Lector de Feeds
MGAA-2026-0148 - Updated drakwizard package fixes bug
Publication date: 03 Oct 2026
Type: bugfix
Affected Mageia releases : 10
Description
/sbin/route is deprecated and drakwizard should use ip (from iproute2) instead. This will let us remove the dependency on the unmaintained Net::Route::Table module, which has not been updated upstream since 2009. This update fixes the reported issue. References
SRPMS 10/core
Type: bugfix
Affected Mageia releases : 10
Description
/sbin/route is deprecated and drakwizard should use ip (from iproute2) instead. This will let us remove the dependency on the unmaintained Net::Route::Table module, which has not been updated upstream since 2009. This update fixes the reported issue. References
SRPMS 10/core
- drakwizard-4.13-1.mga10
Categorías: Actualizaciones de Seguridad
MGAA-2026-0147 - Updated task-cinnamon package fixes bugs
Publication date: 03 Oct 2026
Type: bugfix
Affected Mageia releases : 10
Description
xdg-desktop-portal-xapp package is missing in the requirements. lxdm should not be recommended as display manager for cinnamon. This update fixes the reported issues. References
SRPMS 10/core
Type: bugfix
Affected Mageia releases : 10
Description
xdg-desktop-portal-xapp package is missing in the requirements. lxdm should not be recommended as display manager for cinnamon. This update fixes the reported issues. References
SRPMS 10/core
- task-cinnamon-6.6-1.2.mga10
Categorías: Actualizaciones de Seguridad
MGAA-2026-0146 - Updated guayadeque package fixes bugs
Publication date: 03 Oct 2026
Type: bugfix
Affected Mageia releases : 10
Description
This last version 0.7.7 corrects some bugs and brings an offline help: - Fixed a long standing bug that causes the grids (like Media Library Songs Panel) to not update the screen on horizontal scroll. - Fixed a bug in the playlist vertical scrolling when the playing track is out of view. - The first track out of view in the bottom of the playlist wasn't scrolled to follow the player current track. - Playlist "Select" context-menu fixes - Fixed selections failing when a Directory panel filter was active. - Fixed saving and restoring the last directory path selected in Directory Panel. - Fixed the "enable volume" preference saving the wrong value. - Fixed build for gtk2 based distros. - Added missing Serbian (Latin) language to preferences. - Corrected several translations (Portuguese (Brasil), French, Italian, Catalan, Spanish, Greek, German...) References
SRPMS 10/core
Type: bugfix
Affected Mageia releases : 10
Description
This last version 0.7.7 corrects some bugs and brings an offline help: - Fixed a long standing bug that causes the grids (like Media Library Songs Panel) to not update the screen on horizontal scroll. - Fixed a bug in the playlist vertical scrolling when the playing track is out of view. - The first track out of view in the bottom of the playlist wasn't scrolled to follow the player current track. - Playlist "Select" context-menu fixes - Fixed selections failing when a Directory panel filter was active. - Fixed saving and restoring the last directory path selected in Directory Panel. - Fixed the "enable volume" preference saving the wrong value. - Fixed build for gtk2 based distros. - Added missing Serbian (Latin) language to preferences. - Corrected several translations (Portuguese (Brasil), French, Italian, Catalan, Spanish, Greek, German...) References
SRPMS 10/core
- guayadeque-0.7.7-1.mga10
Categorías: Actualizaciones de Seguridad
MGAA-2026-0145 - Updated php8.5 & php8.4 packages fix bugs
Publication date: 02 Oct 2026
Type: bugfix
Affected Mageia releases : 10
Description
Bug fix releases for php 8.4 and php 8.5 References
Type: bugfix
Affected Mageia releases : 10
Description
Bug fix releases for php 8.4 and php 8.5 References
- https://bugs.mageia.org/show_bug.cgi?id=36368
- https://www.php.net/ChangeLog-8.php#8.4.26
- https://www.php.net/ChangeLog-8.php#8.5.11
- php8.5-8.5.11-1.mga10
- php8.4-8.4.26-1.1.mga10
Categorías: Actualizaciones de Seguridad
MGASA-2026-0467 - Updated python-tornado packages fix security vulnerabilities
Publication date: 02 Oct 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-49853 , CVE-2026-49854 , CVE-2026-49855 Description
Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient Tornado has out-of-bounds memory access via C extension tornado AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb) References
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-49853 , CVE-2026-49854 , CVE-2026-49855 Description
Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient Tornado has out-of-bounds memory access via C extension tornado AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb) References
- https://bugs.mageia.org/show_bug.cgi?id=35712
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/GZ7Q55UOVFEKZDAHBHES3HJS2PZ4OQHV/
- https://www.cve.org/CVERecord?id=CVE-2026-49853
- https://www.cve.org/CVERecord?id=CVE-2026-49854
- https://www.cve.org/CVERecord?id=CVE-2026-49855
- python-tornado-6.5.10-1.1.mga10
Categorías: Actualizaciones de Seguridad
MGASA-2026-0466 - Updated python-urwid & python-wcwidth packages fixes a security vulnerability
Publication date: 02 Oct 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-9323 Description
Insecure PRNG and Information Exposure in urwid Web Display Backend References
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-9323 Description
Insecure PRNG and Information Exposure in urwid Web Display Backend References
- https://bugs.mageia.org/show_bug.cgi?id=36159
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/3XPYRLW6AB7WGF3ENBZSCZHGJCJFF7VI/
- https://github.com/urwid/urwid/security/advisories/GHSA-rjwp-g85x-gmjv
- https://ubuntu.com/security/notices/USN-8751-1
- https://www.cve.org/CVERecord?id=CVE-2026-9323
- python-urwid-4.1.3-1.mga10
- python-wcwidth-0.8.3-1.mga10
Categorías: Actualizaciones de Seguridad
MGASA-2026-0465 - Updated wireshark package fixes security vulnerabilities
Publication date: 02 Oct 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-15163 , CVE-2026-15164 , CVE-2026-15165 , CVE-2026-15166 , CVE-2026-15167 , CVE-2026-15168 , CVE-2026-15169 , CVE-2026-15170 , CVE-2026-15171 , CVE-2026-15172 , CVE-2026-15173 , CVE-2026-15174 Description
Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark. (CVE-2026-15163) Heap-based Buffer Overflow in ciscodump. (CVE-2026-15164) Heap-based Buffer Overflow in Wireshark. (CVE-2026-15165) Stack-based Buffer Overflow in Wireshark. (CVE-2026-15166) Stack-based Buffer Overflow in Wireshark. (CVE-2026-15167) Use of Uninitialized Variable in Wireshark. (CVE-2026-15168) Heap-based Buffer Overflow in Wireshark. (CVE-2026-15169) Heap-based Buffer Overflow in Wireshark. (CVE-2026-15170) NULL Pointer Dereference in Wireshark. (CVE-2026-15171) Unchecked Input for Loop Condition in Wireshark. (CVE-2026-15172) Heap-based Buffer Overflow in Wireshark. (CVE-2026-15173) Heap-based Buffer Overflow in Wireshark. (CVE-2026-15174) References
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-15163 , CVE-2026-15164 , CVE-2026-15165 , CVE-2026-15166 , CVE-2026-15167 , CVE-2026-15168 , CVE-2026-15169 , CVE-2026-15170 , CVE-2026-15171 , CVE-2026-15172 , CVE-2026-15173 , CVE-2026-15174 Description
Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark. (CVE-2026-15163) Heap-based Buffer Overflow in ciscodump. (CVE-2026-15164) Heap-based Buffer Overflow in Wireshark. (CVE-2026-15165) Stack-based Buffer Overflow in Wireshark. (CVE-2026-15166) Stack-based Buffer Overflow in Wireshark. (CVE-2026-15167) Use of Uninitialized Variable in Wireshark. (CVE-2026-15168) Heap-based Buffer Overflow in Wireshark. (CVE-2026-15169) Heap-based Buffer Overflow in Wireshark. (CVE-2026-15170) NULL Pointer Dereference in Wireshark. (CVE-2026-15171) Unchecked Input for Loop Condition in Wireshark. (CVE-2026-15172) Heap-based Buffer Overflow in Wireshark. (CVE-2026-15173) Heap-based Buffer Overflow in Wireshark. (CVE-2026-15174) References
- https://bugs.mageia.org/show_bug.cgi?id=35985
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WDPYZRRCJU7AOWEFKBJ2IXADDJGWH4AH/
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/OUNLKEGMF6HPV3WJRY6PZJF4BTUIQWBO/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/B5DGIBJC6D6UABMCLLUPI5ZU2I3SEFUV/
- https://lists.debian.org/debian-security-announce/2026/msg00382.html
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/UONW2KX7GYYS7MVUGXE7L23MZC42ZLHT/
- https://www.cve.org/CVERecord?id=CVE-2026-15163
- https://www.cve.org/CVERecord?id=CVE-2026-15164
- https://www.cve.org/CVERecord?id=CVE-2026-15165
- https://www.cve.org/CVERecord?id=CVE-2026-15166
- https://www.cve.org/CVERecord?id=CVE-2026-15167
- https://www.cve.org/CVERecord?id=CVE-2026-15168
- https://www.cve.org/CVERecord?id=CVE-2026-15169
- https://www.cve.org/CVERecord?id=CVE-2026-15170
- https://www.cve.org/CVERecord?id=CVE-2026-15171
- https://www.cve.org/CVERecord?id=CVE-2026-15172
- https://www.cve.org/CVERecord?id=CVE-2026-15173
- https://www.cve.org/CVERecord?id=CVE-2026-15174
- wireshark-4.6.8-1.mga10
Categorías: Actualizaciones de Seguridad
MGASA-2026-0464 - Updated libgcrypt package fixes a security vulnerability
Publication date: 02 Oct 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2024-2236 Description
Libgcrypt: vulnerable to marvin attack. (CVE-2024-2236) References
Type: security
Affected Mageia releases : 10
CVE: CVE-2024-2236 Description
Libgcrypt: vulnerable to marvin attack. (CVE-2024-2236) References
- https://bugs.mageia.org/show_bug.cgi?id=36248
- https://ubuntu.com/security/notices/USN-8711-1
- https://bugzilla.redhat.com/show_bug.cgi?id=2268268
- https://lists.gnupg.org/pipermail/gcrypt-devel/2024-March/005607.html
- https://github.com/tomato42/marvin-toolkit/tree/master/example/libgcrypt
- https://people.redhat.com/~hkario/marvin/
- https://dev.gnupg.org/T7136
- https://gitlab.com/redhat-crypto/libgcrypt/libgcrypt-mirror/-/merge_requests/17
- https://www.cve.org/CVERecord?id=CVE-2024-2236
- libgcrypt-1.11.3-1.1.mga10
Categorías: Actualizaciones de Seguridad




