Lector de Feeds
MGASA-2026-0376 - Updated tomcat packages fix security vulnerabilities
Publication date: 04 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-59083 , CVE-2026-59084 , CVE-2026-66299 , CVE-2026-65182 , CVE-2026-65183 , CVE-2026-65637 , CVE-2026-65905 , CVE-2026-65927 , CVE-2026-66422 , CVE-2026-68525 , CVE-2026-68569 , CVE-2026-68763 , CVE-2026-73180 Description
Incorrect URL decoding in RewriteValve may allow security control bypass. (CVE-2026-59083) EncryptInterceptor requirements not clearly documented. (CVE-2026-59084) DoS via WebSocket chat example. (CVE-2026-66299) Bypass longest prefix security constraint. (CVE-2026-65182) TOCTOU when setting specific permissions for Unix Domain Sockets. (CVE-2026-65183) HTTP/2 no-authority bypass of strict SNI validation - CVE-2026-32990 fix incomplete. (CVE-2026-65637) Limited replay attack possible with DIGEST authentication. (CVE-2026-65905) RewriteValve [N] restarts at the second rule and may bypass access control. (CVE-2026-65927) Servlet role references can bypass declarative role constraints. (CVE-2026-66422) Redirect after FORM auth may bypass method specific constraints. (CVE-2026-68525) Principal lookup can fail open in some cases. (CVE-2026-68569) DoS via allocation leak in HTTP/2 backlog tracking when a stream is reset. (CVE-2026-68763) Authenticated WebSocket session survives end of HTTP session. (CVE-2026-73180) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-59083 , CVE-2026-59084 , CVE-2026-66299 , CVE-2026-65182 , CVE-2026-65183 , CVE-2026-65637 , CVE-2026-65905 , CVE-2026-65927 , CVE-2026-66422 , CVE-2026-68525 , CVE-2026-68569 , CVE-2026-68763 , CVE-2026-73180 Description
Incorrect URL decoding in RewriteValve may allow security control bypass. (CVE-2026-59083) EncryptInterceptor requirements not clearly documented. (CVE-2026-59084) DoS via WebSocket chat example. (CVE-2026-66299) Bypass longest prefix security constraint. (CVE-2026-65182) TOCTOU when setting specific permissions for Unix Domain Sockets. (CVE-2026-65183) HTTP/2 no-authority bypass of strict SNI validation - CVE-2026-32990 fix incomplete. (CVE-2026-65637) Limited replay attack possible with DIGEST authentication. (CVE-2026-65905) RewriteValve [N] restarts at the second rule and may bypass access control. (CVE-2026-65927) Servlet role references can bypass declarative role constraints. (CVE-2026-66422) Redirect after FORM auth may bypass method specific constraints. (CVE-2026-68525) Principal lookup can fail open in some cases. (CVE-2026-68569) DoS via allocation leak in HTTP/2 backlog tracking when a stream is reset. (CVE-2026-68763) Authenticated WebSocket session survives end of HTTP session. (CVE-2026-73180) References
- https://bugs.mageia.org/show_bug.cgi?id=35927
- https://www.openwall.com/lists/oss-security/2026/07/14/7
- https://lists.apache.org/thread/3g63zos2gkjo5vgnrk8kxmosv47w6wbq
- https://www.openwall.com/lists/oss-security/2026/07/14/8
- https://lists.apache.org/thread/7w9746ootcxo0gvx26xjpw80l31f1qw7
- https://www.openwall.com/lists/oss-security/2026/07/28/25
- https://lists.apache.org/thread/8owczcc1o8qw1rxmg9gvfk4w2jnh4l5k
- https://www.openwall.com/lists/oss-security/2026/08/26/1
- https://www.openwall.com/lists/oss-security/2026/08/26/2
- https://www.openwall.com/lists/oss-security/2026/08/26/3
- https://www.openwall.com/lists/oss-security/2026/08/26/4
- https://www.openwall.com/lists/oss-security/2026/08/26/5
- https://www.openwall.com/lists/oss-security/2026/08/26/6
- https://www.openwall.com/lists/oss-security/2026/08/26/7
- https://www.openwall.com/lists/oss-security/2026/08/26/8
- https://www.openwall.com/lists/oss-security/2026/08/26/9
- https://www.openwall.com/lists/oss-security/2026/08/26/10
- https://www.cve.org/CVERecord?id=CVE-2026-59083
- https://www.cve.org/CVERecord?id=CVE-2026-59084
- https://www.cve.org/CVERecord?id=CVE-2026-66299
- https://www.cve.org/CVERecord?id=CVE-2026-65182
- https://www.cve.org/CVERecord?id=CVE-2026-65183
- https://www.cve.org/CVERecord?id=CVE-2026-65637
- https://www.cve.org/CVERecord?id=CVE-2026-65905
- https://www.cve.org/CVERecord?id=CVE-2026-65927
- https://www.cve.org/CVERecord?id=CVE-2026-66422
- https://www.cve.org/CVERecord?id=CVE-2026-68525
- https://www.cve.org/CVERecord?id=CVE-2026-68569
- https://www.cve.org/CVERecord?id=CVE-2026-68763
- https://www.cve.org/CVERecord?id=CVE-2026-73180
- tomcat-9.0.121-1.mga10
- tomcat-9.0.121-1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0375 - Updated mbedtls packages fix security vulnerabilities
Publication date: 04 Sep 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-25832 , CVE-2026-35336 , CVE-2026-49300 , CVE-2026-50579 , CVE-2026-50580 , CVE-2026-50581 , CVE-2026-50583 , CVE-2026-50584 , CVE-2026-50585 , CVE-2026-50586 , CVE-2026-50587 , CVE-2026-50588 , CVE-2026-50640 , CVE-2026-50713 , CVE-2026-54435 , CVE-2026-54441 , CVE-2026-73064 Description
TLS 1.3 client accepts HelloRetryRequest selecting an unadvertised group. (CVE-2026-25832) Possible buffer overflow in mbedtls_ecdh_calc_secret(). (CVE-2026-35336) X.509 CA bit forgery via invalid basicConstraints extension. (CVE-2026-49300) Use-after-free in mbedtls_pkcs7_free() when reusing a PKCS7 context. (CVE-2026-50579) Remote buffer overflow in TLS 1.2 ECDHE-PSK client handshake. (CVE-2026-50580) Extended master secret calculation failure ignored. (CVE-2026-50581) A 1-byte buffer overread when parsing a malformed ECC public key in the PK module. (CVE-2026-50583) ChaCha20 counter overflow can reuse keystream. (CVE-2026-50584) Incomplete context reset in mbedtls_ssl_session_reset(). (CVE-2026-50585) A potential information disclosure in TLS 1.2 servers using session tickets. If the session ticket write callback failed without setting the lifetime output parameter, Mbed TLS could send 4 bytes of uninitialized stack memory to the peer in the NewSessionTicket message. (CVE-2026-50586) Timing side-channel in RSA PKCS#1 v1.5 decryption. (CVE-2026-50587) Out-of-bounds read in TLS 1.2 EC J-PAKE ServerKeyExchange parsing. (CVE-2026-50588) Ignored TLS 1.3 resumption secret derivation error. (CVE-2026-50640) Heap corruption with early renegotiation after corrupted record in DTLS. (CVE-2026-50713) Side channel leak in ECC optimized modp. (CVE-2026-54435) Signature algorithm restrictions not enforced on certificate chain. (CVE-2026-54441) A random generator fault can compromise TLS data integrity. (CVE-2026-73064) References
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-25832 , CVE-2026-35336 , CVE-2026-49300 , CVE-2026-50579 , CVE-2026-50580 , CVE-2026-50581 , CVE-2026-50583 , CVE-2026-50584 , CVE-2026-50585 , CVE-2026-50586 , CVE-2026-50587 , CVE-2026-50588 , CVE-2026-50640 , CVE-2026-50713 , CVE-2026-54435 , CVE-2026-54441 , CVE-2026-73064 Description
TLS 1.3 client accepts HelloRetryRequest selecting an unadvertised group. (CVE-2026-25832) Possible buffer overflow in mbedtls_ecdh_calc_secret(). (CVE-2026-35336) X.509 CA bit forgery via invalid basicConstraints extension. (CVE-2026-49300) Use-after-free in mbedtls_pkcs7_free() when reusing a PKCS7 context. (CVE-2026-50579) Remote buffer overflow in TLS 1.2 ECDHE-PSK client handshake. (CVE-2026-50580) Extended master secret calculation failure ignored. (CVE-2026-50581) A 1-byte buffer overread when parsing a malformed ECC public key in the PK module. (CVE-2026-50583) ChaCha20 counter overflow can reuse keystream. (CVE-2026-50584) Incomplete context reset in mbedtls_ssl_session_reset(). (CVE-2026-50585) A potential information disclosure in TLS 1.2 servers using session tickets. If the session ticket write callback failed without setting the lifetime output parameter, Mbed TLS could send 4 bytes of uninitialized stack memory to the peer in the NewSessionTicket message. (CVE-2026-50586) Timing side-channel in RSA PKCS#1 v1.5 decryption. (CVE-2026-50587) Out-of-bounds read in TLS 1.2 EC J-PAKE ServerKeyExchange parsing. (CVE-2026-50588) Ignored TLS 1.3 resumption secret derivation error. (CVE-2026-50640) Heap corruption with early renegotiation after corrupted record in DTLS. (CVE-2026-50713) Side channel leak in ECC optimized modp. (CVE-2026-54435) Signature algorithm restrictions not enforced on certificate chain. (CVE-2026-54441) A random generator fault can compromise TLS data integrity. (CVE-2026-73064) References
- https://bugs.mageia.org/show_bug.cgi?id=35972
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3BALMLPIK3FBKPIGK5RZX3VUWR2QCCGQ/
- https://github.com/Mbed-TLS/mbedtls/releases#release-mbedtls-3.6.7
- https://www.cve.org/CVERecord?id=CVE-2026-25832
- https://www.cve.org/CVERecord?id=CVE-2026-35336
- https://www.cve.org/CVERecord?id=CVE-2026-49300
- https://www.cve.org/CVERecord?id=CVE-2026-50579
- https://www.cve.org/CVERecord?id=CVE-2026-50580
- https://www.cve.org/CVERecord?id=CVE-2026-50581
- https://www.cve.org/CVERecord?id=CVE-2026-50583
- https://www.cve.org/CVERecord?id=CVE-2026-50584
- https://www.cve.org/CVERecord?id=CVE-2026-50585
- https://www.cve.org/CVERecord?id=CVE-2026-50586
- https://www.cve.org/CVERecord?id=CVE-2026-50587
- https://www.cve.org/CVERecord?id=CVE-2026-50588
- https://www.cve.org/CVERecord?id=CVE-2026-50640
- https://www.cve.org/CVERecord?id=CVE-2026-50713
- https://www.cve.org/CVERecord?id=CVE-2026-54435
- https://www.cve.org/CVERecord?id=CVE-2026-54441
- https://www.cve.org/CVERecord?id=CVE-2026-73064
- mbedtls-3.6.7-1.mga10
Categorías: Actualizaciones de Seguridad
MGASA-2026-0374 - Updated microcode packages fix security vulnerabilities
Publication date: 04 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2025-31936 , CVE-2025-31938 , CVE-2026-20917 , CVE-2025-35973 , CVE-2026-20716 , CVE-2026-20760 , CVE-2026-20713 , CVE-2026-20707 Description
A potential security vulnerability for some Intel® Xeon® 6 processor with Intel® Trust Domain Extensions (Intel® TDX) may allow escalation of privilege. (CVE-2025-31936) A potential security vulnerability in some Intel® Xeon® 6 processor with Intel® Trust Domain Extensions (Intel® TDX) may allow information disclosure. (CVE-2025-31938) A potential security vulnerability in some Intel® Processors may allow information disclosure. (CVE-2026-20917) A potential security vulnerability in some Intel® Processors may allow escalation of privilege. (CVE-2025-35973) A potential security vulnerability in some Intel® Processors may allow escalation of privilege. (CVE-2026-20716) A potential security vulnerability in some Intel® Processors may allow denial of service. (CVE-2026-20760) Potential security vulnerabilities in some Intel® Xeon® Processors may allow escalation of privilege. (CVE-2026-20713) A potential security vulnerability in some 3rd Gen Intel® Xeon® Scalable Processors may allow denial of service. (CVE-2026-20707) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2025-31936 , CVE-2025-31938 , CVE-2026-20917 , CVE-2025-35973 , CVE-2026-20716 , CVE-2026-20760 , CVE-2026-20713 , CVE-2026-20707 Description
A potential security vulnerability for some Intel® Xeon® 6 processor with Intel® Trust Domain Extensions (Intel® TDX) may allow escalation of privilege. (CVE-2025-31936) A potential security vulnerability in some Intel® Xeon® 6 processor with Intel® Trust Domain Extensions (Intel® TDX) may allow information disclosure. (CVE-2025-31938) A potential security vulnerability in some Intel® Processors may allow information disclosure. (CVE-2026-20917) A potential security vulnerability in some Intel® Processors may allow escalation of privilege. (CVE-2025-35973) A potential security vulnerability in some Intel® Processors may allow escalation of privilege. (CVE-2026-20716) A potential security vulnerability in some Intel® Processors may allow denial of service. (CVE-2026-20760) Potential security vulnerabilities in some Intel® Xeon® Processors may allow escalation of privilege. (CVE-2026-20713) A potential security vulnerability in some 3rd Gen Intel® Xeon® Scalable Processors may allow denial of service. (CVE-2026-20707) References
- https://bugs.mageia.org/show_bug.cgi?id=36155
- https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20260811
- https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20260812
- https://www.cve.org/CVERecord?id=CVE-2025-31936
- https://www.cve.org/CVERecord?id=CVE-2025-31938
- https://www.cve.org/CVERecord?id=CVE-2026-20917
- https://www.cve.org/CVERecord?id=CVE-2025-35973
- https://www.cve.org/CVERecord?id=CVE-2026-20716
- https://www.cve.org/CVERecord?id=CVE-2026-20760
- https://www.cve.org/CVERecord?id=CVE-2026-20713
- https://www.cve.org/CVERecord?id=CVE-2026-20707
- microcode-0.20260812-1.mga10.nonfree
- microcode-0.20260812-1.mga9.nonfree
Categorías: Actualizaciones de Seguridad
MGASA-2026-0373 - Updated libopenmpt packages fix security vulnerabilities
Publication date: 03 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
Description
Please see the links for information about the vulnerabilities. References
Type: security
Affected Mageia releases : 10 , 9
Description
Please see the links for information about the vulnerabilities. References
- https://bugs.mageia.org/show_bug.cgi?id=36208
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YDG4TQOERFZY33Z6OUALDBHR7XRQKMMA/
- https://lib.openmpt.org/libopenmpt/2026/08/15/releases-0.8.8-0.7.20-0.6.29-0.5.43-0.4.55/
- https://lib.openmpt.org/libopenmpt/2026/08/19/security-updates-0.8.9-0.7.21-0.6.30-0.5.44-0.4.56/
- https://github.com/OpenMPT/openmpt/security/advisories/GHSA-fxf7-wc37-p2cx
- libopenmpt-0.8.9-1.mga10
- libopenmpt-0.7.21-1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0372 - Updated python-gitpython packages fix security vulnerabilities
Publication date: 03 Sep 2026
Type: security
Affected Mageia releases : 9
CVE: CVE-2023-40267 , CVE-2023-41040 , CVE-2026-42215 Description
CVE-2023-40267 GitPython before 3.1.32 does not block insecure non-multi options in clone and clone_from. NOTE: this issue exists because of an incomplete fix for CVE-2022-24439. CVE-2023-41040 In order to resolve some git references, GitPython reads files from the `.git` directory, in some places the name of the file being read is provided by the user, GitPython doesn't check if this file is located outside the `.git` directory. This allows an attacker to make GitPython read any file from the system. CVE-2026-42215 From version 3.1.30 to before version 3.1.47, GitPython blocks dangerous Git options such as --upload-pack and --receive-pack by default, but the equivalent Python kwargs upload_pack and receive_pack bypass that check. If an application passes attacker-controlled kwargs into Repo.clone_from(), Remote.fetch(), Remote.pull(), or Remote.push(), this leads to arbitrary command execution even when allow_unsafe_options is left at its default value of False. This issue has been patched in version 3.1.47. References
Type: security
Affected Mageia releases : 9
CVE: CVE-2023-40267 , CVE-2023-41040 , CVE-2026-42215 Description
CVE-2023-40267 GitPython before 3.1.32 does not block insecure non-multi options in clone and clone_from. NOTE: this issue exists because of an incomplete fix for CVE-2022-24439. CVE-2023-41040 In order to resolve some git references, GitPython reads files from the `.git` directory, in some places the name of the file being read is provided by the user, GitPython doesn't check if this file is located outside the `.git` directory. This allows an attacker to make GitPython read any file from the system. CVE-2026-42215 From version 3.1.30 to before version 3.1.47, GitPython blocks dangerous Git options such as --upload-pack and --receive-pack by default, but the equivalent Python kwargs upload_pack and receive_pack bypass that check. If an application passes attacker-controlled kwargs into Repo.clone_from(), Remote.fetch(), Remote.pull(), or Remote.push(), this leads to arbitrary command execution even when allow_unsafe_options is left at its default value of False. This issue has been patched in version 3.1.47. References
- https://bugs.mageia.org/show_bug.cgi?id=35535
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AV5DV7GBLMOZT7U3Q4TDOJO5R6G3V6GH/
- https://lists.debian.org/debian-lts-announce/2023/09/msg00036.html
- https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-rpm5-65cw-6hj4
- https://github.com/gitpython-developers/GitPython/releases/tag/3.1.50
- https://github.com/gitpython-developers/GitPython/releases/tag/3.1.49
- https://github.com/gitpython-developers/GitPython/releases/tag/3.1.48
- https://github.com/gitpython-developers/GitPython/releases/tag/3.1.47
- https://github.com/gitpython-developers/GitPython/releases/tag/3.1.46
- https://github.com/gitpython-developers/GitPython/releases/tag/3.1.45
- https://github.com/gitpython-developers/GitPython/releases/tag/3.1.44
- https://github.com/gitpython-developers/GitPython/releases/tag/3.1.43
- https://github.com/gitpython-developers/GitPython/releases/tag/3.1.42
- https://github.com/gitpython-developers/GitPython/releases/tag/3.1.41
- https://github.com/gitpython-developers/GitPython/releases/tag/3.1.40
- https://github.com/gitpython-developers/GitPython/releases/tag/3.1.38
- https://github.com/gitpython-developers/GitPython/releases/tag/3.1.37
- https://github.com/gitpython-developers/GitPython/releases/tag/3.1.35
- https://github.com/gitpython-developers/GitPython/releases/tag/3.1.34
- https://github.com/gitpython-developers/GitPython/releases/tag/3.1.33
- https://github.com/gitpython-developers/GitPython/releases/tag/3.1.32
- https://github.com/gitpython-developers/GitPython/releases/tag/3.1.31
- https://www.cve.org/CVERecord?id=CVE-2023-40267
- https://www.cve.org/CVERecord?id=CVE-2023-41040
- https://www.cve.org/CVERecord?id=CVE-2026-42215
- python-gitpython-3.1.50-1.mga9
Categorías: Actualizaciones de Seguridad
MGAA-2026-0119 - Updated drakx-net packages add nl80211 (iw) scan and WPA3 (SAE) support
Publication date: 03 Sep 2026
Type: bugfix
Affected Mageia releases : 10 , 9
Description
Our drakx.net packages still depended on deprecated wext (iwlist), causing problems with finding and connecting to networks for several users. This update adds both nl80211 (iw) scan and WPA3 (SAE) support, thus fixing the issues. References
SRPMS 10/core
Type: bugfix
Affected Mageia releases : 10 , 9
Description
Our drakx.net packages still depended on deprecated wext (iwlist), causing problems with finding and connecting to networks for several users. This update adds both nl80211 (iw) scan and WPA3 (SAE) support, thus fixing the issues. References
SRPMS 10/core
- drakx-net-2.65-1.mga10
- drakx-net-2.65-1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0371 - Updated bubblewrap package fixes security vulnerabilities
Publication date: 02 Sep 2026
Type: security
Affected Mageia releases : 10
Description
Sandbox escape: symlink traversal via /oldroot allows writing files outside sandbox during setup References
Type: security
Affected Mageia releases : 10
Description
Sandbox escape: symlink traversal via /oldroot allows writing files outside sandbox during setup References
- https://bugs.mageia.org/show_bug.cgi?id=36206
- https://lists.debian.org/debian-security-announce/2026/msg00383.html
- https://github.com/containers/bubblewrap/security/advisories/GHSA-pxhw-h44j-8pfx
- https://www.openwall.com/lists/oss-security/2026/08/27/7
- bubblewrap-0.12.0-1.mga10
Categorías: Actualizaciones de Seguridad
MGASA-2026-0370 - Updated perl-Text-CSV_XS packages fix a security vulnerability
Publication date: 02 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-7111 Description
Text::CSV_XS versions before 1.62 for Perl have a use-after-free when registered callbacks extend the Perl argument stack, which may enable type confusion or memory corruption. References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-7111 Description
Text::CSV_XS versions before 1.62 for Perl have a use-after-free when registered callbacks extend the Perl argument stack, which may enable type confusion or memory corruption. References
- https://bugs.mageia.org/show_bug.cgi?id=35547
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/QELUJSCSNBIE4N5UNKH4YGI5LFCHEY65/
- https://lists.security.metacpan.org/cve-announce/msg/39453344/
- https://github.com/cpan-authors/Text-CSV_XS/issues/65
- https://www.cve.org/CVERecord?id=CVE-2026-7111
- perl-Text-CSV_XS-1.640.0-1.mga10
- perl-Text-CSV_XS-1.640.0-1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0369 - Updated libalsa2 packages fix security vulnerabilities
Publication date: 02 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-25068 , CVE-2026-56109 Description
alsa-lib 1.2.15.2 Topology Decoder Heap-based Buffer Overflow. (CVE-2026-25068) ALSA Library < 1.2.16.1 Double-Free via parse_def() in conf.c. (CVE-2026-56109) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-25068 , CVE-2026-56109 Description
alsa-lib 1.2.15.2 Topology Decoder Heap-based Buffer Overflow. (CVE-2026-25068) ALSA Library < 1.2.16.1 Double-Free via parse_def() in conf.c. (CVE-2026-56109) References
- https://bugs.mageia.org/show_bug.cgi?id=35934
- https://ubuntu.com/security/notices/USN-8044-1
- https://ubuntu.com/security/notices/USN-8538-1
- https://lore.kernel.org/alsa-devel/CAGt8pqBU0p2voB+qHxWGcNJrKHAcBhAyHUUBPLBN-Yj_SiV6MQ@mail.gmail.com/
- https://www.cve.org/CVERecord?id=CVE-2026-25068
- https://www.cve.org/CVERecord?id=CVE-2026-56109
- libalsa2-1.2.15.2-1.1.mga10
- libalsa2-1.2.9-1.1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0368 - Updated perl-XML-Bare packages fix security vulnerabilities
Publication date: 02 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-57074 , CVE-2026-13401 Description
XML::Bare versions through 0.53 for Perl have an unbounded character lookahead. XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attributes. References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-57074 , CVE-2026-13401 Description
XML::Bare versions through 0.53 for Perl have an unbounded character lookahead. XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attributes. References
- https://bugs.mageia.org/show_bug.cgi?id=35948
- https://www.openwall.com/lists/oss-security/2026/07/16/1
- https://www.openwall.com/lists/oss-security/2026/07/16/2
- https://www.cve.org/CVERecord?id=CVE-2026-57074
- https://www.cve.org/CVERecord?id=CVE-2026-13401
- perl-XML-Bare-0.530.0-26.mga10
- perl-XML-Bare-0.530.0-22.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0367 - Updated perl-YAML-Syck packages fix security vulnerabilities
Publication date: 02 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-13713 , CVE-2026-57075 , CVE-2026-57076 , CVE-2026-57077 Description
YAML::Syck versions before 1.47 for Perl allow a use-after-free and double-free via an anchor node freed while still on the parser value stack YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via a signed-char lookup-table index in syck_base64dec YAML::Syck versions before 1.47 for Perl allow a heap use-after-free via an anchor name reused as an anchors-table key in syck_hdlr_add_anchor YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via an unbounded newline scan in newline_len References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-13713 , CVE-2026-57075 , CVE-2026-57076 , CVE-2026-57077 Description
YAML::Syck versions before 1.47 for Perl allow a use-after-free and double-free via an anchor node freed while still on the parser value stack YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via a signed-char lookup-table index in syck_base64dec YAML::Syck versions before 1.47 for Perl allow a heap use-after-free via an anchor name reused as an anchors-table key in syck_hdlr_add_anchor YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via an unbounded newline scan in newline_len References
- https://bugs.mageia.org/show_bug.cgi?id=35949
- https://www.openwall.com/lists/oss-security/2026/07/17/1
- https://www.openwall.com/lists/oss-security/2026/07/17/2
- https://www.openwall.com/lists/oss-security/2026/07/17/3
- https://www.openwall.com/lists/oss-security/2026/07/17/4
- https://metacpan.org/release/TODDR/YAML-Syck-1.47/changes
- https://www.cve.org/CVERecord?id=CVE-2026-13713
- https://www.cve.org/CVERecord?id=CVE-2026-57075
- https://www.cve.org/CVERecord?id=CVE-2026-57076
- https://www.cve.org/CVERecord?id=CVE-2026-57077
- perl-YAML-Syck-1.470.0-1.mga10
- perl-YAML-Syck-1.470.0-1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0366 - Updated libarchive packages fix security vulnerabilities
Publication date: 02 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-14164 , CVE-2026-15028 , CVE-2026-5745 , CVE-2025-5918 , CVE-2025-60753 , CVE-2026-4111 , CVE-2026-4424 , CVE-2026-4426 , CVE-2026-5121 Description
Double-free vulnerability in rar5 decompression logic via dangling filtered_buf pointer in init_unpack(). (CVE-2026-14164) Heap overflow oob read while parsing a tar archive contains a pax extended header. (CVE-2026-15028) A null pointer dereference vulnerability exists in the acl parser of libarchive. (CVE-2026-5745) Reading past eof may be triggered for piped file streams. (CVE-2025-5918) An issue was discovered in libarchive bsdtar before version 3.8.1 in function apply_substitution in file tar/subst.c when processing crafted -s substitution rules. This can cause unbounded memory allocation and lead to denial of service (Out-of-Memory crash). (CVE-2025-60753) Infinite loop denial of service in rar5 decompression via archive_read_data() in libarchive. (CVE-2026-4111) Information disclosure via heap out-of-bounds read in rar archive processing. (CVE-2026-4424) Denial of service via malformed iso file processing. (CVE-2026-4426) Arbitrary code execution via integer overflow in iso9660 image processing. (CVE-2026-5121) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-14164 , CVE-2026-15028 , CVE-2026-5745 , CVE-2025-5918 , CVE-2025-60753 , CVE-2026-4111 , CVE-2026-4424 , CVE-2026-4426 , CVE-2026-5121 Description
Double-free vulnerability in rar5 decompression logic via dangling filtered_buf pointer in init_unpack(). (CVE-2026-14164) Heap overflow oob read while parsing a tar archive contains a pax extended header. (CVE-2026-15028) A null pointer dereference vulnerability exists in the acl parser of libarchive. (CVE-2026-5745) Reading past eof may be triggered for piped file streams. (CVE-2025-5918) An issue was discovered in libarchive bsdtar before version 3.8.1 in function apply_substitution in file tar/subst.c when processing crafted -s substitution rules. This can cause unbounded memory allocation and lead to denial of service (Out-of-Memory crash). (CVE-2025-60753) Infinite loop denial of service in rar5 decompression via archive_read_data() in libarchive. (CVE-2026-4111) Information disclosure via heap out-of-bounds read in rar archive processing. (CVE-2026-4424) Denial of service via malformed iso file processing. (CVE-2026-4426) Arbitrary code execution via integer overflow in iso9660 image processing. (CVE-2026-5121) References
- https://bugs.mageia.org/show_bug.cgi?id=35999
- https://ubuntu.com/security/notices/USN-8581-1
- https://www.cve.org/CVERecord?id=CVE-2026-14164
- https://www.cve.org/CVERecord?id=CVE-2026-15028
- https://www.cve.org/CVERecord?id=CVE-2026-5745
- https://www.cve.org/CVERecord?id=CVE-2025-5918
- https://www.cve.org/CVERecord?id=CVE-2025-60753
- https://www.cve.org/CVERecord?id=CVE-2026-4111
- https://www.cve.org/CVERecord?id=CVE-2026-4424
- https://www.cve.org/CVERecord?id=CVE-2026-4426
- https://www.cve.org/CVERecord?id=CVE-2026-5121
- libarchive-3.8.9-1.mga10
- libarchive-3.6.2-5.6.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0365 - Updated perl-Net-OAuth packages fix security vulnerabilities
Publication date: 02 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-72887 , CVE-2026-72888 , CVE-2026-72889 , CVE-2026-75589 Description
Net::OAuth::Client versions before 0.32 for Perl allow the service provider to silently downgrade OAuth 1.0a to OAuth 1.0 in get_request_token Net::OAuth versions before 0.32 for Perl allow memory exhaustion via unbounded caching of failed module loads in smart_require Net::OAuth versions before 0.33 for Perl allow the sender to choose the signature algorithm in verify Net::OAuth versions before 0.33 for Perl check HMAC-SHA1, HMAC-SHA256 and PLAINTEXT signatures with a non-constant-time comparison in verify References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-72887 , CVE-2026-72888 , CVE-2026-72889 , CVE-2026-75589 Description
Net::OAuth::Client versions before 0.32 for Perl allow the service provider to silently downgrade OAuth 1.0a to OAuth 1.0 in get_request_token Net::OAuth versions before 0.32 for Perl allow memory exhaustion via unbounded caching of failed module loads in smart_require Net::OAuth versions before 0.33 for Perl allow the sender to choose the signature algorithm in verify Net::OAuth versions before 0.33 for Perl check HMAC-SHA1, HMAC-SHA256 and PLAINTEXT signatures with a non-constant-time comparison in verify References
- https://bugs.mageia.org/show_bug.cgi?id=36145
- https://www.openwall.com/lists/oss-security/2026/08/16/3
- https://github.com/vurtdev/Net-OAuth/security/advisories/GHSA-jh72-4qq2-8j6g
- https://www.openwall.com/lists/oss-security/2026/08/16/4
- https://github.com/vurtdev/Net-OAuth/security/advisories/GHSA-m2cv-cq5x-47ph
- https://www.openwall.com/lists/oss-security/2026/08/19/2
- https://github.com/vurtdev/Net-OAuth/security/advisories/GHSA-c8rm-g5cm-4pf5
- https://www.openwall.com/lists/oss-security/2026/08/19/3
- https://github.com/vurtdev/Net-OAuth/security/advisories/GHSA-g8xr-69p3-gw56
- https://www.cve.org/CVERecord?id=CVE-2026-72887
- https://www.cve.org/CVERecord?id=CVE-2026-72888
- https://www.cve.org/CVERecord?id=CVE-2026-72889
- https://www.cve.org/CVERecord?id=CVE-2026-75589
- perl-Net-OAuth-0.330.0-1.mga10
- perl-Net-OAuth-0.330.0-1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0364 - Updated apr-util packages fix security vulnerabilities
Publication date: 02 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2025-49506 , CVE-2026-32327 , CVE-2026-34191 , CVE-2026-34501 , CVE-2026-34502 Description
Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack. (CVE-2025-49506) Apache Portable Runtime Utility: apr-util XML stack recursion crash. (CVE-2026-32327) Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracle. (CVE-2026-34191) Apache Portable Runtime Utility: Heap buffer overflow in APR redis client. (CVE-2026-34501) Apache Portable Runtime Utility: Heap buffer overflow in APR memcached client. (CVE-2026-34502) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2025-49506 , CVE-2026-32327 , CVE-2026-34191 , CVE-2026-34501 , CVE-2026-34502 Description
Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack. (CVE-2025-49506) Apache Portable Runtime Utility: apr-util XML stack recursion crash. (CVE-2026-32327) Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracle. (CVE-2026-34191) Apache Portable Runtime Utility: Heap buffer overflow in APR redis client. (CVE-2026-34501) Apache Portable Runtime Utility: Heap buffer overflow in APR memcached client. (CVE-2026-34502) References
- https://bugs.mageia.org/show_bug.cgi?id=36181
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VKNIDBBNHOGIQ7XPC4JGLXADWZC3JEUN/
- https://lists.debian.org/debian-security-announce/2026/msg00348.html
- https://www.cve.org/CVERecord?id=CVE-2025-49506
- https://www.cve.org/CVERecord?id=CVE-2026-32327
- https://www.cve.org/CVERecord?id=CVE-2026-34191
- https://www.cve.org/CVERecord?id=CVE-2026-34501
- https://www.cve.org/CVERecord?id=CVE-2026-34502
- apr-util-1.6.3-3.1.mga10
- apr-util-1.6.3-1.1.mga9
Categorías: Actualizaciones de Seguridad
MGAA-2026-0118 - Updated opencpn-climatology-plugin package fixes bug
Publication date: 02 Sep 2026
Type: bugfix
Affected Mageia releases : 10
Description
Updated package provides more recent climatology data (data from 2026) than the previous version (data from 2019). References
SRPMS 10/core
Type: bugfix
Affected Mageia releases : 10
Description
Updated package provides more recent climatology data (data from 2026) than the previous version (data from 2019). References
SRPMS 10/core
- opencpn-climatology-plugin-1.6.37.0-1.git20260510.mga10
Categorías: Actualizaciones de Seguridad
MGASA-2026-0363 - Updated hplip package fixes security vulnerabilities
Publication date: 01 Sep 2026
Type: security
Affected Mageia releases : 9
CVE: CVE-2026-8631 , CVE-2026-8632 Description
Potential Escalation of Privilege and Arbitrary Code Execution. (CVE-2026-8631, CVE-2026-8632) References
Type: security
Affected Mageia releases : 9
CVE: CVE-2026-8631 , CVE-2026-8632 Description
Potential Escalation of Privilege and Arbitrary Code Execution. (CVE-2026-8631, CVE-2026-8632) References
- https://bugs.mageia.org/show_bug.cgi?id=35583
- https://www.openwall.com/lists/oss-security/2026/05/23/1
- https://support.hp.com/us-en/document/ish_14942099-14942126-16/hpsbpi04118
- https://ubuntu.com/security/notices/USN-8483-1
- https://lists.debian.org/debian-security-announce/2026/msg00313.html
- https://www.cve.org/CVERecord?id=CVE-2026-8631
- https://www.cve.org/CVERecord?id=CVE-2026-8632
- hplip-3.22.10-4.2.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0362 - Updated perl-HTTP-Date packages fix a security vulnerability
Publication date: 01 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-14741 Description
HTTP::Date versions before 6.08 for Perl allow CPU exhaustion via polynomial regex backtracking in parse_date References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-14741 Description
HTTP::Date versions before 6.08 for Perl allow CPU exhaustion via polynomial regex backtracking in parse_date References
- https://bugs.mageia.org/show_bug.cgi?id=35952
- https://www.openwall.com/lists/oss-security/2026/07/17/10
- https://www.cve.org/CVERecord?id=CVE-2026-14741
- perl-HTTP-Date-6.80.0-1.mga10
- perl-HTTP-Date-6.80.0-1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0361 - Updated perl-Date-Manip packages fix security vulnerabilities
Publication date: 01 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-60074 , CVE-2026-60075 Description
Date::Manip versions through 6.99 for Perl return corrupted dates via non-ASCII decimal digits that pass the numeric range tests in check Date::Manip versions through 6.99 for Perl allow CPU exhaustion via quadratic backtracking in the unanchored time substitution in _parse_time References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-60074 , CVE-2026-60075 Description
Date::Manip versions through 6.99 for Perl return corrupted dates via non-ASCII decimal digits that pass the numeric range tests in check Date::Manip versions through 6.99 for Perl allow CPU exhaustion via quadratic backtracking in the unanchored time substitution in _parse_time References
- https://bugs.mageia.org/show_bug.cgi?id=36130
- https://www.openwall.com/lists/oss-security/2026/07/30/19
- https://www.openwall.com/lists/oss-security/2026/07/30/20
- https://www.cve.org/CVERecord?id=CVE-2026-60074
- https://www.cve.org/CVERecord?id=CVE-2026-60075
- perl-Date-Manip-6.990.0-1.mga10
- perl-Date-Manip-6.990.0-1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0360 - Updated perl-HTML-FormHandler packages fix a security vulnerability
Publication date: 01 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2022-4993 Description
HTML::FormHandler versions through 0.40068 for Perl allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notation template References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2022-4993 Description
HTML::FormHandler versions through 0.40068 for Perl allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notation template References
- https://bugs.mageia.org/show_bug.cgi?id=36141
- https://www.openwall.com/lists/oss-security/2026/08/13/9
- https://www.cve.org/CVERecord?id=CVE-2022-4993
- perl-HTML-FormHandler-0.400.680-8.mga10
- perl-HTML-FormHandler-0.400.680-6.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0359 - Updated nodejs packages fix security vulnerabilities
Publication date: 01 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-56846 , CVE-2026-56848 , CVE-2026-58043 , CVE-2026-56850 , CVE-2026-58040 , CVE-2026-58042 , CVE-2026-58045 , CVE-2026-56847 , CVE-2026-58039 , CVE-2026-58044 Description
http2: retain header memory in session accounting. (CVE-2026-56846) http2: defer rst stream while in scope. (CVE-2026-56848) permission: avoid granting radix split nodes. (CVE-2026-58043) https: distinguish PFX object-array agent keys. (CVE-2026-56850) https: bind identity checks to session reuse. (CVE-2026-58040) dns: handle large resolveAny address replies. (CVE-2026-58042) zlib: throw on out-of-bounds write buffers. (CVE-2026-58045) permission: enforce fs write permission for trace events. (CVE-2026-56847) permission: check final report output path. (CVE-2026-58039) http: reject requests exceeding max header count. (CVE-2026-58044) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-56846 , CVE-2026-56848 , CVE-2026-58043 , CVE-2026-56850 , CVE-2026-58040 , CVE-2026-58042 , CVE-2026-58045 , CVE-2026-56847 , CVE-2026-58039 , CVE-2026-58044 Description
http2: retain header memory in session accounting. (CVE-2026-56846) http2: defer rst stream while in scope. (CVE-2026-56848) permission: avoid granting radix split nodes. (CVE-2026-58043) https: distinguish PFX object-array agent keys. (CVE-2026-56850) https: bind identity checks to session reuse. (CVE-2026-58040) dns: handle large resolveAny address replies. (CVE-2026-58042) zlib: throw on out-of-bounds write buffers. (CVE-2026-58045) permission: enforce fs write permission for trace events. (CVE-2026-56847) permission: check final report output path. (CVE-2026-58039) http: reject requests exceeding max header count. (CVE-2026-58044) References
- https://bugs.mageia.org/show_bug.cgi?id=36201
- https://nodejs.org/en/blog/vulnerability/july-2026-security-releases
- https://nodejs.org/en/blog/release/v22.23.2
- https://www.cve.org/CVERecord?id=CVE-2026-56846
- https://www.cve.org/CVERecord?id=CVE-2026-56848
- https://www.cve.org/CVERecord?id=CVE-2026-58043
- https://www.cve.org/CVERecord?id=CVE-2026-56850
- https://www.cve.org/CVERecord?id=CVE-2026-58040
- https://www.cve.org/CVERecord?id=CVE-2026-58042
- https://www.cve.org/CVERecord?id=CVE-2026-58045
- https://www.cve.org/CVERecord?id=CVE-2026-56847
- https://www.cve.org/CVERecord?id=CVE-2026-58039
- https://www.cve.org/CVERecord?id=CVE-2026-58044
- nodejs-22.23.2-1.mga10
- nodejs-22.23.2-1.mga9
Categorías: Actualizaciones de Seguridad




