Lector de Feeds

MGASA-2025-0175 - Updated golang packages fix security vulnerabilities

Mageia Security - 2 Junio, 2025 - 18:55
Publication date: 02 Jun 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-22870 , CVE-2025-22871 Description Matching of hosts against proxy patterns can improperly treat an IPv6 zone ID as a hostname component. For example, when the NO_PROXY environment variable is set to "*.example.com", a request to "[::1%25.example.com]:80` will incorrectly match and not be proxied - CVE-2025-22870. The net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size lines. This can permit request smuggling if a net/http server is used in conjunction with a server that incorrectly accepts a bare LF as part of a chunk-ext - CVE-2025-22871. References SRPMS 9/core
  • golang-1.23.8-1.mga9

MGAA-2025-0056 - Updated mesa packages fix bug

Mageia Security - 2 Junio, 2025 - 18:55
Publication date: 02 Jun 2025
Type: bugfix
Affected Mageia releases : 9
Description mesa-25.0.5-1 introduced a bug that makes Extreme Tuxracer crash on some hardware. This update fixes the reported issue. References SRPMS 9/core
  • mesa-25.0.6-5.mga9
  • rust-cbindgen-0.26.0-0.1.mga9
9/tainted
  • mesa-25.0.6-5.mga9.tainted
Feed