Tumbleweed Monthly Update - August 2026
2. Sep 2026 | Douglas DeMaio | CC-BY-SA-3.0
There were several software package updates for openSUSE Tumbleweed during the month of August, which delivered 22 snapshots across 31 days.
August delivered a packed month of snapshots across the desktop, developer tooling, and security surface. KDE Plasma 6.7.4 landed with KWin GPU management fixes and a workaround for libepoxy issues when a GPU reset happens. KDE Frameworks 6.29.0 and KDE Gear 26.08.0 also arrived in the month. GNOME Shell 50.4 and mutter 50.4 arrived with HiDPI cursor fixes and HDR output improvements. Mesa settled into its 26.2 series, and the Linux kernel progressed from 7.1.5 to 7.2.0 with a long tail of CVE fixes.
As always, be sure to roll back using snapper if any issues arise.
For more details on the change logs for the month, visit the openSUSE Factory mailing list.
New Features and Enhancements
KDE Plasma 6.7.4: The fourth bugfix release of the Plasma 6.7 series brings targeted stability improvements across the desktop. KWin no longer removes GPUs that have no outputs, which prevents a regression where external monitors connected via docks could disappear. A workaround for libepoxy failing when a GPU resets helps stabilize gaming and GPU-accelerated workloads on systems with multiple graphics adapters. The digital clock applet now applies its font family to the time zone label, and dragging items on the taskbar onto grouped tasks no longer breaks when floating applets are enabled. Spectacle gained QR code scanning when editing existing screenshots, and KScreen added a keyboard shortcut to trigger the Configure button from the OSD.
KDE Frameworks 6.29.0: A new feature release of the KDE component libraries arrived with refinements across KIO, Kirigami and KRunner. Solid now returns the mount point as filePath() for the root filesystem through its udisks2 backend, bluez-qt resolves a race condition in Bluetooth object manager initialization, and KTextEditor gained a disabledPlugins property. A separate KWin patch improved behavior after unplugging outputs by increasing the Wayland global removal timer timeout.
KDE Gear 26.08.0: The August feature release of the KDE applications collection brought updates across Dolphin, Konsole, Kate, Okular, and the Akonadi personal information management stack. Konsole implements the Kitty keyboard protocol and gains direct Copy and Open actions for URLs shown as escape-sequence hotspots. Okular adds copy-and-paste support for annotations and no longer executes load-scripts on signed documents, while Kate fixes working-directory handling when invoking git and possible out-of-bounds reads.
Firefox 154.0: The browser’s monthly milestone rolled out with a heavy load of Common Vulnerabilities and Exposures (CVE) fixes addressing more than 40 issues. The release covers a sandbox escape in the Remote Settings client, same-origin policy bypasses in service workers and cookie handling, use-after-free issues across WebAssembly, image loading, and layout text handling, plus multiple privilege escalation and site isolation issues in the graphics stack. It also refreshed mozilla-nss to 3.126.1 and mozjs140 to 140.14.0. Tumbleweed users should update to stay protected.
GNOME Shell 50.4 & mutter 50.4: The GNOME desktop received quality-of-life fixes that clean up day-to-day use. Switching to a minimized window on another workspace no longer causes a visual glitch, and the magnified cursor is correctly scaled on HiDPI displays. A sound glitch caused by pushing redundant volume changes has been eliminated, and menu animations are smoother. On the compositor side, mutter fixes blurred rendering with non-pixel-aligned monitors, fills in mastering display metadata for HDR output, and corrects invalid redraw clips on rotated monitors. GNOME Control Center 50.4 arrived alongside with updated translations.
GStreamer 1.28.6: A wide-ranging update across the core and plugin packages with both security and playback fixes. The playbin3 and playbin elements fix stalls that occurred after re-enabling previously disabled subtitles, and the h265parser resolves out-of-bounds writes in RPS parsing. RTP retransmission bitrate estimation is improved, and the Rust (f)mp4 muxers gain H.266/VVC muxing support. webrtcsink fixes H.264 level and profile negotiation and adds support for nvv4l2h265enc.
OpenSSH 10.5p1: A security-focused release addressing an important vulnerability in agent forwarding. The ssh-agent interaction between locking and the session-bind@openssh.com extension was broken, meaning operations intended to be limited to local use only could be performed remotely when the agent was locked. The restrict keyword in authorized_keys now correctly applies to tunnel forwarding. A potential realloc use-after-free in the client when a remote forwarding is added via the multiplexing socket is fixed, and ssh-keygen gains the ability to set or clear touch-required and verify-required flags on FIDO private keys during passphrase reset.
harfbuzz 14.3.0 & 14.3.1: The text shaping engine that underpins rendering in browsers, desktop environments, and document editors received important improvements. Mark positioning now respects lookup order in the cross-direction, improving compatibility with DirectWrite and Core Text. Mark attachment to ligatures formed from decomposed glyphs is fixed, and the calt feature in Hangul text is now disabled only for the Jamos rather than the entire buffer. The release also adds support for partially instancing of the avar table and the CFF2 table, relevant for variable font workflows. A follow-up 14.3.1 release arrived later in the month with fuzzing and subsetting fixes, a fix for AAT insertion at the end of the text, and rendering fixes in the experimental GPU library.
QEMU 11.1.0: The machine emulator advanced from 11.0.3 with a substantial feature release. Highlights include Universal Flash Storage (UFS) emulation support for Write Booster and Host-Initiated Defragmentation based on the UFS 4.1 specification, and vhost-host-user support for offloading real-time clock handling from the hypervisor when using virtio-rtc. The GUI subsystem gained improvements to virtual console handling and GTK/VNC. ARM support expanded with the new imx8mp-evk machine type and virt board cache topology specification.
Key Package Updates
Linux kernel 7.1.5 through 7.2.0: The kernel progressed through four point releases and a feature release during August with a sustained focus on security and stability. Version 7.1.6 carried fixes for KVM x86 module reload use-after-free, arm64 TLBI errata mitigation, and a virtiofs use-after-free on submount umount. Version 7.1.7 added CVE fixes for batman-adv, ntfs3, and several networking and driver subsystems. Version 7.1.8 addressed an extensive list of CVEs including Bluetooth btusb use-after-free, ksmbd deferred file use-after-free, rtl8723bs out-of-bounds reads and writes, and RDMA fixes across irdma, erdma, and mana_ib. The Btrfs filesystem received fixes for free space cache validation and root leaks during relocation. The month closed with the 7.2.0 feature release, which refreshed the kernel configuration and carried updated AMD Display Core patches.
Mesa 26.1.6, 26.2.0 & 26.2.1: The graphics stack made a major jump from 26.1.5 to the 26.2 series during the month. The 26.1.6 bugfix release addressed regressions from the previous stable series, while the 26.2.0 release brought a new batch of driver improvements for AMD, Intel, and Qualcomm hardware. The 26.2.1 bugfix release soon followed, and the VirtIO Vulkan driver is now enabled in openSUSE’s build, bringing Vulkan support to virtualized environments. Users on AMD and Intel GPUs who experienced rendering issues after earlier Mesa updates should find these releases more stable. The Vulkan drivers continue to see corrections for gaming workloads.
python-cryptography 50.0.0: A major version bump that deprecates Diffie-Hellman key exchange over finite fields and adds the Cobblestone recipe for streaming authenticated encryption. The most important change is a security fix for Bleichenbacher oracle in PKCS7 decryption; pkcs7_decrypt_der no longer exposes distinguishable errors or timing when unwrapping a RecipientInfo’s encryptedKey. X.509 verification APIs are now considered stable, and ML-DSA public keys and signatures are permitted by default.
libssh2: Received two rounds of critical security patches during August. The first batch addressed a heap buffer overflow and the second batch fixed arbitrary code execution via double-free in SFTP sessions, denial of service via integer underflow in AES-GCM cipher negotiation, a heap out-of-bounds read, and heap buffer overflow during SSH negotiation. These are essential updates for any system using libssh2 for SSH or SFTP operations.
vim 9.2.0901: A massive update carrying over 100 fixes including eight security patches. Security fixes address arbitrary code execution via keyword lookup, code injection in netrw via bookmarks, heap overflow when adding more than 65,535 text properties, stack buffer overflow in the socket server, and a use-after-free on JSON decode error. The update also fixes numerous memory leaks, a deeply nested regexp pattern stack overflow, and a GTK4 hardware rendering performance regression.
unbound 1.26.0: The DNS resolver received a major update with a large list of fixes and new features. New options include max-transfer-size and max-transfer-time for limiting auth-zone and RPZ transfers, and new local-zone types block_aaaa, block_a_wdata, and block_aaaa_wdata. A heap out-of-bounds write via size_t-to-int truncation is fixed, along with DNSSEC validation fixes for noncanonical RSA DNSKEYs and a race condition causing segfaults when starting threads.
Qt 6 6.11.2: The second bugfix release of the 6.11 series landed across the full module range from qt6-base through qt6-webengine. The update fixes a regression in icon loading and carries multiple stability corrections for the toolkit that Plasma and most KDE applications build on. qt6-webengine also merges an upstream fix for AMD VA-API flickering on Wayland.
wpa_supplicant 2.12: The Wi-Fi authentication daemon adds more complete EHT/IEEE 802.11be/Wi-Fi 7 support including fixes for message validation issues that could enable denial-of-service attacks, and group key rekeying is corrected. SAE group 20 is now enabled by default when SAE-EXT-KEY is available, and IEEE 802.11bi functionality is supported including changing SAE password identifiers, EPPKE, and association frame encryption. RSN overriding (WPA3-Personal Compatibility Mode) is supported, and Automated Frequency Coordination (AFC) on the 6 GHz band is now available. The build enables CONFIG_IEEE80211BE, CONFIG_SAE_PK, CONFIG_PMKSA_PRIVACY, and CONFIG_IEEE8021X_AUTH by default.
postgresql18 18.6: A major security release for PostgreSQL 18 that fixes more than two dozen CVEs covering remote code execution and denial of service issues. Notable fixes include heap buffer overflows in regular expression matching, to_char formatting, and pg_stat_statements that could execute arbitrary code, a psql issue where early failures in COPY FROM STDIN process data lines as command input, and a logical decoding flaw that could dlopen an arbitrary file. Database administrators on Tumbleweed should plan an update soon.
flatpak 1.18.1: A security-focused bugfix release addressing several sandbox escape and privilege escalation paths in the application framework. Fixes include a sandbox escape with full host filesystem read/write access via a symlink attack on app data directories, a local root privilege escalation via revokefs symlink path traversal and commit tampering, and arbitrary root writes through path traversal in extra-data extraction and flatpak build-init. The release also corrects an anti-downgrade bypass that allowed unprivileged users to downgrade system applications.
Security Updates
libssh2:
-
CVE-2026-58050: Fixes a heap buffer overflow via attacker-controlled attribute count from a publickey-subsystem response.
-
CVE-2026-58051: Addresses uninitialized pointer being freed when a malformed response is sent by an SSH server.
-
CVE-2026-66032: Resolves arbitrary code execution via double-free in SFTP session.
-
CVE-2026-66033: Fixes denial of service via integer underflow in AES-GCM cipher negotiation.
-
CVE-2026-66034: Addresses heap out-of-bounds read leading to information disclosure and potential arbitrary code execution.
-
CVE-2026-66035: Fixes heap buffer overflow during SSH negotiation.
Samba 4.24.5:
-
CVE-2026-6949: Fixes TSIG packet with crafted name compression crashing the internal DNS server.
-
CVE-2026-58224: Addresses CTDB heap out-of-bounds read via unchecked packet length fields.
-
CVE-2026-58216: Resolves 6-byte heap out-of-bounds read in kpasswd service packet parser.
-
CVE-2026-58218: Fixes DNS TKEY negotiation storing unauthenticated GSS contexts in a fixed FIFO before authentication completes.
-
CVE-2026-58221: Addresses authenticated LDAP access to internal LDB special DNs permitting domain takeover.
-
CVE-2026-58222: Resolves LDAP Compare filter injection and trusted-request confusion disclosing protected attributes.
vim 9.2.0901:
-
CVE-2026-8339: Fixes arbitrary code execution via keyword lookup.
-
CVE-2026-8340: Addresses code injection in netrw via bookmarks.
-
CVE-2026-8341: Resolves heap overflow when adding more than 65,535 text properties.
-
CVE-2026-8342: Fixes stack buffer overflow in the socket server.
-
CVE-2026-8343: Addresses popup opacity mask indexed out of bounds.
-
CVE-2026-8344: Resolves use-after-free on JSON decode error.
-
CVE-2026-8345: Fixes arbitrary Ex command execution during C omni-completion.
-
CVE-2026-8346: Addresses heap buffer overflow in
set_sofo().
Linux kernel 7.1.6, 7.1.7 & 7.1.8:
-
CVE-2026-64490: Fixes ALSA virtio control metadata validation.
-
CVE-2026-64489: Addresses ALSA ymfpci
snd_ctl_new1return value check. -
CVE-2026-64486: Resolves ALSA cmipci
snd_ctl_new1return value check. -
CVE-2026-64481: Fixes ALSA hda-cs35l41 firmware load work teardown.
-
CVE-2026-64480: Addresses ALSA ice1712
snd_ctl_new1return value check. -
CVE-2026-64477: Resolves x86 fs/resctrl out-of-bounds access.
-
CVE-2026-64476: Fixes VFIO PCI
disable_idle_d3per-device latch. -
CVE-2026-64475: Addresses VFIO PCI VGA arbiter client release on registration.
-
CVE-2026-64474: Resolves VFIO infinite loop in
vfio_mig_get_next. -
CVE-2026-64471: Fixes Bluetooth btusb use-after-free on registration.
-
CVE-2026-64466: Addresses Rust binder freeze listener cleanup on node removal.
-
CVE-2026-64437: Resolves ksmbd use-after-free of a deferred file location.
-
CVE-2026-64436: Fixes net af_key uninitialized
alg_key_lenfor IPComp. -
CVE-2026-64433: Addresses Bluetooth MGMT use-after-free of
hci_conn_params. -
CVE-2026-64432: Resolves ntfs3 Dirty Page Table capacity validation.
-
CVE-2026-64431: Fixes ntfs avoid calling
post_write_mst_fixupfor invalid ranges. -
CVE-2026-64430: Addresses NTB EPF avoid calling
pci_irq_vectorfrom hardirq. -
CVE-2026-64424: Resolves netpoll use-after-free on shutdown path.
-
CVE-2026-64449: Fixes staging vme_user bound slave read/write to the buffer size.
-
CVE-2026-64445: Addresses staging rtl8723bs WEP length underflow and buffer overflow.
-
CVE-2026-64444: Resolves staging rtl8723bs out-of-bounds read in
OnAssocRspIE. -
CVE-2026-64441: Fixes staging rtl8723bs out-of-bounds reads in
rtw_get_secfunctions. -
CVE-2026-64440: Addresses staging rtl8723bs out-of-bounds write in
HT_caps_hand. -
CVE-2026-64599: Resolves crypto amlogic double cleanup in
meson_cr.
Firefox 154.0:
-
CVE-2026-75874: Fixes a sandbox escape in the Remote Settings client component.
-
CVE-2026-74934: Addresses a site isolation issue in the Graphics CanvasWebGL component.
-
CVE-2026-74936: Resolves a use-after-free in the JavaScript WebAssembly component.
-
CVE-2026-74937: Fixes a use-after-free in the JavaScript GC component.
-
CVE-2026-74939: Addresses a privilege escalation in the DOM Navigation component.
-
CVE-2026-74943: Resolves a use-after-free in the Graphics ImageLib component.
- CVE-2026-74944: Fixes a use-after-free in the DOM Core & HTML component. https://github.com/KDE/kscreen
-
CVE-2026-74953: Addresses a privilege escalation in the Networking Cookies component.
-
CVE-2026-74956: Resolves a same-origin policy bypass in the DOM Service Workers component.
-
CVE-2026-74969: Fixes a use-after-free in the Layout Text and Fonts component.
- CVE-2026-74976: Addresses a JIT miscompilation in the JavaScript Engine JIT component.
WebKitGTK 2.52.6:
-
CVE-2026-43804: Fixes a security vulnerability in the WebKit rendering engine.
-
CVE-2026-64713: Addresses a memory corruption issue in the WebKit rendering engine.
-
CVE-2026-64719: Resolves a security vulnerability in the WebKit rendering engine.
-
CVE-2026-64728: Fixes a memory safety issue in the WebKit rendering engine.
-
CVE-2026-64730: Addresses a security vulnerability in the JavaScriptCore engine.
-
CVE-2026-64757: Resolves a memory corruption issue in the WebKit rendering engine.
-
CVE-2026-64783: Fixes a security vulnerability in the WebKit rendering engine.
postgresql18 18.6:
-
CVE-2026-6464: Fixes
psqlprocessing data lines as command input after an early failure inCOPY FROM STDIN. -
CVE-2026-6471: Addresses logical decoding being able to
dlopenan arbitrary file. -
CVE-2026-14662: Resolves undersize allocations for
tsvectorandtsqueryvia integer wraparound. -
CVE-2026-14664: Fixes a regexp heap buffer overflow that executes arbitrary code.
-
CVE-2026-14669: Addresses a
to_charheap buffer overflow that executes arbitrary code. -
CVE-2026-14676: Resolves a
pg_stat_statementsheap buffer overflow that executes arbitrary code. -
CVE-2026-14679: Fixes a stack buffer overflow in argument match that writes to server memory.
-
CVE-2026-15741: Addresses SQL injection via an
EXTRACTargument during expression deparse. -
CVE-2026-18408: Resolves
psql\unrestrictletting a superuser execute arbitrary code in thepsqlclient. -
CVE-2026-19385: Fixes a
pg_dumpheap buffer overflow that executes arbitrary code.
expat 2.8.2:
-
CVE-2026-50219: Fixes memory corruption affecting Expat bindings by disallowing reentrant calls to functions such as
XML_GetBuffer,XML_Parse, andXML_ParserFree. -
CVE-2026-56131: Addresses
XML_ResumeParserbeing called from a handler, plugging a hole in the CVE-2026-50219 fix. -
CVE-2026-56132: Resolves an out-of-bounds scaffolding index store in
doProlog. -
CVE-2026-56403: Fixes an integer overflow in
storeAtts. -
CVE-2026-56404: Addresses an integer overflow in
addBinding. -
CVE-2026-56405: Resolves an integer overflow in
getAttributeId. -
CVE-2026-56406: Fixes an integer overflow in
XML_ParseBuffer. -
CVE-2026-56407: Addresses an integer overflow in
textLenhandling. -
CVE-2026-56408: Resolves an integer overflow in
copyString. -
CVE-2026-56409: Fixes an integer overflow in the
xmlwfoutput path join. -
CVE-2026-56410: Addresses an integer overflow in the
xmlwfresolveSystemId. -
CVE-2026-56411: Resolves an integer overflow in notation list allocation.
-
CVE-2026-56412: Fixes
XML_TOK_DATA_CHARShandler calls indoCdataSection, plugging a hole in the CVE-2026-50219 fix.
c-ares 1.34.8:
-
CVE-2026-33630: Fixes a use-after-free and double-free in query-completion handling remotely triggerable via
ares_getaddrinfo()over TCP. -
CVE-2026-69184: Addresses a CPU-exhaustion denial of service via unbounded DNS name compression pointer chains.
-
CVE-2026-69186: Resolves a memory-amplification denial of service via unvalidated DNS header record counts.
busybox:
-
CVE-2026-38755: Fixes stack exhaustion in the ash applet caused by unbounded shell function recursion.
-
CVE-2026-38754: Addresses an out-of-bounds read in
ifsbreakup(). -
CVE-2026-38753: Resolves a use-after-free in the awk applet regexp processing code during text replacement operations.
-
CVE-2026-38752: Fixes stack exhaustion in the awk applet caused by unbounded function call recursion.
-
CVE-2023-42366: Addresses a heap buffer overflow in the awk applet when a regexp ends with a backslash.
OpenEXR 3.4.14:
-
CVE-2026-68513: Fixes a PyOpenEXR prefixed literal RGB key collision heap buffer overflow.
-
CVE-2026-68514: Addresses a PyOpenEXR deep prefixed literal RGB key collision heap buffer overflow.
-
CVE-2026-59183: Resolves a signed integer overflow leading to out-of-bounds memory access in deep tile decoding.
-
CVE-2026-59186: Fixes an ILP32
TiledRgbaInputFilelarge tile Array2D heap out-of-bounds write. -
CVE-2026-59187: Addresses an
exrmetricsdeep pixelmode heap buffer overflow. -
CVE-2026-59981: Resolves an OpenEXRUtil SampleCountChannel row nonzero dataWindow heap out-of-bounds read.
-
CVE-2026-59985: Fixes an ILP32 OpenEXRCore RLE decode heap out-of-bounds read denial of service.
-
CVE-2026-61555: Addresses a crash on empty multiView
viewFromChannelNamefiles. -
CVE-2026-62986: Resolves a PyOpenEXR deep prefixed RGB stale lane disclosure.
python313:
-
CVE-2026-0864: Fixes mixed line ending handling in
configparserby normalizing all line endings. -
CVE-2026-11972: Addresses
tarfile._Stream.seeknot breaking at end of file. -
CVE-2026-4360: Resolves a missing
filter_functionpass-through toTarFile._extract_one()during.extract(). -
CVE-2026-15308: Fixes quadratic complexity in incremental
HTMLParserparsing enabling CPU exhaustion.
gzip:
- CVE-2026-41992: Fixes global buffer overflow in the LZH decompression logic.
libXfont2:
-
CVE-2026-59679: Fixes
fs_read_glyphs()heap out-of-bounds read/write via encoding array index mismatch. -
CVE-2026-44950: Addresses
fs_read_glyphs()heap buffer overflow via cumulative glyph data overflow.
glib2 2.88.3:
- CVE-2026-15588: Fixes GDBusServer pre-authentication denial of service via unbounded SASL line buffering.
dracut:
- CVE-2026-15816: Addresses root code execution via unescaped error message written to sourced emergency hook script in
die().
python-cryptography 50.0.0:
- CVE-2026-69247: Fixes Bleichenbacher oracle in PKCS7 decryption where distinguishable errors or timing could leak information when unwrapping a RecipientInfo’s encryptedKey.
libostree 2026.3:
-
CVE-2026-58055: Fixes unbounded LZMA decompression in static delta processing allowing denial of service.
-
CVE-2026-58056: Addresses heap buffer overflow via integer truncation in static delta bspatch on 32-bit systems.
gdm 50.2:
-
CVE-2026-58058: Fixes path traversal vulnerability where a compromised greeter could load arbitrary
.desktopfiles viaSelectSession. -
CVE-2026-58059: Addresses autologin bypass where a compromised greeter could request autologin for any local account.
-
CVE-2026-58060: Resolves denial of service where an invalid session name from the greeter would cause the entire daemon to exit.
udisks2 2.11.2:
- CVE-2026-7867: Fixes an unprivileged D-Bus caller using the
as-userFilesystem.Mount() option combined with fstab entries containinguserorusersmount options to mount on behalf of another user without polkit authorization.
php8 8.5.9:
-
CVE-2026-17543: Fixes SQL injection via
E'...'backslash breakout in PostgreSQL. -
CVE-2026-17544: Addresses out-of-bounds write in
bccomp(). -
CVE-2026-7260: Resolves crash via recursive symlinks in Phar.
-
CVE-2026-9672: Fixes a vulnerability in the GD library upgrade.
libssh2:
-
CVE-2026-58050: Fixes heap buffer overflow via attacker-controlled attribute count from a publickey-subsystem response.
-
CVE-2026-58051: Addresses uninitialized pointer freed when a malformed response is sent by an SSH server.
python-pip 26.2:
- CVE-2026-13346: Fixes double decoding of the URL path while determining a link filename.
gimp:
-
CVE-2026-66757: Fixes a security vulnerability in GIMP image processing.
-
CVE-2026-66758: Addresses a security vulnerability in GIMP.
-
CVE-2026-66759: Resolves a security vulnerability in GIMP.
-
CVE-2026-59087: Fixes a security vulnerability in GIMP image processing.
-
CVE-2026-59088: Addresses a security vulnerability in GIMP.
-
CVE-2026-59090: Resolves a security vulnerability in GIMP.
-
CVE-2026-59091: Fixes a security vulnerability in GIMP.
libheif 1.23.1:
-
CVE-2026-62289: Fixes integer underflow in Fraction constructor via double clap transform application.
-
CVE-2026-62291: Addresses heap out-of-bounds write in uncompressed encoder when writing images with mismatched auxiliary alpha dimensions.
-
CVE-2026-62292: Resolves out-of-bounds read in uncompressed unci tile range slicing.
-
CVE-2026-62377: Fixes reachable assertion in
HeifContext::get_track()aborting on a valid-but-empty HEIF sequence file.
nghttp2 1.70.0:
- CVE-2026-58055: Fixes out-of-bounds read in the base64 decoder.
libgit2 1.9.7:
- CVE-2026-5917: Fixes improper escaping of remote repository paths in libssh2.
bzip2:
- CVE-2026-42250: Fixes an off-by-one error in the
bzip2recoverutility when processing a specially crafted file that can lead to a crash.
openssl-3 3.x:
-
CVE-2026-75803: Fixes AEAD forgeries with empty ciphertext when using
EVP_Cipher(). -
CVE-2026-14456: Addresses unbounded memory growth in QUIC server incoming channel queue.
-
CVE-2026-14457: Resolves RPK server signature algorithm selection dereferencing a missing certificate.
-
CVE-2026-18798: Fixes QUIC server triggering a double free when processing an INITIAL packet.
-
CVE-2026-34181: Addresses PKCS#12 files with PBMAC1 being accepted with short HMAC keys.
-
CVE-2026-54874: Resolves excessive memory use buffering DTLS records for a future epoch.
-
CVE-2026-63072: Fixes a heap buffer overflow in CMS key unwrapping.
-
CVE-2026-63073: Addresses untrusted sender DN used as format string in CMP response validation.
-
CVE-2026-63074: Resolves CMP indefinite cache growth of ExtraCerts.
-
CVE-2026-63075: Fixes QUIC ACK-only packet retention causing memory exhaustion.
-
CVE-2026-63076: Addresses invalid pointer dereference in CMP server via crafted
protectionAlg.
java-25-openjdk 25.0.4.1:
-
CVE-2026-60589: Fixes resource resolving vulnerability.
-
CVE-2026-61308: Addresses HTTP connection enhancement security issue.
-
CVE-2026-70907: Resolves TLS server security vulnerability.
-
CVE-2026-70906: Fixes font loading security vulnerability.
cpio:
-
CVE-2026-66484: Fixes path traversal allowing creation of hard links outside the intended directory via malicious tar archives.
-
CVE-2026-66485: Addresses denial of service via uncontrolled memory allocation from crafted archives.
-
CVE-2026-66486: Resolves terminal control sequence injection via crafted archive member names.
libvirt:
-
CVE-2026-77159: Fixes QEMU TPM following symlinks when chown’ing log files.
-
CVE-2026-18917: Addresses integer overflow in RPC handler for
virNodeGetFreePages.
multipath-tools:
-
GHSA-hmcm-9cq4-r2xm: Fixes denial of service on
multipathdsocket by blocking IPC send operations. -
GHSA-pvp6-c9p3-25fp: Addresses denial of service on
multipathdsocket by exhausting connections. -
GHSA-g5mh-253r-jjw5: Resolves heap out-of-bounds read in custom format string parser via trailing
%. -
GHSA-pxwh-g75c-95pc: Fixes heap out-of-bounds read in device-mapper-multipath ALUA RTPG parsing.
-
GHSA-p6rh-9x9j-3hvx: Addresses
kpartxheap out-of-bounds read in GPT header validation. -
GHSA-gr7q-prfc-q636: Resolves path traversal in device-mapper-multipath
failed_wwidsmanagement. -
GHSA-hj7j-qr9h-5fv6: Fixes
libmpathpersistPRIN READ FULL STATUS parser unbounded descriptor rewrite causing root heap overflow.
Users are advised to update to the latest versions to mitigate these vulnerabilities.
Conclusion
August was a busy month for openSUSE Tumbleweed with 22 snapshots delivering a steady cadence of desktop, developer, and security improvements. KDE Plasma 6.7.4 delivered targeted desktop fixes while KDE Gear 26.08.0 and KDE Frameworks 6.29.0 advanced the KDE application and library stacks, and GNOME Shell 50.4 polished the GNOME desktop. Mesa settled into its 26.2 series, the Linux kernel progressed through point releases to 7.2.0 with extensive CVE coverage, Firefox 154.0 shipped more than 40 security fixes, and GStreamer 1.28.6 brought playback and security fixes across the multimedia stack. Developer tools saw significant updates: Emacs jumped to 31.1, QEMU advanced to 11.1.0 with UFS emulation and RISC-V extensions, GCC reached 16.2, Qt 6 advanced to 6.11.2, OpenSSH 10.5p1 fixed critical agent forwarding issues, and vim addressed eight security vulnerabilities. FreeRDP 3.31.0 patched more than 20 CVEs while improving YUV decoding performance, wpa_supplicant 2.12 brought Wi-Fi 7 support, and chrony 4.9 added NTP-over-PTP and new stratum-bounding directives. Security remained a dominant theme, with critical patches in libssh2, Samba, postgresql18, openssl, expat, webkitgtk, openexr, flatpak, python-cryptography, openvpn, gdm, udisks2, multipath-tools, and php8.
Slowroll Arrivals
Please note that these updates also apply to Slowroll and arrive between an average of 5 to 10 days after being released in Tumbleweed snapshot. This monthly approach has been consistent for many months, ensuring stability and timely enhancements for users. Updated packages for Slowroll are regularly published in emails on openSUSE Factory mailing list.
Contributing to openSUSE Tumbleweed
Stay updated with the latest snapshots by subscribing to the openSUSE Factory mailing list. For those Tumbleweed users who want to contribute or want to engage with detailed technological discussions, subscribe to the openSUSE Factory mailing list . The openSUSE team encourages users to continue participating through bug reports, feature suggestions and discussions.
Your contributions and feedback make openSUSE Tumbleweed better with every update. Whether reporting bugs, suggesting features, or participating in community discussions, your involvement is highly valued.
Categories: Announcements openSUSE Tumbleweed Slowroll MicroOS arm
Tags: openSUSE Tumbleweed Developers sysadmin user Open Source rolling release gamers superuser distrowatch Linux kernel kernel-source Mesa graphics KDE Plasma Frameworks Gear CVE python Power Users Superuser GNOME OpenSSH GStreamer harfbuzz Samba nano openvpn GCC libssh2 Firefox Qt postgresql flatpak webkitgtk expat OpenEXR busybox emacs QEMU FreeRDP chrony wpa_supplicant openssl libjpeg-turbo multipath-tools java-openjdk