Packages changed: apache2 (2.4.64 -> 2.4.65) apache2-manual (2.4.64 -> 2.4.65) apache2-prefork (2.4.64 -> 2.4.65) apache2-utils (2.4.64 -> 2.4.65) ctags emacs libplist libstorage-ng (4.5.265 -> 4.5.266) microos-tools (4.0+git17 -> 4.0+git19) mozc nvidia-settings (570.153.02 -> 570.172.08) openSUSE-release (20250724 -> 20250725) perl-Authen-SASL pipewire (1.4.6 -> 1.4.7) polkit-default-privs (1550+20250603.5d84a17 -> 1550+20250721.f1b71a3) sdbootutil (1+git20250722.bf18f3b -> 1+git20250724.553d46c) yast2-iscsi-client (5.0.8 -> 5.0.9) yast2-storage-ng (5.0.33 -> 5.0.34) === Details === ==== apache2 ==== Version update (2.4.64 -> 2.4.65) - version update to 2.4.65 * ) SECURITY: CVE-2025-54090: Apache HTTP Server: 'RewriteCond expr' always evaluates to true in 2.4.64 (cve.mitre.org) A bug in Apache HTTP Server 2.4.64 results in all "RewriteCond expr ..." tests evaluating as "true". Users are recommended to upgrade to version 2.4.65, which fixes the issue. ==== apache2-manual ==== Version update (2.4.64 -> 2.4.65) - version update to 2.4.65 * ) SECURITY: CVE-2025-54090: Apache HTTP Server: 'RewriteCond expr' always evaluates to true in 2.4.64 (cve.mitre.org) A bug in Apache HTTP Server 2.4.64 results in all "RewriteCond expr ..." tests evaluating as "true". Users are recommended to upgrade to version 2.4.65, which fixes the issue. ==== apache2-prefork ==== Version update (2.4.64 -> 2.4.65) - version update to 2.4.65 * ) SECURITY: CVE-2025-54090: Apache HTTP Server: 'RewriteCond expr' always evaluates to true in 2.4.64 (cve.mitre.org) A bug in Apache HTTP Server 2.4.64 results in all "RewriteCond expr ..." tests evaluating as "true". Users are recommended to upgrade to version 2.4.65, which fixes the issue. ==== apache2-utils ==== Version update (2.4.64 -> 2.4.65) - version update to 2.4.65 * ) SECURITY: CVE-2025-54090: Apache HTTP Server: 'RewriteCond expr' always evaluates to true in 2.4.64 (cve.mitre.org) A bug in Apache HTTP Server 2.4.64 results in all "RewriteCond expr ..." tests evaluating as "true". Users are recommended to upgrade to version 2.4.65, which fixes the issue. ==== ctags ==== - Only Require: alts when using libalternatives, no need for scriplets ==== emacs ==== Subpackages: emacs-el emacs-eln emacs-info emacs-nox etags - Remove ctags.1 that's unused with libalternatives - Requires: alts, not used in scriptlets ==== libplist ==== - Fix build with cython 3.1+: * Add patch 0001-cython-Fix-build-with-cython-3.1.patch ==== libstorage-ng ==== Version update (4.5.265 -> 4.5.266) Subpackages: libstorage-ng-lang libstorage-ng-ruby libstorage-ng1 - merge gh#openSUSE/libstorage-ng#1030 - extended logging in testsuite - 4.5.266 ==== microos-tools ==== Version update (4.0+git17 -> 4.0+git19) - Update to version 4.0+git19: * Add zypp-single-rpmtrans files to spec file * Use single rpmtrans with libzypp by default ==== mozc ==== Subpackages: fcitx-mozc ibus-mozc ibus-mozc-candidate-window mozc-gui-tools - Update mozc.spec: Disable Mozc building with fcitx4 or fcitx5 in SLE, since SLE does not deliver fcitx. Avoid importing too many irrelevant build dependency packages in SLFO. (bsc#1246569, jsc#PED-12066) - Disable fcitx-mozc for Leap 16.0 sicne Fcitx 4 is not available ==== nvidia-settings ==== Version update (570.153.02 -> 570.172.08) - update to version 570.172.08 (boo#1246327) - update to version 570.169 (boo#1244614) ==== openSUSE-release ==== Version update (20250724 -> 20250725) Subpackages: openSUSE-release-appliance-custom openSUSE-release-dvd - automatically generated by openSUSE-release-tools/pkglistgen ==== perl-Authen-SASL ==== - security update - added patches CVE-2025-40918 [bsc#1246623], insecurely generated client nonce + perl-Authen-SASL-CVE-2025-40918.patch ==== pipewire ==== Version update (1.4.6 -> 1.4.7) Subpackages: gstreamer-plugin-pipewire libpipewire-0_3-0 pipewire-alsa pipewire-jack pipewire-lang pipewire-libjack-0_3 pipewire-modules-0_3 pipewire-pulseaudio pipewire-spa-plugins-0_2 pipewire-spa-tools pipewire-tools - Update to version 1.4.7: * Highlights - Improve latency handling in echo-cancel. - Don't leak SyncObj fds in client-node. - Improve the adaptive resampler performance. - Some more fixes and improvements. * modules - Set module-echo-cancel latency correctly. - Avoid extra latency in echo-cancel by dropping samples when one end is paused. - Don't leak SyncObj fds in client-node. (#4807) * SPA - Actually enable echo cancellation when using webrtc 2.0 - Improve ALSA driver resampling setup and follower adaptive resampling. - Fix an off-by-one in the delay filter. - Improve the adaptive resampler performance. * bluetooth - Improve compatibility with some JBL flip and change models. * GStreamer - Add some format validations. ==== polkit-default-privs ==== Version update (1550+20250603.5d84a17 -> 1550+20250721.f1b71a3) - Update to version 1550+20250721.f1b71a3: * profiles: dnf5daemon-server execute_trusted_transaction (bsc#1245451) ==== sdbootutil ==== Version update (1+git20250722.bf18f3b -> 1+git20250724.553d46c) Subpackages: sdbootutil-dracut-measure-pcr sdbootutil-snapper - Update to version 1+git20250724.553d46c: * measure-pcr-validator: fail if the file is missing * measure-pcr-validator.service: Run after initrd-root-device.target * measure-pcr-validator.service: Fix failure handling * Clean the default snapshot in Tumbleweed * Improve volume key extraction ==== yast2-iscsi-client ==== Version update (5.0.8 -> 5.0.9) - Ensure to hide passwords (bsc#1246833) - 5.0.9 - Do not filter netcard cards by iscsioffload feature as for example it is not present in qede/qedi devices (bsc#1236433). ==== yast2-storage-ng ==== Version update (5.0.33 -> 5.0.34) - Fixed an error when encrypting a disk that originally contains partitions (bsc#1246970, related to bsc#1246939) - 5.0.34