Lector de Feeds
MGAA-2026-0145 - Updated php8.5 & php8.4 packages fix bugs
Publication date: 02 Oct 2026
Type: bugfix
Affected Mageia releases : 10
Description
Bug fix releases for php 8.4 and php 8.5 References
Type: bugfix
Affected Mageia releases : 10
Description
Bug fix releases for php 8.4 and php 8.5 References
- https://bugs.mageia.org/show_bug.cgi?id=36368
- https://www.php.net/ChangeLog-8.php#8.4.26
- https://www.php.net/ChangeLog-8.php#8.5.11
- php8.5-8.5.11-1.mga10
- php8.4-8.4.26-1.1.mga10
Categorías: Actualizaciones de Seguridad
MGASA-2026-0467 - Updated python-tornado packages fix security vulnerabilities
Publication date: 02 Oct 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-49853 , CVE-2026-49854 , CVE-2026-49855 Description
Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient Tornado has out-of-bounds memory access via C extension tornado AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb) References
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-49853 , CVE-2026-49854 , CVE-2026-49855 Description
Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient Tornado has out-of-bounds memory access via C extension tornado AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb) References
- https://bugs.mageia.org/show_bug.cgi?id=35712
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/GZ7Q55UOVFEKZDAHBHES3HJS2PZ4OQHV/
- https://www.cve.org/CVERecord?id=CVE-2026-49853
- https://www.cve.org/CVERecord?id=CVE-2026-49854
- https://www.cve.org/CVERecord?id=CVE-2026-49855
- python-tornado-6.5.10-1.1.mga10
Categorías: Actualizaciones de Seguridad
MGASA-2026-0466 - Updated python-urwid & python-wcwidth packages fixes a security vulnerability
Publication date: 02 Oct 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-9323 Description
Insecure PRNG and Information Exposure in urwid Web Display Backend References
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-9323 Description
Insecure PRNG and Information Exposure in urwid Web Display Backend References
- https://bugs.mageia.org/show_bug.cgi?id=36159
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/3XPYRLW6AB7WGF3ENBZSCZHGJCJFF7VI/
- https://github.com/urwid/urwid/security/advisories/GHSA-rjwp-g85x-gmjv
- https://ubuntu.com/security/notices/USN-8751-1
- https://www.cve.org/CVERecord?id=CVE-2026-9323
- python-urwid-4.1.3-1.mga10
- python-wcwidth-0.8.3-1.mga10
Categorías: Actualizaciones de Seguridad
MGASA-2026-0465 - Updated wireshark package fixes security vulnerabilities
Publication date: 02 Oct 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-15163 , CVE-2026-15164 , CVE-2026-15165 , CVE-2026-15166 , CVE-2026-15167 , CVE-2026-15168 , CVE-2026-15169 , CVE-2026-15170 , CVE-2026-15171 , CVE-2026-15172 , CVE-2026-15173 , CVE-2026-15174 Description
Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark. (CVE-2026-15163) Heap-based Buffer Overflow in ciscodump. (CVE-2026-15164) Heap-based Buffer Overflow in Wireshark. (CVE-2026-15165) Stack-based Buffer Overflow in Wireshark. (CVE-2026-15166) Stack-based Buffer Overflow in Wireshark. (CVE-2026-15167) Use of Uninitialized Variable in Wireshark. (CVE-2026-15168) Heap-based Buffer Overflow in Wireshark. (CVE-2026-15169) Heap-based Buffer Overflow in Wireshark. (CVE-2026-15170) NULL Pointer Dereference in Wireshark. (CVE-2026-15171) Unchecked Input for Loop Condition in Wireshark. (CVE-2026-15172) Heap-based Buffer Overflow in Wireshark. (CVE-2026-15173) Heap-based Buffer Overflow in Wireshark. (CVE-2026-15174) References
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-15163 , CVE-2026-15164 , CVE-2026-15165 , CVE-2026-15166 , CVE-2026-15167 , CVE-2026-15168 , CVE-2026-15169 , CVE-2026-15170 , CVE-2026-15171 , CVE-2026-15172 , CVE-2026-15173 , CVE-2026-15174 Description
Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark. (CVE-2026-15163) Heap-based Buffer Overflow in ciscodump. (CVE-2026-15164) Heap-based Buffer Overflow in Wireshark. (CVE-2026-15165) Stack-based Buffer Overflow in Wireshark. (CVE-2026-15166) Stack-based Buffer Overflow in Wireshark. (CVE-2026-15167) Use of Uninitialized Variable in Wireshark. (CVE-2026-15168) Heap-based Buffer Overflow in Wireshark. (CVE-2026-15169) Heap-based Buffer Overflow in Wireshark. (CVE-2026-15170) NULL Pointer Dereference in Wireshark. (CVE-2026-15171) Unchecked Input for Loop Condition in Wireshark. (CVE-2026-15172) Heap-based Buffer Overflow in Wireshark. (CVE-2026-15173) Heap-based Buffer Overflow in Wireshark. (CVE-2026-15174) References
- https://bugs.mageia.org/show_bug.cgi?id=35985
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WDPYZRRCJU7AOWEFKBJ2IXADDJGWH4AH/
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/OUNLKEGMF6HPV3WJRY6PZJF4BTUIQWBO/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/B5DGIBJC6D6UABMCLLUPI5ZU2I3SEFUV/
- https://lists.debian.org/debian-security-announce/2026/msg00382.html
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/UONW2KX7GYYS7MVUGXE7L23MZC42ZLHT/
- https://www.cve.org/CVERecord?id=CVE-2026-15163
- https://www.cve.org/CVERecord?id=CVE-2026-15164
- https://www.cve.org/CVERecord?id=CVE-2026-15165
- https://www.cve.org/CVERecord?id=CVE-2026-15166
- https://www.cve.org/CVERecord?id=CVE-2026-15167
- https://www.cve.org/CVERecord?id=CVE-2026-15168
- https://www.cve.org/CVERecord?id=CVE-2026-15169
- https://www.cve.org/CVERecord?id=CVE-2026-15170
- https://www.cve.org/CVERecord?id=CVE-2026-15171
- https://www.cve.org/CVERecord?id=CVE-2026-15172
- https://www.cve.org/CVERecord?id=CVE-2026-15173
- https://www.cve.org/CVERecord?id=CVE-2026-15174
- wireshark-4.6.8-1.mga10
Categorías: Actualizaciones de Seguridad
MGASA-2026-0464 - Updated libgcrypt package fixes a security vulnerability
Publication date: 02 Oct 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2024-2236 Description
Libgcrypt: vulnerable to marvin attack. (CVE-2024-2236) References
Type: security
Affected Mageia releases : 10
CVE: CVE-2024-2236 Description
Libgcrypt: vulnerable to marvin attack. (CVE-2024-2236) References
- https://bugs.mageia.org/show_bug.cgi?id=36248
- https://ubuntu.com/security/notices/USN-8711-1
- https://bugzilla.redhat.com/show_bug.cgi?id=2268268
- https://lists.gnupg.org/pipermail/gcrypt-devel/2024-March/005607.html
- https://github.com/tomato42/marvin-toolkit/tree/master/example/libgcrypt
- https://people.redhat.com/~hkario/marvin/
- https://dev.gnupg.org/T7136
- https://gitlab.com/redhat-crypto/libgcrypt/libgcrypt-mirror/-/merge_requests/17
- https://www.cve.org/CVERecord?id=CVE-2024-2236
- libgcrypt-1.11.3-1.1.mga10
Categorías: Actualizaciones de Seguridad
MGASA-2026-0463 - Updated python-pillow packages fix security vulnerabilities
Publication date: 01 Oct 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-55380 , CVE-2026-54060 , CVE-2026-54059 , CVE-2026-55379 , CVE-2026-59205 , CVE-2026-59199 , CVE-2026-59197 , CVE-2026-59198 , CVE-2026-54058 , CVE-2026-59204 , CVE-2026-59203 Description
Prevent decompression bomb when parsing PDF WindowsViewer.get_command injection EPS image infinite loop JPEG2000 image memory usage McIdas out-of-bounds (OOB) read Out-of-bounds (OOB) read when saving 1 mode TGA images Out-of-bounds (OOB) write from large RankFilter sizes Out-of-bounds (OOB) write from Image.paste() Out-of-bounds (OOB) write in ImageCmsTransform Prevent FontFile decompression bomb Prevent GD decompression bomb References
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-55380 , CVE-2026-54060 , CVE-2026-54059 , CVE-2026-55379 , CVE-2026-59205 , CVE-2026-59199 , CVE-2026-59197 , CVE-2026-59198 , CVE-2026-54058 , CVE-2026-59204 , CVE-2026-59203 Description
Prevent decompression bomb when parsing PDF WindowsViewer.get_command injection EPS image infinite loop JPEG2000 image memory usage McIdas out-of-bounds (OOB) read Out-of-bounds (OOB) read when saving 1 mode TGA images Out-of-bounds (OOB) write from large RankFilter sizes Out-of-bounds (OOB) write from Image.paste() Out-of-bounds (OOB) write in ImageCmsTransform Prevent FontFile decompression bomb Prevent GD decompression bomb References
- https://bugs.mageia.org/show_bug.cgi?id=35909
- https://github.com/python-pillow/Pillow/blob/main/docs/releasenotes/12.3.0.rst
- https://www.cve.org/CVERecord?id=CVE-2026-55380
- https://www.cve.org/CVERecord?id=CVE-2026-54060
- https://www.cve.org/CVERecord?id=CVE-2026-54059
- https://www.cve.org/CVERecord?id=CVE-2026-55379
- https://www.cve.org/CVERecord?id=CVE-2026-59205
- https://www.cve.org/CVERecord?id=CVE-2026-59199
- https://www.cve.org/CVERecord?id=CVE-2026-59197
- https://www.cve.org/CVERecord?id=CVE-2026-59198
- https://www.cve.org/CVERecord?id=CVE-2026-54058
- https://www.cve.org/CVERecord?id=CVE-2026-59204
- https://www.cve.org/CVERecord?id=CVE-2026-59203
- python-pillow-12.3.0-1.mga10
Categorías: Actualizaciones de Seguridad
MGAA-2026-0144 - Updated glabels & glabels-qt packages fixes bug
Publication date: 01 Oct 2026
Type: bugfix
Affected Mageia releases : 10
Description
glabels can't open previously-created glabels files. We have added a patch to fix the issue but the project is dead upstream and its developer is now focussing on glabels-qt. We are releasing glabels-qt as an alternative. Both versions fix the reported issue; it is your decision what tool to use. References
SRPMS 10/core
Type: bugfix
Affected Mageia releases : 10
Description
glabels can't open previously-created glabels files. We have added a patch to fix the issue but the project is dead upstream and its developer is now focussing on glabels-qt. We are releasing glabels-qt as an alternative. Both versions fix the reported issue; it is your decision what tool to use. References
SRPMS 10/core
- glabels-3.4.1-12.1.mga10
- glabels-qt-3.99-0.2.2026.08.27git554c9f0.mga10
Categorías: Actualizaciones de Seguridad




