Lector de Feeds

MGAA-2026-0071 - Updated amarok packages fix a bug

Mageia Security - 27 Julio, 2026 - 23:45
Publication date: 27 Jul 2026
Type: bugfix
Affected Mageia releases : 10

After right clicking on a music file in Dolphin and selecting to open it with Amarok, Amarok failed to load the file. This update fixes the issue. References SRPMS 10/core
  • amarok-3.3.3-1.mga10

MGAA-2026-0070 - Updated neochat package fixes missing dependency

Mageia Security - 27 Julio, 2026 - 23:45
Publication date: 27 Jul 2026
Type: bugfix
Affected Mageia releases : 10

If purpose wasn't installed, neochat would not start. This update adds the missing dependency on the purpose package. References SRPMS 10/core
  • neochat-25.12.1-1.1.mga10

MGAA-2026-0069 - Updated ocrfeeder package makes it start again

Mageia Security - 27 Julio, 2026 - 23:45
Publication date: 27 Jul 2026
Type: bugfix
Affected Mageia releases : 10

The OCRFeeder package wouldn't start since python3.13. This update fixes the issue. References SRPMS 10/core
  • ocrfeeder-0.8.5-4.1.mga10

MGAA-2026-0068 - Updated byobu package fixes missing desktop entry

Mageia Security - 27 Julio, 2026 - 23:45
Publication date: 27 Jul 2026
Type: bugfix
Affected Mageia releases : 10

The byobu package failed to install its desktop menu entry. This update fixes the issue. References SRPMS 10/core
  • byobu-6.13-1.1.mga10

MGAA-2026-0067 - Updated phonon-vlc packages fix an upgrade conflict

Mageia Security - 27 Julio, 2026 - 23:45
Publication date: 27 Jul 2026
Type: bugfix
Affected Mageia releases : 10

When doing a command line upgrade from Mageia 9 to Mageia 10, there were conflicts between phonon-vlc-i18n-0.12.0-2.mga10.noarch and phonon4qt5-vlc-0.11.3-2.mga9.x86_64. This Mageia 10 update fixes the issue. References SRPMS 10/core
  • phonon-vlc-0.12.0-2.1.mga10

MGASA-2026-0300 - Updated wget packages fix security vulnerabilities

Mageia Security - 25 Julio, 2026 - 19:04
Publication date: 25 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-58469 , CVE-2026-58470 , CVE-2026-58471 , CVE-2026-58472 , CVE-2026-15146
Updated wget packages fix security vulnerabilities: -CVE-2026-58469 Wget incorrectly handled Metalink documents containing a whitespace-only URL. A remote attacker could possibly use this issue to cause a denial of service. This issue only affected Mageia 9 and Mageia 10. -CVE-2026-58470 : Wget incorrectly handled Content-Range header values, leading to an integer overflow. A remote attacker could possibly use this issue to cause download desynchronization. -CVE-2026-58471 : Wget incorrectly handled character set conversion of server-supplied filenames. A remote attacker could possibly use this issue to cause a denial of service or possibly execute arbitrary code. This issue affected Mageia9 and Mageia 10. -CVE-2026-58472: It was discovered that Wget incorrectly handled HTML attributes requiring entity encoding. A remote attacker could possibly use this issue to cause a denial of service or possibly execute arbitrary code. -CVE-2026-15146: GNU Wget did not validate the IP address provided by an FTP PASV response while operating in FTP passive mode. A malicious FTP server, or an HTTP server that redirects to an FTP URL, could exploit this behavior to redirect Wget's data connection to an arbitrary IP address and port. This allowed an attacker to forge server-side requests (SSRF) from the machine running Wget, potentially accessing localhost services or internal network resources. References SRPMS 10/core
  • wget-1.25.0-2.2.mga10
9/core
  • wget-1.21.4-1.4.mga9

MGASA-2026-0299 - Updated libnfs packages fix a security vulnerability

Mageia Security - 25 Julio, 2026 - 19:04
Publication date: 25 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-53689
The updated packages fix a security vulnerability: libnfs through 6.0.2 before 55c18ea does not validate a string size, leading to an integer overflow during a connection to a crafted NFS server. This occurs in libnfs_zdr_string in lib/libnfs-zdr.c. (CVE-2026-53689) References SRPMS 10/core
  • libnfs-6.0.2-2.1.mga10
9/core
  • libnfs-5.0.2-1.1.mga9

MGASA-2026-0298 - Updated graphite2 packages fix a security vulnerability

Mageia Security - 25 Julio, 2026 - 19:04
Publication date: 25 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-50593
The updated packages fix a security vulnerability: Graphite before 1.3.15 has an integer underflow and resultant out-of-bounds write via Graphite actions, because slotat does not ensure that an offset is within the allowed slot-map range. (CVE-2026-50593) References SRPMS 10/core
  • graphite2-1.3.14-4.1.mga10
9/core
  • graphite2-1.3.14-2.1.mga9

MGASA-2026-0297 - Updated vorbis-tools package fixes a security vulnerability

Mageia Security - 25 Julio, 2026 - 19:04
Publication date: 25 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-34253
The updated package fixes a security vulnerability: A buffer underflow vulnerability has been identified in the ogg123 utility from the vorbis-tools 1.4.3 package in function remotethread in remote.c. This vulnerability occurs in the remote control functionality when processing malformed input, leading to a stack buffer underflow that can cause application crashes and potentially allow code execution. (CVE-2026-34253) References SRPMS 10/core
  • vorbis-tools-1.4.3-2.1.mga10
9/core
  • vorbis-tools-1.4.2-3.2.mga9

MGASA-2026-0296 - Updated yelp packages fix a security vulnerability

Mageia Security - 25 Julio, 2026 - 19:04
Publication date: 25 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-13601
The updated packages fix a security vulnerability: Yelp: yelp-xsl: overly permissive content security policy in yelp allows host file disclosure from flatpak applications. (CVE-2026-13601) References SRPMS 10/core
  • yelp-49.0-2.1.mga10
9/core
  • yelp-42.2-1.2.mga9

MGASA-2026-0295 - Updated giflib packages fix a security vulnerability

Mageia Security - 25 Julio, 2026 - 19:04
Publication date: 25 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-26740
The updated packages fix a security vulnerability: Buffer Overflow vulnerability in giflib v.5.2.2 allows a remote attacker to cause a denial of service via the EGifGCBToExtension overwriting an existing Graphic Control Extension block without validating its allocated size. (CVE-2026-26740) References SRPMS 10/core
  • giflib-5.2.2-4.1.mga10
9/core
  • giflib-5.2.1-7.4.mga9

MGAA-2026-0066 - Updated python-zstandard package fixes a bug

Mageia Security - 25 Julio, 2026 - 01:31
Publication date: 25 Jul 2026
Type: bugfix
Affected Mageia releases : 9

The previous update was released with the use of the shared library libzstd1, which is now at version 1.5.7 in Mageia 9. However, python-zstandard supported only version 1.5.5. This update patches python-zstandard to use libzstd version 1.5.7. References SRPMS 9/core
  • python-zstandard-0.21.0-1.3.mga9

MGAA-2026-0065 - Updated suricata packages fix the service not starting

Mageia Security - 25 Julio, 2026 - 01:31
Publication date: 25 Jul 2026
Type: bugfix
Affected Mageia releases : 10 , 9

The suricata server did not start in Mageia 9 and Mageia 10. The updated suricata packages fix the issue. References SRPMS 10/core
  • suricata-7.0.10-3.2.mga10
9/core
  • suricata-7.0.10-1.2.mga9

MGASA-2026-0293 - Updated transmission packages fix a security vulnerability

Mageia Security - 24 Julio, 2026 - 17:09
Publication date: 24 Jul 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-38978
The updated packages fix a security vulnerability: Transmission through 4.1.1 was found to have a clickjacking weakness in the browser-facing WebUI and RPC response paths. (CVE-2026-38978) References SRPMS 10/core
  • transmission-4.1.3-1.mga10

MGASA-2026-0292 - Updated lrzip package fixes security vulnerabilities

Mageia Security - 24 Julio, 2026 - 04:58
Publication date: 24 Jul 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2025-15570 , CVE-2025-9396
The updated package fixes security vulnerabilities: ckolivas lrzip stream.c lzma_decompress_buf use after free. (CVE-2025-15570) ckolivas lrzip strtol_l.c __GI_____strtol_l_internal null pointer dereference. (CVE-2025-9396) References SRPMS 10/core
  • lrzip-0.660-1.mga10

MGAA-2026-0064 - Updated rpm-mageia-setup packages fix incompatibility with emacs

Mageia Security - 24 Julio, 2026 - 04:58
Publication date: 24 Jul 2026
Type: bugfix
Affected Mageia releases : 10

Opening a spec file with emacs on mga10 did no longer provide syntax highlighting. This update fixes the issue. References SRPMS 10/core
  • rpm-mageia-setup-2.84-1.mga10

MGAA-2026-0063 - Updated xonotic packages fix broken online statistics support

Mageia Security - 24 Julio, 2026 - 04:58
Publication date: 24 Jul 2026
Type: bugfix
Affected Mageia releases : 10

Updated Xonotic packages to fix broken online statistics support. References SRPMS 10/core
  • xonotic-0.8.6-2.1.mga10

MGASA-2026-0291 - Updated cifs-utils packages fix a security vulnerability

Mageia Security - 23 Julio, 2026 - 18:45
Publication date: 23 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-12505
The updated packages fix a security vulnerability: Local privilege escalation via forged cifs.spnego key description in cifs.upcall. (CVE-2026-12505) References SRPMS 10/core
  • cifs-utils-7.5-1.1.mga10
9/core
  • cifs-utils-7.0-1.2.mga9

MGASA-2026-0290 - Updated socat package fixes a security vulnerability

Mageia Security - 23 Julio, 2026 - 18:45
Publication date: 23 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-56123
The updated package fixes a security vulnerability: Heap Buffer Overflow via SOCKS5 Reply Parser. (CVE-2026-56123) References SRPMS 10/core
  • socat-1.8.1.0-1.1.mga10
9/core
  • socat-1.8.0.2-1.1.mga9
Feed