Lector de Feeds

MGASA-2026-0463 - Updated python-pillow packages fix security vulnerabilities

Mageia Security - 1 Octubre, 2026 - 01:08
Publication date: 01 Oct 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-55380 , CVE-2026-54060 , CVE-2026-54059 , CVE-2026-55379 , CVE-2026-59205 , CVE-2026-59199 , CVE-2026-59197 , CVE-2026-59198 , CVE-2026-54058 , CVE-2026-59204 , CVE-2026-59203 Description
Prevent decompression bomb when parsing PDF WindowsViewer.get_command injection EPS image infinite loop JPEG2000 image memory usage McIdas out-of-bounds (OOB) read Out-of-bounds (OOB) read when saving 1 mode TGA images Out-of-bounds (OOB) write from large RankFilter sizes Out-of-bounds (OOB) write from Image.paste() Out-of-bounds (OOB) write in ImageCmsTransform Prevent FontFile decompression bomb Prevent GD decompression bomb References
SRPMS 10/core
  • python-pillow-12.3.0-1.mga10

MGAA-2026-0144 - Updated glabels & glabels-qt packages fixes bug

Mageia Security - 1 Octubre, 2026 - 01:08
Publication date: 01 Oct 2026
Type: bugfix
Affected Mageia releases : 10
Description
glabels can't open previously-created glabels files. We have added a patch to fix the issue but the project is dead upstream and its developer is now focussing on glabels-qt. We are releasing glabels-qt as an alternative. Both versions fix the reported issue; it is your decision what tool to use. References
SRPMS 10/core
  • glabels-3.4.1-12.1.mga10
  • glabels-qt-3.99-0.2.2026.08.27git554c9f0.mga10

MGAA-2026-0143 - Updated borgbackup package fixes bug

Mageia Security - 30 Septiembre, 2026 - 16:00
Publication date: 30 Sep 2026
Type: bugfix
Affected Mageia releases : 10
Description
Borgbackup uses the msgpack python module, and it includes a stopping check for exactly the version 1.2.1. It also recognises an option to disable this check. The updated package shunts this check, which seems overzealous. References
SRPMS 10/core
  • borgbackup-1.4.5-1.1.mga10

MGAA-2026-0142 - Updated engrampa package fixes opening zst files

Mageia Security - 30 Septiembre, 2026 - 16:00
Publication date: 30 Sep 2026
Type: bugfix
Affected Mageia releases : 10
Description
Due to a missing requirement on zstd, engrampa can't open zst files. This update fixes the reported issue. References
SRPMS 10/core
  • engrampa-1.28.5-1.mga10

MGAA-2026-0141 - Updated task-lxde package fixes bug

Mageia Security - 30 Septiembre, 2026 - 16:00
Publication date: 30 Sep 2026
Type: bugfix
Affected Mageia releases : 10
Description
LXDM is only installed by task-lxde. If you only install task-lxde-minimal, then you miss LXDM and you only have XDM which doesn't let you select your desktop environment. This update fixes the reported issue, moving the requirement on LXDM to the task-lxde-minimal package. References
SRPMS 10/core
  • task-lxde-10-2.1.mga10

MGAA-2026-0139 - New urpm-ng packages introduce urpm-ng

Mageia Security - 30 Septiembre, 2026 - 02:36
Publication date: 30 Sep 2026
Type: bugfix
Affected Mageia releases : 10 , 9
Description
urpm-ng is a reimplementation of the urpmi toolset, written in Python on top of libsolv. It installs, upgrades, removes and queries packages, and resolves dependencies automatically. This packages introduces urpm-ng in Mageia 9 and 10 to allow early testers do migrations from Mageia 9 to Mageia 10 with the package manager component without add external repositories. We do not recommend it yet for inexperienced users. References
SRPMS 10/core
  • urpm-ng-0.9.14-1.mga10
9/core
  • urpm-ng-0.9.14-1.mga9

MGAA-2026-0138 - Updated boomaga packages fix bug

Mageia Security - 29 Septiembre, 2026 - 20:12
Publication date: 29 Sep 2026
Type: bugfix
Affected Mageia releases : 10 , 9
Description
The tool has changed developers and has been migrated to Qt6. The update fixes bugs in our current release including but not limited to a bug where, in some conditions, the GUI does not start. References
SRPMS 10/core
  • boomaga-3.9.2-1.mga10
9/core
  • boomaga-3.9.2-1.mga9

MGASA-2026-0461 - Updated pam packages fix a security vulnerability

Mageia Security - 28 Septiembre, 2026 - 18:04
Publication date: 28 Sep 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-54411 Description
The updated packages fix a security vulnerability: Linux-PAM pam_userdb Observable Timing Discrepancy in Plaintext Password Comparison. (CVE-2026-54411) References
SRPMS 10/core
  • pam-1.7.1-2.1.mga10

MGASA-2026-0460 - Updated p11-kit packages fix security vulnerabilities

Mageia Security - 28 Septiembre, 2026 - 18:04
Publication date: 28 Sep 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-13757 , CVE-2026-18938 Description
The updated packages fix security vulnerabilities: Stack exhaustion via unbounded recursion in rpc attribute parsing. (CVE-2026-13757) Integer overflow in rpc attribute-array length calculation can under-allocate nested attribute storage on 32 bit systems. (CVE-2026-18938) References
SRPMS 10/core
  • p11-kit-0.25.10-1.1.mga10

MGASA-2026-0459 - Updated libxml2 packages fix security vulnerabilities

Mageia Security - 28 Septiembre, 2026 - 18:04
Publication date: 28 Sep 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-11979 , CVE-2026-86137 , CVE-2026-86138 , CVE-2026-86139 , CVE-2026-86140 , CVE-2026-86141 , CVE-2026-86142 , CVE-2026-86143 , CVE-2026-86144 Description
The updated packages fix several security issues: Stack-Based Buffer Overflow in libxml2. (CVE-2026-11979) In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka an out-of-bounds read in the NXT macro in xmlregexp. (CVE-2026-86137) In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow. (CVE-2026-86138) In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow. (CVE-2026-86139) In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-based buffer overflow. (CVE-2026-86140) xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in xmlRegNewParserCtxt after a strdup failure, i.e., it does not calculate a string length after NULL checking. (CVE-2026-86141) In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation. (CVE-2026-86142) In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback. This has security relevance for many types of uses of that length value within a callback. (CVE-2026-86143) In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for example, the XML_PARSE_NONET flag, if (without it) a custom resource loader accesses the internet and triggers XML external entity injection, SSRF, or a denial of service (e.g., for an attacker-controlled internet resource that is intentionally slow). (CVE-2026-86144) References
SRPMS 10/core
  • libxml2-2.15.1-3.2.mga10
Feed