Lector de Feeds
MGASA-2026-0428 - Updated mpg123 package fixes security vulnerabilities
Publication date: 20 Sep 2026
Type: security
Affected Mageia releases : 10
Description
Updated packages fix security vulnerabilities, please se the reference. References
Type: security
Affected Mageia releases : 10
Description
Updated packages fix security vulnerabilities, please se the reference. References
- https://bugs.mageia.org/show_bug.cgi?id=36131
- https://www.openwall.com/lists/oss-security/2026/08/03/2
- mpg123-1.33.7-1.mga10
Categorías: Actualizaciones de Seguridad
MGASA-2026-0427 - Updated gawk packages fix security vulnerabilities
Publication date: 20 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-40467 , CVE-2026-40468 , CVE-2026-40469 , CVE-2026-40553 Description
Use after free in gawk. (CVE-2026-40467) Heap buffer overflow in gawk. (CVE-2026-40468) Heap buffer overflow in gawk. (CVE-2026-40469) Stack-based buffer overflow in gawk. (CVE-2026-40553) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-40467 , CVE-2026-40468 , CVE-2026-40469 , CVE-2026-40553 Description
Use after free in gawk. (CVE-2026-40467) Heap buffer overflow in gawk. (CVE-2026-40468) Heap buffer overflow in gawk. (CVE-2026-40469) Stack-based buffer overflow in gawk. (CVE-2026-40553) References
- https://bugs.mageia.org/show_bug.cgi?id=35997
- https://ubuntu.com/security/notices/USN-8588-1
- https://www.cve.org/CVERecord?id=CVE-2026-40467
- https://www.cve.org/CVERecord?id=CVE-2026-40468
- https://www.cve.org/CVERecord?id=CVE-2026-40469
- https://www.cve.org/CVERecord?id=CVE-2026-40553
- gawk-5.3.2-2.1.mga10
- gawk-5.2.2-1.1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0426 - Updated perl-YAML packages fix a security vulnerability
Publication date: 20 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-63676 Description
Updated packages fixes CVE-2026-63676 References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-63676 Description
Updated packages fixes CVE-2026-63676 References
- https://bugs.mageia.org/show_bug.cgi?id=35996
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/J2RXBIKA5WZB2UEHKQR7MEKDH6GABEFL/
- https://www.cve.org/CVERecord?id=CVE-2026-63676
- perl-YAML-1.310.0-2.1.mga10
- perl-YAML-1.300.0-3.1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0425 - Updated libssh packages fix security vulnerabilities
Publication date: 20 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-15370 , CVE-2026-59843 , CVE-2026-59844 , CVE-2026-59845 , CVE-2026-59846 , CVE-2026-59847 , CVE-2026-59848 , CVE-2026-59849 , CVE-2026-59850 Description
Stack buffer overflow in SFTP server longname construction. (CVE-2026-15370) Denial of service via zero advertised channel packet size. (CVE-2026-59843) Denial of service via oversized SFTP read length. (CVE-2026-59844) Denial of service via unchecked ProxyCommand fork() failure. (CVE-2026-59845) Information disclosure via ProxyCommand %r username expansion. (CVE-2026-59846) Integrity downgrade via OpenSSL AES-GCM tag verification. (CVE-2026-59847) Denial of service via SFTP responses with unknown request IDs. (CVE-2026-59848) Denial of service via automatic certificate authentication loop. (CVE-2026-59849) Use-after-free via data callbacks on closed channels. (CVE-2026-59850) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-15370 , CVE-2026-59843 , CVE-2026-59844 , CVE-2026-59845 , CVE-2026-59846 , CVE-2026-59847 , CVE-2026-59848 , CVE-2026-59849 , CVE-2026-59850 Description
Stack buffer overflow in SFTP server longname construction. (CVE-2026-15370) Denial of service via zero advertised channel packet size. (CVE-2026-59843) Denial of service via oversized SFTP read length. (CVE-2026-59844) Denial of service via unchecked ProxyCommand fork() failure. (CVE-2026-59845) Information disclosure via ProxyCommand %r username expansion. (CVE-2026-59846) Integrity downgrade via OpenSSL AES-GCM tag verification. (CVE-2026-59847) Denial of service via SFTP responses with unknown request IDs. (CVE-2026-59848) Denial of service via automatic certificate authentication loop. (CVE-2026-59849) Use-after-free via data callbacks on closed channels. (CVE-2026-59850) References
- https://bugs.mageia.org/show_bug.cgi?id=35983
- https://www.openwall.com/lists/oss-security/2026/07/21/7
- https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MIVTLBAG4MPX3WGPMVYDO2UPZB6G3ESR/
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/YZ324UUCGQ4JEC4ZOJMJODWYVPSFBWUU/
- https://lists.debian.org/debian-security-announce/2026/msg00321.html
- https://ubuntu.com/security/notices/USN-8699-1
- https://www.cve.org/CVERecord?id=CVE-2026-15370
- https://www.cve.org/CVERecord?id=CVE-2026-59843
- https://www.cve.org/CVERecord?id=CVE-2026-59844
- https://www.cve.org/CVERecord?id=CVE-2026-59845
- https://www.cve.org/CVERecord?id=CVE-2026-59846
- https://www.cve.org/CVERecord?id=CVE-2026-59847
- https://www.cve.org/CVERecord?id=CVE-2026-59848
- https://www.cve.org/CVERecord?id=CVE-2026-59849
- https://www.cve.org/CVERecord?id=CVE-2026-59850
- libssh-0.11.5-1.mga10
- libssh-0.10.6-1.3.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0424 - Updated ntfs-3g packages fix security vulnerabilities
Publication date: 20 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-42616 , CVE-2026-42617 , CVE-2026-42618 , CVE-2026-46569 , CVE-2026-46570 , CVE-2026-46571 , CVE-2026-46572 , CVE-2026-56135 , CVE-2026-56136 Description
Heap memory corruption when processing a corrupt or maliciously crafted filesystem. (CVE-2026-42616) Heap memory corruption when copying index data from root to an index block in a corrupt or maliciously crafted filesystem. (CVE-2026-42617) Single-byte heap buffer overflow when decompressing maliciously crafted compressed file data. (CVE-2026-42618) Heap buffer overflow when copying the tail data of an index block to a freshly allocated block. (CVE-2026-46569) Heap memory corruption for maliciously crafted or corrupt index data descending to an out-of-bounds tree depth. (CVE-2026-46570) Out-of-bounds read when processing symlink reparse data in a corrupt or maliciously crafted filesystem. (CVE-2026-46571) Heap buffer overflow for maliciously crafted or corrupt index data during a node split. (CVE-2026-46572) Heap buffer overflow when building inherited ACL data. (CVE-2026-56135) Out of bounds access when clearing an index root in maliciously crafted or corrupt index data. (CVE-2026-56136) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-42616 , CVE-2026-42617 , CVE-2026-42618 , CVE-2026-46569 , CVE-2026-46570 , CVE-2026-46571 , CVE-2026-46572 , CVE-2026-56135 , CVE-2026-56136 Description
Heap memory corruption when processing a corrupt or maliciously crafted filesystem. (CVE-2026-42616) Heap memory corruption when copying index data from root to an index block in a corrupt or maliciously crafted filesystem. (CVE-2026-42617) Single-byte heap buffer overflow when decompressing maliciously crafted compressed file data. (CVE-2026-42618) Heap buffer overflow when copying the tail data of an index block to a freshly allocated block. (CVE-2026-46569) Heap memory corruption for maliciously crafted or corrupt index data descending to an out-of-bounds tree depth. (CVE-2026-46570) Out-of-bounds read when processing symlink reparse data in a corrupt or maliciously crafted filesystem. (CVE-2026-46571) Heap buffer overflow for maliciously crafted or corrupt index data during a node split. (CVE-2026-46572) Heap buffer overflow when building inherited ACL data. (CVE-2026-56135) Out of bounds access when clearing an index root in maliciously crafted or corrupt index data. (CVE-2026-56136) References
- https://bugs.mageia.org/show_bug.cgi?id=35940
- https://www.openwall.com/lists/oss-security/2026/07/15/6
- https://lists.debian.org/debian-security-announce/2026/msg00300.html
- https://ubuntu.com/security/notices/USN-8554-1
- https://www.cve.org/CVERecord?id=CVE-2026-42616
- https://www.cve.org/CVERecord?id=CVE-2026-42617
- https://www.cve.org/CVERecord?id=CVE-2026-42618
- https://www.cve.org/CVERecord?id=CVE-2026-46569
- https://www.cve.org/CVERecord?id=CVE-2026-46570
- https://www.cve.org/CVERecord?id=CVE-2026-46571
- https://www.cve.org/CVERecord?id=CVE-2026-46572
- https://www.cve.org/CVERecord?id=CVE-2026-56135
- https://www.cve.org/CVERecord?id=CVE-2026-56136
- ntfs-3g-2026.2.25-1.1.mga10
- ntfs-3g-2022.10.3-1.3.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0423 - Updated patch package fixes security vulnerabilities
Publication date: 20 Sep 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-56288 , CVE-2026-56289 Description
NULL Pointer Dereference in GNU patch. (CVE-2026-56288) Loop with Unreachable Exit Condition in GNU patch. (CVE-2026-56289) References
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-56288 , CVE-2026-56289 Description
NULL Pointer Dereference in GNU patch. (CVE-2026-56288) Loop with Unreachable Exit Condition in GNU patch. (CVE-2026-56289) References
- https://bugs.mageia.org/show_bug.cgi?id=35933
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/5MJXY435MLDAL5GXH6V5OY6MEMOGFEH5/
- https://cert.pl/en/posts/2026/07/CVE-2026-56288/
- https://www.cve.org/CVERecord?id=CVE-2026-56288
- https://www.cve.org/CVERecord?id=CVE-2026-56289
- patch-2.8-1.1.mga10
Categorías: Actualizaciones de Seguridad
MGASA-2026-0422 - Updated bind package fixes security vulnerabilities
Publication date: 20 Sep 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-19033 , CVE-2026-19662 , CVE-2026-19666 , CVE-2026-19667 , CVE-2026-19668 , CVE-2026-19941 , CVE-2026-75029 , CVE-2026-76163 , CVE-2026-77119 , CVE-2026-77692 , CVE-2026-78301 , CVE-2026-80274 , CVE-2026-81563 , CVE-2026-81736 Description
Unauthenticated IXFR deltas are applied to the live zone before TSIG verification (CVE-2026-19033). qpcache NOQNAME proof use-after-free crashes recursive resolver (CVE-2026-19662). Use-after-free in query_addnoqnameproof() via the DNS64 filter64 path (CVE-2026-19666). Remote assertion failure via 16-bit length truncation in dns_ncache_add() (CVE-2026-19667). Resource Exhaustion via Excessive DNSSEC Cryptographic Material Matching (CVE-2026-19668). checkwildcard() accepts an out-of-zone NSEC as a wildcard-nonexistence proof (CVE-2026-19941). Message parser retains every identical singleton RDATA, enabling wire-to-work amplification (CVE-2026-75029). named aborts on a TKEY query when the user configuration has no global options statement (CVE-2026-76163). NSEC3 insecure-referral proof can use unrelated cached NSEC3 RRsets (CVE-2026-77119). Unauthenticated remote crash of named via a single DoH SIG(0) request (CVE-2026-77692). Out-of-zone database nodes can become authoritative zone cuts (CVE-2026-78301). Validating resolver can abort while caching a mismatched NOQNAME proof (CVE-2026-80274). SVCB AliasMode additional-data error leaks qpcache references (CVE-2026-81563). Remote CPU denial of service through cached SVCB/HTTPS AliasMode trees (CVE-2026-81736). References
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-19033 , CVE-2026-19662 , CVE-2026-19666 , CVE-2026-19667 , CVE-2026-19668 , CVE-2026-19941 , CVE-2026-75029 , CVE-2026-76163 , CVE-2026-77119 , CVE-2026-77692 , CVE-2026-78301 , CVE-2026-80274 , CVE-2026-81563 , CVE-2026-81736 Description
Unauthenticated IXFR deltas are applied to the live zone before TSIG verification (CVE-2026-19033). qpcache NOQNAME proof use-after-free crashes recursive resolver (CVE-2026-19662). Use-after-free in query_addnoqnameproof() via the DNS64 filter64 path (CVE-2026-19666). Remote assertion failure via 16-bit length truncation in dns_ncache_add() (CVE-2026-19667). Resource Exhaustion via Excessive DNSSEC Cryptographic Material Matching (CVE-2026-19668). checkwildcard() accepts an out-of-zone NSEC as a wildcard-nonexistence proof (CVE-2026-19941). Message parser retains every identical singleton RDATA, enabling wire-to-work amplification (CVE-2026-75029). named aborts on a TKEY query when the user configuration has no global options statement (CVE-2026-76163). NSEC3 insecure-referral proof can use unrelated cached NSEC3 RRsets (CVE-2026-77119). Unauthenticated remote crash of named via a single DoH SIG(0) request (CVE-2026-77692). Out-of-zone database nodes can become authoritative zone cuts (CVE-2026-78301). Validating resolver can abort while caching a mismatched NOQNAME proof (CVE-2026-80274). SVCB AliasMode additional-data error leaks qpcache references (CVE-2026-81563). Remote CPU denial of service through cached SVCB/HTTPS AliasMode trees (CVE-2026-81736). References
- https://bugs.mageia.org/show_bug.cgi?id=36326
- https://kb.isc.org/docs/cve-2026-19033
- https://kb.isc.org/docs/cve-2026-19662
- https://kb.isc.org/docs/cve-2026-19666
- https://kb.isc.org/docs/cve-2026-19667
- https://kb.isc.org/docs/cve-2026-19668
- https://kb.isc.org/docs/cve-2026-19941
- https://kb.isc.org/docs/cve-2026-75029
- https://kb.isc.org/docs/cve-2026-76163
- https://kb.isc.org/docs/cve-2026-77119
- https://kb.isc.org/docs/cve-2026-77692
- https://kb.isc.org/docs/cve-2026-78301
- https://kb.isc.org/docs/cve-2026-80274
- https://kb.isc.org/docs/cve-2026-81563
- https://kb.isc.org/docs/cve-2026-81736
- https://www.cve.org/CVERecord?id=CVE-2026-19033
- https://www.cve.org/CVERecord?id=CVE-2026-19662
- https://www.cve.org/CVERecord?id=CVE-2026-19666
- https://www.cve.org/CVERecord?id=CVE-2026-19667
- https://www.cve.org/CVERecord?id=CVE-2026-19668
- https://www.cve.org/CVERecord?id=CVE-2026-19941
- https://www.cve.org/CVERecord?id=CVE-2026-75029
- https://www.cve.org/CVERecord?id=CVE-2026-76163
- https://www.cve.org/CVERecord?id=CVE-2026-77119
- https://www.cve.org/CVERecord?id=CVE-2026-77692
- https://www.cve.org/CVERecord?id=CVE-2026-78301
- https://www.cve.org/CVERecord?id=CVE-2026-80274
- https://www.cve.org/CVERecord?id=CVE-2026-81563
- https://www.cve.org/CVERecord?id=CVE-2026-81736
- bind-9.20.29-1.mga10
Categorías: Actualizaciones de Seguridad
MGASA-2026-0421 - Updated python-configargparse packages fix security vulnerabilities
Publication date: 20 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
Description
Config file or environment variable can trigger writing out a config file, overwriting an arbitrary file and disclosing configuration values References
Type: security
Affected Mageia releases : 10 , 9
Description
Config file or environment variable can trigger writing out a config file, overwriting an arbitrary file and disclosing configuration values References
- https://bugs.mageia.org/show_bug.cgi?id=36321
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UWACSE6EO43FMBJWXK22JG7C3LAOLJ3Z/
- https://github.com/bw2/ConfigArgParse/security/advisories/GHSA-6m27-337c-jcgf
- python-configargparse-1.7.7-1.mga10
- python-configargparse-1.7.7-1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0420 - Updated libde265 package fixes security vulnerabilities
Publication date: 20 Sep 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2024-38949 , CVE-2024-38950 , CVE-2025-61147 , CVE-2026-33164 , CVE-2026-33165 , CVE-2026-45382 , CVE-2026-45383 , CVE-2026-49295 , CVE-2026-49337 , CVE-2026-49346 , CVE-2026-54240 , CVE-2026-54241 Description
Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attackers to crash the application via crafted payload to display444as420 function at sdl.cc. (CVE-2024-38949) Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attackers to crash the application via crafted payload to __interceptor_memcpy function. (CVE-2024-38950) strukturag libde265 commit d9fea9d wa discovered to contain a segmentation fault via the component decoder_context::compute_framedrop_table(). (CVE-2025-61147) NULL Pointer Dereference in libde265. (CVE-2026-33164) Heap out-of-bounds write in libde265 1.0.16. (CVE-2026-33165) libde265 has a heap-buffer-overflow READ in decode_slice_unit_tiles via unvalidated PPS tile geometry. (CVE-2026-45382) libde265 has a heap buffer overflow (OOB read) in decode_slice_unit_WPP() via out-of-bounds CtbAddrRStoTS access — libde265 <= v1.0.18. (CVE-2026-45383) libde265 has an out-of-bounds write in process_reference_picture_set via predicted short-term RPS. (CVE-2026-49295) libde265 has an unbounded memory leak via orphaned slice headers in `read_slice_NAL`. (CVE-2026-49337) libde265 has a heap buffer overflow in de265_image_get_buffer via SPS dimension integer overflow. (CVE-2026-49346) Pixel accessor signed integer overflow causes heap OOB read/write. (CVE-2026-54240) SAO sequential filter heap buffer overflow via signed integer overflow. (CVE-2026-54241) References
Type: security
Affected Mageia releases : 10
CVE: CVE-2024-38949 , CVE-2024-38950 , CVE-2025-61147 , CVE-2026-33164 , CVE-2026-33165 , CVE-2026-45382 , CVE-2026-45383 , CVE-2026-49295 , CVE-2026-49337 , CVE-2026-49346 , CVE-2026-54240 , CVE-2026-54241 Description
Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attackers to crash the application via crafted payload to display444as420 function at sdl.cc. (CVE-2024-38949) Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attackers to crash the application via crafted payload to __interceptor_memcpy function. (CVE-2024-38950) strukturag libde265 commit d9fea9d wa discovered to contain a segmentation fault via the component decoder_context::compute_framedrop_table(). (CVE-2025-61147) NULL Pointer Dereference in libde265. (CVE-2026-33164) Heap out-of-bounds write in libde265 1.0.16. (CVE-2026-33165) libde265 has a heap-buffer-overflow READ in decode_slice_unit_tiles via unvalidated PPS tile geometry. (CVE-2026-45382) libde265 has a heap buffer overflow (OOB read) in decode_slice_unit_WPP() via out-of-bounds CtbAddrRStoTS access — libde265 <= v1.0.18. (CVE-2026-45383) libde265 has an out-of-bounds write in process_reference_picture_set via predicted short-term RPS. (CVE-2026-49295) libde265 has an unbounded memory leak via orphaned slice headers in `read_slice_NAL`. (CVE-2026-49337) libde265 has a heap buffer overflow in de265_image_get_buffer via SPS dimension integer overflow. (CVE-2026-49346) Pixel accessor signed integer overflow causes heap OOB read/write. (CVE-2026-54240) SAO sequential filter heap buffer overflow via signed integer overflow. (CVE-2026-54241) References
- https://bugs.mageia.org/show_bug.cgi?id=35987
- https://ubuntu.com/security/notices/USN-8573-1
- https://github.com/strukturag/libde265/issues/460
- https://github.com/strukturag/libde265/issues/484
- https://github.com/strukturag/libde265/security/advisories/GHSA-wqrf-6rf5-v78r
- https://github.com/strukturag/libde265/security/advisories/GHSA-653q-9f73-8hvg
- https://github.com/strukturag/libde265/security/advisories/GHSA-hwhx-x2mq-ccr9
- https://github.com/strukturag/libde265/security/advisories/GHSA-wg9q-ppqw-6q38
- https://github.com/strukturag/libde265/security/advisories/GHSA-g2rg-wj66-w594
- https://github.com/strukturag/libde265/security/advisories/GHSA-g5hj-rf9f-7vxm
- https://github.com/strukturag/libde265/security/advisories/GHSA-vv8h-932h-7r86
- https://github.com/strukturag/libde265/security/advisories/GHSA-ccfw-29x7-rrx3
- https://github.com/strukturag/libde265/security/advisories/GHSA-j2qq-x2xq-g9wr
- https://lists.debian.org/debian-security-announce/2026/msg00324.html
- https://lists.debian.org/debian-security-announce/2026/msg00397.html
- https://www.cve.org/CVERecord?id=CVE-2024-38949
- https://www.cve.org/CVERecord?id=CVE-2024-38950
- https://www.cve.org/CVERecord?id=CVE-2025-61147
- https://www.cve.org/CVERecord?id=CVE-2026-33164
- https://www.cve.org/CVERecord?id=CVE-2026-33165
- https://www.cve.org/CVERecord?id=CVE-2026-45382
- https://www.cve.org/CVERecord?id=CVE-2026-45383
- https://www.cve.org/CVERecord?id=CVE-2026-49295
- https://www.cve.org/CVERecord?id=CVE-2026-49337
- https://www.cve.org/CVERecord?id=CVE-2026-49346
- https://www.cve.org/CVERecord?id=CVE-2026-54240
- https://www.cve.org/CVERecord?id=CVE-2026-54241
- libde265-1.0.16-4.1.mga10
- libde265-1.0.16-4.1.mga10.tainted
Categorías: Actualizaciones de Seguridad
MGASA-2026-0419 - Updated python-httplib2 packages fix a security vulnerability
Publication date: 20 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-59939 Description
Decompression Bomb Denial of Service via Unbounded gzip/deflate Response Handling. (CVE-2026-59939) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-59939 Description
Decompression Bomb Denial of Service via Unbounded gzip/deflate Response Handling. (CVE-2026-59939) References
- https://bugs.mageia.org/show_bug.cgi?id=35936
- https://ubuntu.com/security/notices/USN-8537-1
- https://github.com/httplib2/httplib2/security/advisories/GHSA-j5g9-f88f-gfj3
- https://lists.debian.org/debian-security-announce/2026/msg00352.html
- https://www.cve.org/CVERecord?id=CVE-2026-59939
- python-httplib2-0.22.0-3.1.mga10
- python-httplib2-0.20.4-1.1.mga9
Categorías: Actualizaciones de Seguridad
MGAA-2026-0128 - Updated system-config-printer package fixes bug
Publication date: 20 Sep 2026
Type: bugfix
Affected Mageia releases : 10
Description
Current system-config-printer package does not show a logo in the about dialog box. This update fixes the reported issue. References
SRPMS 10/core
Type: bugfix
Affected Mageia releases : 10
Description
Current system-config-printer package does not show a logo in the about dialog box. This update fixes the reported issue. References
SRPMS 10/core
- system-config-printer-1.5.18-6.2.mga10
Categorías: Actualizaciones de Seguridad
MGAA-2026-0127 - Updated perl-Chart package fixes bug
Publication date: 20 Sep 2026
Type: bugfix
Affected Mageia releases : 10
Description
perl-Chart is updated to version 2.403.9. perl-Graphics-Toolkit-Color is a new runtime requirement for perl-Chart. References
SRPMS 10/core
Type: bugfix
Affected Mageia releases : 10
Description
perl-Chart is updated to version 2.403.9. perl-Graphics-Toolkit-Color is a new runtime requirement for perl-Chart. References
SRPMS 10/core
- perl-Chart-2.403.9-1.mga10
- perl-Graphics-Toolkit-Color-2.220.0-1.mga10
Categorías: Actualizaciones de Seguridad
MGAA-2026-0126 - Updated gnome-software package fixes bug
Publication date: 20 Sep 2026
Type: bugfix
Affected Mageia releases : 10
Description
GUI aplications packaged by mageia are not listed in gnome-software. This updates adds libdnf5-plugin-appstream as optional requirement to allow gnome-software see the GUI applications packaged by mageia and allow to user skip the additional package if they want. References
SRPMS 10/core
Type: bugfix
Affected Mageia releases : 10
Description
GUI aplications packaged by mageia are not listed in gnome-software. This updates adds libdnf5-plugin-appstream as optional requirement to allow gnome-software see the GUI applications packaged by mageia and allow to user skip the additional package if they want. References
SRPMS 10/core
- gnome-software-49.3-2.1.mga10
Categorías: Actualizaciones de Seguridad
MGAA-2026-0125 - Updated isodumper package fixes bugs
Publication date: 20 Sep 2026
Type: bugfix
Affected Mageia releases : 10
Description
When formatting a partition which was already mounted, Isodumper failed. Now, it starts to unmount the partitions on the target device Devices list is also cleaned of optical devices. References
SRPMS 10/core
Type: bugfix
Affected Mageia releases : 10
Description
When formatting a partition which was already mounted, Isodumper failed. Now, it starts to unmount the partitions on the target device Devices list is also cleaned of optical devices. References
SRPMS 10/core
- isodumper-1.93-1.mga10
Categorías: Actualizaciones de Seguridad
MGASA-2026-0418 - Updated gstreamer1.0-plugins-base packages fix a security vulnerability
Publication date: 19 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-18297 Description
GStreamer OGG File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. (CVE-2026-18297) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-18297 Description
GStreamer OGG File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. (CVE-2026-18297) References
- https://bugs.mageia.org/show_bug.cgi?id=36288
- https://lists.debian.org/debian-security-announce/2026/msg00400.html
- https://gstreamer.freedesktop.org/security/sa-2026-0053.html
- https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12044
- https://www.cve.org/CVERecord?id=CVE-2026-18297
- gstreamer1.0-plugins-base-1.26.11-1.1.mga10
- gstreamer1.0-plugins-base-1.22.11-1.4.mga9
Categorías: Actualizaciones de Seguridad
MGAA-2026-0124 - Updated audacity packages fix bug
Publication date: 19 Sep 2026
Type: bugfix
Affected Mageia releases : 10
Description
audacity is updated to version 3.7.9 which has improvements and bugs fixed by the audacity team. References
Type: bugfix
Affected Mageia releases : 10
Description
audacity is updated to version 3.7.9 which has improvements and bugs fixed by the audacity team. References
- https://bugs.mageia.org/show_bug.cgi?id=36271
- https://github.com/audacity/audacity/releases#release-Audacity-3.7.9
- https://github.com/audacity/audacity/releases#release-Audacity-3.7.8
- audacity-3.7.9-1.mga10
Categorías: Actualizaciones de Seguridad
MGASA-2026-0417 - Updated gdk-pixbuf2.0 packages fix security vulnerabilities
Publication date: 18 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2025-7345 , CVE-2026-16768 , CVE-2026-81893 Description
Heap‑buffer‑overflow in gdk‑pixbuf. (CVE-2025-7345) Out-of-bounds read in ico parser. (CVE-2026-16768) Invalid write in jpeg icc profile parser on error recovery. (CVE-2026-81893) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2025-7345 , CVE-2026-16768 , CVE-2026-81893 Description
Heap‑buffer‑overflow in gdk‑pixbuf. (CVE-2025-7345) Out-of-bounds read in ico parser. (CVE-2026-16768) Invalid write in jpeg icc profile parser on error recovery. (CVE-2026-81893) References
- https://bugs.mageia.org/show_bug.cgi?id=36238
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7DP4KY4CEXMYSH2LTCRQAN4JZKGOIKAV/
- https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/issues/302
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MXN4IRXYCTUM4SHIHKYCZ4F65WY26VVT/
- https://lists.debian.org/debian-lts-announce/2025/10/msg00024.html
- https://www.cve.org/CVERecord?id=CVE-2025-7345
- https://www.cve.org/CVERecord?id=CVE-2026-16768
- https://www.cve.org/CVERecord?id=CVE-2026-81893
- gdk-pixbuf2.0-2.44.4-2.1.mga10
- gdk-pixbuf2.0-2.42.10-2.4.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0416 - Updated libpcap packages fix security vulnerabilities
Publication date: 18 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-0799 , CVE-2026-31911 , CVE-2026-31912 , CVE-2026-6244 , CVE-2026-6554 , CVE-2026-18313 , CVE-2026-18238 Description
OOBR and OOBW in libpcap before 1.10.7. (CVE-2026-0799) abort() in libpcap before 1.10.7 on an invalid BPF opcode. (CVE-2026-31911) OOBR in libpcap before 1.10.7. (CVE-2026-31912) Division by zero in libpcap before 1.10.7. (CVE-2026-6244) Infinte loop in libpcap before 1.10.7. (CVE-2026-6554) rpcapd memory leak in libpcap before 1.10.7. (CVE-2026-18313) OOBR in rpcap client in libpcap before 1.10.7. (CVE-2026-18238) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-0799 , CVE-2026-31911 , CVE-2026-31912 , CVE-2026-6244 , CVE-2026-6554 , CVE-2026-18313 , CVE-2026-18238 Description
OOBR and OOBW in libpcap before 1.10.7. (CVE-2026-0799) abort() in libpcap before 1.10.7 on an invalid BPF opcode. (CVE-2026-31911) OOBR in libpcap before 1.10.7. (CVE-2026-31912) Division by zero in libpcap before 1.10.7. (CVE-2026-6244) Infinte loop in libpcap before 1.10.7. (CVE-2026-6554) rpcapd memory leak in libpcap before 1.10.7. (CVE-2026-18313) OOBR in rpcap client in libpcap before 1.10.7. (CVE-2026-18238) References
- https://bugs.mageia.org/show_bug.cgi?id=36286
- https://www.openwall.com/lists/oss-security/2026/09/09/2
- https://www.cve.org/CVERecord?id=CVE-2026-0799
- https://www.cve.org/CVERecord?id=CVE-2026-31911
- https://www.cve.org/CVERecord?id=CVE-2026-31912
- https://www.cve.org/CVERecord?id=CVE-2026-6244
- https://www.cve.org/CVERecord?id=CVE-2026-6554
- https://www.cve.org/CVERecord?id=CVE-2026-18313
- https://www.cve.org/CVERecord?id=CVE-2026-18238
- libpcap-1.10.7-1.mga10
- libpcap-1.10.7-1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0415 - Updated graphicsmagick packages fix a security vulnerability
Publication date: 18 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2025-55154 Description
Integer overflows in MNG magnification. (CVE-2025-55154) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2025-55154 Description
Integer overflows in MNG magnification. (CVE-2025-55154) References
- https://bugs.mageia.org/show_bug.cgi?id=36290
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/UOLRN3FZUDRWOSHYEWPEZNVV7735CFHF/
- https://www.cve.org/CVERecord?id=CVE-2025-55154
- graphicsmagick-1.3.46-5.2.mga10.tainted
- graphicsmagick-1.3.40-1.8.mga9.tainted
Categorías: Actualizaciones de Seguridad
MGASA-2026-0414 - Updated imagemagick package fixes security vulnerabilities
Publication date: 17 Sep 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-86420 , CVE-2026-86421 , CVE-2026-86423 , CVE-2026-86424 , CVE-2026-86425 Description
Heap-use-after-free in Layer method of PerlMagick could result in a crash Path Policy TOCTOU symlink race bypass in the video decoder Heap-use-after-free in the GetList method of PerlMagick could result in a crash Memory Leak in MSL decoder Denial of service when exhausting the process memory budget Policy Bypass in UHDR encoder Division by Zero in FLIF encoder Null Pointer Dereference in PNM coder when hitting a memory limit Policy Bypass in PCD, CUBE and HALD decoder when using a specific command line option. Use after free in ImagesToBlob method References
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-86420 , CVE-2026-86421 , CVE-2026-86423 , CVE-2026-86424 , CVE-2026-86425 Description
Heap-use-after-free in Layer method of PerlMagick could result in a crash Path Policy TOCTOU symlink race bypass in the video decoder Heap-use-after-free in the GetList method of PerlMagick could result in a crash Memory Leak in MSL decoder Denial of service when exhausting the process memory budget Policy Bypass in UHDR encoder Division by Zero in FLIF encoder Null Pointer Dereference in PNM coder when hitting a memory limit Policy Bypass in PCD, CUBE and HALD decoder when using a specific command line option. Use after free in ImagesToBlob method References
- https://bugs.mageia.org/show_bug.cgi?id=36167
- https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-chf5-8rv9-gjqr
- https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-9x6f-98x9-rx6g
- https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-5m9j-96ff-j6qc
- https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4jv7-q6xw-6f4x
- https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4mwf-mggw-29vp
- https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-7hjx-392p-f8cm
- https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4gg2-hfgh-6f5c
- https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-92rw-c5mw-27v4
- https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-89wq-f8f6-2j2v
- https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-3rjr-534c-8v67
- https://www.cve.org/CVERecord?id=CVE-2026-86420
- https://www.cve.org/CVERecord?id=CVE-2026-86421
- https://www.cve.org/CVERecord?id=CVE-2026-86423
- https://www.cve.org/CVERecord?id=CVE-2026-86424
- https://www.cve.org/CVERecord?id=CVE-2026-86425
- imagemagick-7.1.2.31-1.mga10
- imagemagick-7.1.2.31-1.mga10.tainted
Categorías: Actualizaciones de Seguridad




