Lector de Feeds

MGASA-2026-0301 - Updated nginx packages fix security vulnerabilities

Mageia Security - 27 Julio, 2026 - 23:45
Publication date: 27 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-42533 , CVE-2026-56434 , CVE-2026-60005 Description
CVE-2026-42533: Heap buffer overflow might occur in a worker process when using the map directive with regex matching if the map variable was included in a string expression after a capture affected by this map; a similar issue might happen when using a non-cacheable variable in a string expression. Thanks to Mufeed VH of Winfunc Research and Maxim Dounin. . CVE-2026-60005: Uninitialized memory access might occur when using unnamed regex captures with the "slice" directive or background cache update, which could result in worker process memory disclosure or worker process termination. . CVE-2026-56434: Use-after-free might occur when processing a specially crafted proxied backend response with the ngx_http_ssi_filter_module. Thanks to P4P3R-HAK. References SRPMS 10/core
  • nginx-1.30.4-1.mga10
9/core
  • nginx-1.30.4-1.mga9

MGAA-2026-0072 - Updated tdlib & purple-telegram-tdlib packages fix bugs

Mageia Security - 27 Julio, 2026 - 23:45
Publication date: 27 Jul 2026
Type: bugfix
Affected Mageia releases : 10 , 9
Description
purple-telegram-tdlib has been migrated to a new active fork and updated to version 1.1.1. purple-telegram-tdlib updated packages fix an issue where administrators of telegram's groups can't open a chat in the group tdlib has been updated to version 1.8.65, required to build the new version of purple-telegram-tdlib References SRPMS 10/core
  • tdlib-1.8.65-1.git20260613.mga10
  • purple-telegram-tdlib-1.1.1-1.mga10
9/core
  • tdlib-1.8.65-1.git20260613.mga9
  • purple-telegram-tdlib-1.1.1-1.mga9

MGAA-2026-0071 - Updated amarok packages fix a bug

Mageia Security - 27 Julio, 2026 - 23:45
Publication date: 27 Jul 2026
Type: bugfix
Affected Mageia releases : 10
Description
After right clicking on a music file in Dolphin and selecting to open it with Amarok, Amarok failed to load the file. This update fixes the issue. References SRPMS 10/core
  • amarok-3.3.3-1.mga10

MGAA-2026-0070 - Updated neochat package fixes missing dependency

Mageia Security - 27 Julio, 2026 - 23:45
Publication date: 27 Jul 2026
Type: bugfix
Affected Mageia releases : 10
Description
If purpose wasn't installed, neochat would not start. This update adds the missing dependency on the purpose package. References SRPMS 10/core
  • neochat-25.12.1-1.1.mga10

MGAA-2026-0069 - Updated ocrfeeder package makes it start again

Mageia Security - 27 Julio, 2026 - 23:45
Publication date: 27 Jul 2026
Type: bugfix
Affected Mageia releases : 10
Description
The OCRFeeder package wouldn't start since python3.13. This update fixes the issue. References SRPMS 10/core
  • ocrfeeder-0.8.5-4.1.mga10

MGAA-2026-0068 - Updated byobu package fixes missing desktop entry

Mageia Security - 27 Julio, 2026 - 23:45
Publication date: 27 Jul 2026
Type: bugfix
Affected Mageia releases : 10
Description
The byobu package failed to install its desktop menu entry. This update fixes the issue. References SRPMS 10/core
  • byobu-6.13-1.1.mga10

MGAA-2026-0067 - Updated phonon-vlc packages fix an upgrade conflict

Mageia Security - 27 Julio, 2026 - 23:45
Publication date: 27 Jul 2026
Type: bugfix
Affected Mageia releases : 10
Description
When doing a command line upgrade from Mageia 9 to Mageia 10, there were conflicts between phonon-vlc-i18n-0.12.0-2.mga10.noarch and phonon4qt5-vlc-0.11.3-2.mga9.x86_64. This Mageia 10 update fixes the issue. References SRPMS 10/core
  • phonon-vlc-0.12.0-2.1.mga10

MGASA-2026-0300 - Updated wget packages fix security vulnerabilities

Mageia Security - 25 Julio, 2026 - 19:04
Publication date: 25 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-58469 , CVE-2026-58470 , CVE-2026-58471 , CVE-2026-58472 , CVE-2026-15146 Description
Updated wget packages fix security vulnerabilities: -CVE-2026-58469 Wget incorrectly handled Metalink documents containing a whitespace-only URL. A remote attacker could possibly use this issue to cause a denial of service. This issue only affected Mageia 9 and Mageia 10. -CVE-2026-58470 : Wget incorrectly handled Content-Range header values, leading to an integer overflow. A remote attacker could possibly use this issue to cause download desynchronization. -CVE-2026-58471 : Wget incorrectly handled character set conversion of server-supplied filenames. A remote attacker could possibly use this issue to cause a denial of service or possibly execute arbitrary code. This issue affected Mageia9 and Mageia 10. -CVE-2026-58472: It was discovered that Wget incorrectly handled HTML attributes requiring entity encoding. A remote attacker could possibly use this issue to cause a denial of service or possibly execute arbitrary code. -CVE-2026-15146: GNU Wget did not validate the IP address provided by an FTP PASV response while operating in FTP passive mode. A malicious FTP server, or an HTTP server that redirects to an FTP URL, could exploit this behavior to redirect Wget's data connection to an arbitrary IP address and port. This allowed an attacker to forge server-side requests (SSRF) from the machine running Wget, potentially accessing localhost services or internal network resources. References SRPMS 10/core
  • wget-1.25.0-2.2.mga10
9/core
  • wget-1.21.4-1.4.mga9

MGASA-2026-0299 - Updated libnfs packages fix a security vulnerability

Mageia Security - 25 Julio, 2026 - 19:04
Publication date: 25 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-53689 Description
The updated packages fix a security vulnerability: libnfs through 6.0.2 before 55c18ea does not validate a string size, leading to an integer overflow during a connection to a crafted NFS server. This occurs in libnfs_zdr_string in lib/libnfs-zdr.c. (CVE-2026-53689) References SRPMS 10/core
  • libnfs-6.0.2-2.1.mga10
9/core
  • libnfs-5.0.2-1.1.mga9

MGASA-2026-0298 - Updated graphite2 packages fix a security vulnerability

Mageia Security - 25 Julio, 2026 - 19:04
Publication date: 25 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-50593 Description
The updated packages fix a security vulnerability: Graphite before 1.3.15 has an integer underflow and resultant out-of-bounds write via Graphite actions, because slotat does not ensure that an offset is within the allowed slot-map range. (CVE-2026-50593) References SRPMS 10/core
  • graphite2-1.3.14-4.1.mga10
9/core
  • graphite2-1.3.14-2.1.mga9

MGASA-2026-0297 - Updated vorbis-tools package fixes a security vulnerability

Mageia Security - 25 Julio, 2026 - 19:04
Publication date: 25 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-34253 Description
The updated package fixes a security vulnerability: A buffer underflow vulnerability has been identified in the ogg123 utility from the vorbis-tools 1.4.3 package in function remotethread in remote.c. This vulnerability occurs in the remote control functionality when processing malformed input, leading to a stack buffer underflow that can cause application crashes and potentially allow code execution. (CVE-2026-34253) References SRPMS 10/core
  • vorbis-tools-1.4.3-2.1.mga10
9/core
  • vorbis-tools-1.4.2-3.2.mga9

MGASA-2026-0296 - Updated yelp packages fix a security vulnerability

Mageia Security - 25 Julio, 2026 - 19:04
Publication date: 25 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-13601 Description
The updated packages fix a security vulnerability: Yelp: yelp-xsl: overly permissive content security policy in yelp allows host file disclosure from flatpak applications. (CVE-2026-13601) References SRPMS 10/core
  • yelp-49.0-2.1.mga10
9/core
  • yelp-42.2-1.2.mga9

MGASA-2026-0295 - Updated giflib packages fix a security vulnerability

Mageia Security - 25 Julio, 2026 - 19:04
Publication date: 25 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-26740 Description
The updated packages fix a security vulnerability: Buffer Overflow vulnerability in giflib v.5.2.2 allows a remote attacker to cause a denial of service via the EGifGCBToExtension overwriting an existing Graphic Control Extension block without validating its allocated size. (CVE-2026-26740) References SRPMS 10/core
  • giflib-5.2.2-4.1.mga10
9/core
  • giflib-5.2.1-7.4.mga9

MGAA-2026-0066 - Updated python-zstandard package fixes a bug

Mageia Security - 25 Julio, 2026 - 01:31
Publication date: 25 Jul 2026
Type: bugfix
Affected Mageia releases : 9
Description
The previous update was released with the use of the shared library libzstd1, which is now at version 1.5.7 in Mageia 9. However, python-zstandard supported only version 1.5.5. This update patches python-zstandard to use libzstd version 1.5.7. References SRPMS 9/core
  • python-zstandard-0.21.0-1.3.mga9

MGAA-2026-0065 - Updated suricata packages fix the service not starting

Mageia Security - 25 Julio, 2026 - 01:31
Publication date: 25 Jul 2026
Type: bugfix
Affected Mageia releases : 10 , 9
Description
The suricata server did not start in Mageia 9 and Mageia 10. The updated suricata packages fix the issue. References SRPMS 10/core
  • suricata-7.0.10-3.2.mga10
9/core
  • suricata-7.0.10-1.2.mga9

MGASA-2026-0293 - Updated transmission packages fix a security vulnerability

Mageia Security - 24 Julio, 2026 - 17:09
Publication date: 24 Jul 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-38978 Description
The updated packages fix a security vulnerability: Transmission through 4.1.1 was found to have a clickjacking weakness in the browser-facing WebUI and RPC response paths. (CVE-2026-38978) References SRPMS 10/core
  • transmission-4.1.3-1.mga10

MGASA-2026-0292 - Updated lrzip package fixes security vulnerabilities

Mageia Security - 24 Julio, 2026 - 04:58
Publication date: 24 Jul 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2025-15570 , CVE-2025-9396 Description
The updated package fixes security vulnerabilities: ckolivas lrzip stream.c lzma_decompress_buf use after free. (CVE-2025-15570) ckolivas lrzip strtol_l.c __GI_____strtol_l_internal null pointer dereference. (CVE-2025-9396) References SRPMS 10/core
  • lrzip-0.660-1.mga10

MGAA-2026-0064 - Updated rpm-mageia-setup packages fix incompatibility with emacs

Mageia Security - 24 Julio, 2026 - 04:58
Publication date: 24 Jul 2026
Type: bugfix
Affected Mageia releases : 10
Description
Opening a spec file with emacs on mga10 did no longer provide syntax highlighting. This update fixes the issue. References SRPMS 10/core
  • rpm-mageia-setup-2.84-1.mga10

MGAA-2026-0063 - Updated xonotic packages fix broken online statistics support

Mageia Security - 24 Julio, 2026 - 04:58
Publication date: 24 Jul 2026
Type: bugfix
Affected Mageia releases : 10
Description
Updated Xonotic packages to fix broken online statistics support. References SRPMS 10/core
  • xonotic-0.8.6-2.1.mga10
Feed