ChangeLog for: 2026-09-25 00:11:03
a/kbd-2.10.0-x86_64-4.txz: Rebuilt.
Use setfont -R when reverting to bootup defaults.
Apply the new font on all the consoles.
Rearrange to correctly catch the error code from the first use of setfont in
auto mode. Thanks to r1w1s1.
Don't run auto mode if we see nomodeset on the kernel command line.
Put the font list to try in auto mode in /etc/default/rc.font instead of half
coding it in the script to make it easy to use something other than Terminus.
It's a matter of taste, but let's bump the minimum columns to 130.
a/pam-1.7.3-x86_64-1.txz: Upgraded.
ap/fwupd-2.1.8-x86_64-1.txz: Upgraded.
ap/mariadb-12.3.3-x86_64-1.txz: Upgraded.
kde/fcitx5-configtool-5.1.16-x86_64-1.txz: Upgraded.
kde/kirigami-addons-1.14.2-x86_64-1.txz: Upgraded.
kde/plasma-wayland-protocols-1.23.0-x86_64-1.txz: Upgraded.
l/aom-3.15.1-x86_64-1.txz: Upgraded.
l/libuv-1.53.0-x86_64-1.txz: Upgraded.
l/netpbm-11.15.08-x86_64-1.txz: Upgraded.
l/parted-3.8-x86_64-1.txz: Upgraded.
l/python-setuptools_scm-10.3.4-x86_64-1.txz: Upgraded.
l/python-vcs_versioning-2.5.0-x86_64-1.txz: Upgraded.
l/simdutf-9.2.1-x86_64-1.txz: Upgraded.
n/gnupg2-2.5.24-x86_64-1.txz: Upgraded.
n/php-8.5.11-x86_64-1.txz: Upgraded.
This update fixes security issues:
FPM: IPv6 ACL bypass in FastCGI listen.allowed_clients due to partial address
comparison.
MySQLnd: Various packet overreads in mysqlnd wire protocol.
OpenSSL: TLS hostname verification falls back to CN after SAN mismatch.
OpenSSL: Heap buffer overflow in php_openssl_matches_wildcard_name() on
crafted server certificate wildcard CN.
Phar: Integer overflow in phar_tar_number() allowing TAR archive entry
injection.
SOAP: Unbounded recursion in server-side cleanup_xml_node().
SOAP: Integer overflow to buffer overflow in SOAP HTTP parsing.
Standard: Out-of-bounds read in the HTTP stream wrapper when following a
redirect with an empty Location header.
Standard: Out-of-bounds read in convert.* stream filters when
line-break-chars contains NUL.
Standard: Cross-origin credential leak in HTTP stream wrapper redirects.
For more information, see:
https://www.php.net/ChangeLog-8.php#8.5.11
https://www.cve.org/CVERecord?id=CVE-2026-91768
https://www.cve.org/CVERecord?id=CVE-2025-1218
https://www.cve.org/CVERecord?id=CVE-2026-91769
https://www.cve.org/CVERecord?id=CVE-2026-91767
https://www.cve.org/CVERecord?id=CVE-2026-6103
https://www.cve.org/CVERecord?id=CVE-2026-91765
https://www.cve.org/CVERecord?id=CVE-2025-14181
https://www.cve.org/CVERecord?id=CVE-2026-93682
https://www.cve.org/CVERecord?id=CVE-2026-92842
https://www.cve.org/CVERecord?id=CVE-2026-91766
https://www.cve.org/CVERecord?id=CVE-2026-17545
(* Security fix *)
x/fcitx5-5.1.23-x86_64-1.txz: Upgraded.
x/fcitx5-chinese-addons-5.1.15-x86_64-1.txz: Upgraded.
x/fcitx5-m17n-5.1.8-x86_64-1.txz: Upgraded.
x/fcitx5-qt-5.1.16-x86_64-1.txz: Upgraded.
x/libime-1.1.17-x86_64-1.txz: Upgraded.