From 542eee3445cb9a03602156af8cc307cdfdea6a09 Mon Sep 17 00:00:00 2001 From: Unraid Bot <65325399+unraid-bot@users.noreply.github.com> Date: Thu, 24 Sep 2026 15:17:51 -0400 Subject: [PATCH] feat: update Unraid OS 7.4.0 release notes --- docs/unraid-os/release-notes/7.4.0.md | 469 ++++++++++++++++++++------ 1 file changed, 357 insertions(+), 112 deletions(-) diff --git a/docs/unraid-os/release-notes/7.4.0.md b/docs/unraid-os/release-notes/7.4.0.md index 110f41c09d..ce067253c3 100644 --- a/docs/unraid-os/release-notes/7.4.0.md +++ b/docs/unraid-os/release-notes/7.4.0.md @@ -1,12 +1,14 @@ -# Version 7.4.0-beta.2 2026-09-03 +# Version 7.4.0-beta.3 2026-09-24 -Unraid OS 7.4.0-beta.2 adds Docker multi-network and memory controls, shared background task management, boot-device backup improvements, configurable power-button behavior, **mover progress tracking**, and expanded hardware and Hyper-V support. It also improves transient license checking, updates the Linux kernel to 6.18.47-Unraid and the Unraid API to 4.37.3, and includes core package security updates (the same updates to core packages as 7.3.3-rc.1) +Unraid OS 7.4.0-beta.3 is a beta release with security updates and Linux kernel 6.18.52, alongside Docker and storage improvements, expanded hardware and Hyper-V support, and WebGUI enhancements including a shared task tray. -## Fixes / Features From 7.4.0-beta.1 +## What's new in beta.3 -* New: Mover progress and status tracking is now available. Due to a known issue, go to ***Settings → Scheduler → Mover Settings***, set **Mover Progress** to **Disabled**, and select **Apply**. Then set **Mover Progress** to **Enabled** and select **Apply** again. -* Fix: Power Options retains both the Power Mode and Power Button tabs when the Dynamix System Buttons plugin is installed. -* Fix: Power Options no longer shows the virtualization warning on bare-metal servers. +* Fix: Mover now preserves hard links during progress-enabled moves, including files in separate subfolders of the same share. +* Fix: `shfs` no longer deadlocks under concurrent file-lock requests or crashes on an internal unlink assertion that could make `/mnt/user` unavailable. +* Includes package updates and security fixes. + +We recommend beta testers upgrade to receive the security fixes included in this release and help validate the changes before stable availability. ## Upgrading @@ -14,7 +16,7 @@ For step-by-step instructions, see [Updating Unraid](/unraid-os/updating-unraid/ ## Known issues -* No new release-specific known issues are documented. For known issues from the previous release, see the [Unraid OS 7.3.2 release notes](/unraid-os/release-notes/7.3.2/). +* For known issues from the previous release, see the [Unraid OS 7.3.2 release notes](/unraid-os/release-notes/7.3.2/). ## Rolling back @@ -24,146 +26,389 @@ For step-by-step instructions, see [Updating Unraid](/unraid-os/updating-unraid/ ### Security -* Security: Core components include updates addressing reported CVEs and other security fixes. -* Security: Notification integrations now verify the public API certificate instead of bypassing certificate validation. +* Base distro updates address a range of reported CVEs and other security fixes; see the package annotations below. +* OpenTerminal validates request inputs before they are used by shell commands. +* VM Manager displays guest-agent-supplied network-interface names as text rather than active HTML. +* Diagnostics anonymization now hides public IPv6 addresses and related diagnostic output. ### Containers / Docker -* New: Docker container templates support multiple custom networks, with additional network attachments retained when containers are recreated or updated. -* New: Docker Add/Edit forms show a live preview for the container icon URL, with a fallback when the URL is empty or invalid. -* New: Advanced View exposes a Memory limit field for Docker containers. +* New: Docker container templates support multiple custom networks, and additional network attachments are retained when containers are recreated or updated. +* New: Docker Add/Edit forms show a live preview of the container icon URL, with a fallback when the URL is empty or invalid. +* New: Advanced View includes a Memory limit field for Docker containers. +* Improvement: Docker registry update checks accept OCI image manifests and indexes and identify the Unraid client. +* Fix: Dashboard Docker icon fallback handling no longer retries indefinitely when the fallback image is unavailable. ### Storage -* New: Mover progress and status tracking is now available. Due to a known issue, go to ***Settings → Scheduler → Mover Settings***, set **Mover Progress** to **Disabled**, and select **Apply**. Then set **Mover Progress** to **Enabled** and select **Apply** again. -* New: Drive-location support can use SGPIO/IBPI-capable controllers when SES is unavailable. -* Fix: A stopped array now shows offline and filesystem status text instead of 100% utilization. -* Fix: Pressing Enter in encrypted array passphrase fields now starts the array when passphrase validation succeeds. +* New: Mover progress and status tracking is available (finally!). +* New: Drive-location identification supports SGPIO/IBPI-capable controllers when SES is unavailable. +* Improvement: Pressing Enter in an encrypted array passphrase field starts the array when the passphrase is valid. +* Fix: Mover handles files with hard links within the same share across separate subfolders. +* Fix: File Manager moves between user shares on different pools or drives no longer silently remove the source file when a transfer fails. +* Fix: `shfs` no longer deadlocks when concurrent file-lock requests exhaust the FUSE worker pool. +* Fix: `shfs` no longer crashes on an internal unlink assertion that could make `/mnt/user` unavailable. +* Fix: A stopped array no longer shows 100% utilization; it shows offline and filesystem status instead. +* Fix: Boot Device used/free statistics are displayed when the array is stopped. ### WebGUI / System * New: Background operations from plugins, Docker, and virtual machines can be queued and managed from a shared task tray, with foreground recall from any browser tab. -* New: Boot-device backups run as background tasks with selectable compression, live progress, and automatic download when complete. -* New: Configure the physical power button under Settings → Power Settings → Power Button → **Physical power button**, with Shut down, Reboot, and Do nothing actions. -* Improvement: Foreground task sheets now scale with the browser viewport while retaining saved-width and mobile behavior. -* Improvement: License checks now retry to handle transient availability and network conditions. +* New: Configure the physical power button from **Settings → Power Settings → Power Button → Physical power button**. +* Improvement: Foreground task sheets scale with the browser viewport while retaining saved-width and mobile behavior. +* Improvement: Plugin installation progress displays carriage-return updates as separate live updates instead of one buffered line. +* Improvement: The Installed Plugins page checks updates independently so a slow or unreachable plugin does not keep the entire page waiting. +* Improvement: License checks retry to handle transient network or service availability issues. +* Fix: Plugin update validation failures remain visible with an explanation instead of silently reporting the plugin as up to date. +* Fix: Plugin Manager cleanup hooks run when error messages contain shell characters. +* Fix: Installed Plugins update-first ordering remains stable while asynchronous checks complete. * Fix: Power Options retains both the Power Mode and Power Button tabs when the Dynamix System Buttons plugin is installed. * Fix: Power Options no longer shows the virtualization warning on bare-metal servers. -* Fix: The Installed Plugins page checks updates independently so a slow or unreachable plugin does not keep the entire page waiting. -* Fix: Plugin update validation failures remain visible with an explanation instead of silently reporting the plugin as up-to-date. -* Fix: Plugin Manager post-hook cleanup now runs when error messages contain shell characters. ### Networking / Hardware -* New: Added kernel modules and firmware for Realtek RTW88 8812A, 8814A, and 8821A wireless adapters, plus kernel modules for RTW89 8851BU and 8852BU USB adapters. -* New: Added support for additional PlayStation, Nintendo, Steam, and Logitech controllers, along with additional audio codecs. -* Improvement: Network defaults now follow Fedora's `/etc/sysctl.conf` baseline, including CUBIC TCP congestion control and `fq_codel` as the default packet scheduler. +* New: Added driver and firmware support for additional Intel, MediaTek, and Realtek wireless hardware, including Realtek RTW88 8812A, 8814A, and 8821A and RTW89 8851BU and 8852BU adapters. +* New: Added support for additional PlayStation, Nintendo, Steam, and Logitech controllers, hardware sensors, and audio codecs. +* New: Linux netconsole is available as an optional module for network-based kernel crash diagnostics. +* Improvement: Network defaults are aligned with Fedora’s `/etc/sysctl.conf` baseline, we do not expect any outward facing issues from this change. ### Virtualization -* New: Added kernel support for Hyper-V virtualization, including Hyper-V storage, balloon, keyboard, and VMBus modules. +* New: Added kernel support for Hyper-V virtualization, including storage, balloon, keyboard, and virtual-socket modules. * Fix: VM startup no longer logs a PHP deprecation warning when the QEMU location lookup produces no output. -### Unraid API - -* Update [dynamix.unraid.net]() 4.37.3 - see changes. - ### Linux kernel -* Linux kernel: update to 6.18.47-Unraid. +* Linux kernel: update to 6.18.52-Unraid. ## Base distro updates ### Downgraded packages (1) -* shared-mime-info: version 2.5.1 -> 2.4-2 +* shared-mime-info: version 2.5.1 -> 2.4-3 (Slackware maintainer downgrade) ### Added packages (1) * ledctl: version 1.1.0 -### Updated packages (83) - -* aaa_libraries: version 15.1-51 -> 15.1-54 -* at-spi2-core: version 2.60.5 -> 2.60.6 -* bind: version 9.20.24-2 -> 9.20.27 -* btrfs-progs: version 7.0 -> 7.1 -* ca-certificates: version 20260616 -> 20260717 -* cifs-utils: version 7.6 -> 7.7 -* cryptsetup: version 2.8.6 -> 2.8.7 +### Updated packages (319) + +* aaa_base: version 15.1-2 -> 15.1-3 (security fix noted; no CVE IDs listed) +* aaa_glibc-solibs: version 2.43 -> 2.44-7 +* aaa_libraries: version 15.1-51 -> 16.0 +* acl: version 2.4.0 -> 2.4.0-2 +* acpid: version 2.0.34-2 -> 2.0.34-3 +* adwaita-icon-theme: version 50.0 -> 51.0 +* appres: version 1.0.7 -> 1.0.7-2 +* at: version 3.2.5 -> 3.2.5-2 +* at-spi2-core: version 2.60.5 -> 2.60.6-2 +* attr: version 2.6.0 -> 2.6.0-2 +* bash: version 5.3.015-2 -> 5.3.020 +* bin: version 11.1-5 -> 11.1-6 +* bind: version 9.20.24-2 -> 9.20.27-2 +* bluez-firmware: version 1.2-4 -> 1.2-5 +* bridge-utils: version 1.7.1 -> 1.7.1-2 +* brotli: version 1.2.0 -> 1.2.0-2 +* btrfs-progs: version 7.0 -> 7.1-2 +* bzip2: version 1.0.8-3 -> 1.0.8-4 (CVE-2016-3189, CVE-2019-12900) +* ca-certificates: version 20260616 -> 20260910 +* cairo: version 1.18.4 -> 1.18.4-2 +* cifs-utils: version 7.6 -> 7.7-2 +* coreutils: version 9.11 -> 9.12 +* cpio: version 2.15 -> 2.15-2 +* cpufrequtils: version 008-4 -> 008-5 +* cracklib: version 2.10.3 -> 2.10.3-2 +* cryptsetup: version 2.8.6 -> 2.8.8 +* curl: version 8.21.0 -> 8.22.0 (CVE-2026-13608, CVE-2026-18924, CVE-2026-19931, CVE-2026-80229, CVE-2026-80230, CVE-2026-80231, CVE-2026-80255, CVE-2026-82208, CVE-2026-82209) +* db48: version 4.8.30-6 -> 4.8.30-7 +* dbus: version 1.16.2-4 -> 1.16.2-5 +* dbus-glib: version 0.114 -> 0.114-2 +* dejavu-fonts-ttf: version 2.37-8 -> 2.37-9 +* diffutils: version 3.12 -> 3.12-2 +* dmidecode: version 3.7 -> 3.7-2 +* dnsmasq: version 2.93 -> 2.93-2 (CVE-2026-2291) * docker: version 29.5.3-1_LT -> 29.7.1-1_LT -* [dynamix.unraid.net](): version 4.35.1 -> 4.37.3 -* elfutils: version 0.195 -> 0.196 -* elogind: version 255.27 -> 257.16-3 -* ethtool: version 7.0 -> 7.1 -* eudev: version 3.2.14-3 -> 3.2.14-4 -* exfatprogs: version 1.4.2 -> 1.4.3 -* findutils: version 4.10.0 -> 4.11.0 -* fontconfig: version 2.18.1 -> 2.18.3 -* gawk: version 5.4.0 -> 5.4.1 -* gdk-pixbuf2: version 2.44.7 -> 2.44.8 -* glib2: version 2.88.2 -> 2.88.3 -* glibc-zoneinfo: version 2026b -> 2026c -* harfbuzz: version 14.2.1 -> 14.3.1 -* htop: version 3.5.1 -> 3.5.3 -* iproute2: version 7.1.0-2 -> 7.2.0 +* dosfstools: version 4.2-2 -> 4.2-3 +* [dynamix.unraid.net](): version 4.35.1 -> 4.37.4-5 +* e2fsprogs: version 1.47.4 -> 1.47.4-2 +* ebtables: version 2.0.11-3 -> 2.0.11-4 +* editres: version 1.1.1 -> 1.1.1-2 +* efibootmgr: version 18 -> 18-2 +* efivar: version 20201015_cff88dd -> 20201015_cff88dd-2 +* elfutils: version 0.195 -> 0.196-2 +* elogind: version 255.27 -> 257.16-4 +* elvis: version 2.2_0-9 -> 2.2_0-10 +* encodings: version 1.1.0 -> 1.1.0-2 +* etc: version 15.1-17 -> 15.1-18 +* ethtool: version 7.0 -> 7.1-2 +* eudev: version 3.2.14-3 -> 3.2.14-5 +* exfatprogs: version 1.4.2 -> 1.4.3-2 +* file: version 5.48 -> 5.48-2 +* findutils: version 4.10.0 -> 4.11.0-2 +* flex: version 2.6.4-5 -> 2.6.4-6 +* floppy: version 5.6-2 -> 5.6-3 +* fontconfig: version 2.18.1 -> 2.18.3-2 +* freeglut: version 3.8.0 -> 3.8.0-2 +* freetype: version 2.14.3 -> 2.14.3-2 +* fribidi: version 1.0.16 -> 1.0.16-2 +* fuse3: version 3.16.2-2 -> 3.16.2-3_LT +* gawk: version 5.4.0 -> 5.4.1-2 +* gd: version 2.3.3-3 -> 2.3.3-4 +* gdbm: version 1.26 -> 1.26-2 +* gdk-pixbuf2: version 2.44.7 -> 2.44.8-2 +* gettext: version 1.0 -> 1.0-2 +* gettext-tools: version 1.0 -> 1.0-2 +* git: version 2.55.0 -> 2.55.0-2 +* glew: version 2.3.1 -> 2.3.1-2 +* glib2: version 2.88.2 -> 2.90.0 +* glibc: version 2.43 -> 2.44-7 (NVD: CVE-2026-4046, CVE-2026-4437, CVE-2026-4438, CVE-2026-5450, CVE-2026-5928) +* glibc-zoneinfo: version 2026b -> 2026d +* glu: version 9.0.3 -> 9.0.3-2 +* gmp: version 6.3.0 -> 6.3.0-2 +* gnutls: version 3.8.13 -> 3.8.13-2 (CVE-2026-33846) +* gptfdisk: version 1.0.10 -> 1.0.10-2 +* graphite2: version 1.3.15-2 -> 1.3.15-3 +* grep: version 3.12 -> 3.12-2 +* grub: version 2.14-3 -> 2.14-5 +* gtk+3: version 3.24.52 -> 3.24.52-2 +* gzip: version 1.14 -> 1.14-2 +* harfbuzz: version 14.2.1 -> 14.4.0-2 +* hdparm: version 9.65 -> 9.65-2 +* hicolor-icon-theme: version 0.18 -> 0.18-2 +* hostname: version 3.25 -> 3.25-2 +* htop: version 3.5.1 -> 3.5.3-2 +* icu4c: version 78.3 -> 78.3-2 +* inetd: version 1.79s-14 -> 1.79s-15 +* infozip: version 6.0-8 -> 6.0-9 (CVE-2014-8139, CVE-2014-8140, CVE-2014-8141, CVE-2016-9844, CVE-2018-18384, CVE-2018-1000035, CVE-2021-4217, CVE-2022-0529, CVE-2022-0530) +* inih: version 62 -> 62-2 +* inotify-tools: version 4.25.9.0 -> 4.25.9.0-2 +* iproute2: version 7.1.0-2 -> 7.2.0-2 +* iptables: version 1.8.13 -> 1.8.13-2 +* iputils: version 20250605 -> 20250605-2 +* iw: version 6.17 -> 6.17-2 +* jansson: version 2.15.1 -> 2.15.1-2 +* jemalloc: version 5.3.1 -> 5.3.1-2 * jq: version 1.8.1-1_SBo -> 1.8.2-1_SBo (NVD: CVE-2026-40612, CVE-2026-41256, CVE-2026-41257, CVE-2026-43894, CVE-2026-43895, CVE-2026-43896) -* libXfont2: version 2.0.7 -> 2.0.9 (CVE-2026-44950, CVE-2026-59679) -* libarchive: version 3.8.8 -> 3.8.9 (security fix noted; no CVE IDs listed) -* libcap-ng: version 0.9.3 -> 0.9.5 -* libdeflate: version 1.25 -> 1.26 -* libdisplay-info: version 0.3.0 -> 0.4.0 -* libevdev: version 1.13.6 -> 1.13.7 -* libffi: version 3.6.0 -> 3.8.0 -* libpsl: version 0.22.0 -> 0.23.3 -* libssh: version 0.12.0 -> 0.12.2 (CVE-2026-59843) +* json-c: version 0.19 -> 0.19-2 +* json-glib: version 1.10.8 -> 1.10.8-2 +* kbd: version 2.10.0 -> 2.10.0-2 +* keyutils: version 1.6.3-3 -> 1.6.3-4 +* kmod: version 34.2 -> 34.2-2 +* krb5: version 1.22.2-3 -> 1.22.2-4 +* lbzip2: version 2.5-4 -> 2.5-5 +* less: version 704 -> 704-2 +* libICE: version 1.1.2 -> 1.1.2-2 +* libSM: version 1.2.6 -> 1.2.6-2 +* libX11: version 1.8.13 -> 1.8.13-2 +* libXau: version 1.0.12 -> 1.0.12-2 +* libXaw: version 1.0.16 -> 1.0.16-2 +* libXcomposite: version 0.4.7 -> 0.4.7-2 +* libXcursor: version 1.2.3 -> 1.2.3-2 +* libXdamage: version 1.1.7 -> 1.1.7-2 +* libXdmcp: version 1.1.5 -> 1.1.5-2 +* libXevie: version 1.0.3-5 -> 1.0.3-6 +* libXext: version 1.3.7 -> 1.3.7-2 +* libXfixes: version 6.0.2 -> 6.0.2-2 +* libXfont2: version 2.0.7 -> 2.0.9-2 (CVE-2026-44950, CVE-2026-59679) +* libXfontcache: version 1.0.5-5 -> 1.0.5-6 +* libXft: version 2.3.9 -> 2.3.9-2 +* libXi: version 1.8.3 -> 1.8.3-2 +* libXinerama: version 1.1.6 -> 1.1.6-2 +* libXmu: version 1.3.1 -> 1.3.1-2 +* libXpm: version 3.5.19 -> 3.5.19-2 (CVE-2026-4367) +* libXpresent: version 1.0.2 -> 1.0.2-2 +* libXrandr: version 1.5.5 -> 1.5.5-2 +* libXrender: version 0.9.12 -> 0.9.12-2 +* libXres: version 1.2.3 -> 1.2.3-2 +* libXt: version 1.3.1 -> 1.3.1-2 +* libXtst: version 1.2.5 -> 1.2.5-2 +* libXxf86dga: version 1.1.7 -> 1.1.7-2 +* libXxf86misc: version 1.0.4-3 -> 1.0.4-4 +* libXxf86vm: version 1.1.7 -> 1.1.7-2 +* libaio: version 0.3.113 -> 0.3.113-2 +* libarchive: version 3.8.8 -> 3.8.9-2 (security fix noted; no CVE IDs listed) +* libcap-ng: version 0.9.3 -> 0.9.6 +* libcbor: version 0.14.0 -> 0.14.0-2 +* libcgroup: version 3.2.0 -> 3.2.0-2 +* libdeflate: version 1.25 -> 1.26-2 +* libdisplay-info: version 0.3.0 -> 0.4.0-2 +* libdmx: version 1.1.5 -> 1.1.5-2 +* libdrm: version 2.4.134 -> 2.4.134-2 +* libedit: version 20260512_3.1 -> 20260512_3.1-2 +* libepoxy: version 1.5.10 -> 1.5.10-2 +* libevdev: version 1.13.6 -> 1.13.7-2 +* libevent: version 2.1.13 -> 2.1.13-2 (security fix noted; no CVE IDs listed) +* libffi: version 3.6.0 -> 3.8.0-2 +* libfido2: version 1.17.0-2 -> 1.17.0-3 +* libfontenc: version 1.1.9 -> 1.1.9-2 +* libgcrypt: version 1.12.2 -> 1.12.4 +* libglvnd: version 1.7.0-2 -> 1.7.0-3 +* libgpg-error: version 1.61 -> 1.61-2 (security fix noted; no CVE IDs listed) +* libgudev: version 238 -> 238-2 +* libidn: version 1.44 -> 1.44-2 (security fix noted; no CVE IDs listed) +* libjpeg-turbo: version 3.2.0 -> 3.2.0-2 +* libmaxminddb: version 1.13.3 -> 1.14.0 +* libmnl: version 1.0.5 -> 1.0.5-2 +* libnetfilter_conntrack: version 1.1.1 -> 1.1.1-2 +* libnfnetlink: version 1.0.2 -> 1.0.2-2 +* libnftnl: version 1.3.1 -> 1.3.2 +* libnl3: version 3.12.0 -> 3.12.0-2 +* libnvme: version 1.16.2 -> 1.16.2-2 +* libpcap: version 1.10.6 -> 1.10.7 (CVE-2026-0799, CVE-2026-6244, CVE-2026-6554, CVE-2026-18238, CVE-2026-18313, CVE-2026-31911, CVE-2026-31912) +* libpciaccess: version 0.19 -> 0.19-2 +* libpng: version 1.6.58 -> 1.6.58-2 +* libpsl: version 0.22.0 -> 0.23.3-2 +* libpthread-stubs: version 0.5 -> 0.5-2 +* libseccomp: version 2.6.1 -> 2.6.1-2 (security fix noted; no CVE IDs listed) +* libssh: version 0.12.0 -> 0.12.2-2 (CVE-2026-59843; NVD: CVE-2026-59847) +* libssh2: version 1.11.1 -> 1.11.1-2 (CVE-2023-48795) +* libtasn1: version 4.21.0 -> 4.21.0-2 (CVE-2025-13151) +* libtiff: version 4.7.2 -> 4.7.2-2 +* libtirpc: version 1.3.7 -> 1.3.8 +* libunistring: version 1.4.2 -> 1.4.2-2 +* libunwind: version 1.8.3 -> 1.8.3-2 +* liburing: version 2.15 -> 2.15-2 +* libusb: version 1.0.30 -> 1.0.30-2 +* libusb-compat: version 0.1.9 -> 0.1.9-2 +* libuv: version 1.52.1 -> 1.52.1-2 * libvirt-php: version 0.5.8-8.4.23_LT -> 0.5.8_20260609-1_LT -* lmdb: version 1.0.0 -> 1.0.1 -* lvm2: version 2.03.41 -> 2.03.42 -* mcelog: version 210 -> 212 -* mesa: version 26.1.4 -> 26.2.1 -* nano: version 9.1 -> 9.2 -* nfs-utils: version 2.9.1 -> 2.9.2 -* nghttp2: version 1.69.0 -> 1.70.0 -* nghttp3: version 1.17.0 -> 1.18.0 +* libwebp: version 1.6.0 -> 1.6.0-2 +* libx86: version 1.1.1 -> 1.1.1-2 +* libxcb: version 1.17.0 -> 1.17.0-2 +* libxcvt: version 0.1.3 -> 0.1.3-2 +* libxkbcommon: version 1.13.2 -> 1.13.2-2 +* libxkbfile: version 1.2.0 -> 1.2.0-2 +* libxml2: version 2.15.3 -> 2.15.4 (NVD: CVE-2026-11979, CVE-2026-86137, CVE-2026-86138, CVE-2026-86139, CVE-2026-86140, CVE-2026-86141, CVE-2026-86142, CVE-2026-86143, CVE-2026-86144) +* libxshmfence: version 1.3.3 -> 1.3.3-2 +* libxslt: version 1.1.45 -> 1.1.45-2 +* libzip: version 1.11.4 -> 1.11.4-2 +* listres: version 1.0.7 -> 1.0.7-2 +* lmdb: version 1.0.0 -> 1.0.2 +* logrotate: version 3.22.0 -> 3.22.0-2 +* lsof: version 4.99.7 -> 4.99.7-2 +* lsscsi: version 0.32 -> 0.32-2 +* lvm2: version 2.03.41 -> 2.03.42-2 +* lz4: version 1.10.0-2 -> 1.10.0-3 +* lzip: version 1.26 -> 1.26-2 +* lzlib: version 1.16 -> 1.16-2 +* lzo: version 2.10-4 -> 2.10-5 +* mc: version 4.8.33 -> 4.8.33-2 +* mcelog: version 210 -> 212-2 +* mesa: version 26.1.4 -> 26.2.2 +* mkfontscale: version 1.2.4 -> 1.2.4-2 +* mpfr: version 4.2.2 -> 4.2.2-2 +* mtdev: version 1.1.7 -> 1.1.7-2 +* nano: version 9.1 -> 9.2-2 +* ncompress: version 5.0-2 -> 5.0-3 +* ncurses: version 6.6 -> 6.6-2 +* net-tools: version 20181103_0eebece-5 -> 20181103_0eebece-6 (CVE-2025-46836) +* nettle: version 3.10.2 -> 3.10.2-2 +* network-scripts: version 15.1 -> 15.1-2 +* nfs-utils: version 2.9.1 -> 2.9.2-2 +* nghttp2: version 1.69.0 -> 1.70.0-2 +* nghttp3: version 1.17.0 -> 1.18.0-2 * nginx: version 1.30.3-1_SBo_LT -> 1.30.4-1_SBo_LT (NVD: CVE-2026-60005) -* ngtcp2: version 1.24.0 -> 1.25.0 -* noto-fonts-ttf: version 2026.07.01 -> 2026.08.01 -* ntfs-3g: version 2026.2.25 -> 2026.7.7 -* ntp: version 4.2.8p18-8 -> 4.2.8p18-9 -* openssh: version 10.4p1 -> 10.5p1 (security fix noted; no CVE IDs listed) -* openssl: version 3.5.7 -> 3.5.8 (CVE-2026-14456, CVE-2026-14457, CVE-2026-18798, CVE-2026-54874, CVE-2026-63072, CVE-2026-63073, CVE-2026-63074, CVE-2026-63075, CVE-2026-63076, CVE-2026-75803) -* p11-kit: version 0.26.2 -> 0.26.5 (CVE-2026-18938) -* pango: version 1.58.0 -> 1.58.2 -* perl: version 5.42.2-2 -> 5.44.0 +* ngtcp2: version 1.24.0 -> 1.25.0-2 +* noto-fonts-ttf: version 2026.07.01 -> 2026.09.01-2 +* ntfs-3g: version 2026.2.25 -> 2026.7.7-2 +* ntp: version 4.2.8p18-8 -> 4.2.8p18-10 +* nvme-cli: version 2.16 -> 2.16-2 +* oniguruma: version 6.9.10 -> 6.9.10-2 +* openssh: version 10.4p1 -> 10.5p1-2 (security fix noted; no CVE IDs listed) +* openssl: version 3.5.7 -> 3.5.8-2 (CVE-2026-14456, CVE-2026-14457, CVE-2026-18798, CVE-2026-54874, CVE-2026-63072, CVE-2026-63073, CVE-2026-63074, CVE-2026-63075, CVE-2026-63076, CVE-2026-75803) +* p11-kit: version 0.26.2 -> 0.26.5-2 (CVE-2026-18938) +* pam: version 1.7.2-2 -> 1.7.2-3 +* pango: version 1.58.0 -> 1.58.2-2 +* parted: version 3.7 -> 3.7-2 +* patch: version 2.8 -> 2.8-2 (CVE-2018-6951, CVE-2018-6952, CVE-2018-20969, CVE-2018-1000156, CVE-2019-13636, CVE-2019-13638, CVE-2019-20633) +* pciutils: version 3.15.0 -> 3.15.0-2 +* pcre: version 8.45 -> 8.45-2 +* pcre2: version 10.47 -> 10.48-2 (security fix noted; no CVE IDs listed) +* perl: version 5.42.2-2 -> 5.44.0-2 * php: version 8.4.23-1_LT -> 8.4.24-1_LT (CVE-2026-7260, CVE-2026-9672, CVE-2026-17543, CVE-2026-17544) -* pkgtools: version 15.1-32 -> 15.1-33 -* procps-ng: version 4.0.6 -> 4.0.7 -* rsync: version 3.4.4 -> 3.5.0 (security fix noted; no CVE IDs listed) +* pixman: version 0.46.4 -> 0.46.4-2 +* pkgtools: version 15.1-32 -> 15.1-34 +* procps-ng: version 4.0.6 -> 4.0.7-2 +* qrencode: version 4.1.1-3 -> 4.1.1-4 +* readline: version 8.3.003 -> 8.3.003-2 +* rsync: version 3.4.4 -> 3.5.0-2 (security fix noted; no CVE IDs listed) * samba: version 4.22.10-2_LT -> 4.22.11-2_LT (CVE-2026-6949, CVE-2026-58216, CVE-2026-58218, CVE-2026-58221, CVE-2026-58222, CVE-2026-58224) -* sdparm: version 1.12-3 -> 1.12-4 -* sg3_utils: version 1.48 -> 1.49 -* spirv-llvm-translator: version 22.1.4 -> 22.1.5 -* sqlite: version 3.53.3 -> 3.53.4 -* sysvinit: version 3.18 -> 3.18-2 -* sysvinit-scripts: version 15.1-38 -> 15.1-41 -* talloc: version 2.4.4 -> 2.5.0 -* tevent: version 0.17.1 -> 0.17.2 -* wayland: version 1.25.0 -> 1.26.0 -* wpa_supplicant: version 2.11-2 -> 2.12 (security fix noted; no CVE IDs listed) -* xclock: version 1.2.0 -> 1.2.1 -* xfsprogs: version 7.0.1 -> 7.1.1 -* xkbutils: version 1.0.6 -> 1.0.7 -* xload: version 1.2.0 -> 1.2.2 -* xlsatoms: version 1.1.4 -> 1.1.5 -* xmodmap: version 1.0.11 -> 1.0.12 -* xorg-server: version 21.1.23 -> 21.1.24 (CVE-2026-55999, CVE-2026-56000) -* xrdb: version 1.2.2 -> 1.2.3 -* xrefresh: version 1.1.0 -> 1.1.1 -* xset: version 1.2.5 -> 1.2.6 -* xsetroot: version 1.1.3 -> 1.1.4 -* xterm: version 410 -> 411 -* xwd: version 1.0.9 -> 1.0.10 -* xwininfo: version 1.1.6 -> 1.1.7 -* xwud: version 1.0.7 -> 1.0.8 -* zfs: version 2.4.3_6.18.38_Unraid-1_LT -> 2.4.4_6.18.47_Unraid-1_LT +* sdparm: version 1.12-3 -> 1.12-5 +* sed: version 4.10 -> 4.10-2 +* sessreg: version 1.1.4 -> 1.1.4-2 +* setxkbmap: version 1.3.5 -> 1.3.5-2 +* sg3_utils: version 1.48 -> 1.49-2 +* shadow: version 4.19.4-6 -> 4.19.4-7 (security fix noted; no CVE IDs listed) +* smartmontools: version 7.5 -> 7.5-2 +* spirv-llvm-translator: version 22.1.4 -> 22.1.6 +* sqlite: version 3.53.3 -> 3.53.4-2 +* startup-notification: version 0.12-5 -> 0.12-6 +* sudo: version 1.9.17p2 -> 1.9.17p2-2 +* sysfsutils: version 2.1.1 -> 2.1.1-2 +* sysstat: version 12.7.9 -> 12.8.0-2 +* sysvinit: version 3.18 -> 3.18-3 +* sysvinit-scripts: version 15.1-38 -> 16.0 +* talloc: version 2.4.4 -> 2.5.0-2 +* tar: version 1.35 -> 1.35-2 +* tcp_wrappers: version 7.6-7 -> 7.6-8 +* tdb: version 1.4.15 -> 1.4.15-2 +* telnet: version 0.17-8 -> 0.17-9 (CVE-2020-10188) +* tevent: version 0.17.1 -> 0.17.2-2 +* traceroute: version 2.1.6 -> 2.1.6-2 +* transset: version 1.0.4 -> 1.0.4-2 +* tree: version 2.3.2 -> 2.3.2-2 +* usbutils: version 019 -> 019-2 +* userspace-rcu: version 0.15.6 -> 0.15.7 +* utempter: version 1.2.3 -> 1.2.3-2 +* util-linux: version 2.42.2 -> 2.42.3 (CVE-2024-28085, CVE-2026-76642, CVE-2026-78408, CVE-2026-78409, CVE-2026-78410) +* vbetool: version 1.2.2-4 -> 1.2.2-5 +* vsftpd: version 3.0.5-4 -> 3.0.5-5 +* wayland: version 1.25.0 -> 1.26.0-2 +* wget: version 1.25.0 -> 1.25.0-2 (CVE-2024-10524) +* which: version 2.25 -> 2.25-2 +* wireguard-tools: version 1.0.20260223 -> 1.0.20260223-2 +* wireless-regdb: version 2026.05.30 -> 2026.09.03 +* wpa_supplicant: version 2.11-2 -> 2.12-2 (security fix noted; no CVE IDs listed) +* wqy-zenhei-font-ttf: version 0.9.45 -> 0.9.45-2 +* xauth: version 1.1.5 -> 1.1.5-2 +* xcb-util: version 0.4.1 -> 0.4.1-2 +* xcb-util-keysyms: version 0.4.1 -> 0.4.1-2 +* xclock: version 1.2.0 -> 1.2.1-2 +* xdpyinfo: version 1.4.0 -> 1.4.0-2 +* xdriinfo: version 1.0.8 -> 1.0.8-2 +* xev: version 1.2.7 -> 1.2.7-2 +* xf86-input-evdev: version 2.11.0 -> 2.11.0-2 +* xf86-input-synaptics: version 1.10.0 -> 1.10.0-2 +* xf86-video-mga: version 2.1.0 -> 2.1.0-2 +* xf86-video-vesa: version 2.6.0 -> 2.6.0-2 +* xfsprogs: version 7.0.1 -> 7.1.1-2 +* xhost: version 1.0.10 -> 1.0.10-2 +* xinit: version 1.4.4-2 -> 1.4.4-3 +* xkbcomp: version 1.5.0 -> 1.5.0-2 +* xkbevd: version 1.1.6 -> 1.1.6-2 +* xkbutils: version 1.0.6 -> 1.0.7-2 +* xkeyboard-config: version 2.48 -> 2.48-2 +* xkill: version 1.0.7 -> 1.0.7-2 +* xload: version 1.2.0 -> 1.2.2-2 +* xlsatoms: version 1.1.4 -> 1.1.5-2 +* xlsclients: version 1.1.6 -> 1.1.6-2 +* xmessage: version 1.0.7 -> 1.0.7-2 +* xmodmap: version 1.0.11 -> 1.0.12-2 +* xorg-server: version 21.1.23 -> 21.1.24-2 (CVE-2026-55999, CVE-2026-56000) +* xprop: version 1.2.8 -> 1.2.8-2 +* xrandr: version 1.5.4 -> 1.5.4-2 +* xrdb: version 1.2.2 -> 1.2.3-2 +* xrefresh: version 1.1.0 -> 1.1.1-2 +* xset: version 1.2.5 -> 1.2.6-2 +* xsetroot: version 1.1.3 -> 1.1.4-2 +* xsm: version 1.0.6 -> 1.0.6-2 +* xterm: version 410 -> 411-2 +* xtrans: version 1.6.0 -> 1.6.0-2 +* xwd: version 1.0.9 -> 1.0.10-2 +* xwininfo: version 1.1.6 -> 1.1.7-2 +* xwud: version 1.0.7 -> 1.0.8-2 +* xxHash: version 0.8.3 -> 0.8.3-2 +* xz: version 5.8.3 -> 5.8.4 (security fix noted; no CVE IDs listed) +* zfs: version 2.4.3_6.18.38_Unraid-1_LT -> 2.4.4_6.18.52_Unraid-1_LT +* zlib: version 1.3.2 -> 1.3.2-2 (security fix noted; no CVE IDs listed) +* zstd: version 1.5.7 -> 1.5.7-3