#openSUSE Tumbleweed revisión de la semana 40 de 2026
Tumbleweed es una distribución de GNU/Linux «Rolling Release» o de actualización contínua. Aquí puedes estar al tanto de las últimas novedades.

openSUSE Tumbleweed es la versión «rolling release» o de actualización continua de la distribución de GNU/Linux openSUSE.
Hagamos un repaso a las novedades que han llegado hasta los repositorios esta semana.
Y recuerda que puedes estar al tanto de las nuevas publicaciones de snapshots en esta web:
El anuncio original lo puedes leer en el blog de Dominique Leuenberger, publicado bajo licencia CC-by-sa, en este este enlace:
Esta semana se ha publicado un total de 3 snapshots (0924, 0929, y 0930).
Estas son las actualizaciones más importantes de esta semana:
- bash 5.3.20
- bash-completion 2.18.0
- bind 9.20.29
- binutils 2.47
- coreutils 9.12
- flatpak 1.18.3 & 1.18.4
- freerdp 3.32.1
- fwupd 2.1.8
- gucharmap 18.0.0
- hwinfo 26.0
- Linux Kernel 7.2.7 y 7.2.8
- llvm23 23.1.2
- meson 1.12.1
- pam 1.7.3
- parted 3.8
- php8 8.5.11
- shadow 4.20.3
- tuned 2.28.0
- unbound 1.26.1
- VirtualBox 7.2.20
- vlc 3.0.24
Y para próximas snapshots, ya se están preparando las siguientes actualizaciones:
- systemd 261.3
- fontconfig 2.18.3
- expat 2.8.5
- Mesa 26.2.4
- NetworkManager 1.58.1
- ncurses 6.6.20260926
- KDE Plasma 6.8 Beta
- Swig 4.5.0
- libnettle 4.0.0
Si quieres estar a la última con software actualizado y probado utiliza openSUSE Tumbleweed la opción rolling release de la distribución de GNU/Linux openSUSE.
Mantente actualizado y ya sabes: Have a lot of fun!!
Enlaces de interés
- ¿Por qué deberías utilizar openSUSE Tumbleweed?
- zypper dup en Tumbleweed hace todo el trabajo al actualizar
- ¿Cual es el mejor comando para actualizar Tumbleweed?
- ¿Qué es el test openQA?
- http://download.opensuse.org/tumbleweed/iso/
- https://es.opensuse.org/Portal:Tumbleweed
——————————–
Tumbleweed – Review of the week 2026/40
Dear Tumbleweed users and hackers,
This week saw the release of 3 snapshots (0924, 0929, and 0930).
Leading off with our previous outlook, both Linux Kernel 7.2.7 and 7.2.8 were successfully delivered across snapshots 0924 and 0929, keeping hardware support on the fast track. Core toolchains and the everyday terminal environment received a healthy refresh with the rollout of binutils 2.47, coreutils 9.12, bash 5.3.20, and an updated bash-completion 2.18.0. Desktop typography also stepped forward with synchronized support for Unicode 18.0 landing across character utilities and emoji fonts.
On the multimedia and desktop front, VLC 3.0.24 arrived with updated FFmpeg support, VirtualBox stepped up to version 7.2.20, and Flatpak saw two quick bugfix releases (1.18.3 & 1.18.4). Package maintainers also tightened system security defaults and delivered fixes across X11 libraries, GIMP, and Emacs, while kernel-firmware received an extensive sync with upstream.
These 3 snapshots delivered the following updates:
- bash 5.3.20
- bash-completion 2.18.0
- bind 9.20.29
- binutils 2.47
- coreutils 9.12
- flatpak 1.18.3 & 1.18.4
- freerdp 3.32.1
- fwupd 2.1.8
- gucharmap 18.0.0
- hwinfo 26.0
- Linux Kernel 7.2.7 & 7.2.8
- llvm23 23.1.2
- meson 1.12.1
- pam 1.7.3
- parted 3.8
- php8 8.5.11
- shadow 4.20.3
- tuned 2.28.0
- unbound 1.26.1
- VirtualBox 7.2.20
- vlc 3.0.24
Turning our attention to the horizon, here is a look at what is currently brewing across the staging projects:
- systemd 261.3: D-Bus security review has completed and the package is checked into Factory for the next snapshot.
- fontconfig 2.18.3: The AppStream test suite conflict has been resolved, with the package checked into Factory.
- expat 2.8.5: Progressing through staging alongside companion fixes for perl-XML-Twig.
- Mesa 26.2.4
- NetworkManager 1.58.1
- ncurses 6.6.20260926
- KDE Plasma 6.8 Beta: Testing continues in staging while resolving build failures in kwin6-x11 and libksysguard6, along with installcheck issues.
- Swig 4.5.0: YaST integration issues remain under investigation, tracked under boo#1275515.
- libnettle 4.0.0: Remains explicitly excluded from main staging runs while developers work on resolving test suite breakages in libzypp.
Recopilación del boletín de noticias de la Free Software Foundation – octubre de 2026
Recopilación y traducción del boletín mensual de noticias relacionadas con el software libre publicado por la Free Software Foundation.

La Free Software Foundation (FSF) es una organización creada en Octubre de 1985 por Richard Stallman y otros entusiastas del software libre con el propósito de difundir esta filosofía, frente a las restricciones y abusos a los usuarios por parte del software privativo.
La Fundación para el software libre (FSF) se dedica a eliminar las restricciones sobre la copia, redistribución, entendimiento, y modificación de programas de computadoras. Con este objeto, promociona el desarrollo y uso del software libre en todas las áreas de la computación, pero muy particularmente, ayudando a desarrollar el sistema operativo GNU.
Mensualmente publican un boletín (supporter) con noticias relacionadas con el software libre, sus campañas, o eventos. Una forma de difundir los proyectos, para que la gente conozca los hechos, se haga su propia opinión, y tomen partido si creen que la reivindicación es justa!!
- En este enlace podéis leer el original en inglés: https://www.fsf.org/free-software-supporter/2026/october
- Y traducido en español (cuando el equipo de traducción lo tengamos disponible) en este enlace: https://www.fsf.org/free-software-supporter/2026/octubre

Puedes ver todos los números publicados en este enlace: http://www.fsf.org/free-software-supporter/free-software-supporter
¿Te gustaría aportar tu ayuda en la traducción y colaborar con la FSF? Lee el siguiente enlace:
Por aquí te traigo un extracto de algunas de las noticias que ha destacado la FSF este mes de octubre 2026.
Cual es el problema con GitHub
Del 14 de septiembre por Jacob Bachmeyer y Richard Stallman
GitHub, un sitio web privativo para desarrolladores para compilar, almacenar, gestionar y compartir código, no es tan neutral como podría parecer a primera vista. Aunque probablemente haya otros problemas con GitHub, los principales problemas relacionados con la libertad son los siguientes: promoción de prácticas de licencias vagas y confusas; uso forzado de JavaScript no libre para muchas acciones; una variedad de servicios como sustituto de software (SaaSS) desactivados; y centralización intencionada en un sistema distribuido.
Si tú o alguien que conoces utiliza GitHub, te animamos a informarte a ti mismo y a otros sobre por qué GitHub es perjudicial para la libertad del software.
- https://www.gnu.org/philosophy/whats-wrong-with-github.html
- https://www.gnu.org/philosophy/who-does-that-server-really-serve.html
LG acusada de ‘flagrante invasión de la privacidad’ por la recopilación de datos que realizan sus televisiones
Del 8 de septiembre por Connor Jones
Según investigadores de Gamers Nexus, recientemente se sorprendió a los televisores «inteligentes» de LG escaneando redes locales e identificando dispositivos que nunca habían estado conectados al televisor, incluidos teléfonos, impresoras, unidades de aire acondicionado, y la lista continúa. Estos investigadores también informaron que estos televisores «inteligentes» siguen captando audio mucho después de que se active el reconocimiento de voz, incluso cuando el dispositivo está en espera.
LG desestimó estas afirmaciones e incluso afirmó que es «normal» que los televisores «inteligentes» escaneen continuamente dispositivos cercanos. La similitud de este problema no puede usarse para justificar esta grave violación de la privacidad y los derechos de los usuarios.
Puedes saber más sobre cómo LG podría estar infringiendo los derechos de los usuarios en los siguientes artículos.
- https://www.theregister.com/security/2026/09/08/lg-accused-of-egregious-invasion-of-privacy-over-tv-data-collection/5294956
- https://www.fsf.org/campaigns/surveillance

Estas son solo algunas de las noticias recogidas este mes, ¡¡pero hay muchas más muy interesantes!! si quieres leerlas todas (cuando estén traducidas) visita este enlace:
Y todos los números del «supporter» o boletín de noticias de 2026 en español, francés, portugués e inglés aquí:
10 razones para asistir a Akademy-es 2026 de Madrid #akademyes
Del 23 al 25 de octubre, es decir, a menos de un mes vista, se va a celebrar en Madrid la esperada Akademy-es 2026, el encuentro organizado por KDE España para todos los simpatizantes del proyecto que este año será presencial y en línea (si es posible), y es una edición muy especial por muchas razones. Como os evidente os animamos a asistir y por ello en el blog estamos promocionado al máximo el evento. Hoy presentamos 10 razones para asistir a Akademy-es 2026 de Madrid, aunque estoy seguro que existen como mínimo 10 más.
10 razones para asistir a Akademy-es 2026 de Madrid #akademyes
Ya no queda menos para Akademy-es 2026 de Madrid y como ya he anunciado, he decidido que muchos artículos versarán sobre este magno evento, corriendo el riesgo de ser criticado como hace un par de años… pero como es mi blog (y ahora más que nunca) hago lo que quiero. De esta forma he pensado en 10 razones para acudir a Akademy-es 2026 de Madrid aunque en realidad hay muchas más y seguro que alguno de vosotros me las puede sugerir en los comentarios.

De esta forma, la lista sin orden de preferencia es la siguientes:
- Asistir a las charlas de los proyectos más punteros de la Comunidad KDE en castellano. (El programa todavía no está publicado pero pronto lo estará)
- Celebrar los 30 años de KDE o los 20 años de Akademy-es en un ambiente único. ¡Es la primera vez que se celebra así un Akademy-es!
- Disfrutar de un ambiente campestre y comunitario en el Camping Arco Iris (Villaviciosa de Odón) de Madrid. Reserva si todavía no lo has hecho.
- Charlar por las zonas comunes del Camping pasillos, en las comidas o en las cenas con los desarrolladores, traductores, artistas, ideólogos, usuarios destacados, etc. de la Comunidad KDE y del Conocimiento Libre.
- Conocer la increíble y, creo que algo desconocida, zona campestre de Madrid… sin olvidar que que estás cerca de una gran capital cultural de Europa.
- Conocer a personas extraordinarias (José, Albert, Rubén, Adrián, Rosie y muchas más que me dejo en el tintero)
- Poder tocar dispositivos que llevan Plasma instalado por defecto como un KDE Slimbook 6 o una Steam Deck (esperemos).
- Adquirir tu camiseta KDE de la mano de Freewear y que no te venga ni grande ni pequeña.
- Poder aparecer en la magnífica foto de grupo que queda para la posteridad y que suele ser protagonista en posteriores ediciones, como es el caso de la inferior de Málaga.
- Y, lo más importante, participar de un evento que el que prueba repite.
Todo esto sin olvidar que puedes participar activamente en Akademy-es colaborando en su difusión en la redes sociales, no olvides utilizar la etiqueta #akademyes para ello. Toda ayuda es importante.
¿Qué es el Akademy-es?
Akademy-es es el encuentro anual de desarrolladores, colaboradores y usuarios de KDE en España, que se celebra desde el año 2006 en distintas ciudades del territorio español y con esta se llegará a la decimotercera edición.
Por cierto, podéis repasar las anteriores ediciones en estas entradas del blog:
- Camino Akademy-es 2013: Las anteriores ediciones (I): 2006–2008
- Camino Akademy-es 2013: Las anteriores ediciones (II): 2009-2010
- Camino Akademy-es 2013: Las anteriores ediciones (III): 2011-2012
- Camino Akademy-es 2013: Las anteriores ediciones (IV): 2013-2014
La entrada 10 razones para asistir a Akademy-es 2026 de Madrid #akademyes se publicó primero en KDE Blog.
We Are Launching the Content Moderation Feature
Foto de grupo Akademy 2026 de Graz, Austria
No hay evento que se precie que no tenga su instantánea comunitaria, y las reuniones de la Comunidad KDE no puede ser una excepción. He aquí pues la foto de grupo Akademy 2026 de Graz que se realizó del 19 al 24 de septiembre y del que podemos encontrar varios artículos en el Planer dedicados al evento.
Bien sea para mostrar al mundo toda la gente que asiste al evento, bien sea para inmortalizar el momento o simplemente para reunir a la mayor parte de los asistentes en un lugar, las fotografías de grupo son de obligada realización en cualquier reunión.
La foto de grupo es un momento especial en todas las Akademy, todo el mundo suele estar de buen humor y se suceden las bromas. También es un gran momento para presentar y dar a conocer a asistentes de proyectos diferentes.
Foto de grupo Akademy 2026 de Graz, Austria
Como hemos comentado, la Akademy de este año tuvo lugar en Graz (Austria), capital de Estiria. Su centro histórico, inscrito en la Lista del Patrimonio Mundial de la UNESCO, reúne calles y edificios de distintas épocas. Aquí conviven ese patrimonio, la actividad académica de la TU Graz —sede de esta edición— y dos iconos de la arquitectura contemporánea: el Kunsthaus Graz y la Murinsel, una estructura flotante sobre el río Mur.
Este año se celebra el trigésimo cumpleaños de KDE, lo cual ha convertido esta edición en algo muy especial reuniendo no solo a colaboradores, usuarios y socios, sino que también ha sido un lugar de reflexión sobre las tres décadas de comunidad, colaboración, innovación y software libre.

Si pincháis en la imagen podréis verla un poco más grande.
¡KDE Rocks!
¿Qué es Akademy?
Para los que no lo sepan, Akademy es el evento de la Comunidad KDE que aúna en una gran conferencia todo tipo de simpatizantes de KDE como desarrolladores, diseñadores, usuarios, traductores, promotores. Allí se reunirán a lo largo de una semana para compartir charlas, cenas, ponencias, talleres y, en definitiva, para trabajar juntos.
Es una gran semana que sirve para unir más fuerte los lazos que unen nuestra Comunidad, así como para crear nuevos
La entrada Foto de grupo Akademy 2026 de Graz, Austria se publicó primero en KDE Blog.
Tumbleweed Monthly Update - September 2026
There were several software package updates for openSUSE Tumbleweed during the month of September and with openSUSE.Asia Summit 2026 about to begin, we are bringing the monthly review to you early.
September delivered a stacked month of snapshots across the desktop, developer tooling, and security surface. KDE Plasma 6.7.5 landed with fixes for KWin display management and taskbar refinements, while KDE Frameworks 6.30.0 and KDE Gear 26.08.1 delivered new features and bugfixes across the KDE ecosystem. glibc jumped to 2.44 with Transparent Huge Pages tunables and optimized math functions, and LLVM 23.1.1 arrived with important bugfixes. Mesa progressed from 26.2.2 to 26.2.3 and the Linux kernel advanced through 7.2.5 to 7.2.7 with a sustained focus on security. Later in the month the GNOME desktop picked up 50.5 across gnome-shell and mutter, GIMP advanced to 3.2.6, coreutils jumped to 9.12, and rsync arrived at 3.5.1 after a sweeping audit of its path handling and daemon protocol. curl addressed seven CVEs, pcre2 patched six security issues, and ffmpeg rolled up more than 20 CVEs in one pass.
As always, be sure to roll back using snapper if any issues arise.
For more details on the change logs for the month, visit the openSUSE Factory mailing list.
New Features and Enhancements
KDE Plasma 6.7.5: The fifth bugfix release of the Plasma 6.7 series brings targeted refinements across the desktop. KWin fixes the global removal timer timeout for unplugged outputs, and Discover resolves update stalling when fwupd is unavailable and a regression where updates were mistaken for needing a reboot. Spectacle fixes a crash during window-under-pointer detection and annotation submenu overflow, while the taskbar applet corrects right-to-left layout rendering and prevents duplicate favorites launching on Space.
KDE Frameworks 6.30.0: A feature release of the KDE component libraries that arrives with refinements across KIO, Kirigami, and KTextEditor. KIO fixes FTP command case consistency, corrects folder size reporting to include filesystem overhead, and lets a folder with the setgid bit propagate its group to copied files. KTextEditor gains vi-mode filename registers and fixes block operations with tabs. Baloo now excludes .snapshots folders from indexing, KCalendarCore adds recurrenceDescription and translated enum names, and KCodecs improves encoding detection with better confidence scoring. Syntax Highlighting adds DotEnv, KDL, and Just language support, and KGuiAddons adds a geo: URI handler for Cartes.
KDE Gear 26.08.1: The first bugfix release of the 26.08 series arrives with targeted fixes across the KDE application collection. Dolphin fixes the active split pane not being set correctly, corrects default zoom level calculations based on preview state, and prevents zero icon sizes in item layouts. Okular fixes a crash on broken DVI files, addresses dangling form field pointers after saving, and backports a Synctex security fix. Konsole corrects OSC22 mouse cursor shapes for splits and fixes focus shortcut issues in ViewSplitter. Kitinerary adds parsers for Air Canada and Lufthansa PDF itineraries and optimizes Wikidata train station queries. KOrganizer fixes search dialog functionality after editing a result.
GNOME Shell & mutter 50.5: The GNOME desktop received quality-of-life fixes that clean up day-to-day use. The unlock dialog handles keyboard navigation correctly, the screen will no longer unlock once a screen time limit has been reached, and toggling the wireless switch no longer blocks. On the compositor side, mutter fixes a hang on external monitor hotplug, stops multiple monitors from all being reported as primary, corrects desaturated SDR content in HDR mode, and adds per-view control over the software cursor overlay. libadwaita 1.9.4 arrived alongside with annotation and idle-callback fixes in AdwAnimation, AdwActionRow, AdwTabBar and AdwTabGrid, and GNOME Maps 50.5 fixed the secondary icons shown for recent and favorite places in initial search results.
GIMP 3.2.6: The image editor continued its 3.2 series with a large batch of fixes and some preparation for a future GTK 4 port. The Heal tool no longer leaves a dark smudge at crop boundaries, the Crop tool keeps vector layers in place, and the Color Picker correctly honours the Sample Merged option on single-layer images. Layer groups with non-destructive filters no longer get an unwanted pass-through reduction, plug-in pipes and process watching are better managed on exit so fewer warnings appear when closing GIMP, and clipboard brush and pattern sizes are raised to 8192 on AArch64. The XCF format is bumped to version 26 to record path visibility locks and channel filters.
Shotwell 33.0: The GNOME photo manager completed its port to GTK 4, moving to version 33 after the long-running 0.32 series. Printing was reworked, the publishing targets gained a “peek password” icon and now use a simple localhost web server instead of a dedicated authentication helper, and toast notifications replace many of the simpler dialogs. Face detection and recognition see a long list of fixes around names, highlighting and random matching, and the viewer mode now shows system information and can be opened for arbitrary URIs.
glibc 2.44: A major version bump that brings system-wide tunables via /etc/tunables.conf and a new glibc.elf.thp tunable that maps read-only segments with Transparent Huge Pages when the kernel has not disabled THP. The malloc page size is now capped to MAX_THP_PAGESIZE, and the CORE-MATH project contributions bring additional optimized and correctly rounded math functions. On AArch64, log, exp, sin, cas, sinh, cosh, and other special cases are vectorized for SVE and AdvSIMD, while RISC-V gains vector extension optimized variants of memcmp, memcpy, strcmp, strlen, and more. The release also carries two security fixes for stack-based buffer clashing during tilde expansion in wordexp (CVE-2026-6791) and an invalid free() call with WRDE_APPEND (CVE-2026-6368).
LibreOffice 26.8.0.3: A major version bump from the 26.2 series that brings updated bundled pdfium to 7681 and Skia to m147 as required by the new download configuration. The release drops Qt 5 support in Tumbleweed in favor of Qt 6, aligning with the broader KDE ecosystem move away from Qt 5. Users of the office suite will see improved compatibility and performance across Writer, Calc, and Impress.
LLVM 23.1.1: A bugfix release for the LLVM 23.1.0 series that addresses issues found since the initial release. The update is API and ABI compatible with 23.1.0, making it a safe upgrade for developers who depend on the Clang compiler, LLVM libraries, and related tooling. This is particularly relevant for users building packages that depend on the LLVM infrastructure for compilation.
harfbuzz 14.4.0 & 14.5.0: The text shaping engine that underpins rendering in browsers, desktop environments, and document editors received important improvements. In 14.4.0, glyph positions and extents now saturate instead of overflowing, Arabic Windows-1256 fallback shaping is enabled on all platforms, the COLR sweep gradient truncation and unbounded memory use are fixed, and subsetting is faster especially for large GSUB/GPOS and CFF tables. Version 14.5.0 then updated the Unicode data to 18.0, adding script values for Jurchen, Proto-Cuneiform and Seal along with the matching shaping support, and introduced rendering work budgets shared across the raster, vector, GPU and Cairo renderers so nested outline work stays bounded. The DirectWrite backend no longer uses the C++ runtime, and the HarfRust integration shaper sees various improvements.
bubblewrap 0.12.0: The Linux sandboxing tool removes support for building a setuid binary, as all modern distributions now support unprivileged user namespaces. A security fix resolves a symlink issue where a file or directory creation during sandbox setup could follow parent symlinks out of the sandbox. The --not-a-security-boundary flag is added for cases where some sandbox setup failures should not be fatal.
Key Package Updates
Linux kernel 7.2.2 through 7.2.7: The kernel progressed through six point releases during September with a sustained focus on security and stability. Version 7.2.2 carried fixes for ptp vmclock read-only mapping vulnerability and GSO state stripping from fragments before forwarding . Version 7.2.3 addressed an extensive list of USB fixes including use-after-free in usbdev_release(), ALSA USB audio out-of-bounds write in snd_usbmidi_novation_output(), and KVM SEV improvements for SNP guests. Version 7.2.4 added fixes for dm-pcache use-after-free, wifi driver memory leaks across mt76, iwlwifi, and brcmfmac, and I3C device master use-after-free in the unregister path. Version 7.2.5 was dominated by backports, among them a large sweep of NFC fixes bounding device-reported lengths, rejecting undersized LLCP PDUs, and fixing an out-of-bounds write in nci_target_active, alongside futex priority-inheritance races and io_uring iovec leaks. Version 7.2.6 brought an exceptionally long list of nfsd hardening patches covering use-after-free in the fcache disposal path, layout_fence_worker double references, and nfsd_file leaks on inter-server COPY, plus a clocksource IRQ leak fix and an iomap integrity-payload fix. Version 7.2.7 wrapped up the month with a broad set covering Btrfs write-protection during data writeback, AppArmor credential use-after-free and a null-termination out-of-bounds write, mm and MGLRU correctness, and a large group of tracing use-after-free and crash fixes.
Mesa 26.2.2 & 26.2.3: Two bugfix releases landed on the 26.2 branch. Alongside the usual stream of regression fixes, openSUSE’s build gained the rocket Gallium driver for Rockchip NPUs on aarch64, and the new Mesa-teflon-delegate subpackage ships a TensorFlow Lite delegate for NPUs. The changelogs point to the Mesa 26.2.2 and Mesa 26.2.3 release notes for details, and the LLVM 23 build fix that unblocked both releases came along with them. Users on AMD, Intel, or Qualcomm hardware who experienced rendering issues after earlier Mesa updates should find these releases more stable.
rsync 3.5.1: The file synchronization tool received a sweeping security overhaul. A focused audit of path handling and the daemon protocol, a companion fuzzing pass and external reports produced 33 fixes covering restricted-directory escapes in rrsync, daemon module-root chdir escapes under use chroot = no, --relative implied-parent creation escaping the destination tree, daemon --filter merge file bypasses, and a range of symlink races on the sender and receiver sides. The release also fixes an unauthenticated TLS connection in rsync-ssl and a hosts deny rule that failed open when a configured hostname could not be resolved. A 3.5.1 follow-up in the same snapshot fixed several path-handling regressions from 3.5.0, restored access to /dev/stdin and friends inside user namespaces, tightened partial-directory validation on the receiver, added support for internationalised domain names, and bumped the protocol number to 33.
util-linux 2.42.3: The Linux utility suite received a security-focused point release. Four mount(8) and namespace-related CVEs are fixed, including post-mount hooks running after an external mount helper fails and a time-of-check/time-of-use race on the source path in restricted SUID mode. wall and write gained an additional fix for terminal escape sequence injection through the banner hostname, complementing the earlier CVE-2024-28085 work. Alongside the security work, the release fixes an out-of-bounds read of the ISO9660 root directory record in libblkid, an out-of-bounds write in get_line() on invalid multibyte input, and a pg out-of-bounds access on a trailing tab.
PipeWire 1.6.9: The sound and video server shipped a bugfix release that is API and ABI compatible with the rest of the 1.6 series. RAOP (AirPlay) support sees the most work, with encryption fixed for OpenSSL 3 and above, truncated audio and metadata update problems resolved, and RAOP over TCP fixed. The resampler cutoff frequencies were tweaked to preserve more high frequencies when upsampling, potential overflows in client node buffer checks were fixed, and pw-cat now handles EOF correctly for encoded files while pw-record supports A-law.
poppler 26.09.0: The PDF rendering library jumped two minor releases, picking up 26.08.0 on the way. Fonts are now subset when saving changes in annotations and forms through fontconfig, which required making harfbuzz a build dependency. pdftotext gains a -urls option to print link URLs next to their text, pdftohtml no longer crashes when using data URLs and skips tiling patterns earlier for speed, and pdfimages gains min-height and min-width options. The core also stops infinite looping on a wrong NSS password and fixes crashes on malformed documents.
BlueZ 5.87: The Bluetooth stack jumped five releases from 5.82, bringing LE Audio and profile work along with it. Version 5.83 added AVDTP TX timestamps and fixed handling of BAP PAC removal, broadcast receiver SIDs, and HID service records; 5.84 added unicast endpoint reconfiguration, encrypted broadcast sources and HFP Caller Line Identification; 5.85 added HFP call answer and simple 3-way call support and corrected battery charge level display; 5.86 added the Telephony, Ranging, GMAP and TMAP profiles and fixed the G.722 16 kHz codec ID; and 5.87 resolved a long list of BAP, BASS, PBAP, MCP, AVRCP and GATT database issues.
cryptsetup 2.8.8: The disk encryption tool received a feature and hardening release. integritysetup gained support for keyed discards via a new --allow-discards-keyed option, which permanently upgrades the superblock so that an integrity device in standalone mode with a keyed integrity algorithm can no longer have part of itself wiped with a discard pattern. The library also closes a time-of-check/time-of-use issue in LUKS header restore by opening the device only once, which affects both LUKS1 and LUKS2, hardens BITLK metadata validation against a wrong key buffer size and a deliberate infinite loop, and fixes a possible integer overflow in the anti-forensic data size calculation on 32-bit systems.
gzip 1.15: The ubiquitous compression utility reached a new major version, landing fixes for two earlier security issues and a batch of long-standing bugs. A buffer overflow when decompressing an .lzh file after a .Z file is fixed, as is a use of uninitialized memory on some malformed inputs. gzip -d no longer rejects PKZIP signatures and local headers that legitimately appear in well-formed streamed zip files, diagnostics now quote file names containing unusual characters, and gzip --synchronous works again on platforms with O_PATH. Behaviorally, gzip follows the locale from the environment instead of insisting on the C locale, and -l reports -Inf% rather than 0.0% for an empty file.
libinput 1.32: The input handling library arrived with input-device improvements. Circular scrolling now works on circular touchpads such as the Panasonic CF-SV1, dragging on a touchpad automatically enables a drag lock when a finger nears the edge, and disable-while-typing no longer cancels an interaction already in progress. Tablets can now map the physical eraser button to any button, and libinput record accepts a --no-events flag.
lightdm 1.33.1: The display manager received a bugfix release with a notable feature. A Qt6 client library is now shipped alongside the Qt5 one, and the release fixes user switching after logind dropped the CanMultiSession property. Wayland sessions are now allowed on seat0 without VTs, PAM modules that change the home directory are handled correctly, the VNC server command is honored with IPv6 tried first for the bind, a local X server is not reused when the hostname has changed, and memory leaks in session_child_run are plugged.
AppStream 1.2.0: The software metadata standard reached a new major version and marks the libappstream-compose API as stable. appstream-compose gains an out-of-process media worker with a basic Landlock-based sandbox, switches image processing from GdkPixbuf to VIPS, and makes JPEG XL the default output format. New <heading> markup is supported in AppStream descriptions, and the news tools gain inline Markdown support along with header handling across the XML, YAML and Markdown conversions.
xz 5.8.4: The compression library received a bugfix release that includes a security fix. An invalid memory access in lzma_alone_decoder(), lzma_lzip_decoder(), lzma_auto_decoder() and lzma_microlzma_decoder() after a failed allocation is followed by decoder reinitialization is fixed, along with two use-after-free bugs in xz itself via --files/--files0 and --verbose with redirected stderr. Landlock ABI 9 support is added, a performance issue and theoretical integer overflow in lzma_index_cat() are fixed, and xz --list no longer overflows its totals.
VirtualBox 7.2.18: The VirtualBox hypervisor received a bugfix release. Data corruption in VDI differencing images after writing full blocks of zeroes and reopening the image is fixed, a VM process crash on Linux hosts with 3D acceleration enabled is resolved, and the shared clipboard no longer strips the first character from a file name located directly in a filesystem root. Linux 7.3-rc support is added.
libgcrypt 1.12.4: The GnuPG cryptographic library received a follow-up point release. RSA PSS handling of very large salt lengths is fixed, the length of hashed input is validated for RSA PSS, and the RSA OAEP decoder validates all-zero padding for correctness. Padding in cSHAKE was corrected against NIST ACVP conformance vectors, and a build problem with some compiler versions around SM4 instructions is resolved.
GStreamer 1.28.7: A wide-ranging update across the core and plugin packages with both security and playback fixes. The appsrc element fixes a regression where pushing EOS into a blocked appsrc would stall, and glcolorconvert fixes compatibility with older OpenGL and GLSL versions. The mxfdemux element resolves keyframe detection regressions and possible artifacts after seeking, and rtpmanager fixes crashes on malformed RTCP SDES due to uninitialized values. The Rust-based plugins gain DoS protection in rtpsession and limit the number of remote sources tracked in rtprecv. Security fixes span multiple parsers including pnmdec and onnx, and the x264enc high bit depth support is fixed in binary packages.
ffmpeg 8: A massive security update carrying more than 20 CVE patches. Fixes address out-of-bounds reads and writes across numerous demuxers and decoders including HEVC, CineForm, TIFF, Screenpresso, and DVB subtitle parsers. The RTP muxer receives bounds checks for AV1, VC-2, and ASF objects, and the MPEG muxer rejects stream counts that overflow the system header. This is an essential update for any system that processes media files, as the vulnerabilities could be triggered by crafted input.
dracut: Received a security fix for CVE-2026-6893, a root code execution vulnerability via DHCP options command injection. The fix sanitizes values written to network override files, gateway files, and hostname files, and strips DHCP-supplied domains to a safe charset. This is important for any system that uses dracut-generated initrd images with network boot configurations.
Security Updates
rsync 3.5.1:
-
CVE-2026-53783: Fixes an
rrsyncrestricted-directory escape via a validation-versus-execution race and an unsafe option allowlist. -
CVE-2026-53784: Addresses a daemon module-root
chdirescape underuse chroot = no. -
CVE-2026-53785: Resolves
--relativeimplied-parent creation escaping the destination tree. -
CVE-2026-53786: Fixes a daemon
--filtermerge file bypassing the module filter list. -
CVE-2026-53788: Addresses the daemon name-converter accepting newline-bearing names into its line protocol.
-
CVE-2026-53789: Corrects a malicious sender expanding
--deletescope by reclassifying an implied parent. -
CVE-2026-53790: Fixes command and argument injection via unquoted peer- or host-controlled values.
-
CVE-2026-53791: Addresses PROXY-protocol mode letting a direct client spoof the daemon’s source address.
-
CVE-2026-53792: Resolves a receiver-supplied zero checksum block length driving the sender into a negative match.
-
CVE-2026-53793: Fixes a chroot
/./inner-module escape via a parent-component symlink. -
CVE-2026-53794: Addresses a remote peer disabling the per-allocation sanity cap via
--max-alloc=0. -
CVE-2026-53795: Corrects a receiver write escape via an absolute
--temp-diror--link-destdisabling rename and link confinement. -
CVE-2026-53796: Fixes a non-daemon receiver destination-
chdirsymlink race. -
CVE-2026-53797: Addresses a sender source-tree parent-component symlink race leading to out-of-tree disclosure.
-
CVE-2026-53798: Resolves the daemon name-converter mapping an unknown name to uid/gid 0 on an empty response.
-
CVE-2026-53799: Fixes receiver ACL and xattr application following a symlink race for arbitrary ACL setting and local privilege escalation.
-
CVE-2026-53800: Addresses sender
--remove-source-filesunlink following a parent-component symlink race for arbitrary file deletion outside the source tree. -
CVE-2026-53801: Corrects sender and daemon directory-scan enumeration escaping the transfer root for out-of-tree disclosure.
-
CVE-2026-53802: Fixes arbitrary file read and transfer shaping via symlinked operator-supplied input files.
-
CVE-2026-53803: Addresses arbitrary file write and privilege escalation via symlinked operator-supplied output paths.
-
CVE-2026-70463: Fixes
auth usersignoring documented comma-only parsing and silently skipping a deny or read-only rule. -
CVE-2026-70462: Addresses a peer-supplied
MSG_IO_TIMEOUTdefeating the client’s own I/O timeout through signed overflow and a non-positive value. -
CVE-2026-70461: Resolves a peer-driven one-byte heap out-of-bounds write in
add_implied_include(). -
CVE-2026-70460: Fixes a daemon module-root escape through a peer-supplied
--partial-diror--backup-dirresolving via an in-module symlink. -
CVE-2026-70459: Addresses a per-connection daemon child crash from a crafted first incremental file list with a non-directory transfer root.
-
CVE-2026-70458: Corrects an out-of-bounds write from a
FLAG_HLINKEDfile entry accepted without-H. -
CVE-2026-70457: Patches an attacker-chosen-offset write in
parse_size_arg()error formatting. -
CVE-2026-70456: Fixes a remote out-of-bounds heap write in
read_args()when the argument count lands exactly onmaxargs. -
CVE-2026-70454: Addresses
rsync-sslestablishing an unauthenticated TLS connection with no CA verification and no stunnel hostname binding. -
CVE-2026-70453: Resolves quadratic CPU exhaustion in
hash_search()from a crafted equal-weak-checksum chain. -
CVE-2026-70464: Fixes an unauthenticated pre-transfer handshake denial of service locking out an rsync daemon module.
-
CVE-2026-70455: Addresses peer-controlled Zstandard worker exhaustion on an rsync daemon.
-
CVE-2026-70452: Corrects
hosts denyfailing open when a configured hostname cannot be resolved, admitting the host it was meant to block. -
CVE-2025-10158: Fixes an out-of-bounds array access via a negative index.
-
CVE-2026-41035: Addresses a count of entries mismatch leading to a use-after-free.
-
CVE-2026-43617: Resolves authorization bypass via hostname resolution.
-
CVE-2026-43618: Addresses a second authorization bypass, tracked separately from CVE-2026-43617.
-
CVE-2026-29518: Fixes integer overflow information disclosure.
-
CVE-2026-43619: Addresses a symlink race condition via path-based syscalls.
-
CVE-2026-43620: Corrects an out-of-bounds array read via
recv_files(). -
CVE-2026-45232: Fixes an off-by-one stack out-of-bounds write in HTTP CONNECT proxy response parsing.
python313 3.13.15:
-
CVE-2026-19672: Fixes a
tarfilemember that leaves the destination directory and comes back. -
CVE-2026-17084: Addresses Unicode codepoint attributes outside RFC 3454 being considered valid.
-
CVE-2026-15308: Resolves quadratic complexity in incremental parsing of long unterminated constructs in
html.parser.HTMLParser, exploitable for denial of service. -
CVE-2026-6879: Corrects quadratic behavior in
xml.etree.ElementTree.Elementfindall(),iterfind()andfind()when using XPath index predicates on documents with many same-tag siblings. -
CVE-2026-4360: Fixes
tarfile.TarFile.extract()not applying the given filter when it extracts a link target from the archive as a fallback. -
CVE-2026-11972: Addresses
tarfileseeking a stream continuing past the end of the stream. -
CVE-2026-11940: Resolves a bypass of CVE-2025-4330 where crafted archives could create a symlink pointing outside the destination directory through the
tarfiledata and extraction filters. -
CVE-2026-0864: Corrects line endings in multi-line
configparservalues not being normalized to LF+TAB. -
CVE-2025-15366: Fixes NUL, CR and LF characters being accepted in IMAP commands.
-
libexpat 2.8.2: The bundled libexpat is updated to 2.8.2.
util-linux 2.42.3:
-
CVE-2026-76642: Fixes
mount(8)post-mount hooks executing after an external mount helper fails, allowing privileged operations on the pre-existing target filesystem. -
CVE-2026-78410: Addresses a
mount(8)time-of-check/time-of-use race on the source path in restricted SUID mode, letting a local attacker redirect a privileged mount or post-mount ownership change. -
CVE-2026-78409: Resolves an
X-mount.subdirsymlink escape from a detached mount tree inmount(8). -
CVE-2026-78408: Fixes a file descriptor leak in
nsenter(1)andunshare(1)where descriptors were not created withO_CLOEXEC. -
Hostname escape sequence injection: An additional fix for CVE-2024-28085 sanitizes the hostname interpolated into the
wall(1)andwrite(1)banner headers, which an unprivileged user could otherwise poison via a user namespace hostname.
tesseract-ocr:
-
CVE-2026-88047: Fixes a stack buffer overflow in
Classify::ReadNormProtoson a crafted traineddata file. -
CVE-2026-88048: Addresses a heap out-of-bounds write and read in
FullyConnected::Forwardvia a dimension mismatch. -
CVE-2026-88049: Resolves a heap out-of-bounds write in
LSTM::Forwardvia anna_/gate-matrix dimension mismatch. -
CVE-2026-88050: Fixes an out-of-bounds write in
UnicharCompressvia unvalidated recoder code values. -
CVE-2026-88051: Corrects a heap out-of-bounds write in
GenericVector<T>::readvia a reserved/size_used mismatch. -
CVE-2026-88052: Patches a heap out-of-bounds write in
UNICHARSET::load_via_fgetsvia a count/insert desynchronization. -
CVE-2026-88053: Addresses a heap out-of-bounds write in
Classify::ReadIntTemplatesvia unvalidated counts in a crafted traineddata file. -
CVE-2026-88054: Resolves a denial of service via an empty-stack dereference at model load.
-
CVE-2026-73067: Fixes a heap out-of-bounds read in
SquishedDawgon a crafted model, already patched in the shipped 5.5.3.
hplip 3.26.6:
-
CVE-2026-91097: Fixes a security vulnerability in the HP Linux Imaging and Printing utilities.
-
CVE-2026-91098: Addresses a security vulnerability in the HP printer and scanner backend components.
-
CVE-2026-91099: Resolves a security vulnerability in HPLIP’s firmware and device handling code.
-
CVE-2026-91100: Corrects a security vulnerability in the HPLIP scan backend.
-
CVE-2026-91101: Patches a security vulnerability in the HPLIP print queue and status handling.
-
CVE-2026-91102: Fixes a security vulnerability in the HPLIP device discovery code.
-
CVE-2026-91103: Addresses a security vulnerability in the HPLIP model and capability database.
-
CVE-2026-91104: Resolves a security vulnerability in the HPLIP fax and scan utilities.
-
CVE-2026-91105: Corrects a security vulnerability in the HPLIP plugin download and verification path.
-
CVE-2026-91106: Patches a security vulnerability in the HPLIP status and configuration tools.
freeipmi 1.6.19:
-
CVE-2026-85504: Fixes a stack-based buffer overflow via malformed Fujitsu SEL long-text responses.
-
CVE-2026-85505: Addresses a denial of service via a stack-based buffer over-read in
ipmi-oem. -
CVE-2026-85506: Resolves arbitrary code execution via a stack-based buffer overflow in
ipmi-oem. -
CVE-2026-85507: Fixes a stack-based buffer overflow in
_output_dell_system_info_cmc_info. -
CVE-2026-85508: Corrects a stack-based buffer overflow in
_output_dell_system_info_cmc_ipv6_info. -
CVE-2026-85509: Patches a stack-based buffer overflow when a BMC returns more bytes than requested.
gvfs 1.60.3:
-
CVE-2026-88924: Fixes the admin backend setting socket ownership after creation rather than before.
-
CVE-2026-84268: Addresses the sftp backend not clamping the
read_replycount to the requested buffer size. -
CVE-2026-84270: Corrects the mtp backend not validating the read size returned by the device.
flatpak 1.18.3:
-
CVE-2026-87766: Fixes a vulnerability in the bundled bubblewrap 0.12.0 sandbox component.
-
CVE-2026-93676: Addresses a vulnerability in the bundled xdg-dbus-proxy 0.1.8 filtering component.
libsoup:
-
CVE-2026-85534: Fixes libsoup 3 sending more body bytes than nghttp2 requested.
-
CVE-2026-85197: Resolves a crash in
on_data_readafter the connection has been destroyed. -
CVE-2026-77680: Corrects a flaw in HTTP Range header processing in libsoup 2.
-
CVE-2026-77014: Addresses the same HTTP Range header processing flaw in libsoup 2.
p11-kit 0.26.5:
-
CVE-2026-18938: Fixes an overflow when decoding nested attributes.
-
CVE-2026-13757: Addresses server-side stack exhaustion via unbounded recursion in RPC attribute parsing by enforcing a recursion depth limit.
sssd:
- CVE-2026-87853: Fixes cross-user impersonation in the IDP provider by correcting user matching in access token evaluation.
PackageKit 1.4.0:
-
CVE-2026-19816: Fixes the dnf5 backend executing
repo-removefor simulated transactions.
curl 8.22.0:
-
CVE-2026-13608: Fixes OpenLDAP SASL authentication bypass.
-
CVE-2026-18924: Addresses HTTP/2 server push use-after-free.
-
CVE-2026-19931: Resolves Negotiate ambient user connection reuse.
-
CVE-2026-80229: Fixes OpenSSL provider use-after-free.
-
CVE-2026-80230: Addresses OpenSSL pinning bypass.
-
CVE-2026-80255: Resolves secure cookie attribute bypass with tab character.
-
CVE-2026-82209: Fixes domain-scoped PSL domain cookie issue.
NetworkManager:
-
CVE-2026-10805: Fixes dhclient accepting unsafe characters in URLs and hostnames.
-
CVE-2026-19685: Addresses 802.1x rejecting
ca-pathfor private connections.
glibc 2.44:
-
CVE-2026-6791: Fixes stack-based buffer clash during tilde expansion in
wordexp. -
CVE-2026-6368: Resolves invalid call to
free()whenwordexpis used withWRDE_APPEND. -
CVE-2026-18374: Fixes a heap buffer overflow in the libio
ccs=handling. -
CVE-2026-19499: Addresses incorrect right-justification in
strfmon. -
CVE-2026-19542: Resolves an out-of-bounds array write in
tdelete. -
CVE-2026-77117: Fixes SHIFT_JISX0213 decoding leaving a pending character set across conversions.
-
CVE-2026-80489: Corrects the same pending character reset problem for EUC_JISX0213 decoding.
exiv2 0.28.9:
-
CVE-2026-68547: Fixes a security vulnerability in EXIF metadata processing.
-
CVE-2026-68546: Addresses a security vulnerability in image metadata handling.
-
CVE-2026-49275: Resolves a security vulnerability in the metadata library.
dracut:
- CVE-2026-6893: Fixes root code execution via DHCP options command injection.
libpcap 1.10.7:
-
CVE-2026-0799: Fixes safe M[] access in the BPF interpreter.
-
CVE-2026-31912: Addresses program bounds checking in
pcap_offline_filter(). -
CVE-2026-31911: Resolves safe opcode failure handling in the BPF interpreter.
-
CVE-2026-6244: Fixes division by zero via
pcap_offline_filter(). -
CVE-2026-6554: Addresses “ja L” looping limit in
pcap_offline_filter(). -
CVE-2026-18313: Fixes memory leak in rpcapd.
-
CVE-2026-18238: Addresses RPCAP_MSG_PACKET validation.
ffmpeg 8:
-
CVE-2026-75147: Fixes OBU size bounding in AV1 RTP keyframe search loop.
-
CVE-2026-75146: Addresses negative fragment index in DASH demuxer.
-
CVE-2026-75145: Resolves OBU size narrowing to
longin AV1 RTP muxer. -
CVE-2026-75144: Fixes data units larger than RTP payload buffer in VC-2 muxer.
-
CVE-2026-75143: Addresses caller buffer size honoring in librist reader.
-
CVE-2026-75142: Resolves stream count overflow in MPEG muxer.
-
CVE-2026-75141: Fixes hvcC NAL array overflow in HEVC demuxer.
-
CVE-2026-70632: Addresses transform-2 output width validation in CineForm decoder.
-
CVE-2026-70631: Resolves inflate output length check in TIFF decoder.
-
CVE-2026-70630: Fixes deflate output length check in Screenpresso decoder.
-
CVE-2026-70629: Addresses uninitialized data on short input in rscc decoder.
-
CVE-2026-70628: Resolves signed overflow in DVB subtitle parser capacity check.
-
CVE-2026-66037: Fixes count_label validation in IAMF parser.
-
CVE-2026-66036: Addresses dynamic frame size support in hqdn3d filter.
-
CVE-2026-65706: Fixes temp row buffer sizing in swaprect filter.
-
CVE-2026-65705: Resolves unneeded variables in floodfill filter.
-
CVE-2026-65704: Fixes AC3 trim underflow in Ty demuxer.
-
CVE-2026-65703: Addresses reference frame handling in TDSC decoder.
-
CVE-2026-64834: Resolves ASF object size validation in RTP decoder.
-
CVE-2026-64833: Fixes DTS core_size bounding in SPDIF encoder.
-
CVE-2026-58049: Addresses DLTA access bounds checking in RASC decoder.
389-ds 3.3.1:
-
CVE-2026-18355: Fixes heap buffer overflow in the SASL I/O layer.
-
CVE-2026-18663: Addresses pre-authentication double-free via critical Session Tracking control.
-
CVE-2026-11770: Resolves pre-auth LDAP filter injection in CleanAllRUV status check.
-
CVE-2026-18453: Fixes pre-authentication NULL pointer dereference via paged results.
-
CVE-2026-15722: Addresses pre-authentication stack buffer overflow via unbounded replica ID parsing.
-
CVE-2026-18922: Resolves stale identity installation following SASL PLAIN authentication.
-
CVE-2026-19843: Fixes Cockpit LDAP editor shell command injection.
-
CVE-2026-76560: Addresses SELFDN ACI bind-rule evaluator incorrect matching.
xen 4.22.0_04:
-
CVE-2026-62437: Fixes memory leak caused by device model IRQ binding.
-
CVE-2026-79602: Addresses improper handling of HVM emulation return codes.
-
CVE-2026-79603: Resolves TLB flushing not happening before page scrubbing.
coreutils:
-
CVE-2026-56391: Fixes read buffer overrun in
uniq -win multibyte locales. -
CVE-2026-56392: Addresses heap overflow in
unexpand -tfor tab values larger thanSIZE_MAX/16.
gegl 0.4.72:
- CVE-2026-18300: Fixes vulnerability in the RGBE loader for large report files.
cups-filters:
-
CVE-2026-64611: Fixes infinite-loop CPU-exhaustion denial of service in
cfIEEE1284NormalizeMakeModelon empty MDL field. -
CVE-2026-64612: Addresses malformed PNG aborting the CUPS image filter process due to missing libpng setjmp recovery.
alsa:
- CVE-2026-90781: Fixes a denial of service via an off-by-one stack buffer overflow in the control interface parser.
cups 2.4.19:
-
CVE-2026-87875: Addresses a heap out-of-bounds read in
cupsUTF32ToUTF8()due to a missing source-length bound, reachable from SNMP supply-description parsing.
7-Zip 26.03:
- CVE-2026-58052: Fixes 7-Zip failing to preserve the Mark-of-the-Web when extracting a crafted archive, which let an extracted file bypass the trust check meant to keep it quarantined.
GIMP 3.2.6:
- CVE-2026-80101: Fixes invalid guards on XWD parameters, which could lead to a buffer overflow when loading a crafted XWD file.
discount 3.0.2.0:
-
CVE-2026-4833: Addresses uncontrolled recursion in
compile()on deeply nested input, leading to stack exhaustion and a crash. The parser now caps nesting depth, defaulting to 200 and tunable via--with-recursion.
libX11:
-
CVE-2026-88806: Fixes a heap-based buffer overflow in the
XkbGetMapreply by checking the keysym range in_XkbReadKeyActions.
libXrender:
-
CVE-2026-88807: Fixes an out-of-bounds write into
screen->subpixelwhen a malicious server replies toXRenderQueryFormatwith anumSubpixelscount greater than the number of screens.
libtpms:
-
CVE-2026-85769: Fixes a heap out-of-bounds read in TPM2 state unmarshalling via an unchecked
block_skip_read()blocksize.
librsvg 2.62.4:
- Use-after-free with nested Xinclude: Fixes a use-after-free when duplicate XML entities appear in nested Xinclude documents.
Users are advised to update to the latest versions to mitigate these vulnerabilities.
Conclusion
September was a busy month for openSUSE Tumbleweed with snapshots delivering a steady cadence of desktop, developer, and security improvements. KDE Plasma 6.7.5 and KDE Frameworks 6.30.0 refined the KDE desktop and added new features, while KDE Gear 26.08.1 stabilized the application suite with fixes across Dolphin, Okular, and Kitinerary. glibc jumped to 2.44 with Transparent Huge Pages tunables and vectorized math functions, and LLVM 23.1.1 arrived with important toolchain bugfixes. The Linux kernel progressed through 7.2.4 with extensive CVE coverage across USB, networking, and virtualization subsystems, and Mesa settled into its 26.2.2 release. LibreOffice advanced to 26.8.0.3 and harfbuzz improved text shaping performance and correctness. The second half of September carried the month’s heaviest security load. rsync 3.5.1 arrived after an audit of its path handling and daemon protocol that turned up more than 40 vulnerabilities, including a set of chroot and rrsync escapes, a hosts deny rule that failed open when a hostname could not be resolved, and an unauthenticated handshake denial of service against a daemon module. On the desktop side, the GNOME stack picked up 50.5 across gnome-shell and mutter, GIMP advanced to 3.2.6, Shotwell reached 33.0, bash-completion 2.17.0 and coreutils 9.12 landed alongside a burst of late-month updates across Mesa 26.2.3, PipeWire 1.6.9, Poppler 26.09.0, BlueZ 5.87, and xz 5.8.4.
Slowroll Arrivals
Please note that these updates also apply to Slowroll and arrive between an average of 5 to 10 days after being released in Tumbleweed snapshot. This monthly approach has been consistent for many months, ensuring stability and timely enhancements for users. Updated packages for Slowroll are regularly published in emails on openSUSE Factory mailing list.
Contributing to openSUSE Tumbleweed
Stay updated with the latest snapshots by subscribing to the openSUSE Factory mailing list. For those Tumbleweed users who want to contribute or want to engage with detailed technological discussions, subscribe to the openSUSE Factory mailing list . The openSUSE team encourages users to continue participating through bug reports, feature suggestions and discussions.
Your contributions and feedback make openSUSE Tumbleweed better with every update. Whether reporting bugs, suggesting features, or participating in community discussions, your involvement is highly valued.
Content Moderation Becomes Stronger
Kew el reproductor de música minimalista e inmersivo para la terminal
El reproductor Kew está pensado para quien desea una experiencia limpia y sin distracciones a la hora de escuchar música de tu colección propia desde la terminal

kew es un reproductor de música para utilizar en la terminal. El proyecto nació en 2022 y está escrito en C y publicado bajo licencia GPLv2+, cuyo desarrollo se realiza en un repositorio en Codeberg. (aunque hay un mirror en GitHub). Ha sido diseñado desde cero para ser rápido, minimalista, inmersivo y divertido de usar.
Este reproductor lo conocí gracias a un comentario de «el chino» a un artículo de Fanta en su web. Así que gracias por dármelo a conocer y hoy quiero darlo a conocer yo en mi blog.
Hace tiempo, para la terminal utilizaba el reproducto moc (del que he publicado varios artículos en mi blog), pero este reproductor ya hace tiempo que está un poco abandonado. Y gracias al comentario en la web de Fanta conocí Kew y lo instalé en mi openSUSE Tumbleweed desde los repositorios.
La verdad es que es muy visual, y sencillo de utilizar. Al ejecutarlo por primera vez, le das la ruta donde se almacena tu música y a partir de ahí ya puedes ir explorando todas sus funcionalidades, mientras tu propia música.
Puedes familiarizarte con el navegador pulsando F6. Aunque el navegador es para la terminal y su uso mediante el teclado, también se integra muy bien el uso del ratón, pudiendo manejarlo y hacer clic con el cursor en muchas partes.
Quizás lo primero sería darle nuestro toque propio, para eso podemos explorar los diferentes temas de color mediante la tecla «t» (theme). Lo más curioso, es que existe un tema en el que los colores se ajustan dependiendo de los colores de la portada del disco que se está mostrando en ese momento.
También podemos ir descubriendo las diferentes formas de mostrarse que tiene mediante la tecla del tabulador. El reproductor muestra una imagen en pantalla de la portada del disco si la guardamos dentro de la carpeta de reproducción que se está reproduciendo en la lista.
Una de nuestra biblioteca de música desde la que podemos reproducir temas mediante Ctrl+g para añadirlos a la lista de reproducción y añadir o quitar nuevos temas o carpetas mediante Enter.
Pulsando el tabulador pasamos a la vista de la carátula con un espectómetro de audio (similar a chafa), e información de la pista y la lista que se está reproduciendo. Otra en la que buscar un término en nuestra colección, para encontrar justo la canción o artista que queremos. Otra con la ayuda y los atajos de teclado con los que podemos controlar el reproductor. Y la última con la lista de reproducción completa.
Todas estas vistas, además de poder recorrerlas con la tecla tabulador, podemos acceder a ellas con las teclas de función de F2 a F6.
El reproductor Kew reproduce los formatos de música más habituales como son: mp3, flac, opus, ogg, m4a (incluyendo alac), raw aac, wav, webm.
Funcionalidades:
- Puede crear listas de reproducción generadas automáticamente basadas en palabras del artista, álbum o nombre de la canción. Por ejemplo: ‘kew nirvana’.
- Reproducción sin espacios en blanco entre temas.
- Prácticamente no requiere ninguna configuración. Funciona nada más instalarlo, aunque después podamos configurar algunas partes.
- Privado y sin necesidad de estar conectado a servidores externos. Tu propia música.
- Música sin distracciones ni manipulación algorítmica.
- Muestra las portadas guardadas de tus discos a todo color en terminales compatibles con sixel.
- Visualizador de espectro.
- Temas generados automáticamente basados en los colores de los álbumes y temas personalizados
- Explorador de bibliotecas musicales.
- Edición de listas de reproducción (añadir, reordenar, eliminar).
- Puedes buscar en tu colección.
- Puede mostrar las letras de las canciones, incluyendo letras de karaoke.
- Integración de escritorio (tanto Linux como macOS).
- Importar/exportar listas de reproducción.m3u.
- Diseños personalizados.
- Disponible en GNU/Linux, FreeBSD, Android, macOS, Windows y otros.
Y además, como he visto que no estaba disponible en español, me he arremangado y me he puesto mi gorra de traducir y he traducido la aplicación para que esté disponible en español:
Y pronto supongo que se incluya. ¡Incluso el desarrollador me ha incluido en la página de créditos! Y algo que me ha gustado es que el desarrollo se realiza en un repositorio de Codeberg.
Prueba esta pequeña joya para escuchar tu música en la terminal. Sin complicaciones, solo tu música local.
Enlaces de interés
Welcome to openSUSE Asia Summit in Yogyakarta
The wait is almost over! 🎉
The openSUSE.Asia Summit 2026 will begin on Oct. 3-4 at UIN Sunan Kalijaga, Yogyakarta.
On behalf of the organizing committee, we would like to warmly welcome everyone to Yogyakarta and to this year’s Summit. We hope you enjoy the talks, workshops, discussions, and all the activities we have prepared for you.
For those visiting Yogyakarta for the first time, don’t forget to enjoy the city as well. Take some time to explore its food, culture, streets, and atmosphere. Yogyakarta has plenty to offer beyond the conference venue.
And for those meeting old friends again, we hope this summit becomes a warm opportunity to reconnect, catch up, share stories, and spend some good time together with the community. ❤️
Let’s make openSUSE.Asia Summit 2026 a memorable gathering!
Welcome to Yogyakarta, and enjoy the Summit! 🦎💚
