ChangeLog for: 2026-01-14 23:17:42

a/bcachefs-tools-1.35.0-x86_64-1.txz: Upgraded. a/mcelog-210-x86_64-1.txz: Upgraded. d/ruby-4.0.1-x86_64-1.txz: Upgraded. kde/marble-23.08.5-x86_64-10.txz: Rebuilt. Recompiled against protobuf-33.4. l/PyQt5_sip-12.18.0-x86_64-1.txz: Upgraded. l/alsa-lib-1.2.15.3-x86_64-1.txz: Upgraded. l/libappindicator-12.10.1-x86_64-1.txz: Upgraded. Thanks to Willy Sudiarto Raharjo. l/libcap-ng-0.9-x86_64-1.txz: Upgraded. l/libfyaml-0.9.2-x86_64-1.txz: Upgraded. l/libgsf-1.14.55-x86_64-1.txz: Upgraded. l/libpng-1.6.54-x86_64-1.txz: Upgraded. This update fixes security issues: Heap buffer over-read in the libpng simplified API function png_image_finish_read() when processing interlaced 16-bit PNGs with 8-bit output format and non-minimal row stride. Integer truncation in the libpng simplified write API functions png_write_image_16bit() and png_write_image_8bit() causes heap buffer over-read when the caller provides a negative row stride (for bottom-up image layouts) or a stride exceeding 65535 bytes. For more information, see: https://www.cve.org/CVERecord?id=CVE-2026-22695 https://www.cve.org/CVERecord?id=CVE-2026-22801 (* Security fix *) l/mozjs140-140.7.0esr-x86_64-1.txz: Upgraded. l/netpbm-11.13.01-x86_64-1.txz: Upgraded. l/nodejs-22.22.0-x86_64-1.txz: Upgraded. l/protobuf-33.4-x86_64-1.txz: Upgraded. Shared library .so-version bump. (Or, at least, we've been told to always expect ABI breakage) l/pygobject3-3.55.0-x86_64-1.txz: Upgraded. Reverted, as 3.55.1 is causing segfaults. Unless there's a good reason, we'll probably wait for 3.56.0. l/python-trove-classifiers-2026.1.14.14-x86_64-1.txz: Upgraded. l/qt6-6.10.1_20251116_56657e03-x86_64-6.txz: Rebuilt. [PATCH] QtQml: Do not clear objects' propertyCaches on last GC run. Thanks to gmgf. Recompiled against protobuf-33.4. l/zug-0.1.2-x86_64-1.txz: Upgraded. n/dnsmasq-2.92-x86_64-1.txz: Upgraded. n/mosh-1.4.0-x86_64-16.txz: Rebuilt. Recompiled against protobuf-33.4. xap/mozilla-firefox-140.7.0esr-x86_64-1.txz: Upgraded. This update contains security fixes and improvements. For more information, see: https://www.mozilla.org/en-US/firefox/140.7.0/releasenotes/ https://www.mozilla.org/security/advisories/mfsa2026-03/ https://www.cve.org/CVERecord?id=CVE-2026-0877 https://www.cve.org/CVERecord?id=CVE-2026-0878 https://www.cve.org/CVERecord?id=CVE-2026-0879 https://www.cve.org/CVERecord?id=CVE-2026-0880 https://www.cve.org/CVERecord?id=CVE-2026-0882 https://www.cve.org/CVERecord?id=CVE-2025-14327 https://www.cve.org/CVERecord?id=CVE-2026-0883 https://www.cve.org/CVERecord?id=CVE-2026-0884 https://www.cve.org/CVERecord?id=CVE-2026-0885 https://www.cve.org/CVERecord?id=CVE-2026-0886 https://www.cve.org/CVERecord?id=CVE-2026-0887 https://www.cve.org/CVERecord?id=CVE-2026-0890 https://www.cve.org/CVERecord?id=CVE-2026-0891 (* Security fix *) xap/mozilla-thunderbird-140.7.0esr-x86_64-1.txz: Upgraded. This release contains security fixes and improvements. For more information, see: https://www.mozilla.org/en-US/thunderbird/140.7.0esr/releasenotes/ (* Security fix *)