Lector de Feeds

MGASA-2026-0428 - Updated mpg123 package fixes security vulnerabilities

Mageia Security - 20 Septiembre, 2026 - 05:25
Publication date: 20 Sep 2026
Type: security
Affected Mageia releases : 10
Description
Updated packages fix security vulnerabilities, please se the reference. References
SRPMS 10/core
  • mpg123-1.33.7-1.mga10

MGASA-2026-0427 - Updated gawk packages fix security vulnerabilities

Mageia Security - 20 Septiembre, 2026 - 05:25
Publication date: 20 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-40467 , CVE-2026-40468 , CVE-2026-40469 , CVE-2026-40553 Description
Use after free in gawk. (CVE-2026-40467) Heap buffer overflow in gawk. (CVE-2026-40468) Heap buffer overflow in gawk. (CVE-2026-40469) Stack-based buffer overflow in gawk. (CVE-2026-40553) References
SRPMS 10/core
  • gawk-5.3.2-2.1.mga10
9/core
  • gawk-5.2.2-1.1.mga9

MGASA-2026-0426 - Updated perl-YAML packages fix a security vulnerability

Mageia Security - 20 Septiembre, 2026 - 05:25
Publication date: 20 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-63676 Description
Updated packages fixes CVE-2026-63676 References
SRPMS 10/core
  • perl-YAML-1.310.0-2.1.mga10
9/core
  • perl-YAML-1.300.0-3.1.mga9

MGASA-2026-0425 - Updated libssh packages fix security vulnerabilities

Mageia Security - 20 Septiembre, 2026 - 05:25
Publication date: 20 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-15370 , CVE-2026-59843 , CVE-2026-59844 , CVE-2026-59845 , CVE-2026-59846 , CVE-2026-59847 , CVE-2026-59848 , CVE-2026-59849 , CVE-2026-59850 Description
Stack buffer overflow in SFTP server longname construction. (CVE-2026-15370) Denial of service via zero advertised channel packet size. (CVE-2026-59843) Denial of service via oversized SFTP read length. (CVE-2026-59844) Denial of service via unchecked ProxyCommand fork() failure. (CVE-2026-59845) Information disclosure via ProxyCommand %r username expansion. (CVE-2026-59846) Integrity downgrade via OpenSSL AES-GCM tag verification. (CVE-2026-59847) Denial of service via SFTP responses with unknown request IDs. (CVE-2026-59848) Denial of service via automatic certificate authentication loop. (CVE-2026-59849) Use-after-free via data callbacks on closed channels. (CVE-2026-59850) References
SRPMS 10/core
  • libssh-0.11.5-1.mga10
9/core
  • libssh-0.10.6-1.3.mga9

MGASA-2026-0424 - Updated ntfs-3g packages fix security vulnerabilities

Mageia Security - 20 Septiembre, 2026 - 05:25
Publication date: 20 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-42616 , CVE-2026-42617 , CVE-2026-42618 , CVE-2026-46569 , CVE-2026-46570 , CVE-2026-46571 , CVE-2026-46572 , CVE-2026-56135 , CVE-2026-56136 Description
Heap memory corruption when processing a corrupt or maliciously crafted filesystem. (CVE-2026-42616) Heap memory corruption when copying index data from root to an index block in a corrupt or maliciously crafted filesystem. (CVE-2026-42617) Single-byte heap buffer overflow when decompressing maliciously crafted compressed file data. (CVE-2026-42618) Heap buffer overflow when copying the tail data of an index block to a freshly allocated block. (CVE-2026-46569) Heap memory corruption for maliciously crafted or corrupt index data descending to an out-of-bounds tree depth. (CVE-2026-46570) Out-of-bounds read when processing symlink reparse data in a corrupt or maliciously crafted filesystem. (CVE-2026-46571) Heap buffer overflow for maliciously crafted or corrupt index data during a node split. (CVE-2026-46572) Heap buffer overflow when building inherited ACL data. (CVE-2026-56135) Out of bounds access when clearing an index root in maliciously crafted or corrupt index data. (CVE-2026-56136) References
SRPMS 10/core
  • ntfs-3g-2026.2.25-1.1.mga10
9/core
  • ntfs-3g-2022.10.3-1.3.mga9

MGASA-2026-0423 - Updated patch package fixes security vulnerabilities

Mageia Security - 20 Septiembre, 2026 - 05:25
Publication date: 20 Sep 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-56288 , CVE-2026-56289 Description
NULL Pointer Dereference in GNU patch. (CVE-2026-56288) Loop with Unreachable Exit Condition in GNU patch. (CVE-2026-56289) References
SRPMS 10/core
  • patch-2.8-1.1.mga10

MGASA-2026-0422 - Updated bind package fixes security vulnerabilities

Mageia Security - 20 Septiembre, 2026 - 05:25
Publication date: 20 Sep 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-19033 , CVE-2026-19662 , CVE-2026-19666 , CVE-2026-19667 , CVE-2026-19668 , CVE-2026-19941 , CVE-2026-75029 , CVE-2026-76163 , CVE-2026-77119 , CVE-2026-77692 , CVE-2026-78301 , CVE-2026-80274 , CVE-2026-81563 , CVE-2026-81736 Description
Unauthenticated IXFR deltas are applied to the live zone before TSIG verification (CVE-2026-19033). qpcache NOQNAME proof use-after-free crashes recursive resolver (CVE-2026-19662). Use-after-free in query_addnoqnameproof() via the DNS64 filter64 path (CVE-2026-19666). Remote assertion failure via 16-bit length truncation in dns_ncache_add() (CVE-2026-19667). Resource Exhaustion via Excessive DNSSEC Cryptographic Material Matching (CVE-2026-19668). checkwildcard() accepts an out-of-zone NSEC as a wildcard-nonexistence proof (CVE-2026-19941). Message parser retains every identical singleton RDATA, enabling wire-to-work amplification (CVE-2026-75029). named aborts on a TKEY query when the user configuration has no global options statement (CVE-2026-76163). NSEC3 insecure-referral proof can use unrelated cached NSEC3 RRsets (CVE-2026-77119). Unauthenticated remote crash of named via a single DoH SIG(0) request (CVE-2026-77692). Out-of-zone database nodes can become authoritative zone cuts (CVE-2026-78301). Validating resolver can abort while caching a mismatched NOQNAME proof (CVE-2026-80274). SVCB AliasMode additional-data error leaks qpcache references (CVE-2026-81563). Remote CPU denial of service through cached SVCB/HTTPS AliasMode trees (CVE-2026-81736). References
SRPMS 10/core
  • bind-9.20.29-1.mga10

MGASA-2026-0421 - Updated python-configargparse packages fix security vulnerabilities

Mageia Security - 20 Septiembre, 2026 - 05:25
Publication date: 20 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
Description
Config file or environment variable can trigger writing out a config file, overwriting an arbitrary file and disclosing configuration values References
SRPMS 10/core
  • python-configargparse-1.7.7-1.mga10
9/core
  • python-configargparse-1.7.7-1.mga9

MGASA-2026-0420 - Updated libde265 package fixes security vulnerabilities

Mageia Security - 20 Septiembre, 2026 - 05:25
Publication date: 20 Sep 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2024-38949 , CVE-2024-38950 , CVE-2025-61147 , CVE-2026-33164 , CVE-2026-33165 , CVE-2026-45382 , CVE-2026-45383 , CVE-2026-49295 , CVE-2026-49337 , CVE-2026-49346 , CVE-2026-54240 , CVE-2026-54241 Description
Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attackers to crash the application via crafted payload to display444as420 function at sdl.cc. (CVE-2024-38949) Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attackers to crash the application via crafted payload to __interceptor_memcpy function. (CVE-2024-38950) strukturag libde265 commit d9fea9d wa discovered to contain a segmentation fault via the component decoder_context::compute_framedrop_table(). (CVE-2025-61147) NULL Pointer Dereference in libde265. (CVE-2026-33164) Heap out-of-bounds write in libde265 1.0.16. (CVE-2026-33165) libde265 has a heap-buffer-overflow READ in decode_slice_unit_tiles via unvalidated PPS tile geometry. (CVE-2026-45382) libde265 has a heap buffer overflow (OOB read) in decode_slice_unit_WPP() via out-of-bounds CtbAddrRStoTS access — libde265 <= v1.0.18. (CVE-2026-45383) libde265 has an out-of-bounds write in process_reference_picture_set via predicted short-term RPS. (CVE-2026-49295) libde265 has an unbounded memory leak via orphaned slice headers in `read_slice_NAL`. (CVE-2026-49337) libde265 has a heap buffer overflow in de265_image_get_buffer via SPS dimension integer overflow. (CVE-2026-49346) Pixel accessor signed integer overflow causes heap OOB read/write. (CVE-2026-54240) SAO sequential filter heap buffer overflow via signed integer overflow. (CVE-2026-54241) References
SRPMS 10/core
  • libde265-1.0.16-4.1.mga10
10/tainted
  • libde265-1.0.16-4.1.mga10.tainted

MGASA-2026-0419 - Updated python-httplib2 packages fix a security vulnerability

Mageia Security - 20 Septiembre, 2026 - 05:25
Publication date: 20 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-59939 Description
Decompression Bomb Denial of Service via Unbounded gzip/deflate Response Handling. (CVE-2026-59939) References
SRPMS 10/core
  • python-httplib2-0.22.0-3.1.mga10
9/core
  • python-httplib2-0.20.4-1.1.mga9

MGAA-2026-0128 - Updated system-config-printer package fixes bug

Mageia Security - 20 Septiembre, 2026 - 05:25
Publication date: 20 Sep 2026
Type: bugfix
Affected Mageia releases : 10
Description
Current system-config-printer package does not show a logo in the about dialog box. This update fixes the reported issue. References
SRPMS 10/core
  • system-config-printer-1.5.18-6.2.mga10

MGAA-2026-0127 - Updated perl-Chart package fixes bug

Mageia Security - 20 Septiembre, 2026 - 05:25
Publication date: 20 Sep 2026
Type: bugfix
Affected Mageia releases : 10
Description
perl-Chart is updated to version 2.403.9. perl-Graphics-Toolkit-Color is a new runtime requirement for perl-Chart. References
SRPMS 10/core
  • perl-Chart-2.403.9-1.mga10
  • perl-Graphics-Toolkit-Color-2.220.0-1.mga10

MGAA-2026-0126 - Updated gnome-software package fixes bug

Mageia Security - 20 Septiembre, 2026 - 05:25
Publication date: 20 Sep 2026
Type: bugfix
Affected Mageia releases : 10
Description
GUI aplications packaged by mageia are not listed in gnome-software. This updates adds libdnf5-plugin-appstream as optional requirement to allow gnome-software see the GUI applications packaged by mageia and allow to user skip the additional package if they want. References
SRPMS 10/core
  • gnome-software-49.3-2.1.mga10

MGAA-2026-0125 - Updated isodumper package fixes bugs

Mageia Security - 20 Septiembre, 2026 - 05:25
Publication date: 20 Sep 2026
Type: bugfix
Affected Mageia releases : 10
Description
When formatting a partition which was already mounted, Isodumper failed. Now, it starts to unmount the partitions on the target device Devices list is also cleaned of optical devices. References
SRPMS 10/core
  • isodumper-1.93-1.mga10

MGASA-2026-0418 - Updated gstreamer1.0-plugins-base packages fix a security vulnerability

Mageia Security - 19 Septiembre, 2026 - 08:25
Publication date: 19 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-18297 Description
GStreamer OGG File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. (CVE-2026-18297) References
SRPMS 10/core
  • gstreamer1.0-plugins-base-1.26.11-1.1.mga10
9/core
  • gstreamer1.0-plugins-base-1.22.11-1.4.mga9

MGAA-2026-0124 - Updated audacity packages fix bug

Mageia Security - 19 Septiembre, 2026 - 08:25
Publication date: 19 Sep 2026
Type: bugfix
Affected Mageia releases : 10
Description
audacity is updated to version 3.7.9 which has improvements and bugs fixed by the audacity team. References
SRPMS 10/core
  • audacity-3.7.9-1.mga10

MGASA-2026-0416 - Updated libpcap packages fix security vulnerabilities

Mageia Security - 18 Septiembre, 2026 - 18:17
Publication date: 18 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-0799 , CVE-2026-31911 , CVE-2026-31912 , CVE-2026-6244 , CVE-2026-6554 , CVE-2026-18313 , CVE-2026-18238 Description
OOBR and OOBW in libpcap before 1.10.7. (CVE-2026-0799) abort() in libpcap before 1.10.7 on an invalid BPF opcode. (CVE-2026-31911) OOBR in libpcap before 1.10.7. (CVE-2026-31912) Division by zero in libpcap before 1.10.7. (CVE-2026-6244) Infinte loop in libpcap before 1.10.7. (CVE-2026-6554) rpcapd memory leak in libpcap before 1.10.7. (CVE-2026-18313) OOBR in rpcap client in libpcap before 1.10.7. (CVE-2026-18238) References
SRPMS 10/core
  • libpcap-1.10.7-1.mga10
9/core
  • libpcap-1.10.7-1.mga9

MGASA-2026-0415 - Updated graphicsmagick packages fix a security vulnerability

Mageia Security - 18 Septiembre, 2026 - 18:17
Publication date: 18 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2025-55154 Description
Integer overflows in MNG magnification. (CVE-2025-55154) References
SRPMS 10/tainted
  • graphicsmagick-1.3.46-5.2.mga10.tainted
9/tainted
  • graphicsmagick-1.3.40-1.8.mga9.tainted

MGASA-2026-0414 - Updated imagemagick package fixes security vulnerabilities

Mageia Security - 17 Septiembre, 2026 - 15:10
Publication date: 17 Sep 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-86420 , CVE-2026-86421 , CVE-2026-86423 , CVE-2026-86424 , CVE-2026-86425 Description
Heap-use-after-free in Layer method of PerlMagick could result in a crash Path Policy TOCTOU symlink race bypass in the video decoder Heap-use-after-free in the GetList method of PerlMagick could result in a crash Memory Leak in MSL decoder Denial of service when exhausting the process memory budget Policy Bypass in UHDR encoder Division by Zero in FLIF encoder Null Pointer Dereference in PNM coder when hitting a memory limit Policy Bypass in PCD, CUBE and HALD decoder when using a specific command line option. Use after free in ImagesToBlob method References
SRPMS 10/core
  • imagemagick-7.1.2.31-1.mga10
10/tainted
  • imagemagick-7.1.2.31-1.mga10.tainted
Feed