Lector de Feeds

MGASA-2026-0341 - Updated golang packages fix security vulnerabilities

Mageia Security - 30 Agosto, 2026 - 05:17
Publication date: 30 Aug 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-56865 , CVE-2026-56864 , CVE-2026-56859 , CVE-2026-56853 , CVE-2026-56860 , CVE-2026-46600 , CVE-2026-56862 , CVE-2026-56858 , CVE-2026-39821 , CVE-2026-33818 Description
CVE-2026-56865 A malicious GOPROXY was previously capable of forging up to two sumdb tiles that allow for a requested module to bypass the GOSUMDB check and persist attacker-controlled module content to a local Go module cache. CVE-2026-56864 A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log. CVE-2026-56859 Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion. CVE-2026-56853 When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. Previously, this was being done with no timeout applied. ReadHeaderTimeout is now applied for this. CVE-2026-56860 Previously, resolving relative paths containing parent directory (|..|) segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. CVE-2026-4660 Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer. CVE-2026-56862 Previously, we always counted handshake messages, such as KeyUpdate, as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely. CVE-2026-56858 Previously, pathological inputs could close an unescaped |/| early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS. CVE-2026-39821 The ToASCII and ToUnicode functions incorrectly accepted Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returned the name "example.com" rather than an error. CVE-2026-33818 Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures. References
SRPMS 10/core
  • golang-1.25.13-1.mga10
9/core
  • golang-1.25.13-1.mga9

MGASA-2026-0340 - Updated python-nltk packages fix security vulnerabilities

Mageia Security - 29 Agosto, 2026 - 16:47
Publication date: 29 Aug 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-62383 , CVE-2026-62384 , CVE-2026-62385 , CVE-2026-62388 , CVE-2026-63311 , CVE-2026-63312 , CVE-2026-63315 , CVE-2026-71513 , CVE-2026-71514 , CVE-2026-71518 , CVE-2026-78680 , CVE-2026-78681 , CVE-2026-78682 , CVE-2026-78683 , CVE-2026-79657 , CVE-2026-79674 , CVE-2026-79675 , CVE-2026-79676 Description
Updated packages fix security vulnerabilities. Please see the links. References
SRPMS 10/core
  • python-nltk-3.10.3-1.mga10
9/core
  • python-nltk-3.10.3-1.mga9

MGASA-2026-0339 - Updated python-django packages fix security vulnerabilities

Mageia Security - 27 Agosto, 2026 - 20:15
Publication date: 27 Aug 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-15307 , CVE-2026-15337 , CVE-2026-15830 , CVE-2026-15920 Description
CVE-2026-15307: Server-side file-write and request forgery via spatial lookups CVE-2026-15337: Potential denial-of-service vulnerability in `check_for_language()` CVE-2026-15830: Potential denial-of-service vulnerability via nested geometry collections CVE-2026-15920: Potential cross-site scripting via `URLField` values in the admin References
SRPMS 10/core
  • python-django-5.2.17-1.mga10

MGASA-2026-0338 - Updated avahi packages fix security vulnerabilities

Mageia Security - 27 Agosto, 2026 - 20:15
Publication date: 27 Aug 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2025-59529 , CVE-2026-24401 , CVE-2026-34933 Description
Simple protocol server ignores accepts unlimited connections and logs failures without limit. (CVE-2025-59529) Avahi has Uncontrolled Recursion in lookup_handle_cname function. (CVE-2026-24401) Reachable assertion in `transport_flags_from_domain()` via conflicting publish flags crashes avahi-daemon. (CVE-2026-34933) References
SRPMS 10/core
  • avahi-0.8-18.1.mga10
9/core
  • avahi-0.8-10.4.mga9

MGAA-2026-0114 - Updated yt-dlp packages fix bug

Mageia Security - 27 Agosto, 2026 - 20:15
Publication date: 27 Aug 2026
Type: bugfix
Affected Mageia releases : 10 , 9
Description
YouTube videos are no longer loaded and instead terminated with error 'forbidden'. This update fixes the reported issue. References
SRPMS 10/core
  • yt-dlp-2026.08.19-1.1.mga10
9/core
  • yt-dlp-2026.08.19-1.1.mga9

MGAA-2026-0113 - Updated fs-uae packages fix bug

Mageia Security - 27 Agosto, 2026 - 20:15
Publication date: 27 Aug 2026
Type: bugfix
Affected Mageia releases : 10
Description
Drop the unnecessary fs-uae-arcade build and use only the fs-uae-launcher arcade mode. This update preserves the user install and launching procedure. References
SRPMS 10/core
  • fs-uae-3.2.35-2.1.mga10

MGAA-2026-0112 - Updated guayadeque packages fix bug

Mageia Security - 27 Agosto, 2026 - 20:15
Publication date: 27 Aug 2026
Type: bugfix
Affected Mageia releases : 10
Description
This new version allows easily adding 20 French national radio stations that are no longer provided by Tunein. References
SRPMS 10/core
  • guayadeque-0.7.6-1.mga10

MGAA-2026-0111 - Updated mnemosyne packages fix bug

Mageia Security - 27 Agosto, 2026 - 20:15
Publication date: 27 Aug 2026
Type: bugfix
Affected Mageia releases : 10
Description
This release should fix the errors in starting the app due to missing files in python wheels built directly from source, improving the quitting process of the app, and silencing some Qt warnings. References
SRPMS 10/core
  • mnemosyne-2.11-3.2.mga10

MGAA-2026-0110 - Updated opencpn packages fix bug

Mageia Security - 27 Agosto, 2026 - 20:15
Publication date: 27 Aug 2026
Type: bugfix
Affected Mageia releases : 10
Description
The last update of opencpn to version 5.14.0 in core/updates was supposed to obsolete and remove one of its plugins (opencpn-squiddio-plugin) which caused a core dump for opencpn if it were present and activated. This update fixes the reported behaviour. References
SRPMS 10/core
  • opencpn-5.14.0-2.mga10

MGAA-2026-0109 - Updated viking packages fix bug

Mageia Security - 27 Agosto, 2026 - 20:15
Publication date: 27 Aug 2026
Type: bugfix
Affected Mageia releases : 10
Description
Fix a missing dependency on the "proj" database causing a segmentation fault. References
SRPMS 10/core
  • viking-1.11-2.1.mga10
Feed