Tumbleweed Monthly Update - August 2026
There were several software package updates for openSUSE Tumbleweed during the month of August, which delivered 23 snapshots across 31 days.
August delivered a packed month of snapshots across the desktop, developer tooling, and security surface. KDE Plasma 6.7.4 landed with KWin GPU management fixes and a workaround for libepoxy issues when a GPU reset happens. KDE Frameworks 6.29.0 and KDE Gear 26.08.0 also arrived in the month. GNOME Shell 50.4 and mutter 50.4 arrived with HiDPI cursor fixes and HDR output improvements. Mesa settled into its 26.2 series, and the Linux kernel progressed from 7.1.5 to 7.2.0 with a long tail of CVE fixes.
As always, be sure to roll back using snapper if any issues arise.
For more details on the change logs for the month, visit the openSUSE Factory mailing list.
New Features and Enhancements
KDE Plasma 6.7.4: The fourth bugfix release of the Plasma 6.7 series brings targeted stability improvements across the desktop. KWin no longer removes GPUs that have no outputs, which prevents a regression where external monitors connected via docks could disappear. A workaround for libepoxy failing when a GPU resets helps stabilize gaming and GPU-accelerated workloads on systems with multiple graphics adapters. The digital clock applet now applies its font family to the time zone label, and dragging items on the taskbar onto grouped tasks no longer breaks when floating applets are enabled. Spectacle gained QR code scanning when editing existing screenshots, and KScreen added a keyboard shortcut to trigger the Configure button from the OSD.
KDE Frameworks 6.29.0: A new feature release of the KDE component libraries arrived with refinements across KIO, Kirigami and KRunner. Solid now returns the mount point as filePath() for the root filesystem through its udisks2 backend, bluez-qt resolves a race condition in Bluetooth object manager initialization, and KTextEditor gained a disabledPlugins property. A separate KWin patch improved behavior after unplugging outputs by increasing the Wayland global removal timer timeout.
KDE Gear 26.08.0: The August feature release of the KDE applications collection brought updates across Dolphin, Konsole, Kate, Okular, and the Akonadi personal information management stack. Konsole implements the Kitty keyboard protocol and gains direct Copy and Open actions for URLs shown as escape-sequence hotspots. Okular adds copy-and-paste support for annotations and no longer executes load-scripts on signed documents, while Kate fixes working-directory handling when invoking git and possible out-of-bounds reads.
Firefox 154.0: The browser’s monthly milestone rolled out with a heavy load of Common Vulnerabilities and Exposures (CVE) fixes addressing more than 40 issues. The release covers a sandbox escape in the Remote Settings client, same-origin policy bypasses in service workers and cookie handling, use-after-free issues across WebAssembly, image loading, and layout text handling, plus multiple privilege escalation and site isolation issues in the graphics stack. It also refreshed mozilla-nss to 3.126.1 and mozjs140 to 140.14.0. Tumbleweed users should update to stay protected.
GNOME Shell 50.4 & mutter 50.4: The GNOME desktop received quality-of-life fixes that clean up day-to-day use. Switching to a minimized window on another workspace no longer causes a visual glitch, and the magnified cursor is correctly scaled on HiDPI displays. A sound glitch caused by pushing redundant volume changes has been eliminated, and menu animations are smoother. On the compositor side, mutter fixes blurred rendering with non-pixel-aligned monitors, fills in mastering display metadata for HDR output, and corrects invalid redraw clips on rotated monitors. GNOME Control Center 50.4 arrived alongside with updated translations.
GStreamer 1.28.6: A wide-ranging update across the core and plugin packages with both security and playback fixes. The playbin3 and playbin elements fix stalls that occurred after re-enabling previously disabled subtitles, and the h265parser resolves out-of-bounds writes in RPS parsing. RTP retransmission bitrate estimation is improved, and the Rust (f)mp4 muxers gain H.266/VVC muxing support. webrtcsink fixes H.264 level and profile negotiation and adds support for nvv4l2h265enc.
OpenSSH 10.5p1: A security-focused release addressing an important vulnerability in agent forwarding. The ssh-agent interaction between locking and the session-bind@openssh.com extension was broken, meaning operations intended to be limited to local use only could be performed remotely when the agent was locked. The restrict keyword in authorized_keys now correctly applies to tunnel forwarding. A potential realloc use-after-free in the client when a remote forwarding is added via the multiplexing socket is fixed, and ssh-keygen gains the ability to set or clear touch-required and verify-required flags on FIDO private keys during passphrase reset.
harfbuzz 14.3.0 & 14.3.1: The text shaping engine that underpins rendering in browsers, desktop environments, and document editors received important improvements. Mark positioning now respects lookup order in the cross-direction, improving compatibility with DirectWrite and Core Text. Mark attachment to ligatures formed from decomposed glyphs is fixed, and the calt feature in Hangul text is now disabled only for the Jamos rather than the entire buffer. The release also adds support for partially instancing of the avar table and the CFF2 table, relevant for variable font workflows. A follow-up 14.3.1 release arrived later in the month with fuzzing and subsetting fixes, a fix for AAT insertion at the end of the text, and rendering fixes in the experimental GPU library.
QEMU 11.1.0: The machine emulator advanced from 11.0.3 with a substantial feature release. Highlights include Universal Flash Storage (UFS) emulation support for Write Booster and Host-Initiated Defragmentation based on the UFS 4.1 specification, and vhost-host-user support for offloading real-time clock handling from the hypervisor when using virtio-rtc. The GUI subsystem gained improvements to virtual console handling and GTK/VNC. ARM support expanded with the new imx8mp-evk machine type and virt board cache topology specification.
Key Package Updates
Linux kernel 7.1.5 through 7.2.2: The kernel progressed through four point releases and a feature release during August with a sustained focus on security and stability. Version 7.1.6 carried fixes for KVM x86 module reload use-after-free, arm64 TLBI errata mitigation, and a virtiofs use-after-free on submount umount. Version 7.1.7 added CVE fixes for batman-adv, ntfs3, and several networking and driver subsystems. Version 7.1.8 addressed an extensive list of CVEs including Bluetooth btusb use-after-free, ksmbd deferred file use-after-free, rtl8723bs out-of-bounds reads and writes, and RDMA fixes across irdma, erdma, and mana_ib. The Btrfs filesystem received fixes for free space cache validation and root leaks during relocation. The 7.2.0 version refreshed the kernel configuration and carried updated AMD Display Core patches. The month closed with the 7.2.2 release, which resovled CVE-2026-80590.
Mesa 26.1.6, 26.2.0 & 26.2.1: The graphics stack made a major jump from 26.1.5 to the 26.2 series during the month. The 26.1.6 bugfix release addressed regressions from the previous stable series, while the 26.2.0 release brought a new batch of driver improvements for AMD, Intel, and Qualcomm hardware. The 26.2.1 bugfix release soon followed, and the VirtIO Vulkan driver is now enabled in openSUSE’s build, bringing Vulkan support to virtualized environments. Users on AMD and Intel GPUs who experienced rendering issues after earlier Mesa updates should find these releases more stable. The Vulkan drivers continue to see corrections for gaming workloads.
python-cryptography 50.0.0: A major version bump that deprecates Diffie-Hellman key exchange over finite fields and adds the Cobblestone recipe for streaming authenticated encryption. The most important change is a security fix for Bleichenbacher oracle in PKCS7 decryption; pkcs7_decrypt_der no longer exposes distinguishable errors or timing when unwrapping a RecipientInfo’s encryptedKey. X.509 verification APIs are now considered stable, and ML-DSA public keys and signatures are permitted by default.
libssh2: Received two rounds of critical security patches during August. The first batch addressed a heap buffer overflow and the second batch fixed arbitrary code execution via double-free in SFTP sessions, denial of service via integer underflow in AES-GCM cipher negotiation, a heap out-of-bounds read, and heap buffer overflow during SSH negotiation. These are essential updates for any system using libssh2 for SSH or SFTP operations.
vim 9.2.0901: A massive update carrying over 100 fixes including eight security patches. Security fixes address arbitrary code execution via keyword lookup, code injection in netrw via bookmarks, heap overflow when adding more than 65,535 text properties, stack buffer overflow in the socket server, and a use-after-free on JSON decode error. The update also fixes numerous memory leaks, a deeply nested regexp pattern stack overflow, and a GTK4 hardware rendering performance regression.
unbound 1.26.0: The DNS resolver received a major update with a large list of fixes and new features. New options include max-transfer-size and max-transfer-time for limiting auth-zone and RPZ transfers, and new local-zone types block_aaaa, block_a_wdata, and block_aaaa_wdata. A heap out-of-bounds write via size_t-to-int truncation is fixed, along with DNSSEC validation fixes for noncanonical RSA DNSKEYs and a race condition causing segfaults when starting threads.
Qt 6 6.11.2: The second bugfix release of the 6.11 series landed across the full module range from qt6-base through qt6-webengine. The update fixes a regression in icon loading and carries multiple stability corrections for the toolkit that Plasma and most KDE applications build on. qt6-webengine also merges an upstream fix for AMD VA-API flickering on Wayland.
wpa_supplicant 2.12: The Wi-Fi authentication daemon adds more complete EHT/IEEE 802.11be/Wi-Fi 7 support including fixes for message validation issues that could enable denial-of-service attacks, and group key rekeying is corrected. SAE group 20 is now enabled by default when SAE-EXT-KEY is available, and IEEE 802.11bi functionality is supported including changing SAE password identifiers, EPPKE, and association frame encryption. RSN overriding (WPA3-Personal Compatibility Mode) is supported, and Automated Frequency Coordination (AFC) on the 6 GHz band is now available. The build enables CONFIG_IEEE80211BE, CONFIG_SAE_PK, CONFIG_PMKSA_PRIVACY, and CONFIG_IEEE8021X_AUTH by default.
postgresql18 18.6: A major security release for PostgreSQL 18 that fixes more than two dozen CVEs covering remote code execution and denial of service issues. Notable fixes include heap buffer overflows in regular expression matching, to_char formatting, and pg_stat_statements that could execute arbitrary code, a psql issue where early failures in COPY FROM STDIN process data lines as command input, and a logical decoding flaw that could dlopen an arbitrary file. Database administrators on Tumbleweed should plan an update soon.
flatpak 1.18.1: A security-focused bugfix release addressing several sandbox escape and privilege escalation paths in the application framework. Fixes include a sandbox escape with full host filesystem read/write access via a symlink attack on app data directories, a local root privilege escalation via revokefs symlink path traversal and commit tampering, and arbitrary root writes through path traversal in extra-data extraction and flatpak build-init. The release also corrects an anti-downgrade bypass that allowed unprivileged users to downgrade system applications.
Security Updates
libssh2:
-
CVE-2026-58050: Fixes a heap buffer overflow via attacker-controlled attribute count from a publickey-subsystem response.
-
CVE-2026-58051: Addresses uninitialized pointer being freed when a malformed response is sent by an SSH server.
-
CVE-2026-66032: Resolves arbitrary code execution via double-free in SFTP session.
-
CVE-2026-66033: Fixes denial of service via integer underflow in AES-GCM cipher negotiation.
-
CVE-2026-66034: Addresses heap out-of-bounds read leading to information disclosure and potential arbitrary code execution.
-
CVE-2026-66035: Fixes heap buffer overflow during SSH negotiation.
Samba 4.24.5:
-
CVE-2026-6949: Fixes TSIG packet with crafted name compression crashing the internal DNS server.
-
CVE-2026-58224: Addresses CTDB heap out-of-bounds read via unchecked packet length fields.
-
CVE-2026-58216: Resolves 6-byte heap out-of-bounds read in kpasswd service packet parser.
-
CVE-2026-58218: Fixes DNS TKEY negotiation storing unauthenticated GSS contexts in a fixed FIFO before authentication completes.
-
CVE-2026-58221: Addresses authenticated LDAP access to internal LDB special DNs permitting domain takeover.
-
CVE-2026-58222: Resolves LDAP Compare filter injection and trusted-request confusion disclosing protected attributes.
vim 9.2.0901:
-
CVE-2026-8339: Fixes arbitrary code execution via keyword lookup.
-
CVE-2026-8340: Addresses code injection in netrw via bookmarks.
-
CVE-2026-8341: Resolves heap overflow when adding more than 65,535 text properties.
-
CVE-2026-8342: Fixes stack buffer overflow in the socket server.
-
CVE-2026-8343: Addresses popup opacity mask indexed out of bounds.
-
CVE-2026-8344: Resolves use-after-free on JSON decode error.
-
CVE-2026-8345: Fixes arbitrary Ex command execution during C omni-completion.
-
CVE-2026-8346: Addresses heap buffer overflow in
set_sofo().
Linux kernel 7.1.6, 7.1.7 & 7.1.8:
-
CVE-2026-64490: Fixes ALSA virtio control metadata validation.
-
CVE-2026-64489: Addresses ALSA ymfpci
snd_ctl_new1return value check. -
CVE-2026-64486: Resolves ALSA cmipci
snd_ctl_new1return value check. -
CVE-2026-64481: Fixes ALSA hda-cs35l41 firmware load work teardown.
-
CVE-2026-64480: Addresses ALSA ice1712
snd_ctl_new1return value check. -
CVE-2026-64477: Resolves x86 fs/resctrl out-of-bounds access.
-
CVE-2026-64476: Fixes VFIO PCI
disable_idle_d3per-device latch. -
CVE-2026-64475: Addresses VFIO PCI VGA arbiter client release on registration.
-
CVE-2026-64474: Resolves VFIO infinite loop in
vfio_mig_get_next. -
CVE-2026-64471: Fixes Bluetooth btusb use-after-free on registration.
-
CVE-2026-64466: Addresses Rust binder freeze listener cleanup on node removal.
-
CVE-2026-64437: Resolves ksmbd use-after-free of a deferred file location.
-
CVE-2026-64436: Fixes net af_key uninitialized
alg_key_lenfor IPComp. -
CVE-2026-64433: Addresses Bluetooth MGMT use-after-free of
hci_conn_params. -
CVE-2026-64432: Resolves ntfs3 Dirty Page Table capacity validation.
-
CVE-2026-64431: Fixes ntfs avoid calling
post_write_mst_fixupfor invalid ranges. -
CVE-2026-64430: Addresses NTB EPF avoid calling
pci_irq_vectorfrom hardirq. -
CVE-2026-64424: Resolves netpoll use-after-free on shutdown path.
-
CVE-2026-64449: Fixes staging vme_user bound slave read/write to the buffer size.
-
CVE-2026-64445: Addresses staging rtl8723bs WEP length underflow and buffer overflow.
-
CVE-2026-64444: Resolves staging rtl8723bs out-of-bounds read in
OnAssocRspIE. -
CVE-2026-64441: Fixes staging rtl8723bs out-of-bounds reads in
rtw_get_secfunctions. -
CVE-2026-64440: Addresses staging rtl8723bs out-of-bounds write in
HT_caps_hand. -
CVE-2026-64599: Resolves crypto amlogic double cleanup in
meson_cr.
Firefox 154.0:
-
CVE-2026-75874: Fixes a sandbox escape in the Remote Settings client component.
-
CVE-2026-74934: Addresses a site isolation issue in the Graphics CanvasWebGL component.
-
CVE-2026-74936: Resolves a use-after-free in the JavaScript WebAssembly component.
-
CVE-2026-74937: Fixes a use-after-free in the JavaScript GC component.
-
CVE-2026-74939: Addresses a privilege escalation in the DOM Navigation component.
-
CVE-2026-74943: Resolves a use-after-free in the Graphics ImageLib component.
- CVE-2026-74944: Fixes a use-after-free in the DOM Core & HTML component. https://github.com/KDE/kscreen
-
CVE-2026-74953: Addresses a privilege escalation in the Networking Cookies component.
-
CVE-2026-74956: Resolves a same-origin policy bypass in the DOM Service Workers component.
-
CVE-2026-74969: Fixes a use-after-free in the Layout Text and Fonts component.
- CVE-2026-74976: Addresses a JIT miscompilation in the JavaScript Engine JIT component.
WebKitGTK 2.52.6:
-
CVE-2026-43804: Fixes a security vulnerability in the WebKit rendering engine.
-
CVE-2026-64713: Addresses a memory corruption issue in the WebKit rendering engine.
-
CVE-2026-64719: Resolves a security vulnerability in the WebKit rendering engine.
-
CVE-2026-64728: Fixes a memory safety issue in the WebKit rendering engine.
-
CVE-2026-64730: Addresses a security vulnerability in the JavaScriptCore engine.
-
CVE-2026-64757: Resolves a memory corruption issue in the WebKit rendering engine.
-
CVE-2026-64783: Fixes a security vulnerability in the WebKit rendering engine.
postgresql18 18.6:
-
CVE-2026-6464: Fixes
psqlprocessing data lines as command input after an early failure inCOPY FROM STDIN. -
CVE-2026-6471: Addresses logical decoding being able to
dlopenan arbitrary file. -
CVE-2026-14662: Resolves undersize allocations for
tsvectorandtsqueryvia integer wraparound. -
CVE-2026-14664: Fixes a regexp heap buffer overflow that executes arbitrary code.
-
CVE-2026-14669: Addresses a
to_charheap buffer overflow that executes arbitrary code. -
CVE-2026-14676: Resolves a
pg_stat_statementsheap buffer overflow that executes arbitrary code. -
CVE-2026-14679: Fixes a stack buffer overflow in argument match that writes to server memory.
-
CVE-2026-15741: Addresses SQL injection via an
EXTRACTargument during expression deparse. -
CVE-2026-18408: Resolves
psql\unrestrictletting a superuser execute arbitrary code in thepsqlclient. -
CVE-2026-19385: Fixes a
pg_dumpheap buffer overflow that executes arbitrary code.
expat 2.8.2:
-
CVE-2026-50219: Fixes memory corruption affecting Expat bindings by disallowing reentrant calls to functions such as
XML_GetBuffer,XML_Parse, andXML_ParserFree. -
CVE-2026-56131: Addresses
XML_ResumeParserbeing called from a handler, plugging a hole in the CVE-2026-50219 fix. -
CVE-2026-56132: Resolves an out-of-bounds scaffolding index store in
doProlog. -
CVE-2026-56403: Fixes an integer overflow in
storeAtts. -
CVE-2026-56404: Addresses an integer overflow in
addBinding. -
CVE-2026-56405: Resolves an integer overflow in
getAttributeId. -
CVE-2026-56406: Fixes an integer overflow in
XML_ParseBuffer. -
CVE-2026-56407: Addresses an integer overflow in
textLenhandling. -
CVE-2026-56408: Resolves an integer overflow in
copyString. -
CVE-2026-56409: Fixes an integer overflow in the
xmlwfoutput path join. -
CVE-2026-56410: Addresses an integer overflow in the
xmlwfresolveSystemId. -
CVE-2026-56411: Resolves an integer overflow in notation list allocation.
-
CVE-2026-56412: Fixes
XML_TOK_DATA_CHARShandler calls indoCdataSection, plugging a hole in the CVE-2026-50219 fix.
c-ares 1.34.8:
-
CVE-2026-33630: Fixes a use-after-free and double-free in query-completion handling remotely triggerable via
ares_getaddrinfo()over TCP. -
CVE-2026-69184: Addresses a CPU-exhaustion denial of service via unbounded DNS name compression pointer chains.
-
CVE-2026-69186: Resolves a memory-amplification denial of service via unvalidated DNS header record counts.
busybox:
-
CVE-2026-38755: Fixes stack exhaustion in the ash applet caused by unbounded shell function recursion.
-
CVE-2026-38754: Addresses an out-of-bounds read in
ifsbreakup(). -
CVE-2026-38753: Resolves a use-after-free in the awk applet regexp processing code during text replacement operations.
-
CVE-2026-38752: Fixes stack exhaustion in the awk applet caused by unbounded function call recursion.
-
CVE-2023-42366: Addresses a heap buffer overflow in the awk applet when a regexp ends with a backslash.
OpenEXR 3.4.14:
-
CVE-2026-68513: Fixes a PyOpenEXR prefixed literal RGB key collision heap buffer overflow.
-
CVE-2026-68514: Addresses a PyOpenEXR deep prefixed literal RGB key collision heap buffer overflow.
-
CVE-2026-59183: Resolves a signed integer overflow leading to out-of-bounds memory access in deep tile decoding.
-
CVE-2026-59186: Fixes an ILP32
TiledRgbaInputFilelarge tile Array2D heap out-of-bounds write. -
CVE-2026-59187: Addresses an
exrmetricsdeep pixelmode heap buffer overflow. -
CVE-2026-59981: Resolves an OpenEXRUtil SampleCountChannel row nonzero dataWindow heap out-of-bounds read.
-
CVE-2026-59985: Fixes an ILP32 OpenEXRCore RLE decode heap out-of-bounds read denial of service.
-
CVE-2026-61555: Addresses a crash on empty multiView
viewFromChannelNamefiles. -
CVE-2026-62986: Resolves a PyOpenEXR deep prefixed RGB stale lane disclosure.
python313:
-
CVE-2026-0864: Fixes mixed line ending handling in
configparserby normalizing all line endings. -
CVE-2026-11972: Addresses
tarfile._Stream.seeknot breaking at end of file. -
CVE-2026-4360: Resolves a missing
filter_functionpass-through toTarFile._extract_one()during.extract(). -
CVE-2026-15308: Fixes quadratic complexity in incremental
HTMLParserparsing enabling CPU exhaustion.
gzip:
- CVE-2026-41992: Fixes global buffer overflow in the LZH decompression logic.
libXfont2:
-
CVE-2026-59679: Fixes
fs_read_glyphs()heap out-of-bounds read/write via encoding array index mismatch. -
CVE-2026-44950: Addresses
fs_read_glyphs()heap buffer overflow via cumulative glyph data overflow.
glib2 2.88.3:
- CVE-2026-15588: Fixes GDBusServer pre-authentication denial of service via unbounded SASL line buffering.
dracut:
-
CVE-2026-15816: Addresses root code execution via unescaped error message written to sourced emergency hook script in
die().
python-cryptography 50.0.0:
- CVE-2026-69247: Fixes Bleichenbacher oracle in PKCS7 decryption where distinguishable errors or timing could leak information when unwrapping a RecipientInfo’s encryptedKey.
libostree 2026.3:
-
CVE-2026-58055: Fixes unbounded LZMA decompression in static delta processing allowing denial of service.
-
CVE-2026-58056: Addresses heap buffer overflow via integer truncation in static delta bspatch on 32-bit systems.
gdm 50.2:
-
CVE-2026-58058: Fixes path traversal vulnerability where a compromised greeter could load arbitrary
.desktopfiles viaSelectSession. -
CVE-2026-58059: Addresses autologin bypass where a compromised greeter could request autologin for any local account.
-
CVE-2026-58060: Resolves denial of service where an invalid session name from the greeter would cause the entire daemon to exit.
udisks2 2.11.2:
-
CVE-2026-7867: Fixes an unprivileged D-Bus caller using the
as-userFilesystem.Mount() option combined with fstab entries containinguserorusersmount options to mount on behalf of another user without polkit authorization.
php8 8.5.9:
-
CVE-2026-17543: Fixes SQL injection via
E'...'backslash breakout in PostgreSQL. -
CVE-2026-17544: Addresses out-of-bounds write in
bccomp(). -
CVE-2026-7260: Resolves crash via recursive symlinks in Phar.
-
CVE-2026-9672: Fixes a vulnerability in the GD library upgrade.
libssh2:
-
CVE-2026-58050: Fixes heap buffer overflow via attacker-controlled attribute count from a publickey-subsystem response.
-
CVE-2026-58051: Addresses uninitialized pointer freed when a malformed response is sent by an SSH server.
python-pip 26.2:
- CVE-2026-13346: Fixes double decoding of the URL path while determining a link filename.
gimp:
-
CVE-2026-66757: Fixes a security vulnerability in GIMP image processing.
-
CVE-2026-66758: Addresses a security vulnerability in GIMP.
-
CVE-2026-66759: Resolves a security vulnerability in GIMP.
-
CVE-2026-59087: Fixes a security vulnerability in GIMP image processing.
-
CVE-2026-59088: Addresses a security vulnerability in GIMP.
-
CVE-2026-59090: Resolves a security vulnerability in GIMP.
-
CVE-2026-59091: Fixes a security vulnerability in GIMP.
libheif 1.23.1:
-
CVE-2026-62289: Fixes integer underflow in Fraction constructor via double clap transform application.
-
CVE-2026-62291: Addresses heap out-of-bounds write in uncompressed encoder when writing images with mismatched auxiliary alpha dimensions.
-
CVE-2026-62292: Resolves out-of-bounds read in uncompressed unci tile range slicing.
-
CVE-2026-62377: Fixes reachable assertion in
HeifContext::get_track()aborting on a valid-but-empty HEIF sequence file.
nghttp2 1.70.0:
- CVE-2026-58055: Fixes out-of-bounds read in the base64 decoder.
libgit2 1.9.7:
- CVE-2026-5917: Fixes improper escaping of remote repository paths in libssh2.
bzip2:
-
CVE-2026-42250: Fixes an off-by-one error in the
bzip2recoverutility when processing a specially crafted file that can lead to a crash.
openssl-3 3.x:
-
CVE-2026-75803: Fixes AEAD forgeries with empty ciphertext when using
EVP_Cipher(). -
CVE-2026-14456: Addresses unbounded memory growth in QUIC server incoming channel queue.
-
CVE-2026-14457: Resolves RPK server signature algorithm selection dereferencing a missing certificate.
-
CVE-2026-18798: Fixes QUIC server triggering a double free when processing an INITIAL packet.
-
CVE-2026-34181: Addresses PKCS#12 files with PBMAC1 being accepted with short HMAC keys.
-
CVE-2026-54874: Resolves excessive memory use buffering DTLS records for a future epoch.
-
CVE-2026-63072: Fixes a heap buffer overflow in CMS key unwrapping.
-
CVE-2026-63073: Addresses untrusted sender DN used as format string in CMP response validation.
-
CVE-2026-63074: Resolves CMP indefinite cache growth of ExtraCerts.
-
CVE-2026-63075: Fixes QUIC ACK-only packet retention causing memory exhaustion.
-
CVE-2026-63076: Addresses invalid pointer dereference in CMP server via crafted
protectionAlg.
java-25-openjdk 25.0.4.1:
-
CVE-2026-60589: Fixes resource resolving vulnerability.
-
CVE-2026-61308: Addresses HTTP connection enhancement security issue.
-
CVE-2026-70907: Resolves TLS server security vulnerability.
-
CVE-2026-70906: Fixes font loading security vulnerability.
cpio:
-
CVE-2026-66484: Fixes path traversal allowing creation of hard links outside the intended directory via malicious tar archives.
-
CVE-2026-66485: Addresses denial of service via uncontrolled memory allocation from crafted archives.
-
CVE-2026-66486: Resolves terminal control sequence injection via crafted archive member names.
libvirt:
-
CVE-2026-77159: Fixes QEMU TPM following symlinks when chown’ing log files.
-
CVE-2026-18917: Addresses integer overflow in RPC handler for
virNodeGetFreePages.
multipath-tools:
-
GHSA-hmcm-9cq4-r2xm: Fixes denial of service on
multipathdsocket by blocking IPC send operations. -
GHSA-pvp6-c9p3-25fp: Addresses denial of service on
multipathdsocket by exhausting connections. -
GHSA-g5mh-253r-jjw5: Resolves heap out-of-bounds read in custom format string parser via trailing
%. -
GHSA-pxwh-g75c-95pc: Fixes heap out-of-bounds read in device-mapper-multipath ALUA RTPG parsing.
-
GHSA-p6rh-9x9j-3hvx: Addresses
kpartxheap out-of-bounds read in GPT header validation. -
GHSA-gr7q-prfc-q636: Resolves path traversal in device-mapper-multipath
failed_wwidsmanagement. -
GHSA-hj7j-qr9h-5fv6: Fixes
libmpathpersistPRIN READ FULL STATUS parser unbounded descriptor rewrite causing root heap overflow.
Users are advised to update to the latest versions to mitigate these vulnerabilities.
Conclusion
August was a busy month for openSUSE Tumbleweed with 23 snapshots delivering a steady cadence of desktop, developer, and security improvements. KDE Plasma 6.7.4 delivered targeted desktop fixes while KDE Gear 26.08.0 and KDE Frameworks 6.29.0 advanced the KDE application and library stacks, and GNOME Shell 50.4 polished the GNOME desktop. Mesa settled into its 26.2 series, the Linux kernel progressed through point releases to 7.2.0 with extensive CVE coverage, Firefox 154.0 shipped more than 40 security fixes, and GStreamer 1.28.6 brought playback and security fixes across the multimedia stack. Developer tools saw significant updates: Emacs jumped to 31.1, QEMU advanced to 11.1.0 with UFS emulation and RISC-V extensions, GCC reached 16.2, Qt 6 advanced to 6.11.2, OpenSSH 10.5p1 fixed critical agent forwarding issues, and vim addressed eight security vulnerabilities. FreeRDP 3.31.0 patched more than 20 CVEs while improving YUV decoding performance, wpa_supplicant 2.12 brought Wi-Fi 7 support, and chrony 4.9 added NTP-over-PTP and new stratum-bounding directives. Security remained a dominant theme, with critical patches in libssh2, Samba, postgresql18, openssl, expat, webkitgtk, openexr, flatpak, python-cryptography, openvpn, gdm, udisks2, multipath-tools, and php8.
Slowroll Arrivals
Please note that these updates also apply to Slowroll and arrive between an average of 5 to 10 days after being released in Tumbleweed snapshot. This monthly approach has been consistent for many months, ensuring stability and timely enhancements for users. Updated packages for Slowroll are regularly published in emails on openSUSE Factory mailing list.
Contributing to openSUSE Tumbleweed
Stay updated with the latest snapshots by subscribing to the openSUSE Factory mailing list. For those Tumbleweed users who want to contribute or want to engage with detailed technological discussions, subscribe to the openSUSE Factory mailing list . The openSUSE team encourages users to continue participating through bug reports, feature suggestions and discussions.
Your contributions and feedback make openSUSE Tumbleweed better with every update. Whether reporting bugs, suggesting features, or participating in community discussions, your involvement is highly valued.
Reverse dependencies as a zypper plugin
A few years ago I wrote a blog post about a small hackweek project called rdepends. The idea was simple: given a package, find out what other packages depend on it, recursively. It lived in my home project on the build service and it was a useful but rough tool.
Since then a few things happened that made me revisit it.
Zypper got the feature
Back when I started this project, zypper had no built-in way to ask “what depends on package X?”. You could ask the other direction easily with zypper info --requires, but not the reverse. I raised this with the zypper developers and Benjamin Zeller implemented the --requires-pkg flag in zypper 1.14.33. So now you can do:
Mobile Linux Hackday #8: Record Turnout in SUSE's New Prague Office
On Friday, August 28th, the SUSE Prague office hosted Mobile Linux Hackday #8. This event marked two major milestones: we hit a new record attendance for Prague, and attendees got their first hands-on experience in our freshly renovated Karlín space.
If you missed the event, here is a recap of the community highlights, kernel hacking sessions, and key takeaways from the day.
Renovated Prague Office: Great Coffee and Full Capacity
Returning attendees and newcomers were welcomed into our newly reconstructed Karlín office. The expanded social hub in the kitchen was an immediate favorite, providing comfortable sofas for breaks and technical discussions.
The highlight for many was the upgraded coffee station. Attendees put the manual lever espresso machine and external grinder through its paces, while a fully automatic machine served as a reliable backup.
Community Growth and Room Merging
With a peak crowd of 20 to 25 attendees, we set a new record for a Prague Mobile Linux Hackday and put our workspace flexibility to the test. The numbers were strong, especially when compared with earlier community gatherings such as the first Pilsen Mobile Hackday or the combined Budweis and SUSE Labs events, which had historically drawn larger crowds and set the benchmark for what a really “prime” event could look like. This turnout is a clear sign that our outreach and event marketing are gaining traction, and it is encouraging to see the community respond so strongly.
We originally booked the Mint meeting room, but as more people arrived, we pulled open the sliding partition panel and took over the adjoining Avocado room as well. Even after expanding into a double-sized room, we still had to borrow almost every chair from the surrounding area to seat everyone. Moving forward, we will definitely make sure we have plenty of extra seating ready for future gatherings.
Flexible Formats and the Kitchen Talk Dilemma
Unlike previous editions with rigid agendas, this Hackday was a bit more freestyle. Attendees naturally split into smaller working groups, alongside a remote session with David, who joined us from Switzerland and kindly made time for a deeper discussion on a more established topic.
This casual approach sparked fantastic side discussions, but it also highlighted a fun new challenge: the renovated kitchen space was so inviting that some attendees spent most of the day there, drifting into long hallway-track conversations. A big kudos to the facilities team for creating such a comfortable, social space that people simply did not want to leave!
While informal networking is a core part of community building, balancing casual chatter with structured technical sessions is something we plan to fine-tune for future events. We are actively looking into light-touch scheduling methods to help guide attendees smoothly between casual kitchen banter and hands-on coding.
Outreach Insights: Where the Czech Linux Community Gathers
During the event, we surveyed attendees on how they discovered the event to help refine our future community outreach.
- Root.cz: The primary source for most attendees.
- AbcLinuxu.cz: Brought in several key community members.
- Word of Mouth: Direct recommendations from friends and colleagues played a major role in bringing in fresh faces.
- LinuxExpres.cz: This was the first time we included it in our promotion mix. It did not produce a noticeable spike in attendance, but it was still a useful extra step in widening our reach beyond the usual community channels.
- Mastodon: The main communication channel for the community, and many attendees learned about the event through the Mobile Linux CZ/SK Mastodon account.
Every newcomer made sure to leave with plenty of openSUSE swag to mark their first event.
Technical Highlights: AI Tools, BengalOS, and Snapdragon Hacking
Led by Petr Hodina, Mesa 3D GPU driver developer and community maintainer, the technical tracks covered several cutting-edge topics across mobile ecosystem development.
Key Topics Covered:
- LLMs and Developer AI: Practical applications of Large Language Models to streamline daily developer workflows.
- BengalOS Architecture: An overview of BengalOS, including instructions on how to build and test the OS on hardware.
- Qualcomm Snapdragon 845 Kernel Hacking: Hands-on kernel debugging and testing focused on sdm845-based devices, including the OnePlus 6/6T, Xiaomi Poco F1, and Shift 6MQ.
Join the Next Mobile Linux Hackday
A huge thank you to Petr Hodina for driving the sessions, keeping the momentum high, and running an outstanding workshop. As a small token of our appreciation for his dedication to the community, Petr was awarded a giant plush openSUSE chameleon!
Photos from the event, along with broader shots of the refreshed SUSE Prague office, are available in our shared Google Photos album.
To stay updated on upcoming hackdays, follow the Mobile Linux CZ/SK community on Mastodon, or keep an eye out on local tech portals like Root.cz. See you at Hackday #9!
openSUSE Expands AI Support with Intel NPU Driver 1.35.0 and OpenVINO 2026.3.1
Work carried out under the openSUSE Innovator initiative brings the next generation of Intel’s Artificial Intelligence stack to Tumbleweed, Leap 16.0, and Leap 16.1, while also resulting in an upstream contribution to the Intel NPU driver.
As an Intel Innovator and a member of the openSUSE Innovator initiative, I remain committed to bringing the openSUSE ecosystem closer to the latest technologies in Artificial Intelligence and heterogeneous computing.
In this latest work cycle, Intel Linux NPU Driver 1.35.0 has been made available for openSUSE Tumbleweed, openSUSE Leap 16.0, and openSUSE Leap 16.1. This gives users of these versions access to the infrastructure needed to utilize the NPU found in the new generations of Intel® Core™ Ultra processors.
However, this time, the work didn’t stop at packaging. While testing the Intel NPU 1.35.0 driver on openSUSE, I identified an issue that prevented the NPU from initializing correctly in certain Linux environments. The problem occurred within the ResourceCleaner—an internal thread of the NPU’s Level Zero driver—causing the process to terminate with a SIGABRT during startup.
Consequently, as an openSUSE member, I submitted a fix directly to the official intel/linux-npu-driver project via Pull Request #142 as an upstream contribution to Intel’s driver. This demonstrates something I consider essential in the open-source ecosystem: it is not just about using a technology or creating a package for a distribution, but also about investigating issues, identifying their root causes, and contributing the solution back to the original project so the entire community can benefit. ## OpenVINO 2026.3.1 Comes to openSUSE
Alongside work on the NPU driver, I also updated OpenVINO to version 2026.3.1, making packages available for openSUSE Tumbleweed, Leap 16.0, and Leap 16.1. OpenVINO is a cornerstone of Intel’s Artificial Intelligence strategy. It enables the development and execution of inference applications using various computing resources available on the machine, including CPU, GPU, and NPU.
For openSUSE, this means providing developers with a modern stack for building applications involving LLMs, multimodal models, computer vision, speech recognition, embeddings, quantized models, and local generative AI.
For more information, go to linux-npu-driver or openvino!
LACT: Polkit Authentication Bypass and Temporary File Handling Issues
Table of Contents
- 1) Introduction
- 2) The LACT Daemon
- 3) Security Issues
- 3.1) Polkit Authentication Bypass due to PID Race (CVE-2026-75037)
- 3.2) Predictable Temporary File Creation in Snapshot API (CVE-2026-75038)
- 4) Coordinated Disclosure and Upstream Bugfix Release
- 5) Timeline
- 6) References
1) Introduction
LACT is a daemon and graphical user interface for controlling GPU devices on Linux. Beyond providing access to device information, features like GPU overclocking and cooler control are included. In a recent update of LACT a Polkit policy appeared, which triggered a review for the corresponding package in openSUSE Tumbleweed.
During the review we identified a Polkit authentication bypass and a predictable temporary file name issue, resulting in potential local root exploits. The following sections describe the security issues in detail. This report is based on release v0.10.0 of LACT.
2) The LACT Daemon
LACT contains a systemd service unit which runs the lact
program as a daemon with full root privileges. No systemd service hardening is
in place. The daemon exposes a UNIX domain socket in /run/lactd.sock.
Upstream intends this socket to be accessible by members of either the wheel
or the sudo group. In openSUSE Tumbleweed a stricter opt-in model is used
instead: only members of a dedicated lact group are allowed to access the
socket.
The socket is used to exchange LACT-specific messages based on the Rust serde serialization format. In version 0.10.0 of LACT, some of the message types supported by the daemon have been additionally protected by Polkit authentication checks.
3) Security Issues
3.1) Polkit Authentication Bypass due to PID Race (CVE-2026-75037)
The Polkit authentication in the LACT daemon relies on function
check_auth(), which authenticates the client solely based
on its PID, which is a known misuse in Polkit authentication. A malicious
client can attempt to send out the request, then cycle PIDs in an attempt to
replace its own PID by a privileged process to alter the outcome of the Polkit
authentication check.
Polkit authentication in LACT is used to prevent unprivileged users from
adding so-called profile hooks to the LACT configuration. These hooks are
basically scripts that will be executed with full root privileges as soon as a
LACT profile is (de)activated. As a result, a Polkit authentication bypass in
this context allows to gain full root access. Due to the access restrictions
to the LACT UNIX domain socket, the privilege escalation is only possible for
users that already own a certain level of privilege (i.e. membership in the
wheel, sudo or lact group).
We assigned CVE-2026-75037 to track this issue. Upstream fixed this flaw in commit d0478fe4 by additionally passing the caller’s UID to the Polkit daemon, preventing race conditions from influencing the outcome of the authorization.
Shortly before publication of this report the upstream author informed us
about a more deeply rooted issue in Rust crate zbus_polkit
which affects various Rust applications that attempt to pass client UIDs to
Polkit. Due to a D-Bus data type mismatch the UID seems to be silently
dropped from the authentication data, resulting again in the same weakness. An
update of the zbus_polkit crate, which is part of Rust vendor sources of
various packages is thus strongly recommended to developers of affected
applications and distributors. For LACT a bugfix commit is
already available.
3.2) Predictable Temporary File Creation in Snapshot API (CVE-2026-75038)
The generate_snapshot() function is accessible
without Polkit authentication. It creates a tarball in paths of the pattern
/tmp/LACT-v{DAEMON_VERSION}-snapshot-{datetime}.tar.gz, which are
predictable. The system calls used by the daemon to create these files are as
follows (strace excerpt):
openat(AT_FDCWD, "/tmp/LACT-v0.10.0-snapshot-20260819-101819.tar.gz" O_WRONLY|O_CREAT|O_TRUNC|O_CLOEXEC, 0666) = 17
[...]
fchmod(17, 0775) = 0
As can be seen there is no O_NOFOLLOW and no O_EXCL flag passed here. On
systems without the protected_symlinks and protected_regular sysctls
enabled this allows various attack vectors:
- local Denial-of-Service: by pointing symbolic links to vital system files, the target files will be overwritten, breaking the system. The content of the tarball is not attacker-controlled (or at best partly and indirectly), therefore further privilege escalation should not be possible this way.
- Denial-of-Service against the LACT daemon: by placing a special file like a FIFO named pipe in this location the daemon will block forever, trying to write data to it.
- local information leak: the tarball contains data about GPU devices and LACT
configuration; mostly information that is available to all users in the
system anyway. By placing a symlink to a private file, however, the target
file will end up with world-readable permissions, due to the
fchmod(). The content of the file will be lost due to theO_TRUNCflag duringopenat(), but the file might be re-populated with sensitive data by privileged processes at a later time, without restoring the original safe file permissions.
With the kernel hardenings protected_symlinks and protected_regular
enabled, which is the default on most systems, these issues are fortunately
not exploitable.
A side effect of how the tarball creation in LACT works at the moment is that
the snapshot tarball cannot be deleted by the client that asked for it, since
it is owned by root. As there is already a UNIX domain socket available, we
suggested to upstream to use file descriptor passing instead: the client
passes to the daemon an already open file where the tarball data will be
written. This way neither open() nor chmod() calls will be necessary in
the privileged daemon, resulting in a much cleaner design.
We assigned CVE-2026-75038 to track this issue. Upstream fixed this flaw in
commit 2aae677d0 by invoking File::create_new()
instead of plain File::create(). This results in the O_EXCL flag to be
passed to the openat() system call shown above, preventing both opening
already existing files and following symbolic links.
4) Coordinated Disclosure and Upstream Bugfix Release
We offered coordinated disclosure to upstream, who declined and quickly pushed
bugfixes to the LACT GitHub project instead. The bugfixes (including the
zbus_polkit fix) are included in the recently published release
v0.10.1.
5) Timeline
| 2026-08-19 | We reached out privately to the owner of the LACT GitHub project, offering coordinated disclosure. |
| 2026-08-19 | We received a reply in which upstream declined coordinated disclosure, pointing out two public bugfix commits instead. |
| 2026-08-24 | Due to a lost email on our end we only noticed at this time that there was an upstream reply and started acting on it. |
| 2026-08-25 | We assigned CVEs for the issues in this report and shared them with upstream. |
| 2026-08-25 | Our LACT packager backported the upstream bugfixes allowing us to progress with the openSUSE Tumbleweed LACT update to version 0.10.0. |
| 2026-08-28 | We received a follow-up email from upstream pointing out that an issue in Rust’s zbus_polkit causes the subject’s UID information to be silently dropped from Polkit authentication calls. |
| 2026-08-28 | Publication of this report. |
6) References
Binary function coverage part 2: scaling up, fixing daemons, and asking the kernel
In the first post I described the setup: funkoverage eBPF tracing, a podman container running openQA, and the first coverage report with 141 binary targets. That was the starting line. This is what happened next.
Daemon shimming
The biggest limitation in the first round was daemons. Services like sshd, cups, postgresql, and rpcbind couldn’t be shimmed because funkoverage’s wrapper broke systemd’s service lifecycle. Two specific problems: the shim used SIGKILL instead of forwarding SIGTERM to the child process, so daemons couldn’t clean up sockets on restart. And the shim didn’t relay sd_notify, so Type=notify services timed out on start.
Linux Saloon 217 | Application Potluck
Tumbleweed – Review of the week 2026/35
Dear Tumbleweed users and hackers,
This week saw the release of 5 snapshots (0820, 0821, 0822, 0825, and 0826).
It was an exceptionally packed week of updates, successfully delivering three major items that had been brewing in our staging areas. First, snapshot 0821 brought the entire Qt 6.11.2 library stack, laying a solid foundation for the desktop environment. This was immediately followed in snapshot 0825 by the arrival of KDE Gear 26.08.0, which introduces substantial productivity upgrades to Dolphin (with advanced regex-capable filtering and decoupled grouping), Okular (unified settings and improved annotating workflows), and Konsole (which adds Alt+Click drag-and-drop support).
Another monumental addition in snapshot 0825 was the transition to Linux Kernel 7.2.0. This new kernel introduces major performance optimizations including Cache-Aware Scheduling (CAS) to prevent cache bouncing on multi-core chips, initial AMDGPU HDMI 2.1 support, and the integration of Rust GPUVM abstractions. On the application side, snapshot 0822 was highlighted by the delivery of Mozilla Firefox 154.0 (bundled with the 154.0.1 bugfix release), bringing WebSocket local network permissions, smart tab grouping suggestions, and significantly accelerated video seeking latency.
These 5 snapshots delivered the following updates:
- 389-ds 3.2.2
- clamav 1.5.4
- dracut 112+suse.34.g35e16b7
- expat 2.8.2
- KDE Gear 26.08.0
- Linux Kernel 7.2.0
- Mesa 26.2.1
- MozillaFirefox 154.0
- postgresql18 18.6
- Qt 6.11.2
- strace 7.2
- virtualbox 7.2.16
- webkitgtk4 2.52.6
With these massive updates successfully integrated and rolled out to users, we turn our attention forward to see what is currently working its way through our staging projects:
- Rust 1.98: Already checked in, currently building as part of the next snapshot before heading to openQA.
- Linux Kernel 7.2.2: Likely to be shipped in the coming days.
- LLVM 23.1.0: Transition in progress to make this the new system default, replacing version 22.
- Swig 4.5.0: Received a few fixes, but some YaST-related integration issues still remain to be addressed.
- glibc 2.44: Still progressing in Staging:N. The integration issues with rpmlint, python-scipy, and xsimd have been resolved, and the transition is now focused on resolving the remaining build failure in m4.
- icewm 4.1.0: Active in the staging queue, currently awaiting openQA verification results.
- libnettle 4.0.0: Currently excluded from main staging runs while developers work on resolving test suite breakages in libzypp.
Planet News Roundup
This is a roundup of articles from the openSUSE community listed on planet.opensuse.org. This community blog feed aggregator lists the featured highlights below from August 21 to 27.
This week highlights the SUSE security review that uncovered remote root exploits in OpenRGB, the release of LibreOffice 26.8, KDE’s continued work on the Wayland remote desktop and KDE Gear improvements, Matthias Klumpp’s Sovereign Tech Fellowship plans for Freedesktop, AppStream and PackageKit, and six Tumbleweed snapshots delivering KDE Frameworks 6.29.0.
Here is a summary and links for each post:
Script to monitor the power of the WIFI signal in the terminal
Victorhck writes a blog about trying what what he read in another blog from Tecno Y Soft. It goes over a Bash script monitoring real-time Wi-Fi signal strength in the Linux terminal, displaying a color-coded bar, SSID, and transfer rates. It improves upon basic aliases by auto-detecting network interfaces and root requirements for easy, universal execution.
Syslog-ng end of August news, and about scaling back Java support
Peter Czanik reports on the project’s news after the summer break and explains the decision to scale back Java support. With native C drivers now covering Elasticsearch and Kafka and HDFS being dropped, the team disabled packaging of the Java destination in the Debian, Ubuntu and RHEL packages, reducing both RAM and hard drive usage. The post also reviews the pull requests and new issues the team is working through.
LibreOffice 26.8 Released, Now with Professional Typography
The KDE Blog announces LibreOffice 26.8, released by The Document Foundation on August 26 and built by 206 contributors. The new version brings improved support for the world’s writing systems, the Paragraph Composer, native OpenType font variations and broader OOXML chart compatibility - all without any generative AI features, telemetry or account requirements.
Podcast Linux #35: Free Formats
The KDE Blog continues to keep the memory of the paused Podcast Linux project alive by gradually indexing its episodes. Episode 35, “Free Formats”, features Juan Febles explaining why file formats, containers and codecs should be free and internationally standardized, alongside an interview with Lorenzo Carbonell (Atareao) and coverage of Inkscape.
How KDE Improves the Remote Desktop in Wayland: Unattended Mode, Lower Latency and More Compatibility
The KDE Blog details a review of the remote desktop improvements heading to Plasma 6.8 under Wayland. The unattended mode now shows a login screen and then hides the host’s displays for privacy, while frame latency tracking, bidirectional clipboard support, RemoteFX Progressive and hardware-accelerated H.264 encoding, and the migration to libei round out the upgrade.
OpenRGB: Remote System Compromise via Custom Network Protocol
The SUSE Security blog publishes a security review that found high-severity flaws in OpenRGB’s custom network protocol, which runs as root and listens on port 6742. Three CVEs cover arbitrary file overwrite (CVE-2026-59682), remote and local root exploits via the UPDATEMODE and SAVE_PROFILE messages (CVE-2026-59683) and several denial-of-service vectors (CVE-2026-18794). Upstream’s 1.0rc3-hotfix release addresses the worst of the issues.
Sovereign Tech Fellowship for Freedesktop Tasks
Ximions Blog shares Matthias Klumpp’s plans for the second half of 2026 as a Sovereign Tech Fellow with significantly increased hours. He intends to tidy up the Freedesktop specifications and website, push AppStream close to its 1.2.0 release, and design PackageKit 2.0 with a modernized architecture and smoother offline updates.
The News of Okular in KDE Gear 26.08, the “Enjoy Shiny Stuff” Edition
The KDE Blog sums up the improvements in Okular from KDE Gear 26.08, “Enjoy Shiny Stuff”. Signing is now more secure and fluid, the two configuration dialogues are unified, triple-click selects an entire line, highlighted or underlined text is automatically added to an associated note, and annotations can be copied and pasted between documents.
Tellico 4.2.2 Released
The KDE Blog reports the release of Tellico 4.2.2, the KDE collection organizer. The update adds the default .tc extension when saving, an option to disable ISBN validation, improved ISBN formatting for all regions, better image caching in the icon view and drag-and-drop RIS import, while removing the defunct DVDFr data source.
UI and Performance Improvements - This Week in Plasma
The KDE Blog translates Nate Graham’s weekly report on the work shaping Plasma 6.8. Interface highlights include English keyword search in System Settings, disabling autostart entries without removing them, more responsive auto-hiding panels and improved lock screen authentication selection, alongside a long list of bug fixes across Plasma 6.6.7, 6.7.5 and 6.8.
Thunderbird 154.0 Released
Victorhck blogs about the release of Thunderbird 154.0. Highlights include an optional system tray mode that keeps the mail client running in the background when the last window is closed, plus a range of fixes for IMAP connections, calendars, CalDAV sync and RSS subscriptions.
Tumbleweed - Review of the Week 2026/34
Dominique Leuenberger and Victorhck review Tumbleweed’s week 2026/34 with its six snapshots. KDE Frameworks 6.29.0 shipped in snapshot 0817, libalternatives 2.0 and Go 1.27 landed on the core system side, and security updates patched Flatpak, Vim and Python 3.13. The upcoming integration of Qt 6.11.2, KDE Gear 26.08.0, Linux Kernel 7.2 and glibc 2.44 is also tracked.
Reverse Clock for Your Desktop with Girosur - Plasmoids for Plasma 6 (38)
The KDE Blog presents Girosur Clock, the 38th widget in its ongoing Plasma 6 plasmoid series. Created by teovisaires, the analog clock and its hands rotate counterclockwise - fitting for the southern hemisphere - as a playful and original addition to the desktop.
Tiny Wins for Packagers: End-of-Week Update (2026-08-21)
The Open Build Service team shares its end-of-week update with a welcome to new contributor Tanner Kvarfordt, whose first commit was merged. Shipments include the update to Rails 8.1, project authorization handling in Token::ServicePolicy and a new “nocontentchange” publish flag, while build.opensuse.org served 20.2 million HTTP requests and nearly two million package builds.
View more blogs or learn to publish your own on planet.opensuse.org.
Syslog-ng end of August news, and about scaling back Java support
Most of August, I was on vacation, but now I’m back and I try catching up on the events of the past weeks, just like my colleagues do. Currently, we are fixing issues and reviewing contributions, but we also discussed scaling back our efforts on Java support.
While most of the team was away on vacation, the number of syslog-ng contributions suddenly grew. We support both autotools and cmake, and while differences are narrowing, there are still some minor problems to fix. There are pull requests related to cmake, the syslog-ng disk buffer and more. Check https://github.com/syslog-ng/syslog-ng/pulls?q=is%3Apr+ for a full list of pull requests we are working on.
We also received some new issues. One of them was related to a memory leak when syslog-ng is reloaded. While we fixed several problems, Java was not among them. In fact, we rather disabled packaging Java destination support.
To explain this decision: Java support was introduced back when several destinations had no native C drivers and were only implemented in Java. However, Elasticsearch works fine using a wrapper around the http() destination. Kafka now also has a native C driver. And as for HDFS: well, it is dead, and its code will be removed from syslog-ng soon. A few months ago, I also wrote about disabling Java support in my packages. Now the same is happening with Debian / Ubuntu / RHEL packages available from https://www.syslog-ng.com/community/b/blog/posts/syslog-ng-java-destination-disabled At the same time, we also decided not to work on a Java-related memory leak problem, unless we are notified that someone is actually using the Java destination with a self-developed driver. We were aware of such projects 3-4 years ago, but not anymore.
But are there any benefits of not packaging Java, you might ask? Well, in the Debian / Ubuntu world, many users install the syslog-ng package, which is an umbrella package installing all syslog-ng sub-modules and their dependencies. But even without an umbrella package, I have seen similar solutions from RPM users. Removing the unused Java package from the mix reduces both RAM and HDD usage, which benefits everyone.

syslog-ng logo
Originally published at https://www.syslog-ng.com/community/b/blog/posts/syslog-ng-end-of-august-news-and-about-scaling-back-java-support