Lector de Feeds
MGASA-2026-0373 - Updated libopenmpt packages fix security vulnerabilities
Type: security
Affected Mageia releases : 10 , 9
Description
Please see the links for information about the vulnerabilities. References
- https://bugs.mageia.org/show_bug.cgi?id=36208
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YDG4TQOERFZY33Z6OUALDBHR7XRQKMMA/
- https://lib.openmpt.org/libopenmpt/2026/08/15/releases-0.8.8-0.7.20-0.6.29-0.5.43-0.4.55/
- https://lib.openmpt.org/libopenmpt/2026/08/19/security-updates-0.8.9-0.7.21-0.6.30-0.5.44-0.4.56/
- https://github.com/OpenMPT/openmpt/security/advisories/GHSA-fxf7-wc37-p2cx
- libopenmpt-0.8.9-1.mga10
- libopenmpt-0.7.21-1.mga9
MGASA-2026-0372 - Updated python-gitpython packages fix security vulnerabilities
Type: security
Affected Mageia releases : 9
CVE: CVE-2023-40267 , CVE-2023-41040 , CVE-2026-42215 Description
CVE-2023-40267 GitPython before 3.1.32 does not block insecure non-multi options in clone and clone_from. NOTE: this issue exists because of an incomplete fix for CVE-2022-24439. CVE-2023-41040 In order to resolve some git references, GitPython reads files from the `.git` directory, in some places the name of the file being read is provided by the user, GitPython doesn't check if this file is located outside the `.git` directory. This allows an attacker to make GitPython read any file from the system. CVE-2026-42215 From version 3.1.30 to before version 3.1.47, GitPython blocks dangerous Git options such as --upload-pack and --receive-pack by default, but the equivalent Python kwargs upload_pack and receive_pack bypass that check. If an application passes attacker-controlled kwargs into Repo.clone_from(), Remote.fetch(), Remote.pull(), or Remote.push(), this leads to arbitrary command execution even when allow_unsafe_options is left at its default value of False. This issue has been patched in version 3.1.47. References
- https://bugs.mageia.org/show_bug.cgi?id=35535
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AV5DV7GBLMOZT7U3Q4TDOJO5R6G3V6GH/
- https://lists.debian.org/debian-lts-announce/2023/09/msg00036.html
- https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-rpm5-65cw-6hj4
- https://github.com/gitpython-developers/GitPython/releases/tag/3.1.50
- https://github.com/gitpython-developers/GitPython/releases/tag/3.1.49
- https://github.com/gitpython-developers/GitPython/releases/tag/3.1.48
- https://github.com/gitpython-developers/GitPython/releases/tag/3.1.47
- https://github.com/gitpython-developers/GitPython/releases/tag/3.1.46
- https://github.com/gitpython-developers/GitPython/releases/tag/3.1.45
- https://github.com/gitpython-developers/GitPython/releases/tag/3.1.44
- https://github.com/gitpython-developers/GitPython/releases/tag/3.1.43
- https://github.com/gitpython-developers/GitPython/releases/tag/3.1.42
- https://github.com/gitpython-developers/GitPython/releases/tag/3.1.41
- https://github.com/gitpython-developers/GitPython/releases/tag/3.1.40
- https://github.com/gitpython-developers/GitPython/releases/tag/3.1.38
- https://github.com/gitpython-developers/GitPython/releases/tag/3.1.37
- https://github.com/gitpython-developers/GitPython/releases/tag/3.1.35
- https://github.com/gitpython-developers/GitPython/releases/tag/3.1.34
- https://github.com/gitpython-developers/GitPython/releases/tag/3.1.33
- https://github.com/gitpython-developers/GitPython/releases/tag/3.1.32
- https://github.com/gitpython-developers/GitPython/releases/tag/3.1.31
- https://www.cve.org/CVERecord?id=CVE-2023-40267
- https://www.cve.org/CVERecord?id=CVE-2023-41040
- https://www.cve.org/CVERecord?id=CVE-2026-42215
- python-gitpython-3.1.50-1.mga9
MGAA-2026-0119 - Updated drakx-net packages add nl80211 (iw) scan and WPA3 (SAE) support
Type: bugfix
Affected Mageia releases : 10 , 9
Description
Our drakx.net packages still depended on deprecated wext (iwlist), causing problems with finding and connecting to networks for several users. This update adds both nl80211 (iw) scan and WPA3 (SAE) support, thus fixing the issues. References
SRPMS 10/core
- drakx-net-2.65-1.mga10
- drakx-net-2.65-1.mga9
Potions in Mageia. 03 – Elograf or how have voice dictation with Mageia
Have you ever needed voice dictation but couldn’t find a way to do it on Linux? Mageia offers Elograf with everything you need to get it working with just a few clicks. Let’s get started!
Tutorial – Installation
From our Mageia repositories
Since the release of Mageia 9, installing Elograf from our repositories is as simple as selecting the application from the package manager from “Install and remove applications” in the start menu or by entering the Mageia Control Center (MCC), and Mageia will install all the necessary packages to make Elograf fully functional, including kaldi, voxk-api, and nerd-dictation.
Voice model installation
The program requires a voice model function. This model is specific to each language. The available models are listed on this page. The tests were performed using one of the extended models from the link mentioned above. These models can also be downloaded directly from Elograf and can be saved in either user or system space (root password required for this option).
Use
When you launch Elograf from the Mageia application menu, a microphone icon will appear in the system tray, which is disabled by default. Clicking the icon will activate Elograf and begin voice dictation.
Right-clicking displays a menu that allows you to start dictation or access the settings. The settings menu shows options for adding models both locally, by downloading the file from the aforementioned link and specifying the saved location, and online. In the latter case, Elograf will open a list of available models for download and prompt you to choose the installation location, offering the option to install it in the user’s space or the system space from the same window.
By choosing “Activate direct click on the icon”, the start of dictation is controlled by a left click on the icon.
It is recommended to add Elograf to the list of applications set to run automatically at system startup. This will add its icon to the system tray, allowing quick access to commands. The method for configuring this option depends on your desktop environment.
After these settings, you can go to the application where you would normally write text, such as Libreoffice Writer, place the cursor where you want to start and begin dictating. At launch, you may have to wait a little while before the first vocalizations are recognized; this is the template’s loading time.
Some of the advantages you can find with this application:
- Offline dictation. Voice recognition is performed using Vosk and locally downloaded models, so there’s no need to send the audio to a cloud service. This provides privacy and allows dictation even without an internet connection.
- Works in almost any application. The recognized text is entered into the currently active application, so it can be used in text editors, browsers, email, forms, etc.
- Saving on text when writing long texts. Speaking is usually faster and more comfortable than typing large amounts of text, especially for drafts, notes, emails, or documents.
- Reduced keyboard usage. Especially useful when you want to decrease continuous keyboard use or alternate between typing and dictation.
- Control from the system tray.
- A selection of different downloadable language packs.
- Simple setup, compatibility with X11 and Wayland (For Wayland, the keyboard emulator should be set to “DOTOOL” in the “Advanced settings”, with the keyboard specified.
- Open source.
More information in our Wiki!: Voice recognition in Mageia.
Pociones en Mageia. 03 – Elograf o como tener dictado por voz con Mageia
¿Has tenido la necesitad de disponer de dictado por voz pero no has encontrado la forma de hacerlo en Linux? En Mageia tienes Elograf con todo lo necesario para hacerlo funcionar a golpe de clic. Vamos con el proceso!
Tutorial – Instalación
Desde nuestros repositorios de Mageia
Desde el lanzamiento de Mageia 9, la instalación de Elograf desde nuestros repositorios es tan sencilla como seleccionar la aplicación desde el gestor de paquetes desde “Instalar y quitar aplicaciones” en el menú de inicio o entrando al Centro de Control Mageia (MCC) y Mageia instalará todos los paquetes necesarios para que Elograf sea completamente funcional, incluyendo kaldi, voxk-api y ner-dictation.
Instalación del modelo de voz
El programa necesita un modelo de voz para funcionar. Este modelo es específico para cada idioma. En esta página se enumeran los modelos que están disponibles. Las pruebas se han realizado con uno de los modelos extendidos el enlace mencionado anteriormente. Estos modelos también se pueden descargar directamente desde Elograf, y pueden guardarse tanto en el espacio del usuario, como en el espacio del sistema (se solicitará la contraseña de root para esta opción).
Uso
Al iniciar Elograf desde el menú de aplicaciones de Mageia, aparecerá un icono en la bandeja del sistema en forma de micrófono, que aparece como desactivado por defecto. Pulsando en el icono, se activará Elograf para comenzar el dictado por voz
Con un clic derecho, se muestra un menú que permite iniciar el dictado o acceder a la configuración. En la Configuración se muestran las opciones para añadir modelos tanto localmente, descargando el archivo desde el enlace antes mencionado e indicando la ruta donde se ha guardado, como de forma online, donde Elograf abrirá una lista con los modelos disponibles para descarga y solicitará la ubicación de instalación del modelo ofreciendo también la opción de instalar en el espacio del usuario o en el espacio del sistema desde la misma ventana.
Al elegir “Activar clic directo en el icono”, se controla el inicio del dictado con un clic izquierdo en el icono.
Es recomendable agregar Elograf a la lista de aplicaciones con ejecución automática en el inicio del sistema. Esto agregará el icono en la bandeja del sistema, permitiendo acceder rápidamente a los comandos. El método de configuración de esta opción, depende del entorno de escritorio.
Después de estas configuraciones, puedes ir a la aplicación donde normalmente escribirías texto, como por ejemplo Libreoffice Writer, colocar el cursor en el lugar donde quieras empezar y comenzar a dictar.
En el lanzamiento hay que esperar un poco antes de que se reconozcan las primeras vocalizaciones, este es el tiempo de carga del modelo.
Algunas de las ventajas que puedes encontrar con esta aplicación:
- Dictado sin conexión a internet. El reconocimiento de voz se realiza mediante Vosk y los modelos descargados localmente, por lo que no es necesario enviar el audio a un servicio en la nube. Esto aporta privacidad y permite dictar incluso sin conexión.
- Funcionamiento en casi cualquier aplicación. El texto reconocido se introduce en la aplicación que esté activa, de modo que puede utilizarse en editores de texto, navegadores, correo, formularios, etc.
- Ahorro de textos al escribir textos largos. Hablar suele resultar más rápido y cómodo que teclear grandes cantidades de texto, especialmente para redactar borradores, notas, correos o documentación.
- Reducción del uso del teclado. Especialmente útil cuando se quiere disminuir el uso continuado del teclado o alternar entre escritura y dictado.
- Control desde la bandeja del sistema.
- Elección de diferentes modelos de idioma descargables.
- Configuración sencilla, compatibilidad con X11 y Wayland (En el caso de Wayland, el emulador de teclado debe configurarse como «DOTOOL» en la sección «Configuración avanzada», indicando el teclado correspondiente).
- Código abierto.
Más información en nuestra Wiki: Reconocimiento de voz en Mageia
MGASA-2026-0371 - Updated bubblewrap package fixes security vulnerabilities
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-87766 Description
Sandbox escape: symlink traversal via /oldroot allows writing files outside sandbox during setup References
- https://bugs.mageia.org/show_bug.cgi?id=36206
- https://lists.debian.org/debian-security-announce/2026/msg00383.html
- https://github.com/containers/bubblewrap/security/advisories/GHSA-pxhw-h44j-8pfx
- https://www.openwall.com/lists/oss-security/2026/08/27/7
- https://www.cve.org/CVERecord?id=CVE-2026-87766
- bubblewrap-0.12.0-1.mga10
MGASA-2026-0370 - Updated perl-Text-CSV_XS packages fix a security vulnerability
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-7111 Description
Text::CSV_XS versions before 1.62 for Perl have a use-after-free when registered callbacks extend the Perl argument stack, which may enable type confusion or memory corruption. References
- https://bugs.mageia.org/show_bug.cgi?id=35547
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/QELUJSCSNBIE4N5UNKH4YGI5LFCHEY65/
- https://lists.security.metacpan.org/cve-announce/msg/39453344/
- https://github.com/cpan-authors/Text-CSV_XS/issues/65
- https://www.cve.org/CVERecord?id=CVE-2026-7111
- perl-Text-CSV_XS-1.640.0-1.mga10
- perl-Text-CSV_XS-1.640.0-1.mga9
MGASA-2026-0369 - Updated libalsa2 packages fix security vulnerabilities
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-25068 , CVE-2026-56109 Description
alsa-lib 1.2.15.2 Topology Decoder Heap-based Buffer Overflow. (CVE-2026-25068) ALSA Library < 1.2.16.1 Double-Free via parse_def() in conf.c. (CVE-2026-56109) References
- https://bugs.mageia.org/show_bug.cgi?id=35934
- https://ubuntu.com/security/notices/USN-8044-1
- https://ubuntu.com/security/notices/USN-8538-1
- https://lore.kernel.org/alsa-devel/CAGt8pqBU0p2voB+qHxWGcNJrKHAcBhAyHUUBPLBN-Yj_SiV6MQ@mail.gmail.com/
- https://www.cve.org/CVERecord?id=CVE-2026-25068
- https://www.cve.org/CVERecord?id=CVE-2026-56109
- libalsa2-1.2.15.2-1.1.mga10
- libalsa2-1.2.9-1.1.mga9
MGASA-2026-0368 - Updated perl-XML-Bare packages fix security vulnerabilities
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-57074 , CVE-2026-13401 Description
XML::Bare versions through 0.53 for Perl have an unbounded character lookahead. XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attributes. References
- https://bugs.mageia.org/show_bug.cgi?id=35948
- https://www.openwall.com/lists/oss-security/2026/07/16/1
- https://www.openwall.com/lists/oss-security/2026/07/16/2
- https://www.cve.org/CVERecord?id=CVE-2026-57074
- https://www.cve.org/CVERecord?id=CVE-2026-13401
- perl-XML-Bare-0.530.0-26.mga10
- perl-XML-Bare-0.530.0-22.mga9
MGASA-2026-0367 - Updated perl-YAML-Syck packages fix security vulnerabilities
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-13713 , CVE-2026-57075 , CVE-2026-57076 , CVE-2026-57077 Description
YAML::Syck versions before 1.47 for Perl allow a use-after-free and double-free via an anchor node freed while still on the parser value stack YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via a signed-char lookup-table index in syck_base64dec YAML::Syck versions before 1.47 for Perl allow a heap use-after-free via an anchor name reused as an anchors-table key in syck_hdlr_add_anchor YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via an unbounded newline scan in newline_len References
- https://bugs.mageia.org/show_bug.cgi?id=35949
- https://www.openwall.com/lists/oss-security/2026/07/17/1
- https://www.openwall.com/lists/oss-security/2026/07/17/2
- https://www.openwall.com/lists/oss-security/2026/07/17/3
- https://www.openwall.com/lists/oss-security/2026/07/17/4
- https://metacpan.org/release/TODDR/YAML-Syck-1.47/changes
- https://www.cve.org/CVERecord?id=CVE-2026-13713
- https://www.cve.org/CVERecord?id=CVE-2026-57075
- https://www.cve.org/CVERecord?id=CVE-2026-57076
- https://www.cve.org/CVERecord?id=CVE-2026-57077
- perl-YAML-Syck-1.470.0-1.mga10
- perl-YAML-Syck-1.470.0-1.mga9
MGASA-2026-0366 - Updated libarchive packages fix security vulnerabilities
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-14164 , CVE-2026-15028 , CVE-2026-5745 , CVE-2025-5918 , CVE-2025-60753 , CVE-2026-4111 , CVE-2026-4424 , CVE-2026-4426 , CVE-2026-5121 Description
Double-free vulnerability in rar5 decompression logic via dangling filtered_buf pointer in init_unpack(). (CVE-2026-14164) Heap overflow oob read while parsing a tar archive contains a pax extended header. (CVE-2026-15028) A null pointer dereference vulnerability exists in the acl parser of libarchive. (CVE-2026-5745) Reading past eof may be triggered for piped file streams. (CVE-2025-5918) An issue was discovered in libarchive bsdtar before version 3.8.1 in function apply_substitution in file tar/subst.c when processing crafted -s substitution rules. This can cause unbounded memory allocation and lead to denial of service (Out-of-Memory crash). (CVE-2025-60753) Infinite loop denial of service in rar5 decompression via archive_read_data() in libarchive. (CVE-2026-4111) Information disclosure via heap out-of-bounds read in rar archive processing. (CVE-2026-4424) Denial of service via malformed iso file processing. (CVE-2026-4426) Arbitrary code execution via integer overflow in iso9660 image processing. (CVE-2026-5121) References
- https://bugs.mageia.org/show_bug.cgi?id=35999
- https://ubuntu.com/security/notices/USN-8581-1
- https://www.cve.org/CVERecord?id=CVE-2026-14164
- https://www.cve.org/CVERecord?id=CVE-2026-15028
- https://www.cve.org/CVERecord?id=CVE-2026-5745
- https://www.cve.org/CVERecord?id=CVE-2025-5918
- https://www.cve.org/CVERecord?id=CVE-2025-60753
- https://www.cve.org/CVERecord?id=CVE-2026-4111
- https://www.cve.org/CVERecord?id=CVE-2026-4424
- https://www.cve.org/CVERecord?id=CVE-2026-4426
- https://www.cve.org/CVERecord?id=CVE-2026-5121
- libarchive-3.8.9-1.mga10
- libarchive-3.6.2-5.6.mga9
MGASA-2026-0365 - Updated perl-Net-OAuth packages fix security vulnerabilities
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-72887 , CVE-2026-72888 , CVE-2026-72889 , CVE-2026-75589 Description
Net::OAuth::Client versions before 0.32 for Perl allow the service provider to silently downgrade OAuth 1.0a to OAuth 1.0 in get_request_token Net::OAuth versions before 0.32 for Perl allow memory exhaustion via unbounded caching of failed module loads in smart_require Net::OAuth versions before 0.33 for Perl allow the sender to choose the signature algorithm in verify Net::OAuth versions before 0.33 for Perl check HMAC-SHA1, HMAC-SHA256 and PLAINTEXT signatures with a non-constant-time comparison in verify References
- https://bugs.mageia.org/show_bug.cgi?id=36145
- https://www.openwall.com/lists/oss-security/2026/08/16/3
- https://github.com/vurtdev/Net-OAuth/security/advisories/GHSA-jh72-4qq2-8j6g
- https://www.openwall.com/lists/oss-security/2026/08/16/4
- https://github.com/vurtdev/Net-OAuth/security/advisories/GHSA-m2cv-cq5x-47ph
- https://www.openwall.com/lists/oss-security/2026/08/19/2
- https://github.com/vurtdev/Net-OAuth/security/advisories/GHSA-c8rm-g5cm-4pf5
- https://www.openwall.com/lists/oss-security/2026/08/19/3
- https://github.com/vurtdev/Net-OAuth/security/advisories/GHSA-g8xr-69p3-gw56
- https://www.cve.org/CVERecord?id=CVE-2026-72887
- https://www.cve.org/CVERecord?id=CVE-2026-72888
- https://www.cve.org/CVERecord?id=CVE-2026-72889
- https://www.cve.org/CVERecord?id=CVE-2026-75589
- perl-Net-OAuth-0.330.0-1.mga10
- perl-Net-OAuth-0.330.0-1.mga9
MGASA-2026-0364 - Updated apr-util packages fix security vulnerabilities
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2025-49506 , CVE-2026-32327 , CVE-2026-34191 , CVE-2026-34501 , CVE-2026-34502 Description
Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack. (CVE-2025-49506) Apache Portable Runtime Utility: apr-util XML stack recursion crash. (CVE-2026-32327) Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracle. (CVE-2026-34191) Apache Portable Runtime Utility: Heap buffer overflow in APR redis client. (CVE-2026-34501) Apache Portable Runtime Utility: Heap buffer overflow in APR memcached client. (CVE-2026-34502) References
- https://bugs.mageia.org/show_bug.cgi?id=36181
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VKNIDBBNHOGIQ7XPC4JGLXADWZC3JEUN/
- https://lists.debian.org/debian-security-announce/2026/msg00348.html
- https://www.cve.org/CVERecord?id=CVE-2025-49506
- https://www.cve.org/CVERecord?id=CVE-2026-32327
- https://www.cve.org/CVERecord?id=CVE-2026-34191
- https://www.cve.org/CVERecord?id=CVE-2026-34501
- https://www.cve.org/CVERecord?id=CVE-2026-34502
- apr-util-1.6.3-3.1.mga10
- apr-util-1.6.3-1.1.mga9
MGAA-2026-0118 - Updated opencpn-climatology-plugin package fixes bug
Type: bugfix
Affected Mageia releases : 10
Description
Updated package provides more recent climatology data (data from 2026) than the previous version (data from 2019). References
SRPMS 10/core
- opencpn-climatology-plugin-1.6.37.0-1.git20260510.mga10
MGASA-2026-0363 - Updated hplip package fixes security vulnerabilities
Type: security
Affected Mageia releases : 9
CVE: CVE-2026-8631 , CVE-2026-8632 Description
Potential Escalation of Privilege and Arbitrary Code Execution. (CVE-2026-8631, CVE-2026-8632) References
- https://bugs.mageia.org/show_bug.cgi?id=35583
- https://www.openwall.com/lists/oss-security/2026/05/23/1
- https://support.hp.com/us-en/document/ish_14942099-14942126-16/hpsbpi04118
- https://ubuntu.com/security/notices/USN-8483-1
- https://lists.debian.org/debian-security-announce/2026/msg00313.html
- https://www.cve.org/CVERecord?id=CVE-2026-8631
- https://www.cve.org/CVERecord?id=CVE-2026-8632
- hplip-3.22.10-4.2.mga9
MGASA-2026-0362 - Updated perl-HTTP-Date packages fix a security vulnerability
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-14741 Description
HTTP::Date versions before 6.08 for Perl allow CPU exhaustion via polynomial regex backtracking in parse_date References
- https://bugs.mageia.org/show_bug.cgi?id=35952
- https://www.openwall.com/lists/oss-security/2026/07/17/10
- https://www.cve.org/CVERecord?id=CVE-2026-14741
- perl-HTTP-Date-6.80.0-1.mga10
- perl-HTTP-Date-6.80.0-1.mga9
MGASA-2026-0361 - Updated perl-Date-Manip packages fix security vulnerabilities
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-60074 , CVE-2026-60075 Description
Date::Manip versions through 6.99 for Perl return corrupted dates via non-ASCII decimal digits that pass the numeric range tests in check Date::Manip versions through 6.99 for Perl allow CPU exhaustion via quadratic backtracking in the unanchored time substitution in _parse_time References
- https://bugs.mageia.org/show_bug.cgi?id=36130
- https://www.openwall.com/lists/oss-security/2026/07/30/19
- https://www.openwall.com/lists/oss-security/2026/07/30/20
- https://www.cve.org/CVERecord?id=CVE-2026-60074
- https://www.cve.org/CVERecord?id=CVE-2026-60075
- perl-Date-Manip-6.990.0-1.mga10
- perl-Date-Manip-6.990.0-1.mga9
MGASA-2026-0360 - Updated perl-HTML-FormHandler packages fix a security vulnerability
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2022-4993 Description
HTML::FormHandler versions through 0.40068 for Perl allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notation template References
- https://bugs.mageia.org/show_bug.cgi?id=36141
- https://www.openwall.com/lists/oss-security/2026/08/13/9
- https://www.cve.org/CVERecord?id=CVE-2022-4993
- perl-HTML-FormHandler-0.400.680-8.mga10
- perl-HTML-FormHandler-0.400.680-6.mga9
MGASA-2026-0359 - Updated nodejs packages fix security vulnerabilities
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-56846 , CVE-2026-56848 , CVE-2026-58043 , CVE-2026-56850 , CVE-2026-58040 , CVE-2026-58042 , CVE-2026-58045 , CVE-2026-56847 , CVE-2026-58039 , CVE-2026-58044 Description
http2: retain header memory in session accounting. (CVE-2026-56846) http2: defer rst stream while in scope. (CVE-2026-56848) permission: avoid granting radix split nodes. (CVE-2026-58043) https: distinguish PFX object-array agent keys. (CVE-2026-56850) https: bind identity checks to session reuse. (CVE-2026-58040) dns: handle large resolveAny address replies. (CVE-2026-58042) zlib: throw on out-of-bounds write buffers. (CVE-2026-58045) permission: enforce fs write permission for trace events. (CVE-2026-56847) permission: check final report output path. (CVE-2026-58039) http: reject requests exceeding max header count. (CVE-2026-58044) References
- https://bugs.mageia.org/show_bug.cgi?id=36201
- https://nodejs.org/en/blog/vulnerability/july-2026-security-releases
- https://nodejs.org/en/blog/release/v22.23.2
- https://www.cve.org/CVERecord?id=CVE-2026-56846
- https://www.cve.org/CVERecord?id=CVE-2026-56848
- https://www.cve.org/CVERecord?id=CVE-2026-58043
- https://www.cve.org/CVERecord?id=CVE-2026-56850
- https://www.cve.org/CVERecord?id=CVE-2026-58040
- https://www.cve.org/CVERecord?id=CVE-2026-58042
- https://www.cve.org/CVERecord?id=CVE-2026-58045
- https://www.cve.org/CVERecord?id=CVE-2026-56847
- https://www.cve.org/CVERecord?id=CVE-2026-58039
- https://www.cve.org/CVERecord?id=CVE-2026-58044
- nodejs-22.23.2-1.mga10
- nodejs-22.23.2-1.mga9
MGASA-2026-0358 - Updated roundcubemail packages fix security vulnerabilities
Type: security
Affected Mageia releases : 9
Description
* Add basic validation for content proxied by the css proxy acta2.jpg acta.jpg advisories avatar.jpg avatar.png bdk-key.bkup bdk-mga9.txt bdk-new.key bdkpackagers.key bdkpackagers.sec bdkpass bin blogdrake.net bookmarks.html BRF Descargas Desktop diagrana.pdf discover-missing Documentos Dragon Quest: Dai no Daibouken - Bravest Full OP Sub Español [2MZON1ev9DE].mkv ejemplo añadir_archivo1.spec ejemplo añadir_archivo2.spec google-chrome.spec html i18n.pdf Imágenes index.php kernel-backport kernel-cves.enc kernel-cves.txt lqshell-stylesheet.css mageia-advisories MANOLO MUÑOZ VS ALBERTO VAZQUEZ MANO A MANO 24 EXITAZOS RANCHEROS CON MARIACHI.opus MEGA megasync-10.tar.gz #*message*-20260914-112747# mgaadv-error.txt mgarepo mirrorbdk mock Música origen.rss out.pnm PDF Plantillas Precure News - Star Detective PreCure! OP (Movie Footage Edition) [2099120870992310272].mp4 Proyectos qatest qa-testing qphotorec.desktop qphotorec.log reinstall.sh repodkfix.sh repositorio rpm rss Sailor Moon Cosmos AMV - Makenai (Sailor Star Song).mp4 sshrc style.html Taylor Swift, les coulisses du succès [120464-000-A].mp4 test.jpg tmp update-bdkkey.sh urpm-ng-distupgrade-orphans vdhcoapp-2.0.19 Ventoy Backup Vídeos VirtualBox VMs xen test xen-mga#33082 YAML-LibYAML-Test-dir zekemx Fix SSRF bypass via specific local address URLs using 100.64.0.0/10 and fe80::/10 nets, reported by Dmytro Ivanenko acta2.jpg acta.jpg advisories avatar.jpg avatar.png bdk-key.bkup bdk-mga9.txt bdk-new.key bdkpackagers.key bdkpackagers.sec bdkpass bin blogdrake.net bookmarks.html BRF Descargas Desktop diagrana.pdf discover-missing Documentos Dragon Quest: Dai no Daibouken - Bravest Full OP Sub Español [2MZON1ev9DE].mkv ejemplo añadir_archivo1.spec ejemplo añadir_archivo2.spec google-chrome.spec html i18n.pdf Imágenes index.php kernel-backport kernel-cves.enc kernel-cves.txt lqshell-stylesheet.css mageia-advisories MANOLO MUÑOZ VS ALBERTO VAZQUEZ MANO A MANO 24 EXITAZOS RANCHEROS CON MARIACHI.opus MEGA megasync-10.tar.gz #*message*-20260914-112747# mgaadv-error.txt mgarepo mirrorbdk mock Música origen.rss out.pnm PDF Plantillas Precure News - Star Detective PreCure! OP (Movie Footage Edition) [2099120870992310272].mp4 Proyectos qatest qa-testing qphotorec.desktop qphotorec.log reinstall.sh repodkfix.sh repositorio rpm rss Sailor Moon Cosmos AMV - Makenai (Sailor Star Song).mp4 sshrc style.html Taylor Swift, les coulisses du succès [120464-000-A].mp4 test.jpg tmp update-bdkkey.sh urpm-ng-distupgrade-orphans vdhcoapp-2.0.19 Ventoy Backup Vídeos VirtualBox VMs xen test xen-mga#33082 YAML-LibYAML-Test-dir zekemx Fix SSRF filter bypass via various forms of nip.io/sslip.io hostnames evading is_local_url() check, reported by Milan Hoppe acta2.jpg acta.jpg advisories avatar.jpg avatar.png bdk-key.bkup bdk-mga9.txt bdk-new.key bdkpackagers.key bdkpackagers.sec bdkpass bin blogdrake.net bookmarks.html BRF Descargas Desktop diagrana.pdf discover-missing Documentos Dragon Quest: Dai no Daibouken - Bravest Full OP Sub Español [2MZON1ev9DE].mkv ejemplo añadir_archivo1.spec ejemplo añadir_archivo2.spec google-chrome.spec html i18n.pdf Imágenes index.php kernel-backport kernel-cves.enc kernel-cves.txt lqshell-stylesheet.css mageia-advisories MANOLO MUÑOZ VS ALBERTO VAZQUEZ MANO A MANO 24 EXITAZOS RANCHEROS CON MARIACHI.opus MEGA megasync-10.tar.gz #*message*-20260914-112747# mgaadv-error.txt mgarepo mirrorbdk mock Música origen.rss out.pnm PDF Plantillas Precure News - Star Detective PreCure! OP (Movie Footage Edition) [2099120870992310272].mp4 Proyectos qatest qa-testing qphotorec.desktop qphotorec.log reinstall.sh repodkfix.sh repositorio rpm rss Sailor Moon Cosmos AMV - Makenai (Sailor Star Song).mp4 sshrc style.html Taylor Swift, les coulisses du succès [120464-000-A].mp4 test.jpg tmp update-bdkkey.sh urpm-ng-distupgrade-orphans vdhcoapp-2.0.19 Ventoy Backup Vídeos VirtualBox VMs xen test xen-mga#33082 YAML-LibYAML-Test-dir zekemx Fix remote content blocking bypass via unclosed url() in a FuncIRI attribute, reported by Milan Hoppe acta2.jpg acta.jpg advisories avatar.jpg avatar.png bdk-key.bkup bdk-mga9.txt bdk-new.key bdkpackagers.key bdkpackagers.sec bdkpass bin blogdrake.net bookmarks.html BRF Descargas Desktop diagrana.pdf discover-missing Documentos Dragon Quest: Dai no Daibouken - Bravest Full OP Sub Español [2MZON1ev9DE].mkv ejemplo añadir_archivo1.spec ejemplo añadir_archivo2.spec google-chrome.spec html i18n.pdf Imágenes index.php kernel-backport kernel-cves.enc kernel-cves.txt lqshell-stylesheet.css mageia-advisories MANOLO MUÑOZ VS ALBERTO VAZQUEZ MANO A MANO 24 EXITAZOS RANCHEROS CON MARIACHI.opus MEGA megasync-10.tar.gz #*message*-20260914-112747# mgaadv-error.txt mgarepo mirrorbdk mock Música origen.rss out.pnm PDF Plantillas Precure News - Star Detective PreCure! OP (Movie Footage Edition) [2099120870992310272].mp4 Proyectos qatest qa-testing qphotorec.desktop qphotorec.log reinstall.sh repodkfix.sh repositorio rpm rss Sailor Moon Cosmos AMV - Makenai (Sailor Star Song).mp4 sshrc style.html Taylor Swift, les coulisses du succès [120464-000-A].mp4 test.jpg tmp update-bdkkey.sh urpm-ng-distupgrade-orphans vdhcoapp-2.0.19 Ventoy Backup Vídeos VirtualBox VMs xen test xen-mga#33082 YAML-LibYAML-Test-dir zekemx Fix LDAP filter injection via unescaped %u/%fu/%d substitution into the `search_filter`, reported by Milan Hoppe acta2.jpg acta.jpg advisories avatar.jpg avatar.png bdk-key.bkup bdk-mga9.txt bdk-new.key bdkpackagers.key bdkpackagers.sec bdkpass bin blogdrake.net bookmarks.html BRF Descargas Desktop diagrana.pdf discover-missing Documentos Dragon Quest: Dai no Daibouken - Bravest Full OP Sub Español [2MZON1ev9DE].mkv ejemplo añadir_archivo1.spec ejemplo añadir_archivo2.spec google-chrome.spec html i18n.pdf Imágenes index.php kernel-backport kernel-cves.enc kernel-cves.txt lqshell-stylesheet.css mageia-advisories MANOLO MUÑOZ VS ALBERTO VAZQUEZ MANO A MANO 24 EXITAZOS RANCHEROS CON MARIACHI.opus MEGA megasync-10.tar.gz #*message*-20260914-112747# mgaadv-error.txt mgarepo mirrorbdk mock Música origen.rss out.pnm PDF Plantillas Precure News - Star Detective PreCure! OP (Movie Footage Edition) [2099120870992310272].mp4 Proyectos qatest qa-testing qphotorec.desktop qphotorec.log reinstall.sh repodkfix.sh repositorio rpm rss Sailor Moon Cosmos AMV - Makenai (Sailor Star Song).mp4 sshrc style.html Taylor Swift, les coulisses du succès [120464-000-A].mp4 test.jpg tmp update-bdkkey.sh urpm-ng-distupgrade-orphans vdhcoapp-2.0.19 Ventoy Backup Vídeos VirtualBox VMs xen test xen-mga#33082 YAML-LibYAML-Test-dir zekemx Fix arbitrary Sieve script injection via a filter rule name bypassing `managesieve_disabled_actions`, reported by Milan Hoppe acta2.jpg acta.jpg advisories avatar.jpg avatar.png bdk-key.bkup bdk-mga9.txt bdk-new.key bdkpackagers.key bdkpackagers.sec bdkpass bin blogdrake.net bookmarks.html BRF Descargas Desktop diagrana.pdf discover-missing Documentos Dragon Quest: Dai no Daibouken - Bravest Full OP Sub Español [2MZON1ev9DE].mkv ejemplo añadir_archivo1.spec ejemplo añadir_archivo2.spec google-chrome.spec html i18n.pdf Imágenes index.php kernel-backport kernel-cves.enc kernel-cves.txt lqshell-stylesheet.css mageia-advisories MANOLO MUÑOZ VS ALBERTO VAZQUEZ MANO A MANO 24 EXITAZOS RANCHEROS CON MARIACHI.opus MEGA megasync-10.tar.gz #*message*-20260914-112747# mgaadv-error.txt mgarepo mirrorbdk mock Música origen.rss out.pnm PDF Plantillas Precure News - Star Detective PreCure! OP (Movie Footage Edition) [2099120870992310272].mp4 Proyectos qatest qa-testing qphotorec.desktop qphotorec.log reinstall.sh repodkfix.sh repositorio rpm rss Sailor Moon Cosmos AMV - Makenai (Sailor Star Song).mp4 sshrc style.html Taylor Swift, les coulisses du succès [120464-000-A].mp4 test.jpg tmp update-bdkkey.sh urpm-ng-distupgrade-orphans vdhcoapp-2.0.19 Ventoy Backup Vídeos VirtualBox VMs xen test xen-mga#33082 YAML-LibYAML-Test-dir zekemx Fix RCE via cmd_learn driver of markasjunk plugin, reported by nept1337 acta2.jpg acta.jpg advisories avatar.jpg avatar.png bdk-key.bkup bdk-mga9.txt bdk-new.key bdkpackagers.key bdkpackagers.sec bdkpass bin blogdrake.net bookmarks.html BRF Descargas Desktop diagrana.pdf discover-missing Documentos Dragon Quest: Dai no Daibouken - Bravest Full OP Sub Español [2MZON1ev9DE].mkv ejemplo añadir_archivo1.spec ejemplo añadir_archivo2.spec google-chrome.spec html i18n.pdf Imágenes index.php kernel-backport kernel-cves.enc kernel-cves.txt lqshell-stylesheet.css mageia-advisories MANOLO MUÑOZ VS ALBERTO VAZQUEZ MANO A MANO 24 EXITAZOS RANCHEROS CON MARIACHI.opus MEGA megasync-10.tar.gz #*message*-20260914-112747# mgaadv-error.txt mgarepo mirrorbdk mock Música origen.rss out.pnm PDF Plantillas Precure News - Star Detective PreCure! OP (Movie Footage Edition) [2099120870992310272].mp4 Proyectos qatest qa-testing qphotorec.desktop qphotorec.log reinstall.sh repodkfix.sh repositorio rpm rss Sailor Moon Cosmos AMV - Makenai (Sailor Star Song).mp4 sshrc style.html Taylor Swift, les coulisses du succès [120464-000-A].mp4 test.jpg tmp update-bdkkey.sh urpm-ng-distupgrade-orphans vdhcoapp-2.0.19 Ventoy Backup Vídeos VirtualBox VMs xen test xen-mga#33082 YAML-LibYAML-Test-dir zekemx Fix IMAP command injection via mail search and LITERAL+ byte-count desynchronization, reported by Zach Hanley of Horizon3.ai acta2.jpg acta.jpg advisories avatar.jpg avatar.png bdk-key.bkup bdk-mga9.txt bdk-new.key bdkpackagers.key bdkpackagers.sec bdkpass bin blogdrake.net bookmarks.html BRF Descargas Desktop diagrana.pdf discover-missing Documentos Dragon Quest: Dai no Daibouken - Bravest Full OP Sub Español [2MZON1ev9DE].mkv ejemplo añadir_archivo1.spec ejemplo añadir_archivo2.spec google-chrome.spec html i18n.pdf Imágenes index.php kernel-backport kernel-cves.enc kernel-cves.txt lqshell-stylesheet.css mageia-advisories MANOLO MUÑOZ VS ALBERTO VAZQUEZ MANO A MANO 24 EXITAZOS RANCHEROS CON MARIACHI.opus MEGA megasync-10.tar.gz #*message*-20260914-112747# mgaadv-error.txt mgarepo mirrorbdk mock Música origen.rss out.pnm PDF Plantillas Precure News - Star Detective PreCure! OP (Movie Footage Edition) [2099120870992310272].mp4 Proyectos qatest qa-testing qphotorec.desktop qphotorec.log reinstall.sh repodkfix.sh repositorio rpm rss Sailor Moon Cosmos AMV - Makenai (Sailor Star Song).mp4 sshrc style.html Taylor Swift, les coulisses du succès [120464-000-A].mp4 test.jpg tmp update-bdkkey.sh urpm-ng-distupgrade-orphans vdhcoapp-2.0.19 Ventoy Backup Vídeos VirtualBox VMs xen test xen-mga#33082 YAML-LibYAML-Test-dir zekemx Fix password’s modoboa driver leak of an authentication token to a user-controlled host, reported by [meifukun](https://github.com/meifukun) acta2.jpg acta.jpg advisories avatar.jpg avatar.png bdk-key.bkup bdk-mga9.txt bdk-new.key bdkpackagers.key bdkpackagers.sec bdkpass bin blogdrake.net bookmarks.html BRF Descargas Desktop diagrana.pdf discover-missing Documentos Dragon Quest: Dai no Daibouken - Bravest Full OP Sub Español [2MZON1ev9DE].mkv ejemplo añadir_archivo1.spec ejemplo añadir_archivo2.spec google-chrome.spec html i18n.pdf Imágenes index.php kernel-backport kernel-cves.enc kernel-cves.txt lqshell-stylesheet.css mageia-advisories MANOLO MUÑOZ VS ALBERTO VAZQUEZ MANO A MANO 24 EXITAZOS RANCHEROS CON MARIACHI.opus MEGA megasync-10.tar.gz #*message*-20260914-112747# mgaadv-error.txt mgarepo mirrorbdk mock Música origen.rss out.pnm PDF Plantillas Precure News - Star Detective PreCure! OP (Movie Footage Edition) [2099120870992310272].mp4 Proyectos qatest qa-testing qphotorec.desktop qphotorec.log reinstall.sh repodkfix.sh repositorio rpm rss Sailor Moon Cosmos AMV - Makenai (Sailor Star Song).mp4 sshrc style.html Taylor Swift, les coulisses du succès [120464-000-A].mp4 test.jpg tmp update-bdkkey.sh urpm-ng-distupgrade-orphans vdhcoapp-2.0.19 Ventoy Backup Vídeos VirtualBox VMs xen test xen-mga#33082 YAML-LibYAML-Test-dir zekemx Fix stored XSS in “Add to address book” action, reported by Paulos Yibelo from pwn.ai acta2.jpg acta.jpg advisories avatar.jpg avatar.png bdk-key.bkup bdk-mga9.txt bdk-new.key bdkpackagers.key bdkpackagers.sec bdkpass bin blogdrake.net bookmarks.html BRF Descargas Desktop diagrana.pdf discover-missing Documentos Dragon Quest: Dai no Daibouken - Bravest Full OP Sub Español [2MZON1ev9DE].mkv ejemplo añadir_archivo1.spec ejemplo añadir_archivo2.spec google-chrome.spec html i18n.pdf Imágenes index.php kernel-backport kernel-cves.enc kernel-cves.txt lqshell-stylesheet.css mageia-advisories MANOLO MUÑOZ VS ALBERTO VAZQUEZ MANO A MANO 24 EXITAZOS RANCHEROS CON MARIACHI.opus MEGA megasync-10.tar.gz #*message*-20260914-112747# mgaadv-error.txt mgarepo mirrorbdk mock Música origen.rss out.pnm PDF Plantillas Precure News - Star Detective PreCure! OP (Movie Footage Edition) [2099120870992310272].mp4 Proyectos qatest qa-testing qphotorec.desktop qphotorec.log reinstall.sh repodkfix.sh repositorio rpm rss Sailor Moon Cosmos AMV - Makenai (Sailor Star Song).mp4 sshrc style.html Taylor Swift, les coulisses du succès [120464-000-A].mp4 test.jpg tmp update-bdkkey.sh urpm-ng-distupgrade-orphans vdhcoapp-2.0.19 Ventoy Backup Vídeos VirtualBox VMs xen test xen-mga#33082 YAML-LibYAML-Test-dir zekemx Fix HTML/CSS sanitization bypass via SVG animate `by` attribute, reported by vectrain References
- https://bugs.mageia.org/show_bug.cgi?id=36135
- https://www.openwall.com/lists/oss-security/2026/08/10/2
- https://github.com/roundcube/roundcubemail/releases/tag/1.6.18
- roundcubemail-1.6.18-1.mga9




