057 1269058 1269060 1269066 1269192 1269267 1269279 1269408
1269480 1269567 1269568 1269583 1269584 1269622 1269623 1269788
1269790 1269791 1269807 1269824 1269907 1269908 1269909 1269910
1269959 1270008 1270009 1270010 1270016 1270018 1270021 1270040
1270208 1270365 1270393 1270515 1270620 1270706 1270708 1270709
1270772 1270801 1270936 1270994 1271017 1271018 1271044 1271046
1271048 1271049 1271052 1271053 1271054 1271055 1271166 1271167
1271192 1271193 1271194 1271195 1271351 1271352 1271354 1271372
1271397 1271398 1271399 1271435 1271440 1271442 1271458 1271459
1271464 1271465 1271466 1271469 1271629 1271645 1271672 1271673
1271674 1271675 1271676 1271677 1271684 1271705 1271712 1271712
1271727 1271960 1271961 1271980 1271982 1271983 1271984 1271985
1271986 1271987 1271988 1271989 1271990 1272164 1272165 1272166
1272167 1272168 1272169 1272171 1272223 1272224 1272225 1272227
1272228 1272235 1272236 1272237 1272253 1272254 1272255 1272257
1272258 1272259 1272299 1272300 1272301 1272302 1272303 1272304
1272305 1272306 1272307 1272518 1272519 1272554 1272603 1272734
1272735 1272736 1272737 1273184 1273429 1273430 1273431 1273432
1273433 1273434 1273435 1273436 1273437 1273438 1273439 1273440
1273441 1274571 1274984 1275011 1275012 1275013 1275014 1275015
1275016 1275017 1275018 1275217 CVE-2025-15661 CVE-2025-48924
CVE-2025-59529 CVE-2025-66471 CVE-2026-0864 CVE-2026-10536 CVE-2026-10723
CVE-2026-10822 CVE-2026-11331 CVE-2026-11605 CVE-2026-11622 CVE-2026-11721
CVE-2026-11850 CVE-2026-11940 CVE-2026-11972 CVE-2026-11979 CVE-2026-12064
CVE-2026-12087 CVE-2026-12610 CVE-2026-12617 CVE-2026-13204 CVE-2026-13321
CVE-2026-13595 CVE-2026-14380 CVE-2026-14474 CVE-2026-14476 CVE-2026-14740
CVE-2026-14741 CVE-2026-1502 CVE-2026-15043 CVE-2026-15308 CVE-2026-15392
CVE-2026-15779 CVE-2026-26032 CVE-2026-27448 CVE-2026-27456 CVE-2026-3276
CVE-2026-3276 CVE-2026-39821 CVE-2026-40226 CVE-2026-40355 CVE-2026-40356
CVE-2026-40467 CVE-2026-40468 CVE-2026-40553 CVE-2026-41254 CVE-2026-41676
CVE-2026-41677 CVE-2026-41678 CVE-2026-41681 CVE-2026-41898 CVE-2026-41989
CVE-2026-41991 CVE-2026-41992 CVE-2026-42327 CVE-2026-4360 CVE-2026-43964
CVE-2026-44249 CVE-2026-44250 CVE-2026-44605 CVE-2026-44662 CVE-2026-44890
CVE-2026-44891 CVE-2026-44893 CVE-2026-45409 CVE-2026-45409 CVE-2026-45416
CVE-2026-45536 CVE-2026-45673 CVE-2026-45674 CVE-2026-45784 CVE-2026-46340
CVE-2026-46917 CVE-2026-46968 CVE-2026-47010 CVE-2026-47021 CVE-2026-47027
CVE-2026-47059 CVE-2026-47063 CVE-2026-47244 CVE-2026-47691 CVE-2026-4786
CVE-2026-48006 CVE-2026-48043 CVE-2026-48059 CVE-2026-4873 CVE-2026-50010
CVE-2026-50011 CVE-2026-50020 CVE-2026-50229 CVE-2026-50560 CVE-2026-53404
CVE-2026-53434 CVE-2026-53612 CVE-2026-53613 CVE-2026-53614 CVE-2026-53783
CVE-2026-53784 CVE-2026-53785 CVE-2026-53786 CVE-2026-53788 CVE-2026-53789
CVE-2026-53790 CVE-2026-53791 CVE-2026-53792 CVE-2026-53793 CVE-2026-53794
CVE-2026-53795 CVE-2026-53796 CVE-2026-53797 CVE-2026-53798 CVE-2026-53799
CVE-2026-53800 CVE-2026-53801 CVE-2026-53802 CVE-2026-53803 CVE-2026-5435
CVE-2026-54411 CVE-2026-54512 CVE-2026-54513 CVE-2026-54514 CVE-2026-54515
CVE-2026-54515 CVE-2026-55199 CVE-2026-55276 CVE-2026-55831 CVE-2026-55833
CVE-2026-55851 CVE-2026-55955 CVE-2026-55956 CVE-2026-56109 CVE-2026-56288
CVE-2026-56289 CVE-2026-56745 CVE-2026-56746 CVE-2026-56817 CVE-2026-56818
CVE-2026-56819 CVE-2026-56820 CVE-2026-56821 CVE-2026-56822 CVE-2026-57062
CVE-2026-57432 CVE-2026-58010 CVE-2026-58011 CVE-2026-58012 CVE-2026-58013
CVE-2026-58014 CVE-2026-58016 CVE-2026-58050 CVE-2026-58051 CVE-2026-58216
CVE-2026-58218 CVE-2026-58221 CVE-2026-58222 CVE-2026-58224 CVE-2026-59083
CVE-2026-59084 CVE-2026-59843 CVE-2026-59844 CVE-2026-59845 CVE-2026-59846
CVE-2026-59847 CVE-2026-59848 CVE-2026-59850 CVE-2026-59856 CVE-2026-59857
CVE-2026-59858 CVE-2026-59884 CVE-2026-59885 CVE-2026-59886 CVE-2026-59888
CVE-2026-59889 CVE-2026-59898 CVE-2026-59899 CVE-2026-59900 CVE-2026-59901
CVE-2026-59919 CVE-2026-59920 CVE-2026-59921 CVE-2026-59995 CVE-2026-59996
CVE-2026-59997 CVE-2026-59998 CVE-2026-59999 CVE-2026-60000 CVE-2026-60001
CVE-2026-60002 CVE-2026-60081 CVE-2026-60082 CVE-2026-60147 CVE-2026-6019
CVE-2026-6019 CVE-2026-6100 CVE-2026-6238 CVE-2026-66032 CVE-2026-66033
CVE-2026-66034 CVE-2026-66035 CVE-2026-6949 CVE-2026-70452 CVE-2026-70453
CVE-2026-70454 CVE-2026-70455 CVE-2026-70456 CVE-2026-70457 CVE-2026-70458
CVE-2026-70459 CVE-2026-70460 CVE-2026-70461 CVE-2026-70462 CVE-2026-70463
CVE-2026-70464 CVE-2026-7210 CVE-2026-73070 CVE-2026-73071 CVE-2026-73072
CVE-2026-73074 CVE-2026-73075 CVE-2026-73076 CVE-2026-73077 CVE-2026-73078
CVE-2026-7598 CVE-2026-7774 CVE-2026-8286 CVE-2026-8328 CVE-2026-8368
CVE-2026-8376 CVE-2026-8458 CVE-2026-8829 CVE-2026-8924 CVE-2026-8927
CVE-2026-9079 CVE-2026-9080 CVE-2026-9375 CVE-2026-9545 CVE-2026-9547
-----------------------------------------------------------------
The container suse/multi-linux-manager/5.1/x86_64/server was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2781-1
Released: Mon Jul 6 16:12:04 2026
Summary: Security update for postfix
Type: security
Severity: moderate
References: 1264062,CVE-2026-43964
This update for postfix fixes the following issue
- CVE-2026-43964: buffer overread and process crash via an enhanced status code that lacks text after the third number
(bsc#1264062).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2801-1
Released: Wed Jul 8 21:04:39 2026
Summary: Security update for jackson-annotations, jackson-bom, jackson-core, jackson-databind, jackson-dataformats-binary, jackson-modules-base, jackson-parent
Type: security
Severity: important
References: 1268603,1268897,1268898,1268899,1268902,CVE-2026-54512,CVE-2026-54513,CVE-2026-54514,CVE-2026-54515
This update for jackson-annotations, jackson-bom, jackson-core, jackson-databind, jackson-dataformats-binary, jackson-modules-base, jackson-parent fixes the following issues
- CVE-2026-54512: jackson-databind has a PolymorphicTypeValidator bypass via generic type parameters that allows
arbitrary class instantiation (bsc#1268897).
- CVE-2026-54513: jackson-databind: array subtype allowlist bypass in BasicPolymorphicTypeValidator (bsc#1268898).
- CVE-2026-54514: jackson-databind: InetSocketAddress deserialization triggers eager DNS resolution (bsc#1268899).
- CVE-2026-54515: jackson-databindi: case-insensitive deserialization bypasses per-property @JsonIgnoreProperties
(bsc#1268902).
- jackson-core: document length constraint bypass in blocking, async, and DataInput parsers (bsc#1268603).
Changes for jackson-annotations:
- Update to 2.18.8
* No changes since 2.17.3
Changes for jackson-bom:
- Update to 2.18.8
* Changes
+ #68: Remove 'junit' 4.x dependency from 'jackson-base' 2.18.x
to help junit5 migration
+ 'base/pom.xml' now creates '${project.version.underscore}' for
'cleansed' version of '${project.version}'
Changes for jackson-core:
- Update to 2.18.8
* Changes of 2.18.8
+ #1611: Apply number-length validator on streaming integer path
of async parser
* Changes of 2.18.7
+ #1570: Fail parsing from 'DataInput' if 'StreamReadConstraints
.getMaxDocumentLength()' set
(bsc#1268603, GHSA-2m67-wjpj-xhg9)
+ #1600: Rework 3rd party licenses in jar
+ #1602: 'UTF8DataInputJsonParser' needs to enforce
'StreamReadConstraints.maxNameLength' limit
* Changes of 2.18.6
+ #1512: Number-parsing fix for 'UTF8DataInputJsonParser'
+ #1548: 'StreamReadConstraints.maxDocumentLength' not checked
when creating parser with fixed buffer
+ #1555: Enforce 'StreamReadConstraints.maxNumberLength' for
non-blocking (async) parser
* Changes of 2.18.5
+ #1433: 'JsonParser#getNumberType()' throws
'JsonParseException' when the current token is non-numeric
instead of returning null
+ #1446: Invalid package reference to 'java.lang.foreign' from
'com.fasterxml.jackson.core:jackson-core' (from
'FastDoubleParser')
* Changes of 2.18.3
+ #1391: Fix issue where the parser can read back old number
state when parsing later numbers
+ #1397: Jackson changes additional values to infinite in case
of special JSON structures and existing infinite values
+ #1398: Fix issue that feature
COMBINE_UNICODE_SURROGATES_IN_UTF8 doesn't work when custom
characterEscape is used
* Changes of 2.18.2
+ #1359: Non-surrogate characters being incorrectly combined
when 'JsonWriteFeature.COMBINE_UNICODE_SURROGATES_IN_UTF8' is
enabled
* Changes of 2.18.1
+ #1353: Use fastdoubleparser 1.0.90
* Changes of 2.18.
+ #223: 'UTF8JsonGenerator' writes supplementary characters as a
surrogate pair: should use 4-byte encoding
+ #1230: Improve performance of 'float' and 'double' parsing
from 'TextBuffer'
+ #1251: 'InternCache' replace synchronized with 'ReentrantLock'
- the cache size limit is no longer strictly enforced for
performance reasons but we should never go far about the limit
+ #1252: 'ThreadLocalBufferManager' replace synchronized with
'ReentrantLock'
+ #1257: Increase InternCache default max size from 100 to 200
+ #1262: Add diagnostic method 'pooledCount()' in 'RecyclerPool'
+ #1264: Rename shaded 'ch.randelshofer:fastdoubleparser'
classes to prevent use by downstream consumers
+ #1271: Deprecate 'LockFreePool' implementation in 2.18 (remove
from 3.0)
+ #1274: 'NUL'-corrupted keys, values on JSON serialization
+ #1277: Add back Java 22 optimisation in FastDoubleParser
+ #1284: Optimize 'JsonParser.getDoubleValue()/getFloatValue()
/getDecimalValue()' to avoid String allocation
+ #1305: Make helper methods of 'WriterBasedJsonGenerator'
non-final to allow overriding
+ #1310: Add new 'StreamReadConstraints' ('maxTokenCount') to
limit maximum number of Tokens allowed per document#
+ #1331: Update to FastDoubleParser v1.0.1 to fix 'BigDecimal'
decoding proble
Changes for jackson-databind:
- Update to 2.18.8
* Changes of 2.18.8
+ #5950: Improve 'UUIDeserializer' error handling
+ #5951: Improve 'InetSocketAddress' deserialization
(bsc#1268899, CVE-2026-54514)
+ #5969: '@JsonView' by-passed for some 'setterless' creator
properties
+ #5971: '@JsonView' by-passed for unwrapped creator parameters
+ #5974: '@JsonIgnore' on Record property ignored with
'PropertyNamingStrategy'
+ #5981: 'BasicPolymorphicTypeValidator' setting
'allowIfSubTypeIsArray()' should validate element type
(bsc#1268898, CVE-2026-54513)
+ #5988: 'PolymorphicTypeValidator' needs to validate generic
type parameters too (bsc#1268897, CVE-2026-54512)
+ #5993: 'UPPER_SNAKE_CASE' / 'LOWER_CASE' 'NamingStrategyImpls'
fold case using JVM default locale (Turkish-I bug)
* Changes of 2.18.4
+ #4628: '@JsonIgnore' and '@JsonProperty.access=READ_ONLY' on
Record property ignored for deserialization
+ #5049: Duplicate creator property 'b' (index 0 vs 1) on simple
java record
* Changes of 2.18.3
+ #4444: The 'KeyDeserializer' specified in the class with
'@JsonDeserialize(keyUsing = ...)' is overwritten by the
'KeyDeserializer' specified in the 'ObjectMapper'.
+ #4827: Subclassed Throwable deserialization fails since
v2.18.0 - no creator index for property 'cause'
+ #4844: Fix wrapped array handling wrt 'null' by
'StdDeserializer'
+ #4848: Avoid type pollution in 'StringCollectionDeserializer'
+ #4860: 'ConstructorDetector.USE_PROPERTIES_BASED' does not
work with multiple constructors since 2.18
+ #4878: When serializing a Map via
Converter(StdDelegatingSerializer), a NullPointerException is
thrown due to missing key serializer
+ #4908: Deserialization behavior change with @JsonCreator and
@ConstructorProperties between 2.17 and 2.18
+ #4917: 'BigDecimal' deserialization issue when using
'@JsonCreator'
+ #4920: Creator properties are ignored on abstract types when
collecting bean properties, breaking AsExternalTypeDeserializer
+ #4922: Failing '@JsonMerge' with a custom Map
+ #4932: Conversion of 'MissingNode' throws
'JsonProcessingException'
* Changes of 2.18.2
+ #4733: Wrong serialization of Type Ids for certain types of
Enum values
+ #4742: Deserialization with Builder, External type id,
'@JsonCreator' failing
+ #4777: 'StdValueInstantiator.withArgsCreator' is now set for
creators with no arguments
+ #4783 Possibly wrong behavior of @JsonMerge
+ #4787: Wrong 'String.format()' in 'StdDelegatingDeserializer'
hides actual error
+ #4788: 'EnumFeature.WRITE_ENUMS_TO_LOWERCASE' overrides
'@JsonProperty' values
+ #4790: Fix '@JsonAnySetter' issue with 'setter' method
(related to #4639)
+ #4807: Improve 'FactoryBasedEnumDeserializer' to work better
with XML module
+ #4810: Deserialization using '@JsonCreator' with renamed
property failing (since 2.18)
* Changes of 2.18.1
+ #4508: Deserialized JsonAnySetter field in Kotlin data class
is null
+ #4639: @JsonAnySetter on field ignoring unrecognized
properties if they are declared before the last recognized
properties in JSON
+ #4718: Should not fail on trying to serialize
'java.time.DateTimeException'
+ #4724: Deserialization behavior change with Records,
'@JsonCreator' and '@JsonValue' between 2.17 and 2.18
+ #4727: Eclipse having issues due'module-info' class 'lost' on
2.18.0 jars
+ #4741: When 'Include.NON_DEFAULT' setting is used on POJO,
empty values are not included in json if default is 'null'
+ #4749: Fixed a problem with
'StdDelegatingSerializer#serializeWithType' looking up the
serializer with the wrong argument
* Changes of 2.18.0
+ #562: Allow '@JsonAnySetter' to flow through Creators
+ #806: Problem with 'NamingStrategy', creator methods with
implicit names
+ #2977: Incompatible 'FAIL_ON_MISSING_PRIMITIVE_PROPERTIES' and
field level '@JsonProperty'
+ #3120: Return 'ListIterator' from 'ArrayNode.elements()'
+ #3241: 'constructorDetector' seems to invalidate
'defaultSetterInfo' for nullability
+ #3439: Java Record '@JsonAnySetter' value is null after
deserialization
+ #4085: '@JsonView' does not work on class-level for records
+ #4119: Exception when deserialization uses a record with a
constructor property with 'access=READ_ONLY'
+ #4356: 'BeanDeserializerModifier::updateBuilder()' doesn't
work for beans with Creator methods
+ #4407: 'null' type id handling does not work with
'writeTypePrefix()'
+ #4452: '@JsonProperty' not serializing field names properly on
'@JsonCreator' in Record
+ #4453: Allow JSON Integer to deserialize into a single-arg
constructor of parameter type 'double'
+ #4456: Rework locking in 'DeserializerCache'
+ #4458: Rework synchronized block from 'BeanDeserializerBase'
+ #4464: When 'Include.NON_DEFAULT' setting is used, 'isEmpty()'
method is not called on the serializer
+ #4472: Rework synchronized block in 'TypeDeserializerBase'
+ #4483: Remove 'final' on method BeanSerializer.serialize()
+ #4515: Rewrite Bean Property Introspection logic in Jackson
2.x
+ #4545: Unexpected deserialization behavior with
'@JsonCreator', '@JsonProperty' and javac '-parameters'
+ #4570: Deprecate 'ObjectMapper.canDeserialize()'/'ObjectMapper
.canSerialize()'
+ #4580: Add 'MapperFeature
.SORT_CREATOR_PROPERTIES_BY_DECLARATION_ORDER' to use Creator
properties' declaration order for sorting
+ #4584: Provide extension point for detecting 'primary'
Constructor for Kotlin (and similar) data classes
+ #4602: Possible wrong use of _arrayDelegateDeserializer in
BeanDeserializerBase::deserializeFromObjectUsingNonDefault()
+ #4617: Record property serialization order not preserved
+ #4626: '@JsonIgnore' on Record property ignored for
deserialization, if there is getter override
+ #4630: '@JsonIncludeProperties', '@JsonIgnoreProperties'
ignored when serializing Records, if there is getter override
+ #4634: '@JsonAnySetter' not working when annotated on both
constructor parameter & field
+ #4678: Java records don't serialize with 'MapperFeature
.REQUIRE_SETTERS_FOR_GETTERS'
+ #4688: Should allow deserializing with no-arg
'@JsonCreator(mode = DELEGATING)'
+ #4694: Deserializing 'BigDecimal' with large number of
decimals result in incorrect value
+ #4699: Add extra 'writeNumber()' method in 'TokenBuffer'
+ #4709: Add 'JacksonCollectors' with 'toArrayNode()'
implementation
+ Fix #5962: Case-insensitive deserialization may use wrong
@JsonIgnoreProperties (bsc#1268902, CVE-2026-54515)
- Fix 'Not fully interpolated version' error with Maven 4
Changes for jackson-dataformats-binary:
- Update to 2.18.8
* Changes of 2.18.8
+ #696: (ion) Incomplete number length validation in Ion decoder
(for 'BigDecimal' and/or 'BigInteger')
* Changes of 2.18.6
+ #645: (avro) Remove use of Avro 'Schema.Parser()
.setValidate()' to allow use of Avro core 1.12.1 (2.x)
+ #649: (cbor, smile) 'StreamReadConstraints.maxDocumentLength'
not checked when creating parser with fixed buffer
+ #651: (smile) Ensure Smile backend supports
'StreamReadConstraints.maxTokenCount'
+ #652: (cbor) Ensure CBOR backend supports
+ Minor fix to 'ProtobufGenerator._reportEnumError()' helper
method
* Changes of 2.18.5
+ #599: (cbor) Unable to deserialize stringref-enabled CBOR with
ignored properties
+ #623: (ion) Upgrade 'ion-java' dep to 1.11.11 (from 1.11.10)
* Changes of 2.18.4
+ #569: (ion) 'IonParser' fails to parse some 'long' values
saying they are out of range when they are not
+ #584: (protobuf) Missing 'JsonToken.END_OBJECT' for nested
Protobuf Objects
+ (ion) Upgrade 'ion-java' to 1.11.10 (from 1.11.9)
* Changes of 2.18.3
+ #541: (cbor, protobuf, smile) 'SmileParser.getValueAsString()'
FIELD_NAME bug
* Changes of 2.18.1
+ #518: Should not read past end for CBOR string values
* Changes of 2.18.0
+ #167: (avro) Incompatibility with Avro >=1.9.0 (upgrade to
Avro 1.11.3)
+ #484: (protobuf) Rework synchronization in 'ProtobufMapper'
+ #494: (avro) Avro Schema generation: allow mapping Java Enum
properties to Avro String values
+ #508: (avro) Ignore 'specificData' field on serialization
+ #509: IonValueMapper.builder() not implemented, does not
register modules
* (ion) Upgrade 'ion-java' to 1.11.9 (from 1.11.8)
value
Changes for jackson-modules-base:
- Upgrade to 2.18.8
* No changes since 2.18.0
* Changes of 2.18.0
+ #233: (jaxb) Tolerate JAX-RS 2.2 in
jackson-module-jaxb-annotations so that it can be deployed in
Liberty alongside features which use 2.2
+ #248: (android-record) jClass annotations and polymorphic
types are ignored when deserializing Android Record fields
+ #251: (android-record) Constructor is not recognized when a
record uses both arrays and generic types
Changes for jackson-parent:
- Update to 2.18.4
* Changes of 2.18.4
+ Update to latest 'oss-parent' (69)
* Changes of 2.18.3
+ Update to latest 'oss-parent' (68)
+ Switch to publishing via Sonatype Central Portal repo
* Changes of 2.18.2
+ Update to latest 'oss-parent' (66); future-proof for Sonatype
Central Portal
* Changes of 2.18.1
+ #15: Add override to downgrade 'moditect-maven-plugin' from
1.2.2 to 1.1.0 to work around Eclipse issues
* Changes of 2.18
+ Update to oss-parent 61 (plugin version updates)
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2802-1
Released: Wed Jul 8 21:06:07 2026
Summary: Security update for netty, netty-tcnative
Type: security
Severity: important
References: 1268165,1268169,1268170,1268244,1268246,1268247,1268248,1268249,1268250,1268251,1268252,1268255,1268257,1268258,1268259,1268260,1268261,1268262,CVE-2026-44249,CVE-2026-44250,CVE-2026-44890,CVE-2026-44893,CVE-2026-45416,CVE-2026-45536,CVE-2026-45673,CVE-2026-45674,CVE-2026-46340,CVE-2026-47244,CVE-2026-47691,CVE-2026-48006,CVE-2026-48043,CVE-2026-48059,CVE-2026-50010,CVE-2026-50011,CVE-2026-50020,CVE-2026-50560
This update for netty, netty-tcnative fixes the following issue
This update for netty, netty-tcnative fixes the following issues
Upgrade netty to upstream version 4.1.135, netty-tcnative to upstream version 2.0.79:
- CVE-2026-44249: IPv6 Subnet Filter Bypass via Incorrect Comparator Masking (bsc#1268165).
- CVE-2026-44250: Memory Exhaustion in RedisArrayAggregator due to Deeply Nested Arrays (bsc#1268169).
- CVE-2026-44890: Unbounded Direct Memory Consumption in RedisDecoder (bsc#1268170).
- CVE-2026-44893: netty-codec-haproxy: Denial of Service via malformed HAProxy message (bsc#1268244).
- CVE-2026-45416: SNI handler pre-allocates up to 16 MiB from nine attacker bytes (bsc#1268246).
- CVE-2026-45536: Unix-socket fd receive leaks descriptors when peer sends two at once (bsc#1268247).
- CVE-2026-45673: netty-resolver-dns: DNS Cache Poisoning via predictable transaction IDs (bsc#1268248).
- CVE-2026-45674: DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records (bsc#1268249).
- CVE-2026-46340: netty-transport-sctp: Denial of Service due to unbounded memory growth from SctpMessage fragments
(bsc#1268250).
- CVE-2026-47244: HTTP/2: Advertised MAX_CONCURRENT_STREAMS not enforced (bsc#1268251).
- CVE-2026-47691: Insufficient Bailiwick Validation for NS Records (bsc#1268252).
- CVE-2026-48006: netty-codec-redis: Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in
RedisArrayAggregator (bsc#1268255).
- CVE-2026-48043: netty-codec-http2: Denial of Service due to resource leak (bsc#1268257).
- CVE-2026-48059: netty-codec-haproxy: Denial of Service via memory leak from crafted PROXY protocol headers
(bsc#1268258).
- CVE-2026-50010: Wrapping plain trust manager silently disables hostname verification (bsc#1268259).
- CVE-2026-50011: Unbounded pre-allocation in RedisArrayAggregator from RESP array length (bsc#1268260).
- CVE-2026-50020: HttpObjectDecoder skips arbitrary initial control characters when only initial CRLF characters are
permitted (bsc#1268261).
- CVE-2026-50560: Netty susceptible to HTTP/2 Reset Attack with different on-the-wire signature (bsc#1268262).
Changes:
+ MQTT: Allow MQTT 5 CONNECT with password only
+ ChannelInitializer: correct misleading comment on
exceptionCaught route
+ HTTP/2: Parse request-target path like Vert.x (4.1 backport)
+ HttpObjectDecoder skips arbitrary initial control characters
when only initial CRLF characters are permitted
+ IpSubnetFilter: Correctly handle ipv6
+ Configurable bound on RedisArrayAggregator
+ Redis: Limit decoded length
+ DNS: Ensure query id is not predictible
+ Wrapping plain trust manager silently disables hostname
verification
+ MQTT: Reject malformed no-payload packets with non-zero
Remaining Length
+ HAProxy: Reject HAProxyMessages with malformated TLV and not
leak memory
+ SSL: Use sane defaults as limits for the client hello length
and timeout
+ DNS: Only cache CNAME if part of the queried domain
+ HTTP/2: Enforce max concurrent streams for misbehaving clients
+ Dns: Insufficient Bailiwick Validation for NS Records
+ HTTP2: DelegatingDecompressorFrameListener must release memory
in all cases
+ Pass maxAllocation to Brotli and Zstd decoders
+ HTTP/2: Treat clients MAX_HEADER_LIST_SIZE as advisory
+ Add maxWindowLog parameter to ZstdDecoder to bound memory
allocation
+ HAProxy: Fix ByteBuf leak when parsing nested SSL TLVs
+ Epoll / Kqueue: Correctly handle receive of FD
+ SCTP: Limit the number of inflight incomplete SCTP messages
and the number of fragments
+ Redis: Correctly release incomplete message on removal when
using RedisArrayAggregator
+ Redis: Limit the maximum number of nested arrays
+ HTTP: Re-add constructor to HttpProxyHandler that was removed
by mistake
+ Marshalling: Explicit document security requirements
+ Pin HTTP/RTSP version + method normalization to Locale.US
+ Adaptive: Fix concurrency issue in adaptive allocator
+ Pin multipart Content-Type / Content-Transfer-Encoding case
folding to Locale.US
+ Remove dead native declarations
+ Avoid re-parsing openssl key material with non-cached provider
+ IpFilter: Fix ClassCastException caused by IpSubnetFilter if
only ipv6 rules are configured but remote peer is using ipv4
+ Resolve all localhost addresses without querying DNS servers
+ HTTP2: Use 100 as default max concurrent streams setting
+ Route synchronous onLookupComplete exceptions via
fireExceptionCaught
+ Fix MQTT decoder size check after variable header replay
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2828-1
Released: Thu Jul 9 20:30:03 2026
Summary: Security update for python-idna
Type: security
Severity: moderate
References: 1265413,CVE-2026-45409
This update for python-idna fixes the following issue
- CVE-2026-45409: specially crafted inputs to idna.encode() can bypass earlier security fix (bsc#1265413).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2848-1
Released: Fri Jul 10 13:38:57 2026
Summary: Security update for krb5, krb5-mini
Type: security
Severity: important
References: 1263366,1263367,1268131,CVE-2026-11850,CVE-2026-40355,CVE-2026-40356
This update for krb5, krb5-mini fixes the following issues
- CVE-2026-11850: integer underflow in berval2tl_data() leads to heap out-of-bounds read (bsc#1268131).
- CVE-2026-40355: Denial of Service via NULL pointer dereference in NegoEx mechanism (bsc#1263366).
- CVE-2026-40356: Denial of Service via integer underflow and out-of-bounds read (bsc#1263367).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2854-1
Released: Fri Jul 10 19:58:37 2026
Summary: Security update for python-urllib3
Type: security
Severity: moderate
References: 1254867,1270365,CVE-2025-66471
This update for python-urllib3 fixes the following issue
- egression introduced by CVE-2025-66471 fix during file download with pySSL (bsc#1270365).
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:2893-1
Released: Mon Jul 13 13:40:09 2026
Summary: Recommended update for postgresql
Type: recommended
Severity: moderate
References: 1245862
This update for postgresql fixes the following issues:
Changes in postgresql:
- Get rid of update-alternatives and support immutable mode.
See README.SUSE for details. (bsc#1245862, jsc#PED-14820)
- Bump default to 17 for SLE-15-SP7.
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2925-1
Released: Mon Jul 13 19:53:23 2026
Summary: Security update for curl
Type: security
Severity: important
References: 1262631,1268402,1268407,1268409,1268413,1268415,1268416,1268417,1268420,1268422,1268427,CVE-2026-10536,CVE-2026-12064,CVE-2026-4873,CVE-2026-8286,CVE-2026-8458,CVE-2026-8924,CVE-2026-8927,CVE-2026-9079,CVE-2026-9080,CVE-2026-9545,CVE-2026-9547
This update for curl fixes the following issues
- CVE-2026-4873: connection reuse ignores TLS requirement (bsc#1262631).
- CVE-2026-8286: wrong STARTTLS connection reuse (bsc#1268402).
- CVE-2026-8458: wrong reuse for different services (bsc#1268407).
- CVE-2026-8924: traling dot domain super cookie (bsc#1268409).
- CVE-2026-8927: env-set cross-proxy Digest auth state leak (bsc#1268413).
- CVE-2026-9079: stale proxy password leak (bsc#1268415).
- CVE-2026-9080: UAF after pause in socket callback (bsc#1268416).
- CVE-2026-9545: exposing HTTP/3 early data (bsc#1268417).
- CVE-2026-9547: SSH improper host validation (bsc#1268420).
- CVE-2026-10536: HTTP/2 stream-dependency tree UAF (bsc#1268422).
- CVE-2026-12064: proto-default skips SSH verification (bsc#1268427).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2950-1
Released: Tue Jul 14 11:24:27 2026
Summary: Security update for perl-HTML-Parser
Type: security
Severity: moderate
References: 1267606,CVE-2026-8829
This update for perl-HTML-Parser fixes the following issue
- CVE-2026-8829: HTML:Entities versions before 3.84 for Perl read freed heap memory in _decode_entities (bsc#1267606).
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:2951-1
Released: Tue Jul 14 11:32:32 2026
Summary: Recommended update for dmidecode
Type: recommended
Severity: moderate
References:
This update for dmidecode fixes the following issues:
- Update to upstream version 3.7 (jsc#PED-16217):
* Support for SMBIOS 3.8.0. This includes a new processor family.
* Support for SMBIOS 3.9.0. This includes chassis type name
adjustments, new rack attributes, slot ID for more slot types,
and new memory device form factors and types.
* Decode HPE OEM records 193, 195, 202, 211, 226, 229, 232 and 244.
* Update HPE OEM records 203, 216, 242 and 245.
* EDSFF slot names now include their .S/.L suffix.
- Preserve the use of term 'BIOS' to avoid breaking customer scripts.
- Preserve the use of non-binary units to avoid breaking customer scripts.
- Drop legacy 'Provides:' and 'Obsoletes:' tags.
The split from the pmtools package happened 15 years ago so they are no longer relevant.
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2962-1
Released: Tue Jul 14 12:54:51 2026
Summary: Security update for perl-libwww-perl
Type: security
Severity: moderate
References: 1265156,CVE-2026-8368
This update for perl-libwww-perl fixes the following issue
- CVE-2026-8368: LWP: UserAgent: Authorization and Proxy-Authorization headers are leaked on cross-origin redirects
(bsc#1265156).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3026-1
Released: Wed Jul 15 11:49:35 2026
Summary: Security update for python-cryptography
Type: security
Severity: important
References: 1270208,1270515,1270620,1270706,1270772,1270801,1270936,1270994,CVE-2026-41676,CVE-2026-41677,CVE-2026-41678,CVE-2026-41681,CVE-2026-41898,CVE-2026-42327,CVE-2026-44662,CVE-2026-45784
This update for python-cryptography fixes the following issues
- CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1
(bsc#1270208).
- CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length in rust-
openssl crate (bsc#1270620).
- CVE-2026-41678: openssl: incorrect bounds assertion in aes key wrap in rust-openssl crate (bsc#1270706).
- CVE-2026-41681: openssl: MdCtxRef::digest_final() writes past caller buffer with no length check in rust-openssl crate
(bsc#1270772).
- CVE-2026-41898: openssl: unchecked callback-returned length in PSK and cookie generate trampolines can leak adjacent
memory in rust-openssl crate (bsc#1270801).
- CVE-2026-42327: openssl: arbitrary code execution via specially crafted certificate in rust-openssl crate
(bsc#1270515).
- CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key-wrap-with-padding in rust-openssl crate
(bsc#1270936).
- CVE-2026-45784: openssl: out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers in rust-
openssl crate (bsc#1270994).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3030-1
Released: Wed Jul 15 11:53:06 2026
Summary: Security update for glibc
Type: security
Severity: moderate
References: 1263656,1263658,CVE-2026-5435,CVE-2026-6238
This update for glibc fixes the following issues
- CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out-of-bounds write (bsc#1263656).
- CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure
(bsc#1263658).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3041-1
Released: Wed Jul 15 13:48:52 2026
Summary: Security update for sssd
Type: security
Severity: important
References: 1270708,1270709,CVE-2026-14474,CVE-2026-14476
This update for sssd fixes the following issues
- CVE-2026-14474: sudo LDAP provider searches entire directory tree for sudoRole objects by default, enabling privilege
escalation (bsc#1270709).
- CVE-2026-14476: GPO cache path traversal via unsanitized gPCFileSysPath allows Kerberos authentication bypass
(bsc#1270708).
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3060-1
Released: Wed Jul 15 16:08:22 2026
Summary: Recommended update for cloud-regionsrv-client, python-instance-billing-flavor-check
Type: recommended
Severity: moderate
References: 1247539,1250110,1253777,1254702,1254960,1254982,1254984,1260421,1265930,1267739
This update for cloud-regionsrv-client, python-instance-billing-flavor-check contains the following fixes:
cloud-regionsrv-client:
- Update to version 11.0.3
+ Write instance data cache file after cleaning the cache when
the update server fails. (bsc#1265930)
+ Create the cache directory when populating the cache. (bsc#1267739)
- Update to version 11.0.2:
+ Add iputils as a dependency to make automatic NVIDIA repo enablement
work. (bsc#1260421)
- Update to version 11.0.1:
+ Fix attempt to read a deleted file resulting in an error. Refresh
the file list for repos and services for each pass over the
server domains we are looking to clean up the registration.
+ Update user visible messages only showing messages for the
application configuration file.
- Update to version 11.0.0: (bsc#1254960, bsc#1254982, bsc#1253777)
+ Major version bump for main package and plugin sub-packages due to
interpreter change in SLE 15 SP4+ from Python 3.6 to Python 3.11
+ Create cache directory in code and drop from package (jsc#PED-14732)
+ Fix race condition between license watcher timer and registration
(bsc#1254984)
+ Fix cleanup issue in hosts (bsc#1254702)
+ Fix cache clean up
+ Fix exit condition from container registry setup
+ Lock the registration process to ensure single execution (bsc#1254984)
+ Fix traceback on FP and cert mismatch
+ Switch remaining code to updated logging implementation
+ Increase loggin information in log to help with issue debugging
+ Fix exit code on partial registration success
+ Remove obsolete switchcloudguestservices
- Update to version 10.5.3:
+ Move project setup to poetry and apply python standards
+ Fix use of logging facility
Use logging facility in the desired way throughout the entire
code base. This includes the following changes and refactor
* Add handler and formatter for the logfile containing more
information about function and position in code for the message
* Add handler for stdout (INFO and WARNING)
* Add handler for stderr (ERROR).
* Implement Logger class providing the logging setup and methods
* Drop the start_logging() method.
* Fix and refactor all unit tests around the use of logging
with a proper fixture and place all tests for registerutils
into its own class TestRegisterUtils.
* Add --debug switch for registercloudguest. Allow to increase
logfile information. All messages produced via log.debug(...)
in code will be part of the logfile. Debug messages will not
be shown on the console
* Update SLE12 patches due to logging refactor
* Use --debug flag in guestregister service
python-instance-billing-flavor-check:
- Build fix for SLE 16 and later. (bsc#1250110)
+ Switch SLE 15 SP4 - SP7 to Python 3.11 (jsc#PED-8944)a
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3076-1
Released: Thu Jul 16 15:04:17 2026
Summary: Security update for libssh2_org
Type: security
Severity: moderate
References: 1268530,CVE-2026-55199
This update for libssh2_org fixes the following issue
- CVE-2026-55199: pre-Authentication DoS via SSH_MSG_EXT_INFO Handler (bsc#1268530).
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3081-1
Released: Thu Jul 16 17:57:17 2026
Summary: Recommended update for supportutils
Type: recommended
Severity: moderate
References: 1256709,1257383,1258069,1259520
This update for supportutils fixes the following issues:
- Changes to version 3.2.14:
* Integrates supportutils-scrub for data obfuscation, use -j (PED-7324, bsc#1259520)
* Santize env.txt
* ha.txt: Collect hacluster passwd entry
* Added systemd cat unit.service output
* Added softirqs to proc (bsc#1258069)
* Check for /usr/lib/pam.d
* Ignore deprecated crash variable message
* Update supportconfig with note about bpftool
* Added /boot/grub2/grubenv (bsc#1257383)
* Verify procps pkg
- scplugin.rc is restored in package 3.2.12.1 for continued compatibility.
There is no furture development for scplugin.rc. Use supportconfig.rc.
Package version 3.2.12.2 does not have scplugin.rc. (bsc#1256709)
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3088-1
Released: Thu Jul 16 19:59:30 2026
Summary: Security update for tomcat
Type: security
Severity: moderate
References: 1269791,1269824,1269907,1269908,1269909,1269910,CVE-2026-50229,CVE-2026-53404,CVE-2026-53434,CVE-2026-55276,CVE-2026-55955,CVE-2026-55956
This update for tomcat fixes the following issues
Update to Tomcat 9.0.119.
Security issues fixed:
- CVE-2026-50229: improper neutralization of script-related HTML tags in the number guess example (bsc#1269791).
- CVE-2026-53404: always-incorrect control flow implementation in the rewrite valve caused non-OR conditions to be
skipped if the first condition in an OR chain matched (bsc#1269910).
- CVE-2026-53434: error condition not handled when configuring CRLs for a FFM based connector (bsc#1269824).
- CVE-2026-55276: always-incorrect control flow implementation caused special roles and empty authorization constraints
to not be included when the effective web.xml was logged (bsc#1269909).
- CVE-2026-55955: improper authentication allows a replay attack against the EncryptionInterceptor in the cluster
component (bsc#1269908).
- CVE-2026-55956: improper authorization leads to security constraints specified for the default servlet ignoring any
method or method omission configured as part of the constraint (bsc#1269907).
Other updates and bugfixes:
- Tomcat 9.0.119:
* Catalina
+ Add: Add support for literal '%' characters in access log output. Based on
pull request #1002 by Fabian Hahn. (markt)
+ Fix: Prevent duplicate log messages when clustering JARs are not present
on startup. (csutherl)
+ Code: Remove unnecessary code from the SSI processing engine that was
duplicating some of the normalisation checks. (markt)
+ Fix: Cleaner handling of invalid SPNEGO tokens. (remm)
+ Fix: Avoid some NPEs in the Connector class on an uninitialize protocol.
(remm)
+ Fix: Incorrect session average life calculation. (remm)
+ Fix: Improve robustness on using Pipeline.setBasic on a running pipeline.
(remm)
+ Fix: Avoid any init parameter updates when conflicts are found for
filters, similar to what is done for servlets, as required by the servlet
specification. (remm)
+ Fix: Fix container event cleanups in some edge cases. (remm)
+ Fix: Check for last-modified header in ExpiresFilter when a servlet uses
addDateHeader to avoid wrongly considering it has been set. (remm)
+ Fix: Fix hour unit used by ExpiresFilter. (remm)
+ Fix: Remove exception swallowing in DataSourceStore to align it with
FileStore and avoid session loss on errors. (remm)
+ Fix: Add support for single-quote escaped literal as well as quoted
literals in DateFormatCache. (schultz)
+ Fix: On JAAS logout, clear out role principals on the subject that were
added on commit, as recommended by the JAAS specification. (remm)
+ Fix: MemoryRealm should not add a dummy role when none is specified in the
configuration. (remm)
+ Fix: DataSourceUserDatabase should return a null principal on a non
existing user. (remm)
+ Fix: Fix shared lock expiration in WebDAV. (remm)
+ Fix: Inaccurate session exipration statistics when using the persistent
manager. (remm)
+ Fix: Skip BOM when serving files with UTF-32 encoding. (remm)
+ Fix: Mixup of WrapperListener and WrapperLifecycle elements in
storeconfig. (remm)
+ Fix: Incorrect processing of modified users in DataSourceUserDatabase.
(remm)
+ Update: Clarify behavior in the UserDatabase for user, role and group
creation that it does not immediately override existing elements. Removal
(or update) needs to be used instead. (remm)
+ Fix: 70049: Align the web application class loader with parent class
loaders and swallow any errors caused by invalid paths when looking up
resources and behave as if the resources were not found in that case.
(markt)
+ Fix: Improve validation of Range and Content-Range parsers so invalid
ranges trigger a 4xx response rather than a 500 response. Pull request
#1012 provided by Sahana Surendra Bogar. (markt)
+ Fix: Fix connection leak in ProxyErrorReportValve. (remm)
+ Fix: When using the RewriteValve, %{SSL:HTTPS} now returns on or off
rather than true or false to align with httpd. (markt)
+ Fix: Reset the encoding used for query string parameters between requests
in case an application changed the encoding in a previous request. (markt)
+ Fix: When encoding URLs with the CsrfPreventionFilter, don't add the nonce
to URLs that are known not to require it. (markt)
+ Fix: Fix CombinedRealm isAvailable, it allows authentication if at least
one sub realm is available. (remm)
+ Fix: 70048: Correctly handle asynchronous requests in PersistentValve.
(markt)
+ Fix: Improve the detection of cross-context dispatches when using a
RequestDispatcher. (markt)
+ Fix: Fix various instances of double decoding of URL patterns configured
either programmatically or in web.xml. (remm/markt)
+ Fix: Align the rewrite conditions ornext flag processing with mod_rewrite,
which follows a purely sequential evaluation strategy. (remm)
+ Fix: Change the default for the useRedirect attribute of the
ProxyErrorReportValve from true to false. (markt)
+ Add: Add support for the showReport attribute in JsonErrorReportValve and
ProxyErrorReportValve. When set to false, detailed error information
(message, description, stack trace) is suppressed from error responses.
(dsoumis)
+ Fix: Avoid a NoClassDefFoundError at startup when catalina-tribes.jar is
removed but catalina-ha.jar is present and the Cluster element is enabled
in server.xml. Cluster digester rules are now fully conditional on both
JARs being available. (dsoumis)
+ Fix: Fix a potential deadlock when copying resources using WebDAV. (markt)
+ Fix: Add jakarta., org.apache.catalina. and org.apache.tomcat.to the list
of reserved prefixes for SSI variables and request attributes. (markt)
+ Fix: Missing URL decoding when processing addMapping on a Servlet
registration. (remm)
+ Fix: The Timeout WebDAV header allows comma separated values (according to
the examples in the RFC). Use the first acceptable value. (remm)
+ Fix: Fix various issues when logging the effective web.xml for a web
application. Empty sections are no longer logged. Special roles and empty
authorisation constraints are included. (markt)
+ Fix: Expand the write lock for the save process in the MemoryUserDatabase
to avoid concurrency issues with the file save operations. (markt)
+ Fix: Ensure atomic session persistence in FileStore. Based on pull request
#1016 by sahvx655-wq. (markt)
+ Fix: Do not ignore methods configured on security constraints that map to
the default servlet. (markt)
* Cluster
+ Fix: Expand wording and increase visibility of log message when cloud
membership is configured without a trust store as all certificates will be
trusted in this configuration. (markt)
+ Fix: Ensure listeners are correctly added and removed when configuring the
channel coordinator. (markt)
+ Fix: Fix some concurrency issues in FragmentationInterceptor. (markt)
+ Fix: Fix some concurrency issues in OrderInterceptor. (markt)
+ Fix: Fix some concurrency issues in TwoPhaseCommitInterceptor. (markt)
+ Fix: Fix concurrency issues generating MD5 digests in the
CloudMembershipProvider implementations. (markt)
+ Add: Add replay protection to the EncryptInterceptor. This is a breaking
change for the EncryptInterceptor. (markt)
* Coyote
+ Add: Log a suitable warning if an encrypted PEM file is detected using an
insecure form for encryption. (markt)
+ Fix: If TLS groups have been configured, use the configured groups rather
than using OpenSSL's default TLS groups when using Tomcat Native with
OpenSSL based connectors. (markt)
+ Fix: For HTTP/2, ensure that any in progress request body reads are
cancelled if the container resets the associated stream. This prevents
delays waiting for reads to time out when it is known that no more data
will be received. (markt)
+ Fix: Ensure that malformed HTTP/2 messages that should trigger a stream
reset do so, rather than triggered a connection close. (markt)
+ Fix: Improve enforcement of header trailer allow list for HTTP/2. (remm)
+ Fix: 70050: Avoid NPE when no header frame is processed in HTTP/2,
following refactor clean-up of header buffer. (remm)
+ Fix: Properly use pollerThreadPriority for the NIO poller thread. (remm)
+ Fix: Fix MessageByte.equals if called on a null MB. (remm)
+ Fix: Call the delegate key manager in JSSE to retrieve the server key.
(remm)
+ Fix: Avoid overflow scenarios in Asn1Parser. (remm)
+ Fix: 70091: Add a new attribute, allowSchemeMismatch to Http2Protocol that
allows the consistency check for the scheme provided by the user agent to
be bypassed. (markt)
+ Fix: isTrailerFieldsReady was always returning true. (remm)
+ Fix: Align OpenSSL/Panama TLS implementation with other implementations
and throw an exception if there is an error loading the provided CRL(s).
(markt)
+ Fix: Parsing of OpenSSL format cipher expressions incorrectly stopped if
@STRENGTH was encountered, ignoring any subsequent expressions. (markt)
+ Fix: Handle the case where the HTTP/2 payload length is insufficient for
the mandatory data required by the flags set in the header. (markt)
+ Fix: 70102: Correct expected size of ticket keys when calling
setSessionTicketKeys with an FFM connector. (markt)
+ Fix: 69988: Fix post handshake authentication for TLS 1.3. It was broken
by a breaking change in OpenSSL between 1.1.1 and 3.0.0. (markt)
+ Fix: When processing an OpenSSL cipher specification, fully align the
order of the resulting ciphers with the order produced by OpenSSL. (markt)
+ Add: Add support for Brainpool TLS groups. Patch provided by YStankov.
(schultz)
+ Update: Update both the minimum and recommended version for Tomcat Native
1.x to 1.3.8. (markt)
* Jasper
+ Fix: Fix possible EL argument mismatch when it was set to null. (remm)
+ Fix: Fix thread safety of TagPluginManager. (remm)
+ Fix: Correctly use flush on JSP include. (remm)
* Web applications
+ Add: Manager: Add checks to ensure that any uploaded files are uploaded to
the expected location. (markt)
+ Add: Manager: Add checks to ensure that the requested context path for a
deployed WAR, directory or descriptor file is valid. (markt)
+ Add: Documentation: Expand the description of some of the attributes of
the CrawlerSessionManagerValve. (markt)
+ Fix: Documentation: Clearer description and correct documented default for
ocspSoftFail. (markt)
+ Fix: Fix double escaping in the context names for the JSON mode of the
manager servlet. (remm)
+ Fix: Manager: Ensure automatic deployment does not trigger an undeployment
during a Manager triggered web application reload. (markt)
+ Fix: Documentation: Provide better documentation for the scheme and secure
attributes of a Connector. (markt)
* Websocket
+ Fix: Incorrect Future.isDone() return by AsyncChannelWrapperSecure. (remm)
+ Fix: Trigger standard WebSocket error handling if a call to
Endpoint.onOpen() fails for a programmatic endpoint. (markt)
+ Fix: 70110: Fix memory leak if a call to Endpoint.onOpen() fails for a
programmatic endpoint. Test case provided by uabdur. (markt)
+ Fix: If a client presents invalid parameters when negotiating a WebSocket
extension, decline the negotiation offer that includes the invalid
parameters rather than failing the connection. Pull request #1019 provided
by sahvx655-wq. (markt)
* Other
+ Fix: Wrong references to jakarta instead of javax. (remm)
+ Fix: Restore default authenticator to nullafter executing an Ant task.
(remm)
+ Update: Update Commons Daemon to 1.6.1. (markt)
+ Update: Improvements to French translations. (remm)
+ Update: Improvements to Japanese translations provided by tak7iji. (markt)
+ Update: Update Tomcat Native to 1.3.8. (markt)
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3097-1
Released: Fri Jul 17 13:39:27 2026
Summary: Security update for libxml2
Type: security
Severity: important
References: 1269790,CVE-2026-11979
This update for libxml2 fixes the following issue
- CVE-2026-11979: stack-based buffer overflows in the `xmlcatalog` utility when running in `--shell` mode (bsc#1269790).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3100-1
Released: Fri Jul 17 13:41:45 2026
Summary: Security update for python-idna
Type: security
Severity: moderate
References: 1265413,CVE-2026-45409
This update for python-idna fixes the following issue
- CVE-2026-45409: specially crafted inputs to idna.encode() can bypass earlier security fix (bsc#1265413).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3104-1
Released: Fri Jul 17 15:31:14 2026
Summary: Security update for python311
Type: security
Severity: important
References: 1261969,1262098,1262319,1262654,CVE-2026-1502,CVE-2026-4786,CVE-2026-6019,CVE-2026-6100
This update for python311 fixes the following issues
- CVE-2026-1502: CR/LF bytes not rejected by HTTP client proxy tunnel headers or host (bsc#1261969).
- CVE-2026-4786: URLs containing `%action` can bypass mitigation that allows command injection via the
`webbrowser.open()` API (bsc#1262319).
- CVE-2026-6019: HTML parser-sensitive sequence not neutralized by `http.cookies.Morsel.js_output()` (bsc#1262654).
- CVE-2026-6100: use-after-free in decompression modules when a memory allocation fails with a `MemoryError` and the
decompression instance is re-used (bsc#1262098).
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3106-1
Released: Fri Jul 17 16:02:05 2026
Summary: Recommended update for kmod
Type: recommended
Severity: moderate
References:
This update for kmod fixes the following issues:
- Use in-kernel decompression if available (jsc#PED-16303):
* libkmod:
+ Add a separate function to load the file contents when it's needed.
When it's not needed on the path of loading modules via finit_module(),
there is no need to mmap the file.
+ Extract 2 functions to handle finit_module vs init_modules differences,
with a fallback from the former to the latter.
+ Don't only set the type as direct, but also keep track of the compression being used.
+ When creating the context, read /sys/kernel/compression to check.
what's the compression type supported by the kernel.
+ Use kernel decompression when available
+ add fallback MODULE_INIT_COMPRESSED_FILE define
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3118-1
Released: Fri Jul 17 22:18:41 2026
Summary: Recommended update for gcc15
Type: recommended
Severity: moderate
References: 1252306,1253043,1257463
This update for gcc15 fixes the following issues:
- Update to GCC 15.3 release
- Drop -fhardened from RPM_OPT_FLAGS
- Avoid conflicts between %gcc_libc_bootstrap packages of different
versions if update-alternatives are still in use (SLE 15 and older)
- Allow conversions to/from uint32_t. Filter out -Wtime_t-conversion
from flags to build D target library files. [jsc#PED-15601]
- Remove loongarch64 from quadmath_arch. On LoongArch long double
is IEEE quad, so libquadmath is not needed and no longer built.
- includes fix for bogus expression simplification [bsc#1257463]
even when not available at build time. [bsc#1253043]
- Backport fix that cures a miscompile of libgo on arm. [bsc#1252306]
- Check availability of builtins at expand time
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3141-1
Released: Tue Jul 21 09:04:39 2026
Summary: Recommended update for shadow
Type: recommended
Severity: important
References: 1270393
This update for shadow fixes the following issues:
- Fix regression about default GID by setting USERGROUPS_ENAB to no Update (bsc#1270393)
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3145-1
Released: Tue Jul 21 10:38:13 2026
Summary: Recommended update for log4j
Type: recommended
Severity: important
References:
This update for log4j fixes the following issues:
log4j was updated and includes fixes and improvements from versions 2.21.0 through 2.26.0:
- Bugs fixed:
- Fixed crashes when logging errors with stack traces modified by other threads
- Fixed FATAL-level log messages being silently discarded
- Fixed memory leaks in several components
- Fixed log file headers not being written correctly when files are recreated
- Fixed log file rotation failures
- Fixed configuration file loading from HTTP sources
- Fixed date and time formatting issues in logs
- Fixed problems when multiple threads modify logger settings simultaneously
- Fixed MongoDB appender connection issues
- New Features Added:
- Support for ZStandard compression for log files
- Support for LMAX Disruptor 4.x (high-performance logging)
- Better support for GraalVM environments
- Java 8 users now get sub-millisecond precision timestamps
- Features Removed:
- JMX GUI tool (moved to separate release)
- Flume Appender (moved to separate release)
- Kubernetes lookup feature (users should migrate to io.fabric8:kubernetes-log4j)
- JAnsi library support (Windows 10+ has built-in color support)
- Important Changes:
- JMX monitoring is now DISABLED by default (set log4j2.disableJmx=false to enable)
- Default log format has changed
- Configuration scripts now require explicit names
- Deprecations (features to be removed in the future):
- MongoDB4 module (use standard MongoDB module instead)
- EventLogger class
- Some builder methods (replaced with setter methods)
New Runtime Dependencies:
- jackson-dataformat-xml
- stax2-api
- woodstox-core
New and Updated Build Dependencies:
- aalto-xml (updated from version 1.3.3 to 1.4.0)
- jakarta-annotations (new)
- jakarta-messaging (new)
- jspecify (new)
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3155-1
Released: Tue Jul 21 14:58:48 2026
Summary: Security update for python-tornado6
Type: security
Severity: moderate
References: 1269012
This update for python-tornado6 fixes the following issue
- GHSA-pw6j-qg29-8w7f: `CurlAsyncHTTPClient` leaks per-request credentials on handle reuse (bsc#1269012).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3161-1
Released: Tue Jul 21 16:30:29 2026
Summary: Security update for patch
Type: security
Severity: low
References: 1271166,1271167,CVE-2026-56288,CVE-2026-56289
This update for patch fixes the following issues
- CVE-2026-56288: crafted unified-diff patch file can cause null pointer derefence (bsc#1271167).
- CVE-2026-56289: improper validation of hunk line offsets can lead to denial of service (bsc#1271166).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3163-1
Released: Tue Jul 21 16:50:54 2026
Summary: Security update for pam
Type: security
Severity: moderate
References: 1268290,CVE-2026-54411
This update for pam fixes the following issue
- CVE-2026-54411: timing discrepancy in the pam_userdb module's plaintext-password comparison (bsc#1268290).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3182-1
Released: Wed Jul 22 09:25:44 2026
Summary: Security update for libgcrypt
Type: security
Severity: moderate
References: 1262684,CVE-2026-41989
This update for libgcrypt fixes the following issue
- CVE-2026-41989: heap-based buffer overflow when processing crafted ECDH ciphertext can lead to a denial of service
(bsc#1262684).
-----------------------------------------------------------------
Advisory ID: SUSE-OU-2026:3190-1
Released: Wed Jul 22 11:24:58 2026
Summary: Optional update for zypp-plugin
Type: optional
Severity: low
References:
This update for zypp-plugin fixes the following issue:
- Add python311-zypp-plugin to Public Cloud Modules. No source change.
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3191-1
Released: Wed Jul 22 16:08:30 2026
Summary: Recommended update for adcli
Type: recommended
Severity: moderate
References: 1183870
This update for adcli fixes the following issues:
Update to 0.9.3.1; (jsc#PED-13768);
* enroll: check if AD accepts new password
* enroll: allow to add SPNs to manages service accounts
* enroll: add new SPNs from AD to keytab during update
* conn: use 10s timeout for connect()
* enroll: restore SELinux file context of keytab files
* enroll: remove USE_DES_KEY_ONLY during join
* entry: check user and group names for illegal characters
* tools: add --recursive option to delete-computer
* tools: testjoin, use realm from keytab as domain name
* enroll: use realm form the HOST$ entry in the keytab
* Tests: initial framework and tests for adcli based on
sssd-test-framework
* krb5: add adcli_krb5_get_error_message()
* Various fixes for issues found by static code scanners
* enroll: Populate Samba's secrets database using offline domain
join
Update to 0.9.2:
* adenroll: set password via LDAP instead Kerberos
* disco: fall back to LDAPS if CLDAP ping was not successful
* tools: replace getpass()
* adenroll: write SID before secret to Samba's db
* doc: add clarification to add-member command on doc/adcli.xml
* tools: Set umask before calling mkdtemp()
* Avoid undefined behaviour in short option parsing
* library: include endian.h for le32toh
* man: Fix typos and use consistent upper case for some keywords
* configure: check for ns_get16 and ns_get32 as well
* Add setattr and delattr options
* entry: add passwd-user sub-command
* Add dont-expire-password option
Update to 0.9.1:
* tools: add show-computer command
* add description option to join and update
* Use GSS-SPNEGO if available
* add option use-ldaps
* tools: disable SSSD's locator plugin
* doc: explain required AD permissions
* computer: add create-msa sub-command
* Add account-disable option
* fix coredump in discovery (boo#1183870)
Update to 0.9.0:
* doc: add missing samba_data_tool_path.xml(.in) to EXTRA_DIST
* doc: explain how to force password reset
* Do not use arcfour-hmac-md5 when discovering the salt
* Fix for issue found by Coverity
* adenroll: use only enctypes permitted by Kerberos config
* adenroll: add adcli_enroll_get_permitted_keytab_enctypes with tests
* adconn: add adcli_conn_set_krb5_context
* adenroll: make sure only allowed enctypes are used in FIPS mode
* tools: computer - remove errx from parse_option
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3218-1
Released: Thu Jul 23 19:34:12 2026
Summary: Security update for avahi
Type: security
Severity: moderate
References: 1255451,CVE-2025-59529
This update for avahi fixes the following issue:
- CVE-2025-59529: local DoS due to simple protocol server ignoring client limit CLIENTS_MAX (bsc#1255451).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3225-1
Released: Thu Jul 23 20:36:00 2026
Summary: Security update for apache-commons-compress, apache-ivy, brotli-java, zstd-jni
Type: security
Severity: moderate
References: 1269480,1271727,CVE-2026-26032
This update for apache-commons-compress, apache-ivy, brotli-java, zstd-jni fixes the following issue
Security issues fixed:
- CVE-2026-26032: improper pathname limitation in `PackagerResolver` allows for arbitrary files writes outside of the
configured `buildRoot` directory (bsc#1271727).
Other updates and bugfixes:
- Update `apache-commons-compress` to 1.28.0.
- Update `apache-ivy` to 2.6.0.
- Include `brotli-java` and update to 1.2.0.
- Include `zstd-jni` and update to v1.5.7.11.
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3238-1
Released: Fri Jul 24 14:55:49 2026
Summary: Security update for python-pyasn1
Type: security
Severity: important
References: 1271464,1271465,1271466,CVE-2026-59884,CVE-2026-59885,CVE-2026-59886
This update for python-pyasn1 fixes the following issues:
- CVE-2026-59884: BER/CER/DER decoder denial of service via unbounded long-form tag IDs (bsc#1271464).
- CVE-2026-59885: quadratic complexity in OBJECT IDENTIFIER and RELATIVE-OID processing allows denial of service
(bsc#1271465).
- CVE-2026-59886: uncontrolled resource consumption when converting decoded REAL values (bsc#1271466).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3243-1
Released: Fri Jul 24 15:09:32 2026
Summary: Security update for gpg2
Type: security
Severity: low
References: 1269279,CVE-2026-57062
This update for gpg2 fixes the following issue:
- CVE-2026-57062: CMS parsing in gpgsm mishandles the CMS format for AES-GCM (bsc#1269279).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3244-1
Released: Fri Jul 24 15:11:25 2026
Summary: Security update for systemd
Type: security
Severity: moderate
References: 1261400,1261982,1261983,1262305,1267644,1267647,CVE-2026-40226
This update for systemd fixes the following issues
Security issues fixed:
- CVE-2026-40226: nspawn: escape-to-host via malformed optional config file (bsc#1261400).
Other updates and bugfixes:
- Fix soft reboot not restarting user services with default.target (bsc#1262305).
- Import commit e46e1952d5 (bsc#1267647 bsc#1262305 bsc#1267644).
- Import commit 429043ca9a (bsc#1261982 bsc#1261983).
- Import commit 58e5d2e21e (bsc#1261982).
- Import commit 4bd91117cc (bsc#1261983).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3269-1
Released: Mon Jul 27 13:00:16 2026
Summary: Security update for gzip
Type: security
Severity: important
References: 1269622,CVE-2026-41991
This update for gzip fixes the following issue:
- CVE-2026-41991: insecure temporary file handling in the gzexe utility when the mktemp utility is not available in the
user's PATH (bsc#1269622).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3270-1
Released: Mon Jul 27 13:01:22 2026
Summary: Security update for alsa
Type: security
Severity: moderate
References: 1268853,CVE-2026-56109
This update for alsa fixes the following issue
- CVE-2026-56109: double-free vulnerability in parse_def() in src/conf.c that can allow attackers to corrupt memory
(bsc#1268853).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3273-1
Released: Mon Jul 27 13:32:13 2026
Summary: Security update for jackson-annotations, jackson-bom, jackson-core, jackson-databind, jackson-dataformats-binary, jackson-modules-base
Type: security
Severity: moderate
References: 1268902,1271440,1271442,CVE-2026-54515,CVE-2026-59888,CVE-2026-59889
This update for jackson-annotations, jackson-bom, jackson-core, jackson-databind, jackson-dataformats-binary, jackson-modules-base fixes the following issues:
- CVE-2026-54515: rebuilding the property map from unfiltered bean properties could permit a bypass of
@JsonIgnoreProperties exclusions (bsc#1268902).
- CVE-2026-59889: missing view guard when deserializing @JsonUnwrapped properties could allow unauthorized writes to
@JsonView restricted fields (bsc#1271440).
- CVE-2026-59888: mismatch between property renaming and ignore-filtering on Java Records could allow a bypass of
@JsonIgnore restrictions (bsc#1271442).
Changes for jackson-annotations:
- Update to 2.18.9.
Changes for jackson-bom:
- Update to 2.18.9.
Changes for jackson-core:
- Update to 2.18.9.
Changes for jackson-databind:
- Update to 2.18.9:
* honor @JsonView for external-type-id (EXTERNAL_PROPERTY) properties (GHSA-mhm7-754m-9p8w).
Changes for jackson-dataformats-binary:
- Update to 2.18.9.
Changes for jackson-modules-base:
- Update to 2.18.9.
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3330-1
Released: Tue Jul 28 11:35:51 2026
Summary: Security update for libssh
Type: security
Severity: moderate
References: 1272164,1272165,1272166,1272167,1272168,1272169,1272171,CVE-2026-59843,CVE-2026-59844,CVE-2026-59845,CVE-2026-59846,CVE-2026-59847,CVE-2026-59848,CVE-2026-59850
This update for libssh fixes the following issues:
- CVE-2026-59843: denial of service via zero advertised channel packet size (bsc#1272164).
- CVE-2026-59844: denial of service via oversized SFTP read length (bsc#1272165).
- CVE-2026-59845: denial of service via unchecked ProxyCommand fork() failure (bsc#1272166).
- CVE-2026-59846: information disclosure via ProxyCommand %r username expansion (bsc#1272167).
- CVE-2026-59847: integrity downgrade via OpenSSL AES-GCM tag verification (bsc#1272168).
- CVE-2026-59848: denial of service via SFTP responses with unknown request IDs (bsc#1272169).
- CVE-2026-59850: use-after-free via data callbacks on closed channels (bsc#1272171).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3341-1
Released: Tue Jul 28 12:09:19 2026
Summary: Security update for glib2
Type: security
Severity: important
References: 1270008,1270009,1270010,1270016,1270018,1270021,CVE-2026-58010,CVE-2026-58011,CVE-2026-58012,CVE-2026-58013,CVE-2026-58014,CVE-2026-58016
This update for glib2 fixes the following issues:
- CVE-2026-58010: error during gvs_tuple_is_normal alignment validation could cause a 1-byte out-of-bounds read
(bsc#1270009).
- CVE-2026-58011: invalid GDateTime in g_date_time_get_ymd could trigger a 2-byte out-of-bounds read (bsc#1270010).
- CVE-2026-58012: raw byte regex matches with UTF-8 functions during case-change replacements could cause an out-of-
bounds read (bsc#1270016).
- CVE-2026-58013: multi-byte custom line terminator in g_io_channel_read_line_backend could trigger an out-of-bounds
read (bsc#1270018).
- CVE-2026-58014: processing empty key file values in g_key_file_get_locale_string_list could cause a 1-byte out-of-
bounds access (bsc#1270021).
- CVE-2026-58016: malformed D-Bus introspection XML could trigger an unsigned integer overflow (bsc#1270008).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3363-1
Released: Tue Jul 28 14:19:01 2026
Summary: Security update for samba
Type: security
Severity: important
References: 1271469,1271672,1271673,1271674,1271675,1271676,1271677,CVE-2026-15779,CVE-2026-58216,CVE-2026-58218,CVE-2026-58221,CVE-2026-58222,CVE-2026-58224,CVE-2026-6949
This update for samba fixes the following issues
- CVE-2026-6949: TSIG packet with crafted name compression can crash internal DNS server (bsc#1271672).
- CVE-2026-15779: `pam_winbind` module with `mkhomedir` set allows `chown` of critical system paths without validation
(bsc#1271469).
- CVE-2026-58216: 6-byte heap OOB read in packet parser of the `kpasswd` service (bsc#1271674).
- CVE-2026-58218: DNS TKEY negotiation stores unauthenticated GSS contexts in a fixed FIFO before authentication
completes (bsc#1271675).
- CVE-2026-58221: authenticated LDAP access to internal LDB special DNs permits domain takeover (bsc#1271676).
- CVE-2026-58222: LDAP Compare filter injection and trusted-request confusion disclose protected attributes
(bsc#1271677).
- CVE-2026-58224: heap OOB read due to unchecked packet length fields in CTDB (bsc#1271673).
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3381-1
Released: Tue Jul 28 17:35:03 2026
Summary: Recommended update for log4j
Type: recommended
Severity: important
References:
This update for log4j fixes the following issues:
Upgrade to 2.26.1:
* Changed
+ Improve logging for LinkageError scenarios involving the LMAX
Disruptor library
* Fixed
+ Fix the createOnDemand behavior of RollingFileAppender to
correctly defer file and directory creation until the first
log event, while preserving eager creation when disabled
+ Improve documentation for locale handling in the Pattern
Layout date pattern converter
+ Fix handling of non-finite numbers while encoding MapMessage
to JSON
+ Fix encoding of MSGID and SD-ID fields of
StructuredDataMessage to XML
+ Fix stack trace rendering for exceptions with identity
malfunction (e.g., colliding equals() and/or hashCode()
implementations)
+ Fix resource leaks in ConfigurationSource when loading
configuration via URL fails
+ Fix KafkaAppender reporting error to error handler even after
a successful retry
- Generate META-INF/services files using bnd-maven-plugin
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3390-1
Released: Tue Jul 28 17:39:03 2026
Summary: Security update for apache-commons-lang3, google-guice, maven, maven-resolver, xmvn
Type: security
Severity: important
References: CVE-2025-48924
This update for apache-commons-lang3, google-guice, maven, maven-resolver, xmvn fixes the following issues:
apache-commons-lang3 was updated to 3.20.0:
* New features:
+ Add SystemProperties.getPath(String, Supplier<Path>)
+ Add JavaVersion.JAVA_25
+ Add JavaVersion.JAVA_26
+ Add SystemUtils.IS_JAVA_25
+ Add SystemUtils.IS_JAVA_26
+ Add MutablePair.ofNonNull(Map.Entry)
+ Add TimedSemaphore.builder(), Builder, and deprecate
constructors
+ LANG-1504: Adding labels and history to split StopWatch
* Fixed Bugs:
+ Optimize ObjectToStringComparator.compare() method
+ [javadoc] Improve StringUtils Javadoc
+ Fix internal inverted logic in private isEnum() method and
correct its usage in getFirstEnum()
+ Use accessors in ToStringStyle so subclasses can effectively
override them
+ 'LocaleUtils.toLocale(String)' for a 2 letter country code
now returns a value instead of throwing an
'IllegalArgumentException'
+ Fix typo in StringUtils.trunctate() IllegalArgumentException
message and test assertion messages
+ Fix test fixture in
ReflectionDiffBuilderTest.testTransientFieldDifference()
+ LANG-1789: NullPointerException when generating
NoSuchMethodException in MethodUtils
+ LANG-1786: Map deprecated TimeZone short IDs and avoid JRE
WARNINGs to the console
+ LANG-1792: TypeUtils.toString() skips angle brackets for Class
type
+ Mention JDK 25 LTS as a tested version in the release notes
* Changes:
+ Bump org.apache.commons:commons-parent from 88 to 92
Update to 3.19.0:
* New features:
+ Add ArrayUtils.SOFT_MAX_ARRAY_LENGTH
+ Add SystemUtils.IS_OS_NETWARE
+ Add MethodUtils.getAccessibleMethod(Class, Method)
+ Add documentation to site for CVE-2025-48924
ClassUtils.getClass(...) can throw a StackOverflowError on
very long inputs
+ Add StringUtils.indexOfAny(CharSequence, int, char...)
+ Add ConcurrentException.ConcurrentException(String)
+ Add DateUtils.toLocalDateTime(Date[, TimeZone])
+ Add DateUtils.toOffsetDateTime(Date[, TimeZone])
+ Add DateUtils.toZonedDateTime(Date[, TimeZone])
+ Add ByteConsumer
+ Add ByteSupplier
+ Add FailableByteConsumer
+ Add FailableByteSupplier
+ LANG-1784: Add Functions methods for null-safe mapping and
chaining
+ LANG-1784: Add Failable methods for null-safe mapping and
chaining
+ Add DoubleRange.fit(double)
+ Add IntegerRange.fit(int)
+ Add LongRange.fit(long)
+ Add DurationUtils.get(String, TemporalUnit, long)
+ Add DurationUtils.getMillis(String, long)
+ Add DurationUtils.getSeconds(String, long)
+ Add SystemProperties.getBoolean(Class, String, boolean)
+ Add SystemProperties.getInt(Class, String, int)
+ Add SystemProperties.getLong(Class, String, long)
* Fixed Bugs:
+ LANG-1778: MethodUtils.getMatchingMethod() doesn't respect the
hierarchy of methods
+ MethodUtils.getMethodObject(Class<?>, String, Class<?>...) now
returns null instead of throwing a NullPointerException, as it
does for other exception types
+ Reduce spurious failures in ArrayUtilsTest methods that test
ArrayUtils.shuffle() methods
+ MethodUtils cannot find or invoke a public method on a public
class implemented in its package-private superclass
+ AtomicSafeInitializer.get() can spin internally if the
FailableSupplier given to AbstractConcurrentInitializer
.AbstractBuilder.setInitializer(FailableSupplier) throws a
RuntimeException
+ LANG-1783: WordUtils.containsAllWords?() may throw
PatternSyntaxException
+ LANG-1782: MethodUtils cannot find or invoke vararg methods
without providing vararg types or values
+ MethodUtils cannot find or invoke vararg methods of interface
types
+ MethodUtils cannot find or invoke vararg methods when widening
primitive types following the JLS 5.1.2. Widening Primitive
Conversion
+ LANG-1597: Invocation fails because matching varargs method
found but then discarded
+ Don't check accessibility twice in MemberUtils
.setAccessibleWorkaround(T)
+ LANG-1774: Improve handling of ClassUtils
.getShortCanonicalName() for invalid input
+ LANG-1720: Improve Javadocs for Conversion
+ Fix CalendarUtils.toLocalDate() Javadoc return type
description
+ Fix the method name in Javadoc examples for CharUtils.isHex()
+ Deprecate NumberUtils.compare(byte, byte) in favor of
Byte.compare(byte, byte)
+ Deprecate NumberUtils.compare(int, int) in favor of
Integer.compare(int, int)
+ Deprecate NumberUtils.compare(long, long) in favor of
Long.compare(long, long)
+ Deprecate NumberUtils.compare(short, short) in favor of
Short.compare(short, short)
+ Deprecate obsolete system property constant
SystemProperties.AWT_TOOLKIT
+ Deprecate obsolete system property constant
SystemProperties.JAVA_AWT_FONTS
+ Deprecate obsolete system property constant
SystemProperties.JAVA_AWT_GRAPHICSENV
+ Deprecate obsolete system property constant
SystemProperties.JAVA_AWT_HEADLESS
+ Deprecate obsolete system property constant
SystemProperties.JAVA_AWT_PRINTERJOB
+ Deprecate obsolete system property constant
SystemProperties.JAVA_COMPILER
+ Deprecate obsolete system property constant
SystemProperties.JAVA_ENDORSED_DIRS
+ Deprecate obsolete system property constant
SystemProperties.JAVA_EXT_DIRS
+ Deprecate method for obsolete system property constant
SystemProperties.getAwtToolkit()
+ Deprecate method for obsolete system property constant
SystemProperties.getJavaAwtFonts()
+ Deprecate method for obsolete system property constant
SystemProperties.getJavaAwtGraphicsenv()
+ Deprecate method for obsolete system property constant
SystemProperties.getJavaAwtHeadless()
+ Deprecate method for obsolete system property constant
SystemProperties.getJavaAwtPrinterjob()
+ Deprecate method for obsolete system property constant
SystemProperties.getJavaCompiler()
+ Deprecate method for obsolete system property constant
SystemProperties.getJavaEndorsedDirs()
+ Deprecate method for obsolete system property constant
SystemProperties.getJavaExtDirs()
+ Deprecate method for obsolete system property constant
SystemUtils.isJavaAwtHeadless()
+ Deprecate constants for obsolete system property
SystemUtils.JAVA_AWT_FONTS
+ Deprecate constants for obsolete system property
SystemUtils.JAVA_AWT_GRAPHICSENV
+ Deprecate constants for obsolete system property
SystemUtils.JAVA_AWT_HEADLESS
+ Deprecate constants for obsolete system property
SystemUtils.JAVA_AWT_PRINTERJOB
+ Deprecate constants for obsolete system property
SystemUtils.JAVA_COMPILER
+ Deprecate constants for obsolete system property
SystemUtils.JAVA_ENDORSED_DIRS
+ Deprecate constants for obsolete system property
SystemUtils.JAVA_EXT_DIRS
+ [javadoc] General improvements
+ [javadoc] Fix thrown exception documentation for
MethodUtils.getMethodObject(Class<?>, String, Class<?>...)
+ [javadoc] Strings::equalsAny: CI doc string should show it's
insensitive
+ [javadoc] General Javadoc improvements
+ LANG-1780: [javadoc] Fix Strings Javadoc
+ [javadoc] Fix typo in Javadoc of Strings instances
+ [javadoc] Fix Javadocs in ClassUtils
+ [javadoc] Fix @deprecated link for StringUtils#startsWithAny
+ Replace old feather logotype with new oak logotype
* Changes:
+ [test] Bump org.apache.commons:commons-text from 1.13.1 to
1.14.0
+ Bump org.apache.commons:commons-parent from 85 to 88
Update to 3.18.0:
- Fix component version in default.properties to 3.12
* Add and use LocaleUtils.toLocale(Locale) to avoid NPEs.
* Add FailableShortSupplier, handy for JDBC APIs.
* Add JavaVersion.JAVA_17.
* Add StringUtils.substringBefore(String, int).
* Add Range.INTEGER.
* Add DurationUtils.
* Correct implementation of RandomUtils.nextLong(long, long).
* Update maven-surefire-plugin 2.22.2 -> 3.0.0-M5.
* Bump junit-bom from 5.7.0 to 5.7.1.
* Ignored exception 'ignored', should not be called so.
* Change array style from 'int a[]' to 'int[] a'.
google-guice was updated to fix:
- Fix build with Java 25
- Add alias to com.google.inject:guice::classes artifact, needed
by maven 4.x
maven-resolver-supplier was updated to upstream version 1.9.27:
* Bug Fixes
+ Sync TrackingFileManager with 2.x
Update to upstream version 1.9.26:
* New features and improvements
+ GH-1773: Treat 410 Gone as 404 Not Found
+ GH-1737: Revert partially parallel upload change
* Bug Fixes
+ GH-1768; Drastically simplify auth caching
+ [1.9.x] Bug: GH-1703 Locally cached artifacts defy RRF
* Documentation updates
+ Clarify that HTTP Transport uses Apache HTTP Client
* Dependency updates
+ Bump org.redisson:redisson from 3.52.0 to 4.2.0
+ Bump commons-codec:commons-codec from 1.20.0 to 1.21.0
+ Bump org.codehaus.mojo:animal-sniffer-maven-plugin from 1.26
to 1.27
+ Bump org.apache.maven:maven-parent from 46 to 47
+ Bump com.github.siom79.japicmp:japicmp-maven-plugin from
0.25.0 to 0.25.4
+ Bump mavenVersion from 3.9.11 to 3.9.12
- Update to upstream version 1.9.25
* New features and improvements
+ Add scope support for trusted checksums
+ Name mappers cleanup and new GAECV mapper
+ Proper metadata locking support
+ Ability to augment metadata nature for version range request
* Bug Fixes
+ TrackingFileManager changes
+ Maven filters daemon friendly
+ Remove hack from Basic connector
+ Fix locking issues
* Documentation updates
+ Updated the documentation to reflect the current list of name
mappers
* Maintenance
+ Mild backport: support same properties as Resolver 2.x
+ Maven resolver lockrepro
+ Bugfix: Java 25 broke test
* Dependency updates
+ Bump com.github.siom79.japicmp:japicmp-maven-plugin from
0.23.1 to 0.25.0
+ Bump org.codehaus.mojo:animal-sniffer-maven-plugin from 1.24
to 1.26
+ Bump commons-codec:commons-codec from 1.18.0 to 1.20.0
+ Bump org.redisson:redisson from 3.50.0 to 3.52.0
+ Bump com.google.guava:guava from 33.4.8-jre to 33.5.0-jre
+ Bump com.google.code.gson:gson from 2.13.1 to 2.13.2
+ Bump jettyVersion from 9.4.57.v20241219 to 9.4.58.v20250814
+ Bump mavenVersion from 3.9.10 to 3.9.11
- Update to upstream version 1.9.24
* New features and improvements
+ Metadata type out of coordinates
+ RFC9457 implementation
+ Intern context strings
* Maintenance
+ Align plexus-util version with Maven
+ Align guice version with Maven
+ Enable Github Issues (1.9.x branch)
- Build also maven-resolver-supplier package in separate spec file
- Add dependency on objectweb-asm to build with sisu 0.9.0.M4
- Update to upstream version 1.9.23
* Bug
+ MRESOLVER-659: NPE in trusted checksum post processor if
* Improvement
+ MRESOLVER-680: Disable checksum by default for .sigstore.json
as well
+ MRESOLVER-703: HTTP transport should expose config for max
redirects
- Upgrade to upstream version 1.9.22
* Bug
+ MRESOLVER-572: Resolver-Supplier unusable in OSGi runtimes
+ MRESOLVER-574: Invalid Cookie set under proxy conditions
+ MRESOLVER-586: In typical setups, DefaultArtifact copies the
same maps over and over again
+ MRESOLVER-587: Memory consumption improvements
* New Feature
+ MRESOLVER-571: Import o.e.aether packages with the exact same
version in OSGi metadata
* Improvement
+ MRESOLVER-570: Remove excessive strictness of OSGi dependency
metadata
* Task
+ MRESOLVER-576: Allow co-release of Resolver 1.x and 2.x
- Upgrade to upstream version 1.9.20
* Bug
+ MRESOLVER-483: PreorderNodeListGenerator bug: may print
trailing ':'
+ MRESOLVER-522: File locking threads not entering critical
region were 'oversleeping'
+ MRESOLVER-547: BF collector always copies artifacts, even
when it should not
* Improvement
+ MRESOLVER-536: Skip setting last modified time when FS does
not support it
- Add dependency on plexus-xml where relevant
* this will be needed for smooth upgrade to plexus-utils 4.0.0
- Upgrade to upstream version 1.9.18
* Bug
+ MRESOLVER-372: Sporadic AccessDeniedEx on Windows
+ MRESOLVER-441: Undo FileUtils changes that altered non-Windows
execution path
* Improvement
+ MRESOLVER-396: Native transport should retry on HTTP 429
(Retry-After)
* Task
+ MRESOLVER-397: Deprecate Guice modules
+ MRESOLVER-405: Get rid of component name string literals, make
them constants and reusable
+ MRESOLVER-433: Expose configuration for inhibiting
Expect-Continue handshake in 1.x
+ MRESOLVER-435: Refresh download page
+ MRESOLVER-437: Resolver should not override given HTTP
transport default use of expect-continue handshake
- Upgrade to upstream version 1.9.15
* Bug
+ MRESOLVER-373: Remove lock upgrading code
+ MRESOLVER-375: Several key aspects are broken in provided and
trusted checksum feature
+ MRESOLVER-376: StackOverflowError at
BfDependencyCollector.processDependency
+ MRESOLVER-380: Lock diagnostic: attempted lock step is
recorded, but on failed attempt is not removed
+ MRESOLVER-393: Transport HTTP does not retain last modified as
sent by remote end
* Improvement
+ MRESOLVER-220: Modify signaling for unsupported operations
+ MRESOLVER-382: Define local outgoing (bind) address
+ MRESOLVER-385: Reduce default value for
aether.connector.http.connectionMaxTtl
* Task
+ MRESOLVER-378: Update parent POM to 40
+ MRESOLVER-381: Undo MRESOLVER-373 as it was fixed by other
means
+ MRESOLVER-386: Make all injected ctors public, deprecate all
def ctors
+ MRESOLVER-388: Transport HTTP old codec proper override
- Upgrade to upstream version 1.9.12
* Bug
+ [MRESOLVER-371] Unjustified WARNING log added by
MRESOLVER-364
+ [MRESOLVER-361] Unreliable TCP and retries on upload
+ [MRESOLVER-357] ConflictResolver STANDARD verbosity
misbehaves
+ [MRESOLVER-352] Duplicate METADATA_DOWNLOADING event is
being sent
* Improvement
+ [MRESOLVER-360] disable checksum by default for .sigstore
in addition to .asc
* New Feature
+ [MRESOLVER-370] Lock factory should dump lock states on
failure
+ [MRESOLVER-353] Make aether.checksums.algorithms settable
per remote repository
* Task
+ [MRESOLVER-366] Upgrade build plugins
+ [MRESOLVER-364] Revert MRESOLVER-132
+ [MRESOLVER-359] Make build be explicit about build time
requirements
+ [MRESOLVER-356] Remove Guava (is unused)
+ [MRESOLVER-354] Document expected checksums
- Upgrade to upstream version 1.9.8
* Bug
+ [MRESOLVER-345] Conflict resolution in verbose mode is
sensitive to version ordering
+ [MRESOLVER-348] SslConfig httpSecurityMode change is not
detected
+ [MRESOLVER-339] Preemptive Auth broken when default ports used
+ [MRESOLVER-325] [REGRESSION] Suddenly seeing I/O errors under
windows aborting the build
+ [MRESOLVER-330] Static name mapper is unusable with file-lock
factory
+ [MRESOLVER-314] Getting 'IllegalArgumentException: Comparison
method violates its general contract!'
+ [MRESOLVER-316] DF collector enters endless loop when
collecting org.webjars.npm:musquette:1.1.1
+ [MRESOLVER-298] javax.inject should be provided or optional
+ [MRESOLVER-305] Evaluate blocked repositories also when
retrieving metadata
+ [MRESOLVER-309] PrefixesRemoteRepositoryFilterSource aborts
the build while it should not
+ [MRESOLVER-313] Artifact file permissions are 0600 and not
implicitly set by umask
+ [MRESOLVER-296] FileProcessor.write( File, InputStream ) is
defunct
+ [MRESOLVER-292] Documented and used param names mismatch
+ [MRESOLVER-294] Fix JapiCmp configuration and document it
+ [MRESOLVER-285] File locking on Windows knows to misbehave
+ [MRESOLVER-246] m-deploy-p will create hashes for hashes
+ [MRESOLVER-265] Discrepancy between produced and recognized
checksums
+ [MRESOLVER-241] Resolver checksum calculation should be driven
by layout
+ [MRESOLVER-242] When no remote checksums provided by layout,
transfer inevitably fails/warns
+ [MRESOLVER-250] Usage of descriptors map in DataPool prevents
gargabe collection
* New Feature
+ [MRESOLVER-32] Support parallel artifact/metadata uploads
+ [MRESOLVER-319] Support parallel deploy
+ [MRESOLVER-297] Chained LRM
+ [MRESOLVER-167] Support forcing specific repositories for
artifacts
+ [MRESOLVER-268] Apply artifact checksum verification for any
resolved artifact
+ [MRESOLVER-274] Introduce Remote Repository Filter feature
+ [MRESOLVER-275] Introduce trusted checksums source
+ [MRESOLVER-276] Resolver post-processor
+ [MRESOLVER-278] BREAKING: Introduce RepositorySystem shutdown
hooks
+ [MRESOLVER-236] Make it possible to resolve .asc on a 'fail'
respository.
* Improvement
+ [MRESOLVER-346] Too eager locking
+ [MRESOLVER-347] Better connection pool configuration (reuse,
max TTL, maxPerRoute)
+ [MRESOLVER-349] Adapter when locking should 'give up and
retry'
+ [MRESOLVER-350] Get rid of commons-lang dependency
+ [MRESOLVER-327] Make tranport-http obey system properties
regarding proxy settings
+ [MRESOLVER-340] Make WebDAV 'dance' disabled by default
+ [MRESOLVER-341] Add option for preemptive PUT Auth
+ [MRESOLVER-315] Implement preemptive authentication feature
for transport-http
+ [MRESOLVER-328] The transport-http should be able to ignore
cert errors
+ [MRESOLVER-337] Real cause when artifact not found with
repository filtering
+ [MRESOLVER-287] Get rid of deprecated finalize methods
+ [MRESOLVER-317] Improvements for BF collector
+ [MRESOLVER-318] Cleanup redundant code and centralize executor
handling
+ [MRESOLVER-303] Make checksum detection reusable
+ [MRESOLVER-290] Improve file handling resolver wide
+ [MRESOLVER-7] Download dependency POMs in parallel in BF
collector
+ [MRESOLVER-266] Simplify adapter creation and align
configuration for it
+ [MRESOLVER-269] Allow more compact storage of provided
checksums
+ [MRESOLVER-273] Create more compact File locking layout/mapper
+ [MRESOLVER-284] BREAKING: Some Sisu parameters needs to be
bound
+ [MRESOLVER-286] Improve basic connector closed state handling
+ [MRESOLVER-240] Using breadth-first approach to resolve Maven
dependencies
+ [MRESOLVER-247] Avoid unnecessary dependency resolution by a
Skip solution based on BFS
+ [MRESOLVER-248] Make DF and BF collector implementations
coexist
* Task
+ [MRESOLVER-326] Resolver transport-http should retry on
failures
+ [MRESOLVER-331] Make DefaultTrackingFileManager write directly
to tracking files
+ [MRESOLVER-333] Distinguish better resolver errors for
artifact availability
+ [MRESOLVER-320] Investigate slower resolving speeds as
reported by users
+ [MRESOLVER-291] Undo MRESOLVER-284
+ [MRESOLVER-279] Simplify and improve trusted checksum sources
+ [MRESOLVER-281] Update configurations page with new elements
+ [MRESOLVER-282] Drop PartialFile
+ [MRESOLVER-230] Make supported checksum algorithms extensible
+ [MRESOLVER-231] Extend âsmart checksumâ feature
+ [MRESOLVER-234] Introduce âprovidedâ checksums feature
+ [MRESOLVER-237] Make all checksum mismatches handled same
+ [MRESOLVER-239] Update and sanitize dependencies
+ [MRESOLVER-244] Deprecate FileTransformer API
+ [MRESOLVER-245] Isolate Hazelcast tests
* Dependency upgrade
+ [MRESOLVER-311] Upgrade Parent to 39
+ [MRESOLVER-293] Update dependencies, align with Maven
+ [MRESOLVER-272] Update parent POM to 37, remove plugin version
overrides, update bnd
+ [MRESOLVER-280] Upgrade invoker, install, deploy, require
maven 3.8.4+
+ [MRESOLVER-251] Upgrade Redisson to 3.17.5
+ [MRESOLVER-249] Update Hazelcast to 5.1.1 in
named-locks-hazelcast module
- Add an alias for the wagon connector
- Build against the standalone JavaEE modules unconditionally
- Remove the javax.annotation:javax.annotation-api dependency on
distribution versions that do not incorporate the JavaEE modules
- Add the glassfish-annotation-api jar to the build classpath
- Upgrade to upstream version 1.7.3
* Bug
+ [MRESOLVER-96] - Dependency Injection fails after upgrading
to Maven 3.6.2
+ [MRESOLVER-153] - resolver-status.properties file is corrupted
due to concurrent writes
+ [MRESOLVER-171] - Resolver fails when compiled on Java 9+ an
run on Java 8 due to JDK API breakage
+ [MRESOLVER-189] - Using semaphore-redisson followed by
rwlock-redisson on many parallel build of the same project
triggers redisson error
* New Feature
+ [MRESOLVER-90] - HTML content in POM: Maven should validate
content before storing in local repo
+ [MRESOLVER-145] - Introduce more SyncContext implementations
* Improvement
+ [MRESOLVER-103] - Replace deprecated HttpClient classes
+ [MRESOLVER-104] - maven-resolver-demo-maven-plugin uses
reserved artifactId
+ [MRESOLVER-147] - Upgrade to Java 8
+ [MRESOLVER-148] - Use vanilla Guice 4 instead of forked
Guice 3
+ [MRESOLVER-156] - Active dependency management for Google
Guice/Guava
+ [MRESOLVER-168] - add DEBUG message when downloading an
artifact from repositories
+ [MRESOLVER-193] - Properly type lock key names in Redis
+ [MRESOLVER-197] - Minors improvements (umbrella)
+ [MRESOLVER-204] - Add a SessionData#computeIfAbsent method
+ [MRESOLVER-214] - Remove clirr configuration
* Task
+ [MRESOLVER-141] - Review index-based access to collections
+ [MRESOLVER-151] - Enforce a checksum policy to be provided
explicitly
+ [MRESOLVER-152] - Perform null checks when interface
contracts require it
+ [MRESOLVER-154] - Move SyncContextFactory interface to SPI
module
+ [MRESOLVER-155] - Make TrackingFileManager member of
DefaultUpdateCheckManager
+ [MRESOLVER-158] - Simplify SimpleDigest class
+ [MRESOLVER-159] - Mark singleton components as Sisu Singletons
+ [MRESOLVER-160] - Deprecate ServiceLocator
+ [MRESOLVER-162] - Restore binary compatibility broken by
MRESOLVER-154
+ [MRESOLVER-170] - Deprecate org.eclipse.aether.spi.log
+ [MRESOLVER-172] - Make TrackingFileManager shared singleton
component
+ [MRESOLVER-173] - Drop deprecated AetherModule
+ [MRESOLVER-174] - Use all bindings in UTs and tests
+ [MRESOLVER-175] - Drop SyncContextFactory delegates in favor
of a selector approach
+ [MRESOLVER-177] - Move pre-/post-processing of metadata from
ResolveTask to DefaultMetadataResolver
+ [MRESOLVER-183] - Don't require optional dependencies for
Redisson
+ [MRESOLVER-184] - Destroy Redisson semaphores if not used
anymore
+ [MRESOLVER-186] - Update Maven version in Resolver Demo
Snippets
+ [MRESOLVER-188] - Improve documentation on using the named
locks with redis/hazelcast (umbrella)
+ [MRESOLVER-190] - [Regression] Revert MRESOLVER-184
+ [MRESOLVER-191] - Document how to analyze lock issues
+ [MRESOLVER-196] - Document named locks configuration options
+ [MRESOLVER-219] - Implement NamedLock with advisory file
locking
+ [MRESOLVER-227] - Refactor NamedLockFactorySelector to a
managed component
+ [MRESOLVER-232] - Make SimpleNamedLockFactorySelector logic
reusable
* Sub-task
+ [MRESOLVER-198] - Replace assert by simpler but equivalent
calls
+ [MRESOLVER-199] - Java 8 improvements
+ [MRESOLVER-200] - Simplify conditions with the same result
and avoid extra validations
+ [MRESOLVER-201] - Make variables final whenever possible
+ [MRESOLVER-202] - Use isEmpty() instead length() <= 0
* Dependency upgrade
+ [MRESOLVER-185] - Upgrade Redisson to 3.15.6
* Change of API and incompatible with maven-resolver < 1.7
- Upgrade to upstream version 1.6.3
* Bug
+ [MRESOLVER-153] - resolver-status.properties file is corrupted
due to concurrent writes
+ [MRESOLVER-171] - Resolver fails when compiled on Java 9+ and
run on Java 8 due to JDK API breakage
* Improvement
+ [MRESOLVER-168] - add DEBUG message when downloading an
artifact from repositories
* Task
+ [MRESOLVER-177] - Move pre-/post-processing of metadata from
ResolveTask to DefaultMetadataResolver
* Needed for maven 3.8.4
- Do not build/run the tests against the legacy guava20 package
- Upgrade to upstream version 1.6.2
* Sub-task
+ [MRESOLVER-139] - Make SimpleDigest use SHA-1 or MD5 only
+ [MRESOLVER-140] - Default to SHA-1 and MD5 hashing algorithms
* Bug
+ [MRESOLVER-25] - Resume support is broken under high
concurrency
+ [MRESOLVER-114] - ArtifactNotFoundExceptions when building in
parallel
+ [MRESOLVER-129] - Exclusion has no setters
+ [MRESOLVER-137] - Make OSGi bundles reproducible
+ [MRESOLVER-138] - MRESOLVER-56 introduces severe performance
regression
* New Feature
+ [MRESOLVER-109] - AndDependencySelector should override
toString
+ [MRESOLVER-115] - Make checksum algorithms configurable
+ [MRESOLVER-123] - Provide a global locking sync context by
default
+ [MRESOLVER-131] - Introduce a Redisson-based
SyncContextFactory
+ [MRESOLVER-165] - Add support for mirror selector on
external:http:*
+ [MRESOLVER-166] - Add support for blocked
repositories/mirrors
* Improvement
+ [MRESOLVER-56] - Support SHA-256 and SHA-512 as checksums
+ [MRESOLVER-116] - Add page with all supported configuration
options
+ [MRESOLVER-125] - Use type conversions returning primitives
+ [MRESOLVER-127] - Don't use boolean for property
'aether.updateCheckManager.sessionState'
+ [MRESOLVER-136] - Migrate from maven-bundle-plugin to
bnd-maven-plugin
* Task
+ [MRESOLVER-119] - Turn log messages to SLF4J placeholders
+ [MRESOLVER-130] - Move GlobalSyncContextFactory to a separate
module
+ [MRESOLVER-132] - Remove synchronization in
TrackingFileManager
* Dependency upgrade
+ [MRESOLVER-105] - Update Plexus Components
+ [MRESOLVER-106] - Update HttpComponents
+ [MRESOLVER-107] - Update Wagon Provider API to 3.4.0
+ [MRESOLVER-108] - Update mockito-core to 2.28.2
+ [MRESOLVER-117] - Upgrade SLF4J to 1.7.30
+ [MRESOLVER-118] - Upgrade Sisu Components to 0.3.4
* Needed for maven 3.8.x
- Set buildshell to bash for '<<<'.
- Upgrade to upstream version 1.4.2
* Bug:
+ MRESOLVER-38 â SOE/OOME in DefaultDependencyNode.accept
* Improvements:
+ MRESOLVER-93 â PathRecordingDependencyVisitor to handle 3 cycles
+ MRESOLVER-102 â make build Reproducible
- Upgrade to upstream version 1.4.1
* Task
+ [MRESOLVER-92] - Revert MRESOLVER-7
* Bug
+ [MRESOLVER-86] - ResolveArtifactMojo from resolver example
uses plugin repositories to resolve dependencies
* New Feature
+ [MRESOLVER-10] - New 'TransitiveDependencyManager'
supporting transitive dependency management
+ [MRESOLVER-33] - New 'DefaultDependencyManager' managing
dependencies on all levels supporting transitive dependency
management
* Improvement
+ [MRESOLVER-7] - Download dependency POMs in parallel
+ [MRESOLVER-84] - Add support for 'release' qualifier
+ [MRESOLVER-87] - Refresh examples to use maven-resolver
artifacts for demo
+ [MRESOLVER-88] - Code style cleanup to use Java 7 features
- Initial packaging of maven-resolver 1.3.1
- Generate and customize the ant build files
maven-resolver was update to upstream version 1.9.27:
* Bug Fixes
+ Sync TrackingFileManager with 2.x
- Update to upstream version 1.9.26
* New features and improvements
+ GH-1773: Treat 410 Gone as 404 Not Found
+ GH-1737: Revert partially parallel upload change
* Bug Fixes
+ GH-1768; Drastically simplify auth caching
+ [1.9.x] Bug: GH-1703 Locally cached artifacts defy RRF
* Documentation updates
+ Clarify that HTTP Transport uses Apache HTTP Client
* Dependency updates
+ Bump org.redisson:redisson from 3.52.0 to 4.2.0
+ Bump commons-codec:commons-codec from 1.20.0 to 1.21.0
+ Bump org.codehaus.mojo:animal-sniffer-maven-plugin from 1.26
to 1.27
+ Bump org.apache.maven:maven-parent from 46 to 47
+ Bump com.github.siom79.japicmp:japicmp-maven-plugin from
0.25.0 to 0.25.4
+ Bump mavenVersion from 3.9.11 to 3.9.12
- Update to upstream version 1.9.25
* New features and improvements
+ Add scope support for trusted checksums
+ Name mappers cleanup and new GAECV mapper
+ Proper metadata locking support
+ Ability to augment metadata nature for version range request
* Bug Fixes
+ TrackingFileManager changes
+ Maven filters daemon friendly
+ Remove hack from Basic connector
+ Fix locking issues
* Documentation updates
+ Updated the documentation to reflect the current list of name
mappers
* Maintenance
+ Mild backport: support same properties as Resolver 2.x
+ Maven resolver lockrepro
+ Bugfix: Java 25 broke test
* Dependency updates
+ Bump com.github.siom79.japicmp:japicmp-maven-plugin from
0.23.1 to 0.25.0
+ Bump org.codehaus.mojo:animal-sniffer-maven-plugin from 1.24
to 1.26
+ Bump commons-codec:commons-codec from 1.18.0 to 1.20.0
+ Bump org.redisson:redisson from 3.50.0 to 3.52.0
+ Bump com.google.guava:guava from 33.4.8-jre to 33.5.0-jre
+ Bump com.google.code.gson:gson from 2.13.1 to 2.13.2
+ Bump jettyVersion from 9.4.57.v20241219 to 9.4.58.v20250814
+ Bump mavenVersion from 3.9.10 to 3.9.11
- Update to upstream version 1.9.24
* New features and improvements
+ Metadata type out of coordinates
+ RFC9457 implementation
+ Intern context strings
* Maintenance
+ Align plexus-util version with Maven
+ Align guice version with Maven
+ Enable Github Issues (1.9.x branch)
- Build also maven-resolver-supplier package in separate spec file
- Add dependency on objectweb-asm to build with sisu 0.9.0.M4
- Update to upstream version 1.9.23
* Bug
+ MRESOLVER-659: NPE in trusted checksum post processor if
* Improvement
+ MRESOLVER-680: Disable checksum by default for .sigstore.json
as well
+ MRESOLVER-703: HTTP transport should expose config for max
redirects
- Upgrade to upstream version 3.9.16
* Bug Fixes
+ Trim threadConfiguration to accept input surrounded with
spaces
+ Backport: Maven 3.10.x fixed plugin resolution
* Dependency updates
+ Bump org.codehaus.plexus:plexus-classworlds from 2.9.0 to
2.11.0
+ [3.9.x] Bump to parent POM 48
+ Bump commons-io:commons-io from 2.21.0 to 2.22.0
+ Bump com.google.guava:guava from 33.5.0-jre to 33.6.0-jre
+ Bump actions/cache from 5.0.4 to 5.0.5
- There is no need to link the jansi-native library into the tree,
since our jansi java library will load it from the system anyway
- Upgrade to upstream version 3.9.15
* Documentation updates
+ Use new Maven logos in documentation
+ document modelVersion only supported value: 4.0.0
* Dependency updates
+ Bump actions/upload-artifact from 7.0.0 to 7.0.1
+ Bump org.codehaus.plexus:plexus-utils from 3.6.0 to 3.6.1
+ Bump org.fusesource.jansi:jansi from 2.4.2 to 2.4.3
+ Bump actions/cache from 5.0.3 to 5.0.4
+ Bump actions/download-artifact from 8.0.0 to 8.0.1
- Upgrade to upstream version 3.9.14
* Bug Fixes
+ plexus-testing dependencies should be used in test scope
* Dependency updates
+ Bump actions/upload-artifact from 6.0.0 to 7.0.0
+ Bump actions/download-artifact from 7.0.0 to 8.0.0
- Upgrade to upstream version 3.9.13
* Bug Fixes
+ Bug: SecDispatcher is managed by legacy Plexus DI
+ [3.9.x] MavenPluginJavaPrerequisiteChecker: Handle 8/1.8
Java version in ranges as well
* Maintenance
+ Update Maven plugin versions in default-bindings.xml
+ Migrate to JUnit 5 - avoid using TestCase
* Dependency updates
+ Maven Resolver 1.9.27
+ Bump resolverVersion from 1.9.25 to 1.9.26
+ Bump version.sisu-maven-plugin from 0.9.0.M4 to 1.0.0
+ Bump actions/cache from 5.0.0 to 5.0.3
+ Bump org.apache.maven:maven-parent from 45 to 47
+ Bump actions/checkout from 6.0.1 to 6.0.2
+ Bump actions/setup-java from 5.1.0 to 5.2.0
+ Bump org.codehaus.mojo:animal-sniffer-maven-plugin from 1.26
to 1.27
+ Bump org.codehaus.mojo:buildnumber-maven-plugin from 3.2.1
to 3.3.0
+ Bump org.codehaus.plexus:plexus-testing from 2.0.2 to 2.1.0
+ Bump org.ow2.asm:asm from 9.9 to 9.9.1
+ Bump actions/upload-artifact from 5.0.0 to 6.0.0
+ Bump actions/download-artifact from 6.0.0 to 7.0.0
- Specify required maven-resolver version since the
maven-resolver-provider requires methods added in 1.9.25
- Upgrade to upstream version 3.9.12
* New features and improvements
+ Apply resolver changes and improvements
+ Update formatting of prerequisites-requirements error to
improve readability
+ Allow a Maven plugin to require a Java version
+ Use MavenRepositorySystem in ProjectBuildingHelper instead
of deprecated RepositorySystem
+ Make maven.config use UTF8
+ Simplify prefix resolution
* Bug Fixes
+ Add default implementation for new method in
MavenPluginManager
+ Repository layout should be used in MavenRepositorySystem
+ Fix plugin prefix resolution when metadata is not available
from repository
+ Improve source root modification warning message
+ Bug: bad cache isolation between two sessions
+ Set Guice class loading to CHILD - avoid using terminally
deprecated methods
+ Avoid parsing MAVEN_OPTS (3.9.x)
* Documentation updates
+ clarify repository vs deployment repository
+ add maintained branches
* Maintenance
+ Add IntelliJ icon
+ Build by JDK 25
+ Deprecate org.apache.maven.repository.RepositorySystem in
3.9.x
* Build
+ Bump actions/download-artifact from 5.0.0 to 6.0.0
+ Bump actions/upload-artifact from 4.6.2 to 5.0.0
* Dependency updates
+ Bump actions/cache from 4.2.3 to 5.0.0
+ Bump resolverVersion from 1.9.24 to 1.9.25
+ Bump actions/checkout from 5.0.0 to 6.0.1
+ Bump actions/setup-java from 5.0.0 to 5.1.0
+ Bump commons-cli:commons-cli from 1.9.0 to 1.11.0
+ Bump org.codehaus.plexus:plexus-interpolation from 1.28 to
1.29
+ Bump commons-io:commons-io from 2.19.0 to 2.21.0
+ Bump xmlunitVersion from 2.10.3 to 2.11.0
+ Bump org.codehaus.mojo:animal-sniffer-maven-plugin from 1.24
to 1.26
+ Bump org.ow2.asm:asm from 9.8 to 9.9
+ Bump com.google.guava:guava from 33.4.8-jre to 33.5.0-jre
- Upgrade to upstream version 3.9.11
* New features and improvements
+ Augment version range resolution used repositories
* Bug Fixes
+ Deduplicate filtered dependency graph
+ Move ensure in boundaries of project lock
* Maintenance
+ [MNGSITE-393] - remove references to Maven 2
+ Update CONTRIBUTING after GitHub issues enabled
+ Enable Github Issues
+ [MNG-8763] - Remove name from site bannerLeft
* Build
+ Pin GitHub action versions by hash
+ Build the project by JDK 21 as default
+ Use Maven 3.9.10 for build on GitHub
- Upgrade to upstream version 3.9.10
* Bug
+ MNG-8096: Inconsistent dependency resolution behaviour for
concurrent multi-module build can cause failures
+ MNG-8169: MINGW support requires
--add-opens java.base/java.lang=ALL-UNNAMED
+ MNG-8170: Maven 3.9.8 contains weird native library for Jansi
on Windows/arm64
+ MNG-8211: Maven should fail builds that use CI Friendly
versions but have no values set
+ MNG-8248: WARNING: A restricted method in java.lang.System has
been called
+ MNG-8256: ProjectDependencyGraph bug: in case of filtering,
non-direct module links are lost
+ MNG-8315: Failure of mvn.cmd if a .mvn directory is located at
drive root
+ MNG-8396: Maven takes forever to resume
+ MNG-8711: 'Duplicate artifact' in LifecycleDependencyResolver
* Improvement
+ MNG-8370: Introduce maven.repo.local.head
+ MNG-8399: JDK 24+ issues warning about usage of
sun.misc.Unsafe
+ MNG-8707: Add methods to remove compile and test source roots
+ MNG-8712: improve dependency version explanation: it's a
requirement, not always effective version
+ MNG-8717: Remove maven-plugin-plugin:addPluginArtifactMetadata
from default binding
+ MNG-8722: Use a single standalone version of asm
+ MNG-8731: Use https for xsi:schemaLocation in generated
descriptors
+ MNG-8734: Simplify scripting like 'get project version' cases
* Task
+ MNG-8728: Bump Eclipse Sisu from 0.9.0.M3 to 0.9.0.M4 and use
Java 24 on CI
- Link also the objectweb-asm/asm to the lib directory
+ MNG-8177: Warning
xmvn-connector was updated to fix:
- Add dependency on objectweb-asm to build with sisu 0.9.0.M4
- Upgrade to version 4.3.0
* Changes:
+ Fix typo in JavadocMojo
+ Reproducible javadoc
+ Reproducible manifest injection
+ Deprecate UUIDs
+ Implement MetadataResult.getPackageMetadataMap()
xmvn-mojo was updated to fix:
Upgrade to version 4.3.0
* Changes:
+ Fix typo in JavadocMojo
+ Reproducible javadoc
+ Reproducible manifest injection
+ Deprecate UUIDs
+ Implement MetadataResult.getPackageMetadataMap()
xmvn-parent was updated to fix:
- Upgrade to version 4.3.0
* Changes:
+ Fix typo in JavadocMojo
+ Reproducible javadoc
+ Reproducible manifest injection
+ Deprecate UUIDs
+ Implement MetadataResult.getPackageMetadataMap()
xmvn-tools was updated to:
- The new commons-compress needs commons-lang3
- Upgrade to version 4.3.0
* Changes:
+ Fix typo in JavadocMojo
+ Reproducible javadoc
+ Reproducible manifest injection
+ Deprecate UUIDs
+ Implement MetadataResult.getPackageMetadataMap()
xmvn was updated to fix:
- Adapt to no libjansi.so linked into the arch independent path
- Fix build after removal of the default %%{java_home} define
- Upgrade to version 4.3.0
* Changes:
+ Fix typo in JavadocMojo
+ Reproducible javadoc
+ Reproducible manifest injection
+ Deprecate UUIDs
+ Implement MetadataResult.getPackageMetadataMap()
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3397-1
Released: Tue Jul 28 20:31:23 2026
Summary: Security update for python-urllib3
Type: security
Severity: moderate
References: 1268683,CVE-2026-9375
This update for python-urllib3 fixes the following issue
- CVE-2026-9375: decompression bomb bypass in the streaming API when using Brotli support can lead to a denial of
service (bsc#1268683).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3401-1
Released: Wed Jul 29 12:39:03 2026
Summary: Security update for sssd
Type: security
Severity: moderate
References: 1269807,CVE-2026-12610
This update for sssd fixes the following issue:
- CVE-2026-12610: cancelled or completed PAM request while the asynchronous child process is still running can lead to a
use-after-free (bsc#1269807).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3406-1
Released: Wed Jul 29 13:09:09 2026
Summary: Security update for java-17-openjdk
Type: security
Severity: important
References: 1264396,1264994,1267355,1272223,1272224,1272225,1272227,1272228,1272235,1272236,1272237,CVE-2026-41254,CVE-2026-46917,CVE-2026-46968,CVE-2026-47010,CVE-2026-47021,CVE-2026-47027,CVE-2026-47059,CVE-2026-47063,CVE-2026-60147
This update for java-17-openjdk fixes the following issues:
Upgrade to upstream tag jdk-17.0.20+8 (July 2026 CPU).
Security issues fixed:
- CVE-2026-41254: lcms: information disclosure and denial of service via integer overflow in `CubeSize` (bsc#1264994).
- CVE-2026-46917: unauthenticated attacker with network access via TLS can cause a partial denial of service
(bsc#1272223).
- CVE-2026-46968: unauthenticated attacker with network access via TLS can gain unauthorized creation, deletion or
modification access to critical data(bsc#1272224).
- CVE-2026-47010: unauthenticated attacker with network access via multiple protocols can gain unauthorized update,
insert or delete access to some data (bsc#1272225).
- CVE-2026-47021: unauthenticated attacker with network access via multiple protocols can cause a partial denial of
service (bsc#1272227).
- CVE-2026-47027: unauthenticated attacker with network access via multiple protocols can cause a partial denial of
service (bsc#1272228).
- CVE-2026-47059: unauthenticated attacker with network access via multiple protocols can cause a partial denial of
service (bsc#1272235).
- CVE-2026-47063: unauthenticated attacker with network access via multiple protocols can gain unauthorized creation,
deletion or modification access to critical data (bsc#1272236).
- CVE-2026-60147: unauthenticated attacker with network access via multiple protocols can gain unauthorized update,
insert, delete and read access to some(bsc#1272237).
Other updates and bugfixes:
- Errors from update-alternatives when installing java-25-openjdk (bsc#1267355).
- Make post scripts less noisy (bsc#1267355).
- Use libalternatives instead of update-alternatives for distributions where libalternatives is available.
- Upgrade to upstream tag jdk-17.0.20+8 (July 2026 CPU):
+ JDK-7184899: Test sun/java2d/X11SurfaceData/
/SharedMemoryPixmapsTest/SharedMemoryPixmapsTest.sh fail
+ JDK-8015444: java/awt/Focus/KeyStrokeTest.java sometimes fails
+ JDK-8064922: [macos] Test javax/swing/JTabbedPane/4624207/
/bug4624207.java fails
+ JDK-8068293: [TEST_BUG] Test closed/com/sun/java/swing/plaf/
/motif/InternalFrame/4150591/bug4150591.java fails with
GTKLookAndFeel
+ JDK-8068310: [TEST_BUG] Test javax/swing/JColorChooser/
/Test4234761.java fails with GTKL&F
+ JDK-8068378: [TEST_BUG]The java/awt/Modal/PrintDialogsTest/
/PrintDialogsTest.java instruction need to update
+ JDK-8183336: Better cleanup for jdk/test/java/lang/module/
/customfs/ModulesInCustomFileSystem.java
+ JDK-8221451: PIT: sun/java2d/X11SurfaceData/
/SharedMemoryPixmapsTest/SharedMemoryPixmapsTest.sh fails
+ JDK-8240908: RetransformClass does not know about
MethodParameters attribute
+ JDK-8255463: java/nio/channels/spi/SelectorProvider/
/inheritedChannel/InheritedChannelTest.java failed with
ThreadTimeoutException
+ JDK-8272477: Additional cleanup of test/jdk/java/nio/file/spi/
/SetDefaultProvider.java
+ JDK-8274082: Wrong test name in jtreg run tag for java/awt/
/print/PrinterJob/SwingUIText.java
+ JDK-8277444: Data race between
JvmtiClassFileReconstituter::copy_bytecodes and class linking
+ JDK-8281243: Test java/lang/instrument/
/RetransformWithMethodParametersTest.java is failing
+ JDK-8282044: [JVMCI] Export _sha3_implCompress,
_md5_implCompress and aarch64::_has_negatives stubs to JVMCI
compiler.
+ JDK-8284993: Replace System.exit call in swing tests with
RuntimeException
+ JDK-8286258: [Accessibility,macOS,VoiceOver] VoiceOver reads
the spinner value wrong and sometime partially
+ JDK-8286865: vmTestbase/vm/mlvm/meth/stress/jni/
/nativeAndMH/Test.java fails with Out of space in CodeCache
+ JDK-8287062: com/sun/jndi/ldap/LdapPoolTimeoutTest.java failed
due to different timeout message
+ JDK-8290504: Close streams returned by ModuleReader::list
+ JDK-8293484: AArch64:
TestUseSHA512IntrinsicsOptionOnSupportedCPU.java fails on CPU
with SHA512 feature support
+ JDK-8297191: [macos] Printing a page range with starting
page > 1 results in missing pages
+ JDK-8298783: java/lang/ref/FinalizerHistogramTest.java failed
with 'RuntimeException: MyObject is not found in test output'
+ JDK-8298823: [macos] java/awt/Mouse/EnterExitEvents/
/DragWindowTest.java continues to fail with 'No MouseReleased
event on label!'
+ JDK-8299304: Test 'java/awt/print/PrinterJob/
/PageDialogTest.java' fails on macOS 13 x64 because the Page
Dialog blocks the Toolkit
+ JDK-8304065: HttpServer.stop should terminate immediately if
no exchanges are in progress
+ JDK-8309142: Refactor test/langtools/tools/javac/versions/
/Versions.java
+ JDK-8316274: javax/swing/ButtonGroup/
/TestButtonGroupFocusTraversal.java fails in Ubuntu 23.10 with
Motif LAF
+ JDK-8317801: java/net/Socket/asyncClose/Race.java fails
intermittently (aix)
+ JDK-8320677: Printer tests use invalid '@run main/manual=yesno
+ JDK-8321182: SourceExample.SOURCE_14 comment should refer to
'switch expressions' instead of 'text blocks'
+ JDK-8321303: Intermittent open/test/jdk/java/awt/
/KeyboardFocusmanager/ConsumeNextMnemonicKeyTypedTest/
/ConsumeNextMnemonicKeyTypedTest.java failure on Linux
+ JDK-8323089: networkaddress.cache.ttl is not a system property
+ JDK-8323545: java/awt/GraphicsDevice/CheckDisplayModes.java
fails with 'exit code: 133'
+ JDK-8323672: Suppress unwanted autoconf added flags in CC and
CXX
+ JDK-8324345: Stack overflow during C2 compilation when
splitting memory phi
+ JDK-8324641: [IR Framework] Add Setup method to provide custom
arguments and set fields
+ JDK-8328300: Convert PrintDialogsTest.java from Applet to main
program
+ JDK-8332495: java/util/logging/LoggingDeadlock2.java fails
with AssertionError: Some tests failed
+ JDK-8334928: Test sun/security/ssl/SSLSocketImpl/
/ReuseAddr.java failed: java.net.BindException: Address
already in use
+ JDK-8337876: [IR Framework] Add support for IR tests with
@Stable
+ JDK-8338103: Stabilize and open source a Swing OGL
ButtonResizeTest
+ JDK-8338112: Test testlibrary_tests/ir_framework/tests/
/TestPrivilegedMode.java fails with release build
+ JDK-8338344: Test TestPrivilegedMode.java intermittent fails
java.lang.NoClassDefFoundError: jdk/test/lib/Platform
+ JDK-8338554: Fix inconsistencies in javadoc/doclet/
/testLinkOption/TestRedirectLinks.java
+ JDK-8338883: Show warning when CreateCoredumpOnCrash set, but
core dump will not happen
+ JDK-8339233: Test javax/swing/JButton/
/SwingButtonResizeTestWithOpenGL.java#id failed: Button
renderings are different after window resize
+ JDK-8339238: Update to use jtreg 7.5.1
+ JDK-8339879: Open some dialog awt tests
+ JDK-8339975: Open some dialog awt tests 2
+ JDK-8340140: Open some dialog awt tests 3
+ JDK-8340336: Open some checkbox awt tests
+ JDK-8340494: Open some dialog awt tests 4
+ JDK-8340851: Open some TextArea awt tests
+ JDK-8340987: Open some TextArea awt tests 1
+ JDK-8341055: Open some TextArea awt tests 2
+ JDK-8341292: Open some TextArea awt tests 3
+ JDK-8341376: Open some TextArea awt tests 4
+ JDK-8341427: JFR: Adjust object sampler span handling
+ JDK-8342401: [TESTBUG] javax/swing/JSpinner/8223788/
/JSpinnerButtonFocusTest.java test fails in ubuntu 22.04 on
SBR Hosts
+ JDK-8345618: javax/swing/text/Caret/8163124/
/CaretFloatingPointAPITest.java leaves Caret is not complete
+ JDK-8346154: [XWayland] Some tests fail intermittently in the
CI, but not locally
+ JDK-8347811: Container detection code for cgroups v2 should
use cgroup.controllers
+ JDK-8347836: Disabled PopupMenu shows shortcuts on Mac
+ JDK-8349192: jvmti/scenarios/contention/TC05/tc05t001 fails:
ERROR: tc05t001.cpp, 281: (waitedThreadCpuTime -
waitThreadCpuTime) < (EXPECTED_ACCURACY * 1000000)
+ JDK-8349533: Refactor validator tests shell files to java
+ JDK-8349988: Change cgroup version detection logic to not
depend on /proc/cgroups
+ JDK-8350749: Upgrade JLine to 3.29.0
+ JDK-8352685: Opensource JInternalFrame tests - series2
+ JDK-8352733: Improve RotFontBoundsTest test
+ JDK-8352877: Opensource Several Font related tests - Batch 1
+ JDK-8353488: Open some JComboBox bugs 3
+ JDK-8353552: Opensource Several Font related tests - Batch 3
+ JDK-8354163: Open source Swing tests Batch 1
+ JDK-8354469: Keytool exposes the password in plain text when
command is piped using | grep
+ JDK-8354695: Open source several swing tests batch7
+ JDK-8354878: File Leak in
CgroupSubsystemFactory::determine_type of
cgroupSubsystem_linux.cpp:300
+ JDK-8354900: javax/swing/AbstractButton/bug4133768.java
failing on macosx-aarch64
+ JDK-8355048: ProblemList TestGlyphVectorLayout.java on all
platforms
+ JDK-8355179: Reinstate javax/swing/JScrollBar/4865918/
/bug4865918.java headful and macos run
+ JDK-8355332: Fix failing semi-manual test EDT issue
+ JDK-8355443: [java.io] Use @requires tag instead of exiting
based on File.separatorChar value
+ JDK-8355445: [java.nio] Use @requires tag instead of exiting
based on 'os.name' property value
+ JDK-8356107: [java.lang] Use @requires tag instead of exiting
based on os.name or separatorChar property
+ JDK-8357062: Update Public Suffix List to 823beb1
+ JDK-8357082: Stabilize and add debug logs to CopyAreaOOB.java
+ JDK-8357141: Update to use jtreg 7.5.2
+ JDK-8357280: (bf) Remove @requires tags from java/nio/Buffer/
/LimitDirectMemory[NegativeTest].java
+ JDK-8357390: java/awt/Toolkit/ScreenInsetsTest/
/ScreenInsetsTest.java Test failing on Ubuntu 24.04 Vm Hosts
used by Oracle's internal CI system
+ JDK-8358058: sun/java2d/OpenGL/DrawImageBg.java Test fails
intermittently
+ JDK-8358751: C2: Recursive inlining check for compiled lambda
forms is broken
+ JDK-8359978: Test javax/net/ssl/SSLSocket/Tls13PacketSize.java
failed again with java.net.SocketException: An established
connection was aborted by the software in your host machine
+ JDK-8360160: ubuntu-22-04 machine is failing client tests
+ JDK-8360882: Tests throw SkippedException when they should
fail
+ JDK-8361106: [TEST] com/sun/net/httpserver/Test9.java fails
with java.nio.file.FileSystemException
+ JDK-8361606: ConsumeNextMnemonicKeyTypedTest.java fails on
Windows: character typed with VK_A: a
+ JDK-8362428: Update IANA Language Subtag Registry to Version
2025-08-25
+ JDK-8364190: JFR: RemoteRecordingStream withers don't work
+ JDK-8364315: Remove unused xml files from test/jaxp/javax/xml/
/jaxp/functional/javax/xml/transform/xmlfiles
+ JDK-8364927: Add @requires annotation to
TestReclaimStringsLeaksMemory.java
+ JDK-8365379: SU3.applyInsets may produce wrong results
+ JDK-8365423: [macos26] java/awt/MenuBar/8007006/
/bug8007006.java fails on macOS 26
+ JDK-8365424: [macos26] java/awt/Frame/DisposeTest.java fails
on macOS 26
+ JDK-8365526: Crash with null Symbol passed to
SystemDictionary::resolve_or_null
+ JDK-8365625: Can't change accelerator colors in Windows L&F
+ JDK-8366128: jdk/jdk/nio/zipfs/TestPosix.java::testJarFile
uses wrong file
+ JDK-8366261: Provide utility methods for
sun.security.util.Password
+ JDK-8366369: Add @requires linux for GTK L&F tests
+ JDK-8366852: java/awt/Choice/ChoiceMouseWheelTest/
/ChoiceMouseWheelTest.java test is failing
+ JDK-8367583: sun/security/util/AlgorithmConstraints/
/InvalidCryptoDisabledAlgos.java fails after JDK-8244336
+ JDK-8367772: Refactor createUI in PassFailJFrame
+ JDK-8367784: java/awt/Focus/InitialFocusTest/
/InitialFocusTest1.java failed with Wrong focus owner
+ JDK-8368041: Enhance TLS certificate handling
+ JDK-8368335: Refactor the rest of Locale TestNG based tests to
JUnit
+ JDK-8368498: Use JUnit instead of TestNG for jdk_text tests
+ JDK-8368551: Core dump warning may be confusing
+ JDK-8368670: Deadlock in JFR on event register + class load
+ JDK-8368683: [process] Increase jtreg debug output
maxOutputSize for TreeTest
+ JDK-8368754: runtime/cds/appcds/SignedJar.java log regex is
too strict
+ JDK-8368885: NMT CommandLine tests can check for error better
+ JDK-8368892: Make JEditorPane/TestBrowserBGColor.java headless
+ JDK-8369251: Opensource few tests
+ JDK-8369319: java/net/httpclient/CancelRequestTest.java fails
intermittently
+ JDK-8369335: Two sun/java2d/OpenGL tests fail on Windows
after JDK-8358058
+ JDK-8369561: sun/java2d/OpenGL/DrawBitmaskImage.java#id0:
Incorrect color for first pixel (actual=ff000000)
+ JDK-8369851: Remove darcy author tags from langtools tests
+ JDK-8369858: Remove darcy author tags from jdk tests
+ JDK-8369911: Test sun/java2d/marlin/ClipShapeTest.java
#CubicDoDash, #Cubic and #Poly fail intermittent
+ JDK-8369950: TLS connection to IPv6 address fails with BCJSSE
due to IllegalArgumentException
+ JDK-8370325: G1: Disallow GC for TLAB allocation
+ JDK-8370511: test/jdk/javax/swing/JSlider/bug4382876.java does
not release previously pressed keys
+ JDK-8370732: Use WhiteBox.getWhiteBox().fullGC() to provoking
gc for nsk/jvmti tests
+ JDK-8370942: test/jdk/java/security/Provider/NewInstance.java
and /test/jdk/java/security/cert/CertStore/NoLDAP.java may
skip without notifying
+ JDK-8371365: Update javax/swing/JFileChooser/bug4759934.java
to use Util.findComponent()
+ JDK-8371366: java/net/httpclient/whitebox/
/RawChannelTestDriver.java fails intermittently in jtreg
timeout
+ JDK-8371383: Test sun/security/tools/jarsigner/
/DefaultOptions.java failed due to
CertificateNotYetValidException
+ JDK-8371503: RETAIN_IMAGE_AFTER_TEST do not work for some
tests
+ JDK-8372120: Add missing sound keyword to MIDI tests
+ JDK-8372351: Add 2 WISeKey roots
+ JDK-8372609: Bug4944439 does not enforce locale correctly
+ JDK-8372661: Add a null-safe static factory method to
'jdk.test.lib.net.SimpleSSLContext'
+ JDK-8372988: Test runtime/Nestmates/membership/
/TestNestHostErrorWithMultiThread.java failed: Unexpected
interrupt
+ JDK-8373101: JdkClient and JdkServer test classes ignore
namedGroups field
+ JDK-8373239: Test java/awt/print/PrinterJob/PageRanges.java
fails with incorrect selection of printed pages
+ JDK-8373275: Improve DTLS handshaking
+ JDK-8373623: Refactor Serialization tests for Records to JUnit
+ JDK-8373650: Test 'javax/swing/JMenuItem/6458123/
/ManualBug6458123.java' fails because the check icons are not
aligned properly as expected
+ JDK-8373690: Unexpected Keystore message using
jdk.crypto.disabledAlgorithms
+ JDK-8373716: Refactor further java/util tests from TestNG to
JUnit
+ JDK-8373807: test/jdk/java/net/httpclient/websocket/
/DummyWebSocketServer.java getURI() uses 'localhost'
+ JDK-8373847: Test javax/swing/JMenuItem/MenuItemTest/
/bug6197830.java failed because The test case automatically
fails when clicking any items in the âNothingâ menu in all
four windows (Left-to-right)-Menu Item Test and
(Right-to-left)-Menu Item Test
+ JDK-8373869: Refactor java/net/httpclient/
/ThrowingPushPromises*.java tests to use JUnit5
+ JDK-8373928: 4 Dangling pointer defect groups in java.c
+ JDK-8373931: Test javax/sound/sampled/Clip/
/AutoCloseTimeCheck.java timed out
+ JDK-8374058: Enhance JPEG handling
+ JDK-8374178: Missing include in systemDictionary.cpp after
JDK-8365526
+ JDK-8374304: MultiResolutionSplashTest.java fails in CI:
'Image with wrong resolution is used for splash screen!'
+ JDK-8374433: java/util/Locale/PreserveTagCase.java does not
run any tests
+ JDK-8374506: Incorrect positioning of arrow icon in parent
JMenu in Windows L&F
+ JDK-8374548: Process httpserver cancelled keys more quickly
+ JDK-8374555: No need for visible input warning in
s.s.u.Password when not reading from System.in
+ JDK-8374711: Hotspot runtime/CommandLine/OptionsValidation/
/TestOptionsWithRanges fails without printing the option name
+ JDK-8374888: Implement internal test cache to help
UserIterCount test performance
+ JDK-8374998: Failing os::write - remove bad file
+ JDK-8375065: Update LCMS to 2.18
+ JDK-8375080: The tools/jpackage/windows/Win8365790Test.java
may fail with ClassNotFoundException: jtreg.SkippedException
+ JDK-8375231: Refactor util/ServiceLoader tests to use JUnit
+ JDK-8375232: Refactor util/StringJoiner tests to use JUnit
+ JDK-8375233: Refactor util/Vector tests to use JUnit
+ JDK-8375999: com/sun/jndi/ldap/LdapPoolTimeoutTest.java fails
sporadically on Windows
+ JDK-8376031: HttpsURLConnection.getServerCertificates() throws
'java.lang.IllegalStateException: connection not yet open' for
the HEAD method
+ JDK-8376152: Test javax/sound/sampled/Clip/bug5070081.java
timed out then completed
+ JDK-8376233: Clean up code in Desktop native peer
+ JDK-8377158: Enhance XBM image support
+ JDK-8377167: javax/imageio/ReadAbortTest.java throw NPE when
x11 unavailable
+ JDK-8377498: Improve HttpServer handling
+ JDK-8377602: Create automated test for PageRange
+ JDK-8377678: G1: Heap Dumping crashes with -UseClassUnloading
+ JDK-8377727: Ghost caret and focus appear in nonâeditable text
fields
+ JDK-8377833: Enhance Jar file processing
+ JDK-8377910: Minor cleanup of java/io/FileDescriptor/
/Sharing.java
+ JDK-8377944: LowMemoryTest2.java#id1 intermittent fails OOME:
Metaspace
+ JDK-8378113: Add sun/java2d/OpenGL/ScaleParamsOOB.java to the
ProblemList.txt file
+ JDK-8378201: [OGL] glXMakeContextCurrent() drops the buffers
of the unbound drawable
+ JDK-8378417: Printing All pages results in NPE for 1.1
PrintJob
+ JDK-8378687: Improve delegation of HttpURLConnection
+ JDK-8378777: Bump update version for OpenJDK: jdk-17.0.20
+ JDK-8378802: [21u] backport changes to TKit.java by
JDK-8352419
+ JDK-8380316: Test runtime/os/AvailableProcessors.java fails
Invalid argument
+ JDK-8380565: PPC64: deoptimization stub should save vector
registers
+ JDK-8380672: Improve certification checking
+ JDK-8380947: Add pull request template
+ JDK-8381039: Enhance AWT ImagingLib
+ JDK-8381049: Enhance Jar handling
+ JDK-8381205: GHA: Upgrade Node.js 20 to 24
+ JDK-8381519: Enhance Der Value Handling
+ JDK-8381796: Enhance Certificate parsing
+ JDK-8382242: JFR: Metadata reconstruction invalidates
ConstantMap for java.lang.String
+ JDK-8383175: (tz) Update Timezone Data to 2026b
+ JDK-8383354: Update LCMS to 2.19.1
+ JDK-8383473: Follow on from tzdata2026b time change to include
temporary hack BC time change
+ JDK-8383601: RISC-V:
ShenandoahBarrierSetAssembler::load_reference_barrier calls
'weak' on 'phantom' path
+ JDK-8383630: Fix iteration in tests doing class redefinition
+ JDK-8383659: [17u] JVM crashes during stub routines generation
on Windows and rare combination of CPU features
+ JDK-8384158: GHA: Downgrade Windows GHA runners to
windows-2022 temporarily
+ JDK-8384486: NTLM tests fail on Windows 11 and Windows Server
2025
+ JDK-8384495: Update Libpng to 1.6.58
+ JDK-8384540: [25u, 21u, 17u] Update GHA JDKs after Apr/26
updates
+ JDK-8384815: SelectOneKeyOutOfMany and PreferredKey fail after
expired test certificate
+ JDK-8384902: Update GIFlib to 6.1.3
+ JDK-8385390: Update FreeType to 2.14.3
+ JDK-8385490: Update HarfBuzz to 14.2.0
+ JDK-8386343: [17u] Fix NTLMHeadTest after backport of 8384486
+ JDK-8386551: Windows build broken because of MSys2/Make update
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3415-1
Released: Thu Jul 30 08:54:36 2026
Summary: Security update for perl-DBI
Type: security
Severity: important
References: 1271017,1271018,1271399,1271458,1271459,1271629,CVE-2026-14380,CVE-2026-14740,CVE-2026-15043,CVE-2026-15392,CVE-2026-60081,CVE-2026-60082
This update for perl-DBI fixes the following issues
- CVE-2026-14380: unvalidated string eval interpolation of the Profile package name can lead to arbitrary Perl code
execution (bsc#1271018).
- CVE-2026-14740: one-byte out-of-bounds read when deleting an initial SQL comment line can lead to a process crash
(bsc#1271017).
- CVE-2026-15043: incorrect predicate evaluation in `DBI:SQL:Nano` can lead to bypass of file-backed filters
(bsc#1271399).
- CVE-2026-15392: missing checks to ensure the table file is not a symlink to an untrusted location in `DBD::File`
allows for arbitrary file reads and writes (bsc#1271629).
- CVE-2026-60081: no limiting of the path index in profile parser of `DBI:ProfileData` can enable small-file
memory-amplification DoS (bsc#1271458).
- CVE-2026-60082: out-of-bounds access in `_set_fbav` when a statement handle has zero fields but a non-empty row
can lead to a process crash (bsc#1271459).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3419-1
Released: Thu Jul 30 09:08:26 2026
Summary: Security update for tomcat
Type: security
Severity: important
References: 1271397,1271398,CVE-2026-59083,CVE-2026-59084
This update for tomcat fixes the following issues:
Update to Tomcat 9.0.120.
Security issues fixed:
- CVE-2026-59083: incorrect URL decoding in `RewriteValve` may allow security control bypass (bsc#1271397).
- CVE-2026-59084: `EncryptInterceptor` requirements are not clearly documented (bsc#1271398).
Other updates and bugfixes:
- Tomcat 9.0.120:
* Catalina
+ Fix: Avoid a race condition with concurrent lookups for a singleton JNDI
resource. (markt)
+ Fix: Improve the performance of range validation for the default
servlet. (markt)
+ Fix: Avoid NPE in RewriteValve. (markt)
+ Fix: 70127: Fix use of Bootstrap through reflection by restoring the
public constructor. Use through scripts was not affected. (remm)
+ Fix: Restore ability to extend many element classes from
AbstractAccessLogValve. (remm)
+ Fix: Align DIGEST authentication with RFC 7616 and require clients to
provide a valid qop parameter. (markt)
+ Fix: Use Files API to create temporary docBase when antiLockingDocBase
is enabled. (markt)
+ Fix: Improve validation of configuration when DataSourceRealm starts.
(remm)
+ Fix: JAASRealm should do a logout if login does not fail outright but
does not produce a Principal. (remm)
+ Fix: Various edge cases for SSI substitutions, quoting and escaping.
+ Fix: unintentional conversion of literal + to a space during rule
processing in the RewriteValve. (markt)
* Coyote
+ Fix: Avoid a potential JVM crash if a suitable version of Tomcat Native
is not available when the connector is explicitly configured to use
Tomcat Native with OpenSSL for TLS. (markt)
+ Fix: Correct a regression introduced in 9.0.119 that broke reading of
some request bodies via a Reader. (markt)
* Jasper
+ Fix: 70120: The fix for 69399 (itself a fix for a regression in the fix
for 69333) was incomplete and tags that threw exceptions in doStartTag()
and doEndTag() were incorrectly re-used. This fix prevents tags from
being re-used if such an exception occurs. (markt)
+ Fix: 70135: Fix security classload regression. (remm)
+ Add: support for specifying Java 28 (with the value 28) as the compiler
source and/or compiler target for JSP compilation. If used with an
Eclipse JDT compiler version that does not support these values, a
warning will be logged and the default will be used. (markt)
* WebSocket
+ Fix: 70126: Fix WebSocket extension permessage-deflate so that it does
not drop bytes if a compressed message inflates to more than the
available buffer. Fix written by GPT-5.5. Test case written by Hironori
Ichimiya. (markt)
+ Fix: Optimise WebSocket client processing of server responses during
WebSocket HTTP upgrade process. (markt)
* Other
+ Update: Byte Buddy to 1.18.9. (markt)
+ Update: UnboundID to 7.0.5. (markt)
+ Update: JaCoCo to 0.8.15. (markt)
+ Update: BND to 7.3.0. (markt)
+ Add: Improvements to French translations. (remm)
+ Add: Improvements to Japanese translations provided by tak7iji. (markt)
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3424-1
Released: Thu Jul 30 13:07:33 2026
Summary: Security update for python3-pyOpenSSL
Type: security
Severity: low
References: 1259804,CVE-2026-27448
This update for python3-pyOpenSSL fixes the following issue:
- CVE-2026-27448: unhandled exception in `set_tlsext_servername_callback` callback can result in connection not being
cancelled and allows for possible security measure bypassing (bsc#1259804).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3426-1
Released: Thu Jul 30 13:12:03 2026
Summary: Security update for bind
Type: security
Severity: important
References: 1271982,1271983,1271984,1271985,1271986,1271987,1271988,1271989,1271990,CVE-2026-10723,CVE-2026-10822,CVE-2026-11331,CVE-2026-11605,CVE-2026-11622,CVE-2026-11721,CVE-2026-12617,CVE-2026-13204,CVE-2026-13321
This update for bind fixes the following issues:
Upgrade to release 9.20.26.
Security issues fixed:
- CVE-2026-10723: incorrect acceptance of NSEC3 records (bsc#1271982).
- CVE-2026-10822: key record using PRIVATEDNS algorithm may lead to unexpected exit (bsc#1271983).
- CVE-2026-11331: potential wildcard CNAME RPZ policy bypass (bsc#1271984).
- CVE-2026-11605: unnecessary validation of DNSSEC signed records (bsc#1271985).
- CVE-2026-11622: potential memory usage beyond configured limits (bsc#1271986).
- CVE-2026-11721: cache poisoning possible with label count discrepancy, RRSIG, and wildcards (bsc#1271987).
- CVE-2026-12617: record ordering based unexpected exit with CNAME or DNAME (bsc#1271988).
- CVE-2026-13204: unexpected exit in certain situations with NSEC and NSEC3 both present (bsc#1271989).
- CVE-2026-13321: DNSSEC validation bypass via out-of-zone NSEC Next field (bsc#1271990).
Other updates and bugfixes:
- Release 9.20.26:
* Reclaim memory promptly when DNSSEC validations are canceled.
* Removed Features:
* Remove the secondary validator in query.c.
* Remove ineffective TCP fallback after repeated UDP timeouts.
* Feature Changes:
* Fall back to TCP on receipt of a UDP response with a mismatched
query ID.
* Limit the number of glue records cached from a referral.
* Fix a resolver stall on a CNAME response to a DS query.
* Bug Fixes:
* Fix a bug in DNS UPDATE processing with inline-signing enabled.
* Properly detect private records before copying.
* Tighten referral DS acceptance.
* Don't synthesize negative responses with pending NSEC.
* Check that an NSEC signer is at or above the name to be
validated.
* Don't evict DNSSEC-validated cache data on a CD=1 NXDOMAIN.
* Fix a deny-answer-aliases configuration bypass issue.
* Reject external referrals from forwarders.
* Fix a zone transfer over TLS (XoT) issue when using the
opportunistic TLS mode.
* Unvalidated opt-out NSEC3 could be accepted in insecurity
proof.
* Check wildcard signer and NOQNAME signer match.
* Fix CNAME resolution failure caused by a cached SERVFAIL
response.
* Reject unsupported RSA DNSKEY shapes during DNSSEC validation.
* Fix a bug in GeoIP2 string matching.
* Fix DNS-over-HTTPS (DoH) quota configuration issue.
* Truncated reply to a TSIG query no longer stalls the resolver.
* Ignore updates removing DNSKEY RRset with class ANY.
* Ignore 0-byte reads in the TCP read callback.
* Only print per-zone glue stats when zone-statistics is set to
full.
* CDS/CDNSKEY records were not removed when re-configuring the
server.
* Fix a crash when querying an empty non-terminal in a wildcard
zone in RBTDB.
* Stop reusing outgoing TCP connections the peer has already
closed.
* Fix DNSSEC validation failures for names under an apex DNAME.
* The resolver now removes other RRsets at the same name when
caching a CNAME.
* Fix nxdomain-redirect combined with dns64.
* Fix DNS64 owner case after DNAME restart.
* Clear REDIRECT flag when it isn't needed.
* Disable output escaping in bind9.xsl.
* Fix crash on badly configured secondary signer.
* Fix a possible crash on concurrent TKEY DELETE for the same
key.
* Reject RRSIG records covering meta-types.
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3429-1
Released: Thu Jul 30 13:18:04 2026
Summary: Security update for libarchive
Type: security
Severity: moderate
References: 1254340,1254341,1260998,1261002,1261003
This update for libarchive fixes the following issues:
- creating temporary files in the current working directory instead of the target directory can lead to file creation
failures when the working directory is not writable (bsc#1254340).
- file descriptor leak in the mtree parser cleanup path could lead to file descriptor exhaustion and denial of service
(bsc#1261003).
- NULL pointer dereference in archive_acl_from_text_w() could lead to a segmentation fault (bsc#1260998).
- reading from an invalid index when buffer size is smaller than H_LEVEL_OFFSET can lead to an out-of-bounds buffer
overrun (bsc#1254341).
- incorrect pointer handling for RAR5 files declaring over 8192 filters can lead to excessive resource usage and denial
of service (bsc#1261002).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3444-1
Released: Fri Jul 31 22:04:31 2026
Summary: Security update for openssl-3
Type: security
Severity: moderate
References: 1271712
This update for openssl-3 fixes the following issues:
- HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations
(bsc#1271712).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3454-1
Released: Mon Aug 3 13:45:25 2026
Summary: Security update for perl-HTTP-Date
Type: security
Severity: moderate
References: 1271705,CVE-2026-14741
This update for perl-HTTP-Date fixes the following issue
- CVE-2026-14741: CPU exhaustion due to polynomial regex backtracking in `parse_date` when processing specially crafted
date strings (bsc#1271705).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3455-1
Released: Mon Aug 3 13:46:45 2026
Summary: Security update for gawk
Type: security
Severity: moderate
References: 1271351,1271352,1271354,CVE-2026-40467,CVE-2026-40468,CVE-2026-40553
This update for gawk fixes the following issues:
- CVE-2026-40467: use-after-free in the `io.c` program file via the `do_getline_redir()` routine (bsc#1271351).
- CVE-2026-40468: integer overflow in the `builtin.c` program file (bsc#1271352).
- CVE-2026-40553: buffer overflow in the `extension/readdir.c` program file via the `ftype()` routine (bsc#1271354).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3458-1
Released: Mon Aug 3 14:00:20 2026
Summary: Security update for vim
Type: security
Severity: important
References: 1268162,1271193,1271194,1271195,1271684,CVE-2026-59856,CVE-2026-59857,CVE-2026-59858
This update for vim fixes the following issues:
This update for vim fixes the following issues:
Security issues fixed:
- CVE-2026-59856: Arbitrary Code Execution via PHP Omni-Completion (bsc#1271194).
- CVE-2026-59857: Out-of-bounds Write in SAL Soundfolding (bsc#1271195).
- CVE-2026-59858: Arbitrary Code Execution via C Omni-Completion (bsc#1271193).
Non security issue fixed:
- Guard suse.vimrc against re-entry to prevent an infinite sourcing
loop (bsc#1271684).
- allow 'wrap' and 'linebreak' to be set from a modeline (bsc#1268162).
Changes for vim:
- Updated to version 9.2.0780:
* filetype detect missing from completion (9.2.0726).
* popup images not rendered correctly when unfocused (9.2.0727).
* filetype: supertux info pattern is relative to current dir
(9.2.0728).
* % skips parens on continued quoted lines (9.2.0729).
* GTK4 GUI tabline is not updated (9.2.0730).
* GTK4 GUI scrollbar size not updated when restoring a session
(9.2.0731).
* session: terminal restored using absolute columns/rows (9.2.0732).
* GTK3: GUI slow on X11 since dropping the alpha channel (9.2.0733).
* function pointer passed to STRNCMP() instead of a length
(9.2.0734).
* tests: comment test can be improved (9.2.0737).
* completion: 'autocompletedelay' blocks the main loop and drops
autocommands (9.2.0739).
* GTK4: scrollbar wrongly displayed (9.2.0740).
* complete_check() does not return TRUE for mapped input (9.2.0741).
* filetype: SSH keys and related filetypes not recognized (9.2.0742).
* string macros silently accept a size of the wrong type (9.2.0743).
* popup_atcursor() closes immediately on white space (9.2.0744).
* cscope: connection leak when growing the array fails (9.2.0747).
* 'autocompletedelay' interferes with CTRL-G U (9.2.0748).
* 'autocompletedelay' interferes with i_CTRL-K (9.2.0749).
* completion: 'autocompletedelay' deferral leaks state (9.2.0750).
* GTK3 GUI is slow under Wayland (9.2.0751).
* GTK4: drag-and-drop does not support HTML (9.2.0752).
* GTK GUI deferred redraw skipped on 'lazyredraw' (9.2.0753).
* repeated completion length lookup in search_for_exact_line
(9.2.0754).
* 'autocomplete' behaves inconsistently when recording (9.2.0755).
* session with multiple tabpages sets 'winminheight' to 0 (9.2.0756).
* pum: no opacity when background not set for Popup menu group
(9.2.0758).
* some code for 'autocompletedelay' is no longer needed (9.2.0759).
* compiler warning for using potentially uninitialized var
(9.2.0760).
* runtime(netrw): Unix: unable to open '\' file (9.2.0761).
* duplicated sub-option name check in :set completion (9.2.0762).
* compiler warning about unused function (9.2.0764).
* popup: opacity popup over a terminal is not cleared when moved
(9.2.0765).
* quick_tab entries for empty letters point to the wrong index
(9.2.0766).
* legacy/vim9cmd modifiers do not set script version for options
values (9.2.0767).
* legacy/vim9cmd modifiers are not exclusive (9.2.0768).
* conversion to utf-16be using iconv is inconsistent (9.2.0769).
* dict_add_dict() has inconsistent ownership on failure (9.2.0770).
* dict_add_list() has inconsistent ownership on failure (9.2.0771).
* Vim9: null dereference inside alloc_type() (9.2.0772).
* memory leak in evalfunc.c on alloc failure (9.2.0773).
* memory leak in f_getscriptinfo() on alloc failure (9.2.0774).
* memory leak in highlight_get_info() on alloc failure (9.2.0775).
* memory leak in sign_getlist() on alloc failure (9.2.0776).
* memory leak in add_defer() on alloc failure (9.2.0777).
* memory leak in compile_dict() on alloc failure (9.2.0778).
* memory leak in type_name_func() on alloc failure (9.2.0779).
* memory leak in evalvars.c on alloc failure (9.2.0780).
- Updated to version 9.2.0725:
* GTK: preedit font size is wrong for fractional point sizes (9.2.0532).
* '[ mark moved to end of inserted text after CTRL-R CTRL-P paste (9.2.0533).
* GTK UI does not support fullscreen mode (9.2.0534).
* GTK4: mouse popup menu does not show up at mouse pointer (9.2.0537).
* Cannot keep leading whitespace in %{} statusline expr (9.2.0538).
* filetype: too many Bitbake include files are recognized (9.2.0539).
* Vim9: endclass/endenum/endinterface can give errors (9.2.0541).
* Vim9: wrong error when redeclaring a typed variable (9.2.0543).
* GTK4: window blank after a resize or drag (9.2.0544).
* popup: blending uses hardcoded fallback colors (9.2.0545).
* configure: GTK4 build requires GTK >= 4.10 (9.2.0546).
* '%v' in 'errorformat' is affected by 'tabstop' (9.2.0547).
* GTK4: terminal and pty job output is not processed (9.2.0548).
* Cursor wrong after autoindent strip is skipped (9.2.0549).
* GTK4: 'mousehide' unhides cursor when switching tabs (9.2.0550).
* filetype: Tolk files are not recognized (9.2.0551).
* GTK4: F10 does nothing when the menubar is hidden (9.2.0552).
* runtime(netrw): netrw rejects hostnames containing _ (9.2.0553).
* GTK4: memory leak in free_menu() (9.2.0554).
* too many strlen() in ex_substitute() (9.2.0555).
* GTK4: scrollbars not shown and do not respond to clicks (9.2.0556).
* filetype: Kawasaki Robots files are not recognized (9.2.0557).
* filetype: Popcap Reanimation files are not recognized (9.2.0558).
* filetype: Kaitai struct files are not recogonized (9.2.0559).
* filetype: busybox shebang lines are not recognized (9.2.0560).
* [security]: possible code execution with python3complete (9.2.0561).
* filetype: SGF files are not recognized (9.2.0562).
* GTK3/Wayland: crash with right mouse-button in tabline (9.2.0563).
* GTK4: tabline does not respond to mouse clicks (9.2.0564).
* [security]: out-of-bounds read in update_snapshot() (9.2.0565).
* <C-w>f duplicates window if do_ecmd() is aborted (9.2.0566).
* dict function name allocation failure not handled (9.2.0567).
* pythoncomplete: g:pythoncomplete_allow_import had no effect (9.2.0568).
* out-of-bounds access in libvterm CSI 8 t resize (9.2.0569).
* GTK4: mouse wheel scrolling does not work correctly (9.2.0570).
* Vim9: memory leak in compile_nested_function() on failure (9.2.0571).
* lines disappear with wrapping virtual text after a double-width char (9.2.0572).
* Vim9: missing EX_WHOLE on some block keywords (9.2.0573).
* popup_create() not blocked in secure/sandbox (9.2.0576).
* GTK4: window resizing issues (9.2.0577).
* GTK4: :unmenu does not remove entries from the menubar (9.2.0578).
* :mksession, :mkview and :mkvimrc emit legacy Vim script (9.2.0579).
* xxd: binary output is not colored with -R (9.2.0580).
* After maximizing and deleting the quickfix buffer, window height is wrong (9.2.0581).
* GTK4: compile error when XFONTSET is defined (9.2.0582).
* completion: indent not ignored for fuzzy line completion (9.2.0583).
* GTK4: missing UI features (9.2.0584).
* line number wrong after undoing a deletion in quickfix buffer (9.2.0585).
* Crash with TextPut autocmd when pasting in terminal buffer (9.2.0586).
* GTK4: left scrollbar overlaps drawarea (9.2.0587).
* GTK4: drawing area loses focus after closing a menubar popover (9.2.0588).
* filetype: xinitrc files are not recognized (9.2.0589).
* GTK4: drawing area loses focus shape on popup menu open (9.2.0590).
* 'scrolljump' ignored when scrolling up (9.2.0591).
* Error when restoring session with terminal window (9.2.0592).
* :wqall ignores term_setkill() on running terminal buffers (9.2.0593).
* Use-after-free with ':wqall' and a running terminal job (9.2.0594).
* MS-Windows: Wrong buffer size calculation for gvimext (9.2.0595).
* cmdline completion popup cannot be scrolled with the mouse (9.2.0596).
* [security]: possible code execution with python complete (9.2.0597).
* popup: title set with popup_setoptions() is not shown (9.2.0599).
* clientserver method needs to be given as argument (9.2.0600).
* matchfuzzypos() returns garbage positions for long candidates (9.2.0601).
* popup: No opacity when background not set for Popup group (9.2.0602).
* possible heap-buffer-overflow when resizing the GUI (9.2.0603).
* GTK4: does not support all clipboard formats (9.2.0606).
* GTK4: inputdialog() does not work as expected (9.2.0607).
* popup_setoptions()/ch_setoptions() does not check secure mode (9.2.0608).
* completion info popup cannot be scrolled with the keyboard (9.2.0609).
* cindent: closing brace in a comment affects the next line's indent (9.2.0610).
* MS-Windows: evim.exe not working with VIMDLL (9.2.0611).
* Cannot render images in popup windows (9.2.0612).
* opacity popup leaves stale cells (9.2.0614).
* sixel encoder drops pixels on the right edge of shapes (9.2.0615).
* GTK4: use-after-free on clipboard read timeout (9.2.0616).
* GvimExt: does not support different runtime dirs (9.2.0617).
* use-after-free in popup_getoptions() on dict_add() failure (9.2.0618).
* integer overflow in popup image size validation (9.2.0619).
* runtime(netrw): fix 2match pattern rebuild (9.2.0620).
* 'autoindent' not stripped with virtualedit=onemore (9.2.0621).
* str2blob() does not work with wide UTF-16 encoding (9.2.0622).
* possible integer overflow in spellfile tree bounds check (9.2.0623).
* C-N/C-P cannot be mapped in complete() completion (9.2.0624).
* GTK4: Link error when Wayland is disabled (9.2.0625).
* Vim9: illegal characters allowed in dict key names with dot notation (9.2.0626).
* :vim9cmd source handles all scripts as Vim9 script (9.2.0627).
* popup image: wrong overlap layering, kitty laggy (9.2.0628).
* 0x80 and 0x9b byte not unescaped when check for valid abbr (9.2.0629).
* popup images: kitty images output in GUI mode (9.2.0630).
* DECRQM and SGR Mouse not supported in foot terminal (9.2.0631).
* GTK4: no support for hardware-accelerated rendering (9.2.0632).
* MS-Windows: No support for kitty graphics support in terminal (9.2.0633).
* GTK4: no minimum resize limit (9.2.0634).
* checking the syntax contains/cluster list is slow (9.2.0635).
* popup image: stale pixels under RGBA animation frames (9.2.0636).
* sixel: anti-aliased RGBA images render with visible outline (9.2.0637).
* cannot return matches containing spaces from a custom completion (9.2.0638).
* gq with 'formatprg' fails on an empty buffer (9.2.0639).
* the '%' command jumps to parens and braces inside comments (9.2.0640).
* GTK4: crash in gui_mch_menu_hidden() (9.2.0641).
* statusline: buffer overflow with item groups (9.2.0642).
* Missing Image ifdefs (9.2.0643).
* popup image: duplicate sync-output code (9.2.0644).
* Composing chars no longer accepted in end-id abbr (9.2.0645).
* GTK3 GUI slow on HiDPI/4K with software rendering (9.2.0646).
* matchfuzzypos() false exact match for long equal-length candidates (9.2.0647).
* MS-Windows: Compile warnings (9.2.0648).
* filetype: tf files sometimes incorrectly recognized (9.2.0649).
* Vim aborts at startup when built with the example -O2 CFLAGS (9.2.0650).
* completion: 'smartcase' doesn't work with 'longest' (9.2.0651).
* popup: stale kitty image after clipwindow scrolls out of view (9.2.0652).
* [security]: out-of-bounds write in tree_count_words() (9.2.0653).
* GTK4: using uninitialised colors in gui_mch_init() (9.2.0654).
* GTK4: missing NULL checks in vim_form_measure() (9.2.0655).
* completion: using wrong tolower() in smartcase filtering (9.2.0656).
* GTK4: missing menu when right-clicking in tabline (9.2.0657).
* xxd: signed integer overflow in huntype() (9.2.0658).
* GTK4: no balloon support in GUI (9.2.0659).
* Dragging the scrollbar does not trigger WinScrolled (9.2.0660).
* unintended wipe of Vim's temp dir, causes errors (9.2.0661).
* [security] Stack out-of-bounds write in dump_prefixes() (9.2.0662).
* [security]: runtime(netrw): code injection in local file deletion (9.2.0663).
* GTK4: GTK critical error on exit printed (9.2.0665).
* Terminal-Normal mode does not color empty lines with a background color (9.2.0666).
* patch 9.2.0590 was wrong (9.2.0667).
* GTK4: minimum horizontal size is too small (9.2.0668).
* GTK4: toolbar can be improved (9.2.0669).
* [security]: Out-of-bounds read with text properties (9.2.0670).
* [security]: possible out-of-bounds read with sodium encrypted files (9.2.0671).
* corrupted text property causes internal error (9.2.0672).
* configure: clears dynamic ruby linker flags (9.2.0674).
* MS-Windows: cannot switch to a buffer with '%' in its name (9.2.0676).
* Cannot clear the alternate file register # (9.2.0677).
* [security]: potential powershell code execution in zip.vim (9.2.0678).
* [security]: Out-of-bounds read with text property virtual text (9.2.0679).
* keytrans() doesn't replace '|' and '\' (9.2.0680).
* configure: -lruby added even for a dynamic ruby build (9.2.0681).
* Wrong dot-repeat when calling complete() while filtering completion (9.2.0682).
* filetype completion mishandles finished sub options (9.2.0683).
* :reg # does not display the value of the '#' register (9.2.0684).
* clipboard.c does not get the Wayland CFLAGS on GTK2 (9.2.0685).
* style: strcmp usage is inconsistent (9.2.0686).
* popup_image_composites_frames() has improper if block scope (9.2.0687).
* Terminal-Normal mode does not show the Visual selection on a colored empty line (9.2.0688).
* the '%' command is slow on a long line with many slashes (9.2.0689).
* Solaris: swap file names are too long (9.2.0690).
* Solaris: Test_terminal_composing_unicode() fails (9.2.0691).
* GTK2: build failure, popup images not drawn correctly (9.2.0692).
* Solaris: some tests faiures due to Solaris peculiarities (9.2.0694).
* Solaris: test_delete_temp_dir() fails because of missing flock (9.2.0695).
* GTK4: A few issues with toolbar support (9.2.0696).
* possible overflow when parsing CSI keys (9.2.0697).
* [security]: Out-of-bounds write with soundfold() (9.2.0698).
* [security]: possible code execution with python complete (9.2.0699).
* configure: -lrt requirement for timer_create not detected (9.2.0700).
* :windo and :tabdo create an extra window with 'winfixbuf' (9.2.0702).
* session file does not store relative Vim9 autoload imports (9.2.0703).
* GTK4: not handling mouse events (9.2.0704).
* :delete # silently fails to update '# and clobbers '0 (9.2.0705).
* completion: popup misplaced when text before it is concealed (9.2.0707).
* Leaks in do_autocmd in error case (9.2.0708).
* GTK4: a few minor issues (9.2.0709).
* GTK4 GUI resize handling can be improved (9.2.0710).
* leak in ins_compl_infercase_gettext() in error case (9.2.0711).
* GTK4: dialogs not handling mnemonics correctly (9.2.0712).
* completion: ruler not updated correctly when the popup menu is visible (9.2.0713).
* Coverity warns for NULL deref (9.2.0714).
* Coverity warns about copy/paste error in hl_blend_attr() (9.2.0715).
* filetype: not all supertux files are recognized (9.2.0716).
* :syn sync without an argument also lists syntax cluster (9.2.0718).
* GTK4: default menu is lacking (9.2.0719).
* GTK4: no support for browsefilter (9.2.0720).
* serverlist() returns strings separated by \n (9.2.0721).
* GTK4: find/replace dialog can be improved (9.2.0722).
* term_start() does not support 'noclose' (9.2.0723).
* use-after-free when freeing exit_cb job on exit (9.2.0724).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3482-1
Released: Tue Aug 4 13:46:06 2026
Summary: Security update for netty, netty-tcnative
Type: security
Severity: important
References: 1271435,1271960,1271961,1272253,1272254,1272255,1272257,1272258,1272259,1272299,1272300,1272301,1272302,1272303,1272304,1272305,1272306,1272307,1272518,1272519,1272603,CVE-2026-44891,CVE-2026-55831,CVE-2026-55833,CVE-2026-55851,CVE-2026-56745,CVE-2026-56746,CVE-2026-56817,CVE-2026-56818,CVE-2026-56819,CVE-2026-56820,CVE-2026-56821,CVE-2026-56822,CVE-2026-59898,CVE-2026-59899,CVE-2026-59900,CVE-2026-59901,CVE-2026-59919,CVE-2026-59920,CVE-2026-59921
This update for netty, netty-tcnative fixes the following issues:
Upgrade netty to upstream version 4.1.136 and netty-tcnative to version 2.0.80 Final.
Security issues fixed
- CVE-2026-44891: memory exhaustion in `io.netty:netty-codec-stomp` (bsc#1271435).
- CVE-2026-55831: resource exhaustion/DoS in `io.netty:netty-codec-http` (bsc#1271960).
- CVE-2026-55833: zip bomb in `io.netty:netty-codec-http` (bsc#1271961).
- CVE-2026-55851: memory exhaustion in `io.netty:netty-codec-haproxy` (bsc#1272253).
- CVE-2026-56745: memory exhaustion in `io.netty:netty-codec-http` (bsc#1272254).
- CVE-2026-56746: improper access control in `io.netty:netty-codec-http` (CORS) (bsc#1272255).
- CVE-2026-56817: insecure defaults in XML parsing in `io.netty:netty-codec-xml` (bsc#1272257).
- CVE-2026-56818: memory leak in `io.netty:netty-codec-redis` (bsc#1272603).
- CVE-2026-56819: memory leak in `io.netty:netty-codec-http2` (bsc#1272258).
- CVE-2026-56820: improper certificate validation in `io.netty:netty-handler-ssl-ocsp` (bsc#1272259).
- CVE-2026-56821: improper certificate revocation check in `io.netty:netty-handler-ssl-ocsp` (bsc#1272299).
- CVE-2026-56822: time-of-check/time-of-use in `io.netty:netty-handler-ssl-ocsp` (bsc#1272300).
- CVE-2026-59898: protocol version confusion in `io.netty:netty-codec-http` (websocket) (bsc#1272302).
- CVE-2026-59899: memory exhaustion in `io.netty:netty-codec-http` (bsc#1272301).
- CVE-2026-59900: improper header neutralization in `io.netty:netty-codec-http2` (bsc#1272303).
- CVE-2026-59901: infinite loop in `io.netty:netty-codec-compression` (bzip2) (bsc#1272304).
- CVE-2026-59919: improper CR/LF neutralization in `io.netty:netty-codec-haproxy` (bsc#1272305).
- CVE-2026-59920: improper CR/LF neutrolization in `io.netty:netty-codec-stomp` (bsc#1272306).
- CVE-2026-59921: improper CR/LF neutralization in `io.netty:netty-codec-http` (multipart) (bsc#1272307).
- Memory leak in `io.netty:netty-codec-dns` (bsc#1272519).
- Uncontrolled resource consumption in `io.netty:netty-codec-xml` (bsc#1272518).
Other updates and bugfixes:
- Upgrade to upstream version 4.1.136:
+ SingleThreadEventExecutor: document Throwable safety contract
on run()
+ Make HTTP/2 frame hashCode consistent with equals
+ Add BlockHound exception for DnsQueryIdSpace (#16896)
+ FlowControlHandler: Fix autoRead behavior
+ Fix incorrect bounds in error message of
HpackDecoder.setMaxHeaderListSize
+ MQTT: Fix MQTT decoder size check after variable header replay
+ MQTT: Make the decodeProperties early-REPLAY check actually
fire
+ Reject control characters at the boundary of HTTP method names
(#16723)
+ Update to latest tcnative release
+ Fix HTTP 2 PUSH_PROMISE stream association validation
+ Fix GZIP FEXTRA extra-field handling in JdkZlibDecoder
+ Add opt-in validation of mandatory pseudo-header fields for
HTTP/2
+ Strictly validate MQTT UTF-8 Encoded String (#16939)
+ Stop DateFormatter trailing token from running past the parse
end
+ IpFilter: Deprecate constructor which use accept by default
+ Add RFC 10008 QUERY Method support (#16966)
+ Correctly release and fail queued traffic-shaping writes on
close (#16959)
+ FlowControlHandler: respect auto-read when toggled while
dequeueing
+ IdleStateHandler: reset firstWriter/ReaderIdleEvent in
resetWriteTimeout/resetReadTimeout (#16982)
+ Fix typo in AbstractSniHandler Javadoc
+ Reconcile AbstractCoalescingBufferQueue readableBytes when it
drains, and fail stuck HTTP/2 streams instead of spinning
empty DATA frames
+ Reject control characters at the boundary of the HTTP version
token (#16971)
+ Reset UTF-8 decode state on CR in StompSubframeDecoder
+ HTTP2: Pass the correct number of arguments when logging
goaway
+ FastLz: Guard decompression against truncated input (#17000)
+ Fix propagation of startTls for client SslContext handler
+ Reject non-token characters in HTTP/2 header names
+ Update lz4-java to 1.11.1
+ Pin github actions to reduce risk (#17043)
+ Merge branches from forks (#17063)
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3493-1
Released: Tue Aug 4 14:11:00 2026
Summary: Security update for libpng16
Type: security
Severity: important
References:
This update for libpng16 fixes the following issues:
Changes for libpng16:
- version update to 1.6.58 (jsc#PED-16190).
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3495-1
Released: Tue Aug 4 16:06:59 2026
Summary: Recommended update for policycoreutils
Type: recommended
Severity: moderate
References: 1271645
This update for policycoreutils fixes the following issues:
- Drop /tmp cleanup to avoid TOCTOU issues (bsc#1271645):
* can be dropped once 'policycoreutils/scripts/fixfiles:
drop /tmp cleanup' is in the upstream release
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3531-1
Released: Fri Aug 7 17:11:25 2026
Summary: Recommended update for python-instance-billing-flavor-check
Type: recommended
Severity: moderate
References: 1261166
This update for python-instance-billing-flavor-check fixes the following issues:
- Update to version 1.0.2:
* Fix crashes with AttributeError when update servers are unreachable (bsc#1261166)
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3541-1
Released: Mon Aug 10 14:50:04 2026
Summary: Security update for libssh2_org
Type: security
Severity: important
References: 1263890,1268546,1269567,1269568,1272734,1272735,1272736,1272737,CVE-2025-15661,CVE-2026-58050,CVE-2026-58051,CVE-2026-66032,CVE-2026-66033,CVE-2026-66034,CVE-2026-66035,CVE-2026-7598
This update for libssh2_org fixes the following issues:
- CVE-2025-15661: out-of-bounds heap read vulnerability in the `sftp_symlink()` function in `src/sftp.c` (bsc#1268546).
- CVE-2026-7598: integer overflow in function `userauth_password` of file `src/userauth.c` (bsc#1263890).
- CVE-2026-58050: heap buffer overflow due to missing bounds check in attribute count of publickey-subsystem response
(bsc#1269568).
- CVE-2026-58051: uninitialized pointer freed when malformed responses are sent by an SSH server (bsc#1269567).
- CVE-2026-66032: arbitrary code execution via double-free in SFTP session (bsc#1272737).
- CVE-2026-66033: denial of service via integer underflow in AES-GCM cipher negotiation (bsc#1272736).
- CVE-2026-66034: information disclosure and potential arbitrary code execution via heap out-of-bounds read
(bsc#1272735).
- CVE-2026-66035: arbitrary code execution via heap buffer overflow during SSH negotiation (bsc#1272734).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3558-1
Released: Mon Aug 10 20:01:21 2026
Summary: Security update for perl
Type: security
Severity: important
References: 1266304,1268349,1271372,CVE-2026-12087,CVE-2026-57432,CVE-2026-8376
This update for perl fixes the following issues:
- CVE-2026-8376: heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds
(bsc#1266304).
- CVE-2026-12087: `Socket`'s `pack_ip_mreq_source()` can copy adjacent heap memory into the returned packed structure
(bsc#1268349).
- CVE-2026-57432: an integer overflow in `S_measure_struct` leads to an out-of-bounds heap read in `pack` and `unpack`
(bsc#1271372).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3560-1
Released: Mon Aug 10 20:09:08 2026
Summary: Security update for python311
Type: security
Severity: important
References: 1264962,1265268,1267581,1267821,1268375,1268977,1269066,1269788,1269959,1271192,CVE-2026-0864,CVE-2026-11940,CVE-2026-11972,CVE-2026-15308,CVE-2026-3276,CVE-2026-4360,CVE-2026-7210,CVE-2026-7774,CVE-2026-8328
This update for python311 fixes the following issues:
Security issues fixed:
- CVE-2026-0864: improper handling of line-ending characters can lead to configuration file injection when the
`configparser` module is used (bsc#1269066).
- CVE-2026-3276: quadratic complexity in `unicodedata.normalize()` can lead to DoS when processing specially crafted
Unicode input (bsc#1267581).
- CVE-2026-4360: in the Tarfile.extract() function, the filter parameter is not passed properly when extracting
hardlinks (bsc#1269959).
- CVE-2026-7210: `xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding
protection (bsc#1264962).
- CVE-2026-7774: `tarfile.data_filter` path traversal bypass allows writing outside the extraction directory
(bsc#1267821).
- CVE-2026-8328: `ftpcp()` does not use actual peer address and trusts server-supplied PASV host address (bsc#1265268).
- CVE-2026-11940: tarfile extraction filter bypass via a crafted archive allows escaping the destination directory and
enables arbitrary file reads and writes (bsc#1268977).
- CVE-2026-11972: infinite loop due to improper EOF handling in the tarfile module streaming mode can lead to DoS
(bsc#1269788).
- CVE-2026-15308: Incremental HTMLParser allows CPU-exhaustion DoS via repeated unterminated markup declarations
(bsc#1271192).
Non security issue fixed:
- [kernel 7.1] udplite was removed -> python fails in tests (bsc#1268375).
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3567-1
Released: Tue Aug 11 07:34:13 2026
Summary: Recommended update for grub2
Type: recommended
Severity: important
References: 1259132,1271980
This update for grub2 fixes the following issues:
- Fix crash in booting kernel on some AMD systems (bsc#1271980)
- Fix broken bash completion on arm64 images when the bash-completion package
is not installed (bsc#1259132)
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3578-1
Released: Tue Aug 11 15:58:41 2026
Summary: Security update for openssl-1_1
Type: security
Severity: moderate
References: 1271712
This update for openssl-1_1 fixes the following issues:
- HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations
(bsc#1271712).
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3582-1
Released: Tue Aug 11 16:35:48 2026
Summary: Recommended update for timezone
Type: recommended
Severity: moderate
References:
This update for timezone fixes the following issues:
- Update to 2026c:
* Alberta moved to permanent -06 on 2026-06-18.
* Morocco moves to permanent +00 on 2026-09-20.
* More integer overflow bugs have been fixed in zic.
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3592-1
Released: Wed Aug 12 11:15:00 2026
Summary: Security update for gzip
Type: security
Severity: moderate
References: 1269623,1272554,CVE-2026-41992
This update for gzip fixes the following issues:
- CVE-2026-41992: global buffer overflow in the LZH decompression logic due to improper reuse of shared global state
between different decompression formats within a single execution (bsc#1269623).
- Crafted LZW file followed by a crafted LZH file can cause an out-of-bounds memory buffer access (bsc#1272554).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3600-1
Released: Wed Aug 12 13:59:10 2026
Summary: Security update for rpm
Type: security
Severity: important
References: 1240054,1269584,CVE-2026-44605
This update for rpm fixes the following issues:
Security issues fixed:
- CVE-2026-44605: heap buffer overflow in NDB database backend due to unchecked 32-bit arithmetic when parsing the slot
table (bsc#1269584).
Other updates and bugfixes:
- Fix `libelf` handle not being closed, resulting in build errors when using a NFS buildroot (bsc#1240054).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3605-1
Released: Thu Aug 13 08:35:24 2026
Summary: Security update for openssh
Type: security
Severity: important
References: 1271044,1271046,1271048,1271049,1271052,1271053,1271054,1271055,CVE-2026-59995,CVE-2026-59996,CVE-2026-59997,CVE-2026-59998,CVE-2026-59999,CVE-2026-60000,CVE-2026-60001,CVE-2026-60002
This update for openssh fixes the following issues:
- Backported support for the mlkemx25519 key exchange from upstream (jsc#PED-16473).
- CVE-2026-59995: sftp: location of downloaded files not properly constrained when `sftp server:/path .` is used with
an attacker-controlled server (bsc#1271044).
- CVE-2026-59996: scp: file placed in the parent directory of an intended target directory when copy occurs between two
remote destinations (bsc#1271046).
- CVE-2026-59997: sshd: `internal-sftp` command lines are silently truncated after the 9th argument (bsc#1271048).
- CVE-2026-59998: sshd: undocumented security-relevant `GSSAPIStrictAcceptorCheck` behavior in Windows Active Directory
is not documented (bsc#1271049).
- CVE-2026-59999: sshd: `DisableForwarding=yes` does not override `PermitTunnel=yes` (bsc#1271052).
- CVE-2026-60000: sshd: pre-authentication denial of service when GSSAPIAuthentication is enabled (bsc#1271053).
- CVE-2026-60001: sshd: minimum authentication delay is not honored (bsc#1271054).
- CVE-2026-60002: ssh: client-side use-after-free when a server changes its host key during a key reexchange
(bsc#1271055).
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3608-1
Released: Thu Aug 13 10:31:46 2026
Summary: Recommended update for tomcat
Type: recommended
Severity: moderate
References: 1273184
This update for tomcat fixes the following issues:
- Fix executable bit on tomcat, tomcat-digest, tomcat-tool-wrapper (bsc#1273184)
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3618-1
Released: Fri Aug 14 07:18:50 2026
Summary: Recommended update for apache-logging-parent, log4j
Type: recommended
Severity: moderate
References:
This update for apache-logging-parent, log4j fixes the following issues:
apache-logging-parent:
- Upgrade to logging-parent 12.1.1
* Main changes
+ Update to the latest upstream release (includes major updates
from versions 10, 11, and 12).
+ Better Security Tracking: Added tools (CycloneDX) to
automatically list all software ingredients (SBOM) used in the
build.
+ Updated Java Module Building: Swapped the old
maven-bundle-plugin for bnd-maven-plugin to better handle OSGi
and modern Java modules.
+ Stricter Code Quality: Added spotless-maven-plugin to enforce
a standard code style, and grouped bug-catching tools (Error
Prone, SpotBugs) into one place.
+ New Changelog System: Replaced the old Maven changes plugin
with a custom log4j-changelog-maven-plugin for managing
release notes.
+ Standardized Automation: Centralized GitHub Actions workflows
to make testing, building, and deploying more consistent
across projects.
+ Reliable Builds: Updated core Maven plugins and enforced
strict timestamp settings so that the same source code always
produces the exact same final files (reproducible builds).
log4j:
- Build with apache-logging-parent 12.1.1
+ Full osgi metadata generation
+ Bring back the annotation processing and generating the
Log4j2Plugins.dat descriptors
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3619-1
Released: Fri Aug 14 07:22:39 2026
Summary: Recommended update for libtcnative-1-0
Type: recommended
Severity: moderate
References:
This update for libtcnative-1-0 fixes the following issues:
- Update to 1.3.8:
* Changes:
+ Fix a memory leak when parsing certificates
+ Fix two potential memory leaks on error paths identified by Copilot
+ Fix post handshake authentication when Tomcat is configured
with a trust store using JSSE style configuration
+ Correct expected size of tickets when calling SSLContext.setSessionTicketKeys
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3648-1
Released: Wed Aug 19 11:54:08 2026
Summary: Security update for python311
Type: security
Severity: important
References: 1263083,CVE-2026-3276,CVE-2026-6019
This update for python311 fixes the following issues:
- Regression in `http.cookies` (bsc#1263083).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3657-1
Released: Thu Aug 20 19:06:03 2026
Summary: Security update for rsync
Type: security
Severity: important
References: 1269039,1269040,1269041,1269042,1269043,1269044,1269045,1269046,1269047,1269048,1269049,1269050,1269051,1269052,1269053,1269054,1269055,1269056,1269057,1269058,1269060,1273429,1273430,1273431,1273432,1273433,1273434,1273435,1273436,1273437,1273438,1273439,1273440,1273441,CVE-2026-53783,CVE-2026-53784,CVE-2026-53785,CVE-2026-53786,CVE-2026-53788,CVE-2026-53789,CVE-2026-53790,CVE-2026-53791,CVE-2026-53792,CVE-2026-53793,CVE-2026-53794,CVE-2026-53795,CVE-2026-53796,CVE-2026-53797,CVE-2026-53798,CVE-2026-53799,CVE-2026-53800,CVE-2026-53801,CVE-2026-53802,CVE-2026-53803,CVE-2026-70452,CVE-2026-70453,CVE-2026-70454,CVE-2026-70455,CVE-2026-70456,CVE-2026-70457,CVE-2026-70458,CVE-2026-70459,CVE-2026-70460,CVE-2026-70461,CVE-2026-70462,CVE-2026-70463,CVE-2026-70464
This update for rsync fixes the following issues:
- CVE-2026-53783: rrsync restricted-directory escape (validation-vs-exec race + unsafe option allowlist) (bsc#1269041).
- CVE-2026-53784: Daemon module-root chdir escape under 'use chroot = no' (bsc#1269042).
- CVE-2026-53785: --relative implied-parent creation escapes the destination tree (bsc#1269043).
- CVE-2026-53786: Daemon --filter merge file bypasses the module filter list (bsc#1269044).
- CVE-2026-53788: Daemon name-converter accepts newline-bearing names into its line protocol (bsc#1269046).
- CVE-2026-53789: Malicious sender expands --delete scope by reclassifying an implied parent (bsc#1269047).
- CVE-2026-53790: Command / argument injection via unquoted peer- or host-controlled values (bsc#1269048).
- CVE-2026-53791: PROXY-protocol mode lets a direct client spoof the daemon's source address (bsc#1269049).
- CVE-2026-53792: Receiver-supplied zero checksum block length drives sender matching negative (bsc#1269050).
- CVE-2026-53793: Chroot '/./' inner-module escape via a parent-component symlink (bsc#1269051).
- CVE-2026-53794: Remote peer disables the per-allocation sanity cap via --max-alloc=0 (bsc#1269052).
- CVE-2026-53795: Receiver write escape via an absolute --temp-dir / --link-dest disabling rename/link confinement
(bsc#1269053).
- CVE-2026-53796: Non-daemon receiver destination-chdir symlink race (TOCTOU) (bsc#1269054).
- CVE-2026-53797: Sender source-tree parent-component symlink race -> out-of-tree disclosure (bsc#1269055).
- CVE-2026-53798: Daemon name-converter empty response maps an unknown name to uid/gid 0 (bsc#1269045).
- CVE-2026-53799: Receiver ACL/xattr application follows a symlink-race -> arbitrary ACL set (local privilege
escalation) (bsc#1269056).
- CVE-2026-53800: Sender --remove-source-files unlink follows a parent-component symlink race -> arbitrary file deletion
outside the source tree (bsc#1269057).
- CVE-2026-53801: Sender/daemon directory-scan enumeration escapes the transfer root / module -> out-of-tree disclosure
(bsc#1269058).
- CVE-2026-53802: Arbitrary file read / transfer-shaping via symlinked operator-supplied input files (bsc#1269039).
- CVE-2026-53803: Arbitrary file write / privilege escalation via symlinked operator-supplied output paths
(bsc#1269040).
- CVE-2026-70452: `hosts deny` fails OPEN when a configured hostname cannot be resolved, admitting the host it was meant
to block (bsc#1273441).
- CVE-2026-70453: Quadratic CPU exhaustion in hash_search() from a crafted equal-weak-checksum chain (bsc#1273440).
- CVE-2026-70454: rsync-ssl establishes an unauthenticated TLS connection (bsc#1273439).
- CVE-2026-70455: Peer-controlled Zstandard worker exhaustion on an rsync daemon (bsc#1273438).
- CVE-2026-70456: Remote out-of-bounds heap write in read_args() when the argument count lands exactly on maxargs
(bsc#1273437).
- CVE-2026-70457: Attacker-chosen-offset write in parse_size_arg() error formatting (bsc#1273436).
- CVE-2026-70458: Out-of-bounds write from a FLAG_HLINKED file entry accepted without -H (bsc#1273435).
- CVE-2026-70459: Per-connection daemon child crash from a crafted first incremental file list with a non-directory
transfer root (bsc#1273434).
- CVE-2026-70460: Daemon module-root escape through a peer-supplied --partial-dir / --backup-dir resolving via an in-
module symlink (bsc#1273433).
- CVE-2026-70461: Peer-driven one-byte heap out-of-bounds write in add_implied_include() (bsc#1273432).
- CVE-2026-70462: Peer-supplied MSG_IO_TIMEOUT defeats the client's own I/O timeout (bsc#1273431).
- CVE-2026-70463: 'auth users' ignores documented comma-only parsing, silently skipping a deny/read-only rule
(bsc#1273430).
- CVE-2026-70464: Unauthenticated pre-transfer handshake DoS locks out an rsync daemon module (bsc#1273429).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3680-1
Released: Fri Aug 21 16:21:23 2026
Summary: Security update for vim
Type: security
Severity: important
References: 1275011,1275012,1275013,1275014,1275015,1275016,1275017,1275018,CVE-2026-73070,CVE-2026-73071,CVE-2026-73072,CVE-2026-73074,CVE-2026-73075,CVE-2026-73076,CVE-2026-73077,CVE-2026-73078
This update for vim fixes the following issues:
- CVE-2026-73070: stack buffer overflow in the socket server can lead to denial of service (bsc#1275018).
- CVE-2026-73071: use-after-free in JSON decoding can lead to process crash (bsc#1275017).
- CVE-2026-73072: heap buffer overflow when loading a spell file can lead to crash or potential code execution
(bsc#1275016).
- CVE-2026-73074: heap buffer overflow in text property handling can lead to a crash or potential code execution
(bsc#1275015).
- CVE-2026-73075: out-of-bounds access in popup opacity handling can lead to a conditional memory write (bsc#1275014).
- CVE-2026-73076: arbitrary command execution via the vimball record file (bsc#1275013).
- CVE-2026-73077: arbitrary code execution due to insecure shell command handling (bsc#1275012).
- CVE-2026-73078: arbitrary code execution via crafted netrw menu entries (bsc#1275011).
Changes for vim:
- Updated to version 9.2.0957.
* tests: Test_fuzzy_completion_bufname_fullpath() creates unnecessary dir (9.2.0781).
* tests: missing cleanup in test_mksession.vim (9.2.0782).
* tests: personal spell files leak into later tests (9.2.0783).
* crash when borrowing statusline highlight in silent Ex mode (9.2.0784).
* WinResized not triggered when the whole Vim is resized (9.2.0785).
* filetype: containerfile is not recognized (9.2.0786).
* regexp: code 0x1ecb duplicated for equivalence class (9.2.0787).
* filetype: hip files are not recognized (9.2.0788).
* 'statuslineopt' status line too high after a window is minimized (9.2.0789).
* 'completeslash' breaks :find completion with 'findfunc' (9.2.0790).
* wincol() counts from right side for 'rightleft' (9.2.0791).
* runtime(netrw): explore without optional dir broken (9.2.0792).
* if session restored a tiny window, restore fails (9.2.0793).
* extend() and extendnew() don't handle NULL expr2 properly (9.2.0794).
* popup menu shadow is not cleared when the menu shrinks (9.2.0795).
* Visual block reselection wrong with 'virtualedit' (9.2.0796).
* memory leak in get_qfline_items() on alloc failure (9.2.0797).
* memory leak in compile_expr6() on alloc failure (9.2.0798).
* memory leak in compile_def_function_body() on alloc failure (9.2.0799).
* memory leak in call_func() on alloc failure (9.2.0800).
* memory leak in f_getreginfo() on alloc failure (9.2.0801).
* memory leak with list_append_dict/dict_add_list on alloc failure (9.2.0802).
* memory leak on alloc failure with taglist/gettagstack() (9.2.0803).
* wincol() is wrong for a double-wide character with 'rightleft' (9.2.0804).
* screenpos() 'curscol' is wrong with 'rightleft' (9.2.0805).
* 'showcmd' may show internal command keys (9.2.0806).
* MS-Windows: ellipsis character is garbled (9.2.0807).
* getregionpos: double-free on alloc failure (9.2.0808).
* getframelayout() uses wrong function to free lists (9.2.0809).
* add_llist_tags() uses wrong function to free dict (9.2.0810).
* mksession writes terminal command unquoted (9.2.0811).
* :argdelete with pattern leads to wrong argidx() (9.2.0812).
* dict_add_func() may corrupt funcref count on failure (9.2.0813).
* Vim9: E1041 when reloading an autoload script with exported variables (9.2.0814).
* deeply nested regexp patterns may cause stack overflow (9.2.0815).
* GTK4: memory leak in gui_gtk_set_dnd_targets() (9.2.0816).
* crash when building a stacktrace during an autocommand (9.2.0817).
* tests: client-server test fails without X11 server (9.2.0818).
* MS-Windows: sixel image shown as raw text in the console (9.2.0819).
* GUI: hidden popup image is displayed and not erased (9.2.0820).
* filetype: msmtp system-wide rc file not detected (9.2.0821).
* GTK4: crash menu id is null in gui_mch_destroy_menu() (9.2.0822).
* tests: Test_clientserver_servlist_list may fail (9.2.0823).
* Makefile: make tags depends on configure (9.2.0824).
* regexp: submatch in a look-behind is empty with the NFA engine (9.2.0825).
* highlighting for broken terminals can be improved (9.2.0826).
* :startinsert enters Insert mode in a non-modifiable buffer (9.2.0827).
* GTK4: hardware rendering can be improved (9.2.0828).
* sessions do not preserve script version for expression options (9.2.0829).
* the completion menu is not used on terminals without colors (9.2.0830).
* diff highlighting hard to read with syntax enabled (9.2.0831).
* socketserver: remote commands can be processed in reverse order (9.2.0832).
* GTK4: menu mnemonics do not work properly (9.2.0833).
* cleared last search pattern is restored from viminfo (9.2.0834).
* features in version.c are not sorted (9.2.0835).
* filetype: .git-blame-ignore-revs file is not recognized (9.2.0836).
* using wrong colors in hl_blend_attr() (9.2.0837).
* searchcount() returns wrong cached maxcount (9.2.0838).
* [security]: arbitrary code execution via keyword lookup (9.2.0839).
* [security]: code injection in netrw via bookmarks (9.2.0840).
* [security]: heap overflow when adding > 65535 text properties (9.2.0841).
* [security]: stack buffer overflow in socket server (9.2.0842).
* [security]: popup: opacity mask indexed out of bounds (9.2.0843).
* [security]: use-after-free on json decode error (9.2.0844).
* [security]: arbitrary Ex command execution during C omni-completion (9.2.0845).
* [security]: heap buffer overflow in set_sofo() (9.2.0846).
* [security]: vimball: code execution via .VimballRecord file (9.2.0847).
* tagfunc 'cmd' with a generic Ex command corrupts the tag entry (9.2.0848).
* filetype: osquery config files are not recognized (9.2.0849).
* MS-Windows: commands from a client can be lost (9.2.0850).
* focus autocommands triggered inconsistently (9.2.0851).
* GTK: ligatures not correctly displayed (9.2.0852).
* popup: popup images do not support scaling (9.2.0853).
* memory leak when reading a spell file with SN_SAL and SN_SOFO (9.2.0854).
* 'showcmd' not redrawn with empty mapping triggered on timeout (9.2.0855).
* GTK4: undercurl rendering is inefficient (9.2.0856).
* popup: opacity popup over a terminal is not cleared when closed (9.2.0857).
* MS-Windows GUI: white flash when VimEnter is slow (9.2.0858).
* GTK2: link error (9.2.0859).
* filetype: xilinx design constraint files are not recognized (9.2.0860).
* GTK4: bleed region updates in jumps (9.2.0861).
* missing test change from v9.2.0857 (9.2.0862).
* MS-Windows GUI: window contents can be missing when VimEnter is slow (9.2.0863).
* using some dead code in Wayland feature (9.2.0864).
* GTK4: non-hardware accelerated UI is too slow (9.2.0865).
* MS-Windows: ':language messages' only works once (9.2.0866).
* MS-Windows: messages are not in the display language (9.2.0867).
* GTK: window Manager hint prevents giving focus to dialog (9.2.0868).
* buf_copy_options() can lose the P_INSECURE flag (9.2.0869).
* filetype: marko files are not recognized (9.2.0870).
* screen line is lost when splitting a 'winfixheight' window (9.2.0871).
* popup with opacity does not use the font of the highlight group (9.2.0872).
* :redrawstatus does not update the ruler of the last window (9.2.0873).
* fold size is compared against 'foldminlines' of the wrong window (9.2.0874).
* GTK4: GUI does not support command-line arguments (9.2.0875).
* GTK4: compile error with disabled netbeans feat (9.2.0876).
* Vim9: crash when a closure assigns to a variable declared in a loop (9.2.0877).
* Vim9: cannot use a script variable of an enclosing block in a lambda (9.2.0878).
* popup: 'maxwidth' is not respected when 'wrap' is off (9.2.0879).
* scroll: window scrolls when using the autocommand window (9.2.0880).
* 'smoothscroll' position is lost when the window height changes (9.2.0881).
* :bwipe crashes if WinLeave wipes all other buffers (9.2.0882).
* scroll: 'smoothscroll' position is lost when using '|' (9.2.0883).
* scroll: unreachable 'smoothscroll' code in cursor_correct() (9.2.0884).
* scroll: 'smoothscroll' position is lost when the window is squeezed (9.2.0885).
* :set completion works for an invalid sub-option name (9.2.0886).
* scroll: jump-scrolling when moving the cursor onto a wrapping line (9.2.0887).
* mapping: modifier is not recognized after a partial mapping (9.2.0888).
* VMS: spurious 'INVALID DECC FEATURE VALUE' message at every startup (9.2.0889).
* test: test for patch v9.2.0888 can be clarified (9.2.0890).
* MS-Windows: filename-modifier ':8:t' causes underflow (9.2.0891).
* highlight: wrong column highlighted with 'cursorcolumn' (9.2.0892).
* MS-Windows: '*.vim' also matches files with a longer extension (9.2.0893).
* filetype: ed script files not recognised (9.2.0894).
* test: Test_aucmd_win_scroll_multibyte() is flaky in the GUI (9.2.0895).
* scroll: 'smoothscroll' position is lost when splitting a window (9.2.0896).
* GTK3 X11 redraws are not coalesced (9.2.0897).
* printing support is lacking (9.2.0898).
* command output temporary files may collide (9.2.0899).
* FocusGained still triggered when closing dialog (9.2.0900).
* textprop: wrong cursor line with truncated virtual text (9.2.0901).
* Vim9: iterating over a tuple leaks memory (9.2.0902).
* Vim9: cannot use an exported function of an autoload import (9.2.0903).
* 'zb' scrolls incorrectly with cursor just above fold (9.2.0904).
* MS-Windows: ghost cursor with ligatures (9.2.0905).
* slow transstr() with long strings (9.2.0906).
* popup: virtual text is not redrawn when a text property changes (9.2.0907).
* cannot use a {} block in a nested :autocmd (9.2.0908).
* insert completion is slow to collect many matches (9.2.0909).
* runtime(vim): update syntax, contain Ex commands (9.2.0910).
* makefiles do not build hardcopy_postscript.c (9.2.0911).
* hardcopy: prototypes are hand-written instead of generated (9.2.0912).
* statusline: cell below the vertical separator keeps the old highlight (9.2.0913).
* diff: undo after :diffget into an empty buffer leaves a line behind (9.2.0914).
* tests: two terminal tests in test_popupwin fail on FreeBSD (9.2.0915).
* configure: honor `--disable-hardcopy-pango` with GTK UI (9.2.0916).
* :quitall not allowed in the command-line window (9.2.0917).
* screen: fill char with a zero low byte is stored as a NUL cell (9.2.0918).
* screen: the wrong array is copied into ScreenCols on a resize (9.2.0919).
* filetype: json-ld files are not recognized (9.2.0920).
* test: terminal tests fail on FreeBSD (9.2.0921).
* Wayland: modeless selection not redrawn (9.2.0922).
* tabpage: closing a tab page loses the alternate tab page (9.2.0923).
* tests: Test_termwinscroll() fails on FreeBSD (9.2.0924).
* crash when getcompletiontype() gets a NULL string (9.2.0925).
* filetype: business Central files are not recognized (9.2.0926).
* curswant not set on 8g8 (9.2.0927).
* MinGW: tests hang when Vim is built with coverage enabled (9.2.0928).
* incorrect completion for 'pumopt' and 'pumborder' (9.2.0929).
* floating point exception when displaying pum (9.2.0930).
* the GTK4 GUI is still experimental and untested by CI (9.2.0931).
* NFA engine fallback can double free the compiled program (9.2.0932).
* u_read_undo() leaks the file name when the undo file owner differs (9.2.0933).
* filetype: hlsl files are not recognized (9.2.0934).
* reading an undo file is slow with many undo headers (9.2.0935).
* stringifying a list or dict can free the item being iterated (9.2.0936).
* sort() with a numeric option converts each item on every comparison (9.2.0937).
* cursorbind: cursor in the other window is not updated after undo (9.2.0938).
* mbyte: wrong cell count for an overlong UTF-8 sequence (9.2.0939).
* GTK4: columns are lost when a scrollbar appears (9.2.0940).
* tests: clipboard tests fail in the GUI when the terminal has no clipboard (9.2.0941).
* test: test_mksession_winpos() fails on GTK4 UI (9.2.0942).
* test: test_hardcopy fails on GTK4 UI (9.2.0943).
* test: tests fail when checking for GTK4 feature (9.2.0944).
* sort() with a numeric option can be improved (9.2.0945).
* GTK2/3: mouse move starts Visual selection after a dialog (9.2.0946).
* GTK4: screen is cleared when moving the mouse after startup (9.2.0947).
* GTK4: mouse move starts Visual selection after a dialog (9.2.0948).
* GDK_KEY_VoidSymbol might be undefined (9.2.0949).
* transstr() can be improved (after 9.2.0906) (9.2.0950).
* GTK3: cursor does no longer blink (9.2.0951).
* locking a container while stringifying can be improved (9.2.0952).
* insert completion code can be improved (9.2.0953).
* u_read_undo() can be improved (after 9.2.0935) (9.2.0954).
* tests: terminal tests are flaky (9.2.0955).
* GTK4: crash when the window is resized while redrawing (9.2.0956).
* filetype: ArgoCD config file is not recognized (9.2.0957).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3684-1
Released: Fri Aug 21 20:23:10 2026
Summary: Security update for util-linux
Type: security
Severity: important
References: 1261606,1268886,1269583,CVE-2026-13595,CVE-2026-27456,CVE-2026-53612,CVE-2026-53613,CVE-2026-53614
This update for util-linux fixes the following issues:
- CVE-2026-13595: heap use-after-free read in `libblkid` nested partition probing (bsc#1269583).
- CVE-2026-27456: TOCTOU race condition in the mount program when setting up loop devices (bsc#1261606).
- Several security issues in releases prior to v2.42.2 and v2.41.5 (bsc#1268886).
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3712-1
Released: Mon Aug 24 04:52:59 2026
Summary: Maintenance update for Multi-Linux Manager 5.1.5
Type: recommended
Severity: important
References: 1243168,1244141,1245944,1247004,1253505,1254201,1257102,1257295,1258500,1258567,1259225,1259254,1259594,1259720,1260342,1260396,1261195,1262012,1262168,1262664,1263822,1263823,1265334,1266481,1267619,1267871,1268006,1268151,1268229,1268309,1268325,1268567,1268570,1268673,1269192,1269267,1269408,1270040,1274571,1274984,1275217,CVE-2026-39821
Maintenance update for Multi-Linux Manager 5.1.5: Server, Proxy and Retail Branch Server
This is a codestream only update
The following package changes have been done:
- libssh-config-0.9.8-150600.11.15.1 updated
- glibc-2.38-150600.14.52.1 updated
- libuuid1-2.40.4-150700.4.18.1 updated
- libsmartcols1-2.40.4-150700.4.18.1 updated
- libgcc_s1-15.3.0+git11272-150000.1.12.1 updated
- libxml2-2-2.12.10-150700.4.14.1 updated
- libstdc++6-15.3.0+git11272-150000.1.12.1 updated
- libudev1-254.27-150600.4.71.2 updated
- login_defs-4.17.2-150600.17.21.1 updated
- libglib-2_0-0-2.78.6-150600.4.38.1 updated
- libopenssl3-3.2.3-150700.5.40.1 updated
- libgcrypt20-1.11.0-150700.5.10.1 updated
- libblkid1-2.40.4-150700.4.18.1 updated
- perl-base-5.26.1-150300.17.23.1 updated
- libopenssl-3-fips-provider-3.2.3-150700.5.40.1 updated
- krb5-1.20.1-150600.11.19.1 updated
- gpg2-2.4.4-150600.3.18.1 updated
- libmount1-2.40.4-150700.4.18.1 updated
- libfdisk1-2.40.4-150700.4.18.1 updated
- libssh4-0.9.8-150600.11.15.1 updated
- libcurl4-8.14.1-150700.7.20.1 updated
- pam-1.3.0-150000.6.89.1 updated
- libsubid5-4.17.2-150600.17.21.1 updated
- shadow-4.17.2-150600.17.21.1 updated
- util-linux-2.40.4-150700.4.18.1 updated
- curl-8.14.1-150700.7.20.1 updated
- gzip-1.10-150200.16.1 updated
- timezone-2026c-150600.91.12.1 updated
- openssl-3-3.2.3-150700.5.40.1 updated
- libkmod2-29-150600.13.6.1 updated
- libsystemd0-254.27-150600.4.71.2 updated
- systemd-254.27-150600.4.71.2 updated
- dmidecode-3.7-150400.16.14.1 updated
- gawk-4.2.1-150000.3.6.1 updated
- glibc-locale-base-2.38-150600.14.52.1 updated
- libarchive13-3.7.2-150600.3.23.1 updated
- libasound2-1.2.10-150600.4.3.1 updated
- libatomic1-15.3.0+git11272-150000.1.12.1 updated
- libavahi-common3-0.8-150600.15.21.1 updated
- libgmodule-2_0-0-2.78.6-150600.4.38.1 updated
- libgobject-2_0-0-2.78.6-150600.4.38.1 updated
- libgomp1-15.3.0+git11272-150000.1.12.1 updated
- libipa_hbac0-2.10.2-150700.9.37.1 updated
- libitm1-15.3.0+git11272-150000.1.12.1 updated
- liblsan0-15.3.0+git11272-150000.1.12.1 updated
- libopenssl1_1-1.1.1w-150700.11.25.2 updated
- libpng16-16-1.6.58-150600.3.23.1 updated
- libquadmath0-15.3.0+git11272-150000.1.12.1 updated
- libssh2-1-1.11.0-150600.20.6.1 updated
- libsss_idmap0-2.10.2-150700.9.37.1 updated
- libsss_nss_idmap0-2.10.2-150700.9.37.1 updated
- libxml2-tools-2.12.10-150700.4.14.1 updated
- openssh-common-9.6p1-150600.6.49.1 updated
- patch-2.7.6-150000.5.12.1 updated
- python311-base-3.11.15-150600.3.65.1 updated
- libpython3_11-1_0-3.11.15-150600.3.65.1 updated
- release-notes-multi-linux-manager-5.1.5-150700.5.43.1 updated
- susemanager-schema-utility-5.1.20-150700.3.25.9 updated
- uyuni-config-modules-5.1.26-150700.3.32.1 updated
- vim-data-common-9.2.0957-150500.20.64.1 updated
- supportutils-3.2.14.2-150600.3.12.1 updated
- glibc-locale-2.38-150600.14.52.1 updated
- libavahi-client3-0.8-150600.15.21.1 updated
- perl-5.26.1-150300.17.23.1 updated
- libtcnative-1-0-1.3.8-150600.16.6.1 updated
- postgresql-18-150700.23.6.1 updated
- libsss_certmap0-2.10.2-150700.9.37.1 updated
- bind-utils-9.20.26-150700.3.29.1 updated
- glibc-devel-2.38-150600.14.52.1 updated
- openssh-fips-9.6p1-150600.6.49.1 updated
- python311-3.11.15-150600.3.65.1 updated
- susemanager-docs_en-5.1-150700.10.15.1 updated
- policycoreutils-3.5-150600.3.3.1 updated
- libgio-2_0-0-2.78.6-150600.4.38.1 updated
- glib2-tools-2.78.6-150600.4.38.1 updated
- spacewalk-java-lib-5.1.31-150700.3.31.9 updated
- vim-9.2.0957-150500.20.64.1 updated
- perl-HTTP-Date-6.02-150000.3.3.1 updated
- perl-DBI-1.647.0-150600.12.18.1 updated
- openssh-server-9.6p1-150600.6.49.1 updated
- openssh-clients-9.6p1-150600.6.49.1 updated
- python3-zypp-plugin-0.6.5-150600.18.10.1 updated
- python3-rpm-4.14.3-150400.59.19.1 updated
- python3-idna-2.6-150000.3.9.1 updated
- adcli-0.9.3.1-150600.22.8.1 updated
- libldb2-4.21.10+git.533.31d7e5508d-150700.3.29.1 updated
- postfix-3.8.4-150600.3.6.1 updated
- susemanager-tools-salt-5.1.19-150700.3.18.1 updated
- python311-zypp-plugin-0.6.5-150600.18.10.1 updated
- python311-tornado6-6.3.2-150400.9.21.1 updated
- python311-toml-0.10.2-150400.5.7.1 updated
- python311-rpm-4.14.3-150400.59.19.1 updated
- python311-pyasn1-0.5.0-150400.12.16.1 updated
- python311-idna-3.4-150400.11.13.1 updated
- susemanager-docs_en-pdf-5.1-150700.10.15.1 updated
- susemanager-schema-5.1.20-150700.3.25.9 updated
- susemanager-sync-data-5.1.11-150700.3.15.1 updated
- rsync-3.2.7-150600.3.24.1 updated
- openssh-9.6p1-150600.6.49.1 updated
- grub2-2.12-150700.19.34.1 updated
- grub2-i386-pc-2.12-150700.19.34.1 updated
- spacewalk-backend-sql-postgresql-5.1.18-150700.3.15.15 updated
- sssd-ldap-2.10.2-150700.9.37.1 updated
- sssd-2.10.2-150700.9.37.1 updated
- sssd-krb5-common-2.10.2-150700.9.37.1 updated
- samba-client-libs-4.21.10+git.533.31d7e5508d-150700.3.29.1 updated
- perl-HTML-Parser-3.830.0-150000.3.6.1 updated
- susemanager-build-keys-15.5.3-150700.5.17.1 updated
- grub2-x86_64-efi-2.12-150700.19.34.1 updated
- grub2-powerpc-ieee1275-2.12-150700.19.34.1 updated
- grub2-arm64-efi-2.12-150700.19.34.1 updated
- sssd-krb5-2.10.2-150700.9.37.1 updated
- sssd-dbus-2.10.2-150700.9.37.1 updated
- python3-sssd-config-2.10.2-150700.9.37.1 updated
- sssd-ad-2.10.2-150700.9.37.1 updated
- java-17-openjdk-headless-17.0.20.0-150400.3.69.1 updated
- python311-cryptography-41.0.3-150600.23.9.1 updated
- spacewalk-base-minimal-5.1.22-150700.3.23.21 updated
- perl-libwww-perl-6.31-150000.3.3.1 updated
- susemanager-build-keys-web-15.5.3-150700.5.17.1 updated
- rpm-build-4.14.3-150400.59.19.1 updated
- sssd-tools-2.10.2-150700.9.37.1 updated
- sssd-ipa-2.10.2-150700.9.37.1 updated
- tomcat-servlet-4_0-api-9.0.120-150200.117.1 updated
- tomcat-el-3_0-api-9.0.120-150200.117.1 updated
- stax2-api-4.3.0-150200.3.8.1 added
- java-17-openjdk-17.0.20.0-150400.3.69.1 updated
- jackson-core-2.18.9-150200.3.25.1 updated
- jackson-annotations-2.18.9-150200.3.25.1 updated
- bea-stax-api-1.2.0-150200.11.3.1 added
- apache-commons-lang3-3.20.0-150200.3.15.2 updated
- spacewalk-base-minimal-config-5.1.22-150700.3.23.21 updated
- python3-pyOpenSSL-21.0.0-150400.22.1 updated
- tomcat-jsp-2_3-api-9.0.120-150200.117.1 updated
- woodstox-core-7.2.1-150200.3.10.1 added
- aalto-xml-1.4.0-150200.5.6.1 updated
- jackson-databind-2.18.9-150200.3.33.1 updated
- guava-33.2.1-150200.3.15.1 updated
- python311-urllib3-2.0.7-150400.7.33.1 updated
- python3-urllib3-1.25.10-150300.4.30.1 updated
- spacewalk-base-5.1.22-150700.3.23.21 updated
- tomcat-lib-9.0.120-150200.117.1 updated
- netty-4.1.136-150200.4.53.1 updated
- apache-commons-compress-1.28.0-150200.3.21.1 updated
- jackson-dataformat-xml-2.18.8-150200.5.5.1 added
- jackson-module-jaxb-annotations-2.18.9-150200.5.22.1 updated
- spacewalk-backend-5.1.18-150700.3.15.15 updated
- log4j-2.26.1-150200.4.42.1 updated
- salt-3006.0-150700.14.26.14 updated
- python311-salt-3006.0-150700.14.26.14 updated
- spacewalk-backend-sql-5.1.18-150700.3.15.15 updated
- python3-spacewalk-certs-tools-5.1.12-150700.3.16.1 updated
- spacewalk-certs-tools-5.1.12-150700.3.16.1 updated
- spacewalk-search-5.1.8-150700.3.11.4 updated
- log4j-slf4j-2.26.1-150200.4.42.1 updated
- log4j-jcl-2.26.1-150200.4.42.1 updated
- salt-master-3006.0-150700.14.26.14 updated
- spacewalk-backend-server-5.1.18-150700.3.15.15 updated
- tomcat-9.0.120-150200.117.1 updated
- salt-api-3006.0-150700.14.26.14 updated
- spacewalk-backend-xmlrpc-5.1.18-150700.3.15.15 updated
- spacewalk-backend-xml-export-libs-5.1.18-150700.3.15.15 updated
- spacewalk-backend-package-push-server-5.1.18-150700.3.15.15 updated
- spacewalk-backend-app-5.1.18-150700.3.15.15 updated
- spacewalk-java-postgresql-5.1.31-150700.3.31.9 updated
- spacewalk-java-config-5.1.31-150700.3.31.9 updated
- spacewalk-html-5.1.22-150700.3.23.21 updated
- spacewalk-taskomatic-5.1.31-150700.3.31.9 updated
- spacewalk-java-5.1.31-150700.3.31.9 updated
- spacewalk-backend-tools-5.1.18-150700.3.15.15 updated
- spacewalk-admin-5.1.9-150700.3.12.1 updated
- susemanager-sls-5.1.26-150700.3.32.1 updated
- susemanager-tools-5.1.19-150700.3.18.1 updated
- susemanager-5.1.19-150700.3.18.1 updated
- spacewalk-utils-5.1.11-150700.3.12.1 updated
- container:bci-bci-init-15.7-d7698212781e43919a02b9740b540b93d15660c3027e740eaf4db8e59e8df379-0 updated
- woodstox-4.4.2-150700.1.49 removed
More information about the sle-container-updates
mailing list