Lector de Feeds
MGASA-2026-0354 - Updated redis packages fix a security vulnerability
Publication date: 31 Aug 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-62356 Description
The updated package fixes security vulnerabilities, including: Miscalculated buffer size in CMSketch RDB loading may lead to heap OOB write. (CVE-2026-62356) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-62356 Description
The updated package fixes security vulnerabilities, including: Miscalculated buffer size in CMSketch RDB loading may lead to heap OOB write. (CVE-2026-62356) References
- https://bugs.mageia.org/show_bug.cgi?id=36195
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/LJCOCIGFJRTGSL7B6LBQA4CBTCFCTL75/
- https://www.heise.de/en/news/Redis-Security-updates-against-code-injection-vulnerabilities-11417601.html
- https://github.com/redis/redis/releases/tag/8.6.6
- https://github.com/redis/redis/releases/tag/7.2.16
- https://www.cve.org/CVERecord?id=CVE-2026-62356
- redis-8.6.6-1.mga10
- redis-7.2.16-1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0353 - Updated openssl packages fix security vulnerabilities
Publication date: 31 Aug 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-14456 , CVE-2026-18798 , CVE-2026-63072 , CVE-2026-63076 , CVE-2026-14457 , CVE-2026-54874 , CVE-2026-63073 , CVE-2026-63074 , CVE-2026-63075 , CVE-2026-75803 Description
Unbounded Memory Growth in QUIC Server Incoming Channel Queue. (CVE-2026-14456) QUIC Server May Trigger Double Free When Processing INITIAL Packet. (CVE-2026-18798) Heap Buffer Overflow in CMS Key Unwrapping. (CVE-2026-63072) Invalid Pointer Dereference in CMP Server via Crafted protectionAlg. (CVE-2026-63076) RPK Server Signature Algorithm Selection Can Dereference a Missing Certificate. (CVE-2026-14457) Excessive Memory Use Buffering DTLS Records for a Future Epoch. (CVE-2026-54874) Untrusted Sender DN Used as Format String in CMP Response Validation. (CVE-2026-63073) CMP Indefinite Cache Growth of ExtraCerts. (CVE-2026-63074) QUIC ACK-only Packet Retention Can Cause Memory Exhaustion. (CVE-2026-63075) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-14456 , CVE-2026-18798 , CVE-2026-63072 , CVE-2026-63076 , CVE-2026-14457 , CVE-2026-54874 , CVE-2026-63073 , CVE-2026-63074 , CVE-2026-63075 , CVE-2026-75803 Description
Unbounded Memory Growth in QUIC Server Incoming Channel Queue. (CVE-2026-14456) QUIC Server May Trigger Double Free When Processing INITIAL Packet. (CVE-2026-18798) Heap Buffer Overflow in CMS Key Unwrapping. (CVE-2026-63072) Invalid Pointer Dereference in CMP Server via Crafted protectionAlg. (CVE-2026-63076) RPK Server Signature Algorithm Selection Can Dereference a Missing Certificate. (CVE-2026-14457) Excessive Memory Use Buffering DTLS Records for a Future Epoch. (CVE-2026-54874) Untrusted Sender DN Used as Format String in CMP Response Validation. (CVE-2026-63073) CMP Indefinite Cache Growth of ExtraCerts. (CVE-2026-63074) QUIC ACK-only Packet Retention Can Cause Memory Exhaustion. (CVE-2026-63075) References
- https://bugs.mageia.org/show_bug.cgi?id=36139
- https://www.openwall.com/lists/oss-security/2026/08/13/4
- https://openssl-library.org/news/secadv/20260813.txt
- https://www.openwall.com/lists/oss-security/2026/08/25/3
- https://openssl-library.org/news/secadv/20260825.txt
- https://lists.debian.org/debian-security-announce/2026/msg00376.html
- https://www.cve.org/CVERecord?id=CVE-2026-14456
- https://www.cve.org/CVERecord?id=CVE-2026-18798
- https://www.cve.org/CVERecord?id=CVE-2026-63072
- https://www.cve.org/CVERecord?id=CVE-2026-63076
- https://www.cve.org/CVERecord?id=CVE-2026-14457
- https://www.cve.org/CVERecord?id=CVE-2026-54874
- https://www.cve.org/CVERecord?id=CVE-2026-63073
- https://www.cve.org/CVERecord?id=CVE-2026-63074
- https://www.cve.org/CVERecord?id=CVE-2026-63075
- https://www.cve.org/CVERecord?id=CVE-2026-75803
- openssl-3.5.8-1.mga10
- openssl-3.0.22-1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0352 - Updated expat & mingw-expat packages fix security vulnerabilities
Publication date: 31 Aug 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-50219 , CVE-2026-56131 , CVE-2026-56132 , CVE-2026-56403 , CVE-2026-56404 , CVE-2026-56405 , CVE-2026-56406 , CVE-2026-56407 , CVE-2026-56408 , CVE-2026-56409 , CVE-2026-56410 , CVE-2026-56411 , CVE-2026-56412 , CVE-2026-72522 Description
Missing control flow integrity checks. (CVE-2026-50219) Missing control flow integrity checks. (CVE-2026-56131) Out-of-bounds write. (CVE-2026-56132) Integer overflow. (CVE-2026-56403) Integer overflow. (CVE-2026-56404) Integer overflow. (CVE-2026-56405) Integer overflow. (CVE-2026-56406) Integer overflow. (CVE-2026-56407) Integer overflow. (CVE-2026-56408) Integer overflow. (CVE-2026-56409) Integer overflow. (CVE-2026-56410) Integer overflow. (CVE-2026-56411) Missing control flow integrity checks. (CVE-2026-56412) References
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-50219 , CVE-2026-56131 , CVE-2026-56132 , CVE-2026-56403 , CVE-2026-56404 , CVE-2026-56405 , CVE-2026-56406 , CVE-2026-56407 , CVE-2026-56408 , CVE-2026-56409 , CVE-2026-56410 , CVE-2026-56411 , CVE-2026-56412 , CVE-2026-72522 Description
Missing control flow integrity checks. (CVE-2026-50219) Missing control flow integrity checks. (CVE-2026-56131) Out-of-bounds write. (CVE-2026-56132) Integer overflow. (CVE-2026-56403) Integer overflow. (CVE-2026-56404) Integer overflow. (CVE-2026-56405) Integer overflow. (CVE-2026-56406) Integer overflow. (CVE-2026-56407) Integer overflow. (CVE-2026-56408) Integer overflow. (CVE-2026-56409) Integer overflow. (CVE-2026-56410) Integer overflow. (CVE-2026-56411) Missing control flow integrity checks. (CVE-2026-56412) References
- https://bugs.mageia.org/show_bug.cgi?id=35758
- https://www.openwall.com/lists/oss-security/2026/06/25/10
- https://blog.hartwork.org/posts/expat-2-8-2-released/
- https://github.com/libexpat/libexpat/blob/R_2_8_2/expat/Changes
- https://www.cve.org/CVERecord?id=CVE-2026-50219
- https://www.cve.org/CVERecord?id=CVE-2026-56131
- https://www.cve.org/CVERecord?id=CVE-2026-56132
- https://www.cve.org/CVERecord?id=CVE-2026-56403
- https://www.cve.org/CVERecord?id=CVE-2026-56404
- https://www.cve.org/CVERecord?id=CVE-2026-56405
- https://www.cve.org/CVERecord?id=CVE-2026-56406
- https://www.cve.org/CVERecord?id=CVE-2026-56407
- https://www.cve.org/CVERecord?id=CVE-2026-56408
- https://www.cve.org/CVERecord?id=CVE-2026-56409
- https://www.cve.org/CVERecord?id=CVE-2026-56410
- https://www.cve.org/CVERecord?id=CVE-2026-56411
- https://www.cve.org/CVERecord?id=CVE-2026-56412
- https://www.cve.org/CVERecord?id=CVE-2026-72522
- expat-2.8.3-1.mga10
- mingw-expat-2.8.3-1.mga10
Categorías: Actualizaciones de Seguridad
MGASA-2026-0351 - Updated perl-Catalyst-Plugin-Authentication packages fix a security vulnerability
Publication date: 31 Aug 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2009-10007 Description
Catalyst::Plugin::Authentication versions before 0.10_027 for Perl is susceptible to session fixation attacks. (CVE-2009-10007) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2009-10007 Description
Catalyst::Plugin::Authentication versions before 0.10_027 for Perl is susceptible to session fixation attacks. (CVE-2009-10007) References
- https://bugs.mageia.org/show_bug.cgi?id=35654
- https://www.openwall.com/lists/oss-security/2026/06/09/10
- https://www.cve.org/CVERecord?id=CVE-2009-10007
- perl-Catalyst-Plugin-Authentication-0.100.280-1.mga10
- perl-Catalyst-Plugin-Authentication-0.100.230-12.2.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0350 - Updated perl-Plack packages fix a security vulnerability
Publication date: 31 Aug 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-7381 Description
Plack::Middleware::XSendfile versions through 1.0053 for Perl can allow client-controlled path rewriting. References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-7381 Description
Plack::Middleware::XSendfile versions through 1.0053 for Perl can allow client-controlled path rewriting. References
- https://bugs.mageia.org/show_bug.cgi?id=35449
- https://www.openwall.com/lists/oss-security/2026/04/29/27
- https://www.cve.org/CVERecord?id=CVE-2026-7381
- perl-Plack-1.5.400-1.mga10
- perl-Plack-1.5.400-1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0349 - Updated python-hpack packages fix a security vulnerability
Publication date: 31 Aug 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-59980 Description
Users of the python-hyper/hpack library, most commonly used as downstream dependency of the python-hyper/h2 library (an HTTP/2 client and server implementation). Unbounded variable integer decoding can cause run-away computation on malformed input leading to O(n^2) runtime, effectively blocking further processing with large enough unsanitized input. A fix python-hyper/hpack v4.2.0 restricts variable integer decoding to uint32 to prevent run-away computation. References
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-59980 Description
Users of the python-hyper/hpack library, most commonly used as downstream dependency of the python-hyper/h2 library (an HTTP/2 client and server implementation). Unbounded variable integer decoding can cause run-away computation on malformed input leading to O(n^2) runtime, effectively blocking further processing with large enough unsanitized input. A fix python-hyper/hpack v4.2.0 restricts variable integer decoding to uint32 to prevent run-away computation. References
- https://bugs.mageia.org/show_bug.cgi?id=36197
- https://github.com/python-hyper/hpack/security/advisories/GHSA-8v8h-hg4w-mvq2
- https://www.cve.org/CVERecord?id=CVE-2026-59980
- python-hpack-4.2.0-1.mga10
Categorías: Actualizaciones de Seguridad
MGASA-2026-0348 - Updated clamav packages fix security vulnerabilities
Publication date: 31 Aug 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-20345 , CVE-2026-20339 , CVE-2026-20346 , CVE-2026-20347 , CVE-2026-20348 Description
n indexing error while converting GPT partition names that could read or write beyond a stack-allocated partition entry. (CVE-2026-20345) An integer overflow in the PESpin unpacker that could allocate an undersized buffer and then write beyond it while rebuilding a PE file. (CVE-2026-20339) An integer underflow in the PDF parser that could cause a crash while reading a malformed hex string. (CVE-2026-20346) Undefined behavior and integer overflow in the Mach-O parser that could cause a crash while scanning a malformed Mach-O file. (CVE-2026-20347) XAR parser size handling that could request an excessive allocation or exceed scan limits while decompressing a malformed table of contents. (CVE-2026-20348) References
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-20345 , CVE-2026-20339 , CVE-2026-20346 , CVE-2026-20347 , CVE-2026-20348 Description
n indexing error while converting GPT partition names that could read or write beyond a stack-allocated partition entry. (CVE-2026-20345) An integer overflow in the PESpin unpacker that could allocate an undersized buffer and then write beyond it while rebuilding a PE file. (CVE-2026-20339) An integer underflow in the PDF parser that could cause a crash while reading a malformed hex string. (CVE-2026-20346) Undefined behavior and integer overflow in the Mach-O parser that could cause a crash while scanning a malformed Mach-O file. (CVE-2026-20347) XAR parser size handling that could request an excessive allocation or exceed scan limits while decompressing a malformed table of contents. (CVE-2026-20348) References
- https://bugs.mageia.org/show_bug.cgi?id=36180
- https://blog.clamav.net/2026/08/clamav-154-and-146-security-patch.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OQHYDS3XT2PKXIDL3B6FNNJ3JT27FJ2T/
- https://www.cve.org/CVERecord?id=CVE-2026-20345
- https://www.cve.org/CVERecord?id=CVE-2026-20339
- https://www.cve.org/CVERecord?id=CVE-2026-20346
- https://www.cve.org/CVERecord?id=CVE-2026-20347
- https://www.cve.org/CVERecord?id=CVE-2026-20348
- clamav-1.4.6-1.mga10
Categorías: Actualizaciones de Seguridad
MGAA-2026-0117 - Updated mga-advisor package fixes bugs
Publication date: 31 Aug 2026
Type: bugfix
Affected Mageia releases : 10
Description
The updated package brigs improvement to our graphic tool to make advisories, the changes include but are not limited to: Ver. 6 - Choose only the Mageia versions affected by a bug - Dedupe the package names before checking package info - Allow multiple CVEs or references to be added at once - Improve duplicate CVE warnings - Expand bracket expressions in the list of CVEs - Retrieve package info in parallel for speed - Open a URL in the references by double-clicking it - Join package names in the subject with & or , - Improve the package name regex to solve problems with dots in names - Use singular form in subject with only one package or vuln - Add a status message for each package being retrieved - Fix search in release 10 for source packages Ver. 5 - Run more data checks after loading from Bugzilla - Open a URL in the references by double-clicking it - Join package names in the subject with & or , - Improve the package name regex to solve problems with dots in names - Internal refactoring & minor changes - Use singular form in subject with only one package or vuln - Add a status message for each package being retrieved - Add a timeout when reading from Bugzilla - Display the version number on-screen Ver. 4 - Increase widths of text fields in dialogs - Fix search in release 10 for source packages Ver. 3 - Add syntax checks on package name - Add whitespace checks on subject - Use slash when displaying sources - Drop mga8 as a source and replace with mga10 - Add checks for invalid CVE IDs and URL references - Send a custom User-Agent with Bugzilla requests - Internal cleanups References
SRPMS 10/core
Type: bugfix
Affected Mageia releases : 10
Description
The updated package brigs improvement to our graphic tool to make advisories, the changes include but are not limited to: Ver. 6 - Choose only the Mageia versions affected by a bug - Dedupe the package names before checking package info - Allow multiple CVEs or references to be added at once - Improve duplicate CVE warnings - Expand bracket expressions in the list of CVEs - Retrieve package info in parallel for speed - Open a URL in the references by double-clicking it - Join package names in the subject with & or , - Improve the package name regex to solve problems with dots in names - Use singular form in subject with only one package or vuln - Add a status message for each package being retrieved - Fix search in release 10 for source packages Ver. 5 - Run more data checks after loading from Bugzilla - Open a URL in the references by double-clicking it - Join package names in the subject with & or , - Improve the package name regex to solve problems with dots in names - Internal refactoring & minor changes - Use singular form in subject with only one package or vuln - Add a status message for each package being retrieved - Add a timeout when reading from Bugzilla - Display the version number on-screen Ver. 4 - Increase widths of text fields in dialogs - Fix search in release 10 for source packages Ver. 3 - Add syntax checks on package name - Add whitespace checks on subject - Use slash when displaying sources - Drop mga8 as a source and replace with mga10 - Add checks for invalid CVE IDs and URL references - Send a custom User-Agent with Bugzilla requests - Internal cleanups References
SRPMS 10/core
- mga-advisor-6-1.mga10
Categorías: Actualizaciones de Seguridad
MGAA-2026-0116 - Updated kcalc package fixes bug
Publication date: 31 Aug 2026
Type: bugfix
Affected Mageia releases : 10
Description
You can't copy and paste from the Edit menu in kcalc, It has no effect. Updated packages fixes the reported issue. References
Type: bugfix
Affected Mageia releases : 10
Description
You can't copy and paste from the Edit menu in kcalc, It has no effect. Updated packages fixes the reported issue. References
- https://bugs.mageia.org/show_bug.cgi?id=36216
- https://www.mageialinux-online.org/forum/topic.php?id=32796&pt=1#m338940
- kcalc-25.12.1-1.1.mga10
Categorías: Actualizaciones de Seguridad
MGAA-2026-0115 - Updated krita-ai-diffusion package fixes bug
Publication date: 31 Aug 2026
Type: bugfix
Affected Mageia releases : 10
Description
krita-ai-diffusion is updated to version 1.53.0 References
Type: bugfix
Affected Mageia releases : 10
Description
krita-ai-diffusion is updated to version 1.53.0 References
- https://bugs.mageia.org/show_bug.cgi?id=36122
- https://github.com/Acly/krita-ai-diffusion/releases/tag/v1.53.0
- krita-ai-diffusion-1.53.0-1.mga10
Categorías: Actualizaciones de Seguridad
MGASA-2026-0347 - Updated postgresql18 & postgresql15 packages fix security vulnerabilities
Publication date: 31 Aug 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-6464 , CVE-2026-6469 , CVE-2026-6470 , CVE-2026-6471 , CVE-2026-14662 , CVE-2026-14663 , CVE-2026-14664 , CVE-2026-14666 , CVE-2026-14668 , CVE-2026-14669 , CVE-2026-14670 , CVE-2026-14671 , CVE-2026-14672 , CVE-2026-14673 , CVE-2026-14676 , CVE-2026-14677 , CVE-2026-14678 , CVE-2026-14679 , CVE-2026-14680 , CVE-2026-14681 , CVE-2026-15741 , CVE-2026-15742 , CVE-2026-16238 , CVE-2026-16239 , CVE-2026-16241 , CVE-2026-18024 , CVE-2026-18408 , CVE-2026-19385 Description
psql COPY FROM STDIN early failure processes data lines as psql commands. (CVE-2026-6464) ALTER TABLE ALTER TYPE resets extended statistics ownership. (CVE-2026-6469) Fails to check type USAGE privilege. (CVE-2026-6470) Logical decoding can dlopen arbitrary file. (CVE-2026-6471) tsvector and tsquery undersize allocations, via integer wraparound. (CVE-2026-14662) pgcrypto, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext. (CVE-2026-14663) Regexp heap buffer overflow executes arbitrary code. (CVE-2026-14664) Row security caching disregards role modifications. (CVE-2026-14666) ctid type confusion in selectivity estimator discloses derivative of arbitrary read. (CVE-2026-14668) to_char heap buffer overflow executes arbitrary code. (CVE-2026-14669) plperl tied object heap buffer overflow executes arbitrary code. (CVE-2026-14670) refint plan cache type confusion executes arbitrary code. (CVE-2026-14671) Observable response discrepancy with non-default scram_iterations provides user existence oracle. (CVE-2026-14672) amcheck does not clear untrusted search path. (CVE-2026-14673) pg_stat_statements heap buffer overflow executes arbitrary code. (CVE-2026-14676) 32-bit pltcl and plperl undersize allocations, via integer wraparound. (CVE-2026-14677) pg_trgm picksplit reads past end of buffer. (CVE-2026-14678) Stack buffer overflow in argument match writes 0x0 and 0x1 to server memory. (CVE-2026-14679) Type confusion via "internal" arguments. (CVE-2026-14680) Improper enforcement of GSSAPI encryption when coupled with SSL. (CVE-2026-14681) Expression deparse allows SQL injection via EXTRACT argument. (CVE-2026-15741) fuzzystrmatch writes effectively-arbitrary addresses, via integer wraparound. (CVE-2026-15742) Type confusion in pg_restore_attribute_stats() executes arbitrary code. (CVE-2026-16238) Type confusion in cursor CLOSE + DECLARE executes arbitrary code. (CVE-2026-16239) ECPG integer underflow can crash the client. (CVE-2026-16241) ascii() function reads past end of buffer. (CVE-2026-18024) psql unrestrict lets superuser of pg_dump origin server execute arbitrary code in psql client. (CVE-2026-18408) pg_dump heap buffer overflow executes arbitrary code. (CVE-2026-19385) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-6464 , CVE-2026-6469 , CVE-2026-6470 , CVE-2026-6471 , CVE-2026-14662 , CVE-2026-14663 , CVE-2026-14664 , CVE-2026-14666 , CVE-2026-14668 , CVE-2026-14669 , CVE-2026-14670 , CVE-2026-14671 , CVE-2026-14672 , CVE-2026-14673 , CVE-2026-14676 , CVE-2026-14677 , CVE-2026-14678 , CVE-2026-14679 , CVE-2026-14680 , CVE-2026-14681 , CVE-2026-15741 , CVE-2026-15742 , CVE-2026-16238 , CVE-2026-16239 , CVE-2026-16241 , CVE-2026-18024 , CVE-2026-18408 , CVE-2026-19385 Description
psql COPY FROM STDIN early failure processes data lines as psql commands. (CVE-2026-6464) ALTER TABLE ALTER TYPE resets extended statistics ownership. (CVE-2026-6469) Fails to check type USAGE privilege. (CVE-2026-6470) Logical decoding can dlopen arbitrary file. (CVE-2026-6471) tsvector and tsquery undersize allocations, via integer wraparound. (CVE-2026-14662) pgcrypto, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext. (CVE-2026-14663) Regexp heap buffer overflow executes arbitrary code. (CVE-2026-14664) Row security caching disregards role modifications. (CVE-2026-14666) ctid type confusion in selectivity estimator discloses derivative of arbitrary read. (CVE-2026-14668) to_char heap buffer overflow executes arbitrary code. (CVE-2026-14669) plperl tied object heap buffer overflow executes arbitrary code. (CVE-2026-14670) refint plan cache type confusion executes arbitrary code. (CVE-2026-14671) Observable response discrepancy with non-default scram_iterations provides user existence oracle. (CVE-2026-14672) amcheck does not clear untrusted search path. (CVE-2026-14673) pg_stat_statements heap buffer overflow executes arbitrary code. (CVE-2026-14676) 32-bit pltcl and plperl undersize allocations, via integer wraparound. (CVE-2026-14677) pg_trgm picksplit reads past end of buffer. (CVE-2026-14678) Stack buffer overflow in argument match writes 0x0 and 0x1 to server memory. (CVE-2026-14679) Type confusion via "internal" arguments. (CVE-2026-14680) Improper enforcement of GSSAPI encryption when coupled with SSL. (CVE-2026-14681) Expression deparse allows SQL injection via EXTRACT argument. (CVE-2026-15741) fuzzystrmatch writes effectively-arbitrary addresses, via integer wraparound. (CVE-2026-15742) Type confusion in pg_restore_attribute_stats() executes arbitrary code. (CVE-2026-16238) Type confusion in cursor CLOSE + DECLARE executes arbitrary code. (CVE-2026-16239) ECPG integer underflow can crash the client. (CVE-2026-16241) ascii() function reads past end of buffer. (CVE-2026-18024) psql unrestrict lets superuser of pg_dump origin server execute arbitrary code in psql client. (CVE-2026-18408) pg_dump heap buffer overflow executes arbitrary code. (CVE-2026-19385) References
- https://bugs.mageia.org/show_bug.cgi?id=36165
- https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
- https://www.cve.org/CVERecord?id=CVE-2026-6464
- https://www.cve.org/CVERecord?id=CVE-2026-6469
- https://www.cve.org/CVERecord?id=CVE-2026-6470
- https://www.cve.org/CVERecord?id=CVE-2026-6471
- https://www.cve.org/CVERecord?id=CVE-2026-14662
- https://www.cve.org/CVERecord?id=CVE-2026-14663
- https://www.cve.org/CVERecord?id=CVE-2026-14664
- https://www.cve.org/CVERecord?id=CVE-2026-14666
- https://www.cve.org/CVERecord?id=CVE-2026-14668
- https://www.cve.org/CVERecord?id=CVE-2026-14669
- https://www.cve.org/CVERecord?id=CVE-2026-14670
- https://www.cve.org/CVERecord?id=CVE-2026-14671
- https://www.cve.org/CVERecord?id=CVE-2026-14672
- https://www.cve.org/CVERecord?id=CVE-2026-14673
- https://www.cve.org/CVERecord?id=CVE-2026-14676
- https://www.cve.org/CVERecord?id=CVE-2026-14677
- https://www.cve.org/CVERecord?id=CVE-2026-14678
- https://www.cve.org/CVERecord?id=CVE-2026-14679
- https://www.cve.org/CVERecord?id=CVE-2026-14680
- https://www.cve.org/CVERecord?id=CVE-2026-14681
- https://www.cve.org/CVERecord?id=CVE-2026-15741
- https://www.cve.org/CVERecord?id=CVE-2026-15742
- https://www.cve.org/CVERecord?id=CVE-2026-16238
- https://www.cve.org/CVERecord?id=CVE-2026-16239
- https://www.cve.org/CVERecord?id=CVE-2026-16241
- https://www.cve.org/CVERecord?id=CVE-2026-18024
- https://www.cve.org/CVERecord?id=CVE-2026-18408
- https://www.cve.org/CVERecord?id=CVE-2026-19385
- postgresql18-18.6-1.mga10
- postgresql15-15.19-1.mga10
- postgresql15-15.19-1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0346 - Updated thunderbird packages fix security vulnerabilities
Publication date: 31 Aug 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-74934 , CVE-2026-74935 , CVE-2026-74936 , CVE-2026-74937 , CVE-2026-74938 , CVE-2026-74939 , CVE-2026-74940 , CVE-2026-74941 , CVE-2026-74942 , CVE-2026-74943 , CVE-2026-74944 , CVE-2026-74945 , CVE-2026-74946 , CVE-2026-74947 , CVE-2026-74948 , CVE-2026-74950 , CVE-2026-74953 , CVE-2026-74954 , CVE-2026-74955 , CVE-2026-74956 , CVE-2026-74957 , CVE-2026-74958 , CVE-2026-74959 , CVE-2026-74960 , CVE-2026-74961 , CVE-2026-74962 , CVE-2026-74963 , CVE-2026-74964 , CVE-2026-74965 , CVE-2026-74966 , CVE-2026-74967 , CVE-2026-74968 , CVE-2026-74969 , CVE-2026-74970 , CVE-2026-74971 , CVE-2026-74972 , CVE-2026-74949 , CVE-2026-74973 , CVE-2026-74974 , CVE-2026-74976 , CVE-2026-74977 , CVE-2026-74978 , CVE-2026-74979 , CVE-2026-74981 , CVE-2026-74982 , CVE-2026-74983 , CVE-2026-74984 , CVE-2026-74985 , CVE-2026-74986 , CVE-2026-74987 , CVE-2026-74988 , CVE-2026-74990 Description
Site isolation issue in the Graphics: CanvasWebGL component. (CVE-2026-74934) Privilege escalation in the DOM: Networking component. (CVE-2026-74935) Use-after-free in the JavaScript: WebAssembly component. (CVE-2026-74936) Use-after-free in the JavaScript: GC component. (CVE-2026-74937) Mitigation bypass in the JavaScript: GC component. (CVE-2026-74938) Privilege escalation in the DOM: Navigation component. (CVE-2026-74939) Use-after-free in the Graphics: Text component. (CVE-2026-74940) Privilege escalation in the Graphics: CanvasWebGL component. (CVE-2026-74941) Privilege escalation in the Remote Settings Client component. (CVE-2026-74942) Use-after-free in the Graphics: ImageLib component. (CVE-2026-74943) Use-after-free in the DOM: Core & HTML component. (CVE-2026-74944) Information disclosure in the Graphics: Text component. (CVE-2026-74945) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-74946) Privilege escalation due to invalid pointer in the Graphics component. (CVE-2026-74947) Information disclosure in the Graphics component. (CVE-2026-74948) Privilege escalation in the Downloads API component. (CVE-2026-74950) Privilege escalation in the Networking: Cookies component. (CVE-2026-74953) Information disclosure due to side-channel in the Storage: Cache API component. (CVE-2026-74954) Privilege escalation in the Request Handling component. (CVE-2026-74955) Same-origin policy bypass in the DOM: Service Workers component. (CVE-2026-74956) Mitigation bypass in the Safe Browsing component. (CVE-2026-74957) Information disclosure in the WebRTC component. (CVE-2026-74958) Mitigation bypass in the Storage: Cache API component. (CVE-2026-74959) Site isolation issue in the WebExtensions component. (CVE-2026-74960) Side-channel in the Web Audio component. (CVE-2026-74961) Site isolation issue in the Networking: Cookies component. (CVE-2026-74962) Same-origin policy bypass in the Networking: Cookies component. (CVE-2026-74963) Integer overflow in the Graphics component. (CVE-2026-74964) Privilege escalation in the Shell Integration component. (CVE-2026-74965) Information disclosure in the Form Autofill component. (CVE-2026-74966) Same-origin policy bypass in the Audio/Video: Playback component. (CVE-2026-74967) Site isolation issue in the Graphics: WebRender component. (CVE-2026-74968) Use-after-free in the Layout: Text and Fonts component. (CVE-2026-74969) Site isolation issue in the Graphics component. (CVE-2026-74970) Information disclosure in the DOM: UI Events & Focus Handling component. (CVE-2026-74971) Information disclosure in the DOM: Push Subscriptions component. (CVE-2026-74972) Use-after-free in the Graphics: Canvas2D component. (CVE-2026-74949) Race condition, use-after-free in the Graphics component. (CVE-2026-74973) Same-origin policy bypass in the Graphics: ImageLib component. (CVE-2026-74974) JIT miscompilation in the JavaScript Engine: JIT component. (CVE-2026-74976) Integer overflow in the Graphics component. (CVE-2026-74977) Clickjacking issue in the Widget component. (CVE-2026-74978) Mitigation bypass in the Add-ons Manager component. (CVE-2026-74979) Site isolation issue in the Audio/Video: Web Codecs component. (CVE-2026-74981) Denial-of-service in the Widget component. (CVE-2026-74982) Mitigation bypass in the Data Loss Prevention component. (CVE-2026-74983) Race condition in the JavaScript Engine component. (CVE-2026-74984) Privilege escalation in the Enterprise Policies component. (CVE-2026-74985) Site isolation issue in the CSS Parsing and Computation component. (CVE-2026-74986) Internally found bugs fixed in Thunderbird ESR 140.14, Thunderbird ESR 153.1 and Thunderbird 154. (CVE-2026-74987) Internally found bugs fixed in Thunderbird ESR 153.1 and Thunderbird 154 (CVE-2026-74988) Internally found bugs fixed in Thunderbird ESR 140.14, Thunderbird ESR 153.1 and Thunderbird 154. (CVE-2026-74990) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-74934 , CVE-2026-74935 , CVE-2026-74936 , CVE-2026-74937 , CVE-2026-74938 , CVE-2026-74939 , CVE-2026-74940 , CVE-2026-74941 , CVE-2026-74942 , CVE-2026-74943 , CVE-2026-74944 , CVE-2026-74945 , CVE-2026-74946 , CVE-2026-74947 , CVE-2026-74948 , CVE-2026-74950 , CVE-2026-74953 , CVE-2026-74954 , CVE-2026-74955 , CVE-2026-74956 , CVE-2026-74957 , CVE-2026-74958 , CVE-2026-74959 , CVE-2026-74960 , CVE-2026-74961 , CVE-2026-74962 , CVE-2026-74963 , CVE-2026-74964 , CVE-2026-74965 , CVE-2026-74966 , CVE-2026-74967 , CVE-2026-74968 , CVE-2026-74969 , CVE-2026-74970 , CVE-2026-74971 , CVE-2026-74972 , CVE-2026-74949 , CVE-2026-74973 , CVE-2026-74974 , CVE-2026-74976 , CVE-2026-74977 , CVE-2026-74978 , CVE-2026-74979 , CVE-2026-74981 , CVE-2026-74982 , CVE-2026-74983 , CVE-2026-74984 , CVE-2026-74985 , CVE-2026-74986 , CVE-2026-74987 , CVE-2026-74988 , CVE-2026-74990 Description
Site isolation issue in the Graphics: CanvasWebGL component. (CVE-2026-74934) Privilege escalation in the DOM: Networking component. (CVE-2026-74935) Use-after-free in the JavaScript: WebAssembly component. (CVE-2026-74936) Use-after-free in the JavaScript: GC component. (CVE-2026-74937) Mitigation bypass in the JavaScript: GC component. (CVE-2026-74938) Privilege escalation in the DOM: Navigation component. (CVE-2026-74939) Use-after-free in the Graphics: Text component. (CVE-2026-74940) Privilege escalation in the Graphics: CanvasWebGL component. (CVE-2026-74941) Privilege escalation in the Remote Settings Client component. (CVE-2026-74942) Use-after-free in the Graphics: ImageLib component. (CVE-2026-74943) Use-after-free in the DOM: Core & HTML component. (CVE-2026-74944) Information disclosure in the Graphics: Text component. (CVE-2026-74945) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-74946) Privilege escalation due to invalid pointer in the Graphics component. (CVE-2026-74947) Information disclosure in the Graphics component. (CVE-2026-74948) Privilege escalation in the Downloads API component. (CVE-2026-74950) Privilege escalation in the Networking: Cookies component. (CVE-2026-74953) Information disclosure due to side-channel in the Storage: Cache API component. (CVE-2026-74954) Privilege escalation in the Request Handling component. (CVE-2026-74955) Same-origin policy bypass in the DOM: Service Workers component. (CVE-2026-74956) Mitigation bypass in the Safe Browsing component. (CVE-2026-74957) Information disclosure in the WebRTC component. (CVE-2026-74958) Mitigation bypass in the Storage: Cache API component. (CVE-2026-74959) Site isolation issue in the WebExtensions component. (CVE-2026-74960) Side-channel in the Web Audio component. (CVE-2026-74961) Site isolation issue in the Networking: Cookies component. (CVE-2026-74962) Same-origin policy bypass in the Networking: Cookies component. (CVE-2026-74963) Integer overflow in the Graphics component. (CVE-2026-74964) Privilege escalation in the Shell Integration component. (CVE-2026-74965) Information disclosure in the Form Autofill component. (CVE-2026-74966) Same-origin policy bypass in the Audio/Video: Playback component. (CVE-2026-74967) Site isolation issue in the Graphics: WebRender component. (CVE-2026-74968) Use-after-free in the Layout: Text and Fonts component. (CVE-2026-74969) Site isolation issue in the Graphics component. (CVE-2026-74970) Information disclosure in the DOM: UI Events & Focus Handling component. (CVE-2026-74971) Information disclosure in the DOM: Push Subscriptions component. (CVE-2026-74972) Use-after-free in the Graphics: Canvas2D component. (CVE-2026-74949) Race condition, use-after-free in the Graphics component. (CVE-2026-74973) Same-origin policy bypass in the Graphics: ImageLib component. (CVE-2026-74974) JIT miscompilation in the JavaScript Engine: JIT component. (CVE-2026-74976) Integer overflow in the Graphics component. (CVE-2026-74977) Clickjacking issue in the Widget component. (CVE-2026-74978) Mitigation bypass in the Add-ons Manager component. (CVE-2026-74979) Site isolation issue in the Audio/Video: Web Codecs component. (CVE-2026-74981) Denial-of-service in the Widget component. (CVE-2026-74982) Mitigation bypass in the Data Loss Prevention component. (CVE-2026-74983) Race condition in the JavaScript Engine component. (CVE-2026-74984) Privilege escalation in the Enterprise Policies component. (CVE-2026-74985) Site isolation issue in the CSS Parsing and Computation component. (CVE-2026-74986) Internally found bugs fixed in Thunderbird ESR 140.14, Thunderbird ESR 153.1 and Thunderbird 154. (CVE-2026-74987) Internally found bugs fixed in Thunderbird ESR 153.1 and Thunderbird 154 (CVE-2026-74988) Internally found bugs fixed in Thunderbird ESR 140.14, Thunderbird ESR 153.1 and Thunderbird 154. (CVE-2026-74990) References
- https://bugs.mageia.org/show_bug.cgi?id=36124
- https://www.thunderbird.net/en-US/thunderbird/140.14.0esr/releasenotes/
- https://www.thunderbird.net/en-US/thunderbird/153.1.0esr/releasenotes/
- https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/
- https://www.mozilla.org/en-US/security/advisories/mfsa2026-80/
- https://www.cve.org/CVERecord?id=CVE-2026-74934
- https://www.cve.org/CVERecord?id=CVE-2026-74935
- https://www.cve.org/CVERecord?id=CVE-2026-74936
- https://www.cve.org/CVERecord?id=CVE-2026-74937
- https://www.cve.org/CVERecord?id=CVE-2026-74938
- https://www.cve.org/CVERecord?id=CVE-2026-74939
- https://www.cve.org/CVERecord?id=CVE-2026-74940
- https://www.cve.org/CVERecord?id=CVE-2026-74941
- https://www.cve.org/CVERecord?id=CVE-2026-74942
- https://www.cve.org/CVERecord?id=CVE-2026-74943
- https://www.cve.org/CVERecord?id=CVE-2026-74944
- https://www.cve.org/CVERecord?id=CVE-2026-74945
- https://www.cve.org/CVERecord?id=CVE-2026-74946
- https://www.cve.org/CVERecord?id=CVE-2026-74947
- https://www.cve.org/CVERecord?id=CVE-2026-74948
- https://www.cve.org/CVERecord?id=CVE-2026-74950
- https://www.cve.org/CVERecord?id=CVE-2026-74953
- https://www.cve.org/CVERecord?id=CVE-2026-74954
- https://www.cve.org/CVERecord?id=CVE-2026-74955
- https://www.cve.org/CVERecord?id=CVE-2026-74956
- https://www.cve.org/CVERecord?id=CVE-2026-74957
- https://www.cve.org/CVERecord?id=CVE-2026-74958
- https://www.cve.org/CVERecord?id=CVE-2026-74959
- https://www.cve.org/CVERecord?id=CVE-2026-74960
- https://www.cve.org/CVERecord?id=CVE-2026-74961
- https://www.cve.org/CVERecord?id=CVE-2026-74962
- https://www.cve.org/CVERecord?id=CVE-2026-74963
- https://www.cve.org/CVERecord?id=CVE-2026-74964
- https://www.cve.org/CVERecord?id=CVE-2026-74965
- https://www.cve.org/CVERecord?id=CVE-2026-74966
- https://www.cve.org/CVERecord?id=CVE-2026-74967
- https://www.cve.org/CVERecord?id=CVE-2026-74968
- https://www.cve.org/CVERecord?id=CVE-2026-74969
- https://www.cve.org/CVERecord?id=CVE-2026-74970
- https://www.cve.org/CVERecord?id=CVE-2026-74971
- https://www.cve.org/CVERecord?id=CVE-2026-74972
- https://www.cve.org/CVERecord?id=CVE-2026-74949
- https://www.cve.org/CVERecord?id=CVE-2026-74973
- https://www.cve.org/CVERecord?id=CVE-2026-74974
- https://www.cve.org/CVERecord?id=CVE-2026-74976
- https://www.cve.org/CVERecord?id=CVE-2026-74977
- https://www.cve.org/CVERecord?id=CVE-2026-74978
- https://www.cve.org/CVERecord?id=CVE-2026-74979
- https://www.cve.org/CVERecord?id=CVE-2026-74981
- https://www.cve.org/CVERecord?id=CVE-2026-74982
- https://www.cve.org/CVERecord?id=CVE-2026-74983
- https://www.cve.org/CVERecord?id=CVE-2026-74984
- https://www.cve.org/CVERecord?id=CVE-2026-74985
- https://www.cve.org/CVERecord?id=CVE-2026-74986
- https://www.cve.org/CVERecord?id=CVE-2026-74987
- https://www.cve.org/CVERecord?id=CVE-2026-74988
- https://www.cve.org/CVERecord?id=CVE-2026-74990
- thunderbird-153.1.0-1.mga10
- thunderbird-l10n-153.1.0-1.mga10
- thunderbird-140.14.0-1.mga9
- thunderbird-l10n-140.14.0-1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0345 - Updated nspr, nss, & firefox packages fix security vulnerabilities
Publication date: 31 Aug 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-74934 , CVE-2026-74935 , CVE-2026-74936 , CVE-2026-74937 , CVE-2026-74938 , CVE-2026-74939 , CVE-2026-74940 , CVE-2026-74941 , CVE-2026-74942 , CVE-2026-74943 , CVE-2026-74944 , CVE-2026-74945 , CVE-2026-74946 , CVE-2026-74947 , CVE-2026-74948 , CVE-2026-74950 , CVE-2026-74953 , CVE-2026-74954 , CVE-2026-74955 , CVE-2026-74956 , CVE-2026-74957 , CVE-2026-74958 , CVE-2026-74959 , CVE-2026-74960 , CVE-2026-74961 , CVE-2026-74962 , CVE-2026-74963 , CVE-2026-74964 , CVE-2026-74965 , CVE-2026-74966 , CVE-2026-74967 , CVE-2026-74968 , CVE-2026-74969 , CVE-2026-74970 , CVE-2026-74971 , CVE-2026-74972 , CVE-2026-74949 , CVE-2026-74973 , CVE-2026-74974 , CVE-2026-74976 , CVE-2026-74977 , CVE-2026-74978 , CVE-2026-74979 , CVE-2026-74981 , CVE-2026-74982 , CVE-2026-74983 , CVE-2026-74984 , CVE-2026-74985 , CVE-2026-74986 , CVE-2026-74987 , CVE-2026-74988 , CVE-2026-74990 Description
Site isolation issue in the Graphics: CanvasWebGL component. (CVE-2026-74934) Privilege escalation in the DOM: Networking component. (CVE-2026-74935) Use-after-free in the JavaScript: WebAssembly component. (CVE-2026-74936) Use-after-free in the JavaScript: GC component. (CVE-2026-74937) Mitigation bypass in the JavaScript: GC component. (CVE-2026-74938) Privilege escalation in the DOM: Navigation component. (CVE-2026-74939) Use-after-free in the Graphics: Text component. (CVE-2026-74940) Privilege escalation in the Graphics: CanvasWebGL component. (CVE-2026-74941) Privilege escalation in the Remote Settings Client component. (CVE-2026-74942) Use-after-free in the Graphics: ImageLib component. (CVE-2026-74943) Use-after-free in the DOM: Core & HTML component. (CVE-2026-74944) Information disclosure in the Graphics: Text component. (CVE-2026-74945) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-74946) Privilege escalation due to invalid pointer in the Graphics component. (CVE-2026-74947) Information disclosure in the Graphics component. (CVE-2026-74948) Privilege escalation in the Downloads API component. (CVE-2026-74950) Privilege escalation in the Networking: Cookies component. (CVE-2026-74953) Information disclosure due to side-channel in the Storage: Cache API component. (CVE-2026-74954) Privilege escalation in the Request Handling component. (CVE-2026-74955) Same-origin policy bypass in the DOM: Service Workers component. (CVE-2026-74956) Mitigation bypass in the Safe Browsing component. (CVE-2026-74957) Information disclosure in the WebRTC component. (CVE-2026-74958) Mitigation bypass in the Storage: Cache API component. (CVE-2026-74959) Site isolation issue in the WebExtensions component. (CVE-2026-74960) Side-channel in the Web Audio component. (CVE-2026-74961) Site isolation issue in the Networking: Cookies component. (CVE-2026-74962) Same-origin policy bypass in the Networking: Cookies component. (CVE-2026-74963) Integer overflow in the Graphics component. (CVE-2026-74964) Privilege escalation in the Shell Integration component. (CVE-2026-74965) Information disclosure in the Form Autofill component. (CVE-2026-74966) Same-origin policy bypass in the Audio/Video: Playback component. (CVE-2026-74967) Site isolation issue in the Graphics: WebRender component. (CVE-2026-74968) Use-after-free in the Layout: Text and Fonts component. (CVE-2026-74969) Site isolation issue in the Graphics component. (CVE-2026-74970) Information disclosure in the DOM: UI Events & Focus Handling component. (CVE-2026-74971) Information disclosure in the DOM: Push Subscriptions component. (CVE-2026-74972) Use-after-free in the Graphics: Canvas2D component. (CVE-2026-74949) Race condition, use-after-free in the Graphics component. (CVE-2026-74973) Same-origin policy bypass in the Graphics: ImageLib component. (CVE-2026-74974) JIT miscompilation in the JavaScript Engine: JIT component. (CVE-2026-74976) Integer overflow in the Graphics component. (CVE-2026-74977) Clickjacking issue in the Widget component. (CVE-2026-74978) Mitigation bypass in the Add-ons Manager component. (CVE-2026-74979) Site isolation issue in the Audio/Video: Web Codecs component. (CVE-2026-74981) Denial-of-service in the Widget component. (CVE-2026-74982) Mitigation bypass in the Data Loss Prevention component. (CVE-2026-74983) Race condition in the JavaScript Engine component. (CVE-2026-74984) Privilege escalation in the Enterprise Policies component. (CVE-2026-74985) Site isolation issue in the CSS Parsing and Computation component. (CVE-2026-74986) Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154. (CVE-2026-74987) Internally found bugs fixed in Firefox ESR 153.1 and Firefox 154. (CVE-2026-74988) Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154. (CVE-2026-74990) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-74934 , CVE-2026-74935 , CVE-2026-74936 , CVE-2026-74937 , CVE-2026-74938 , CVE-2026-74939 , CVE-2026-74940 , CVE-2026-74941 , CVE-2026-74942 , CVE-2026-74943 , CVE-2026-74944 , CVE-2026-74945 , CVE-2026-74946 , CVE-2026-74947 , CVE-2026-74948 , CVE-2026-74950 , CVE-2026-74953 , CVE-2026-74954 , CVE-2026-74955 , CVE-2026-74956 , CVE-2026-74957 , CVE-2026-74958 , CVE-2026-74959 , CVE-2026-74960 , CVE-2026-74961 , CVE-2026-74962 , CVE-2026-74963 , CVE-2026-74964 , CVE-2026-74965 , CVE-2026-74966 , CVE-2026-74967 , CVE-2026-74968 , CVE-2026-74969 , CVE-2026-74970 , CVE-2026-74971 , CVE-2026-74972 , CVE-2026-74949 , CVE-2026-74973 , CVE-2026-74974 , CVE-2026-74976 , CVE-2026-74977 , CVE-2026-74978 , CVE-2026-74979 , CVE-2026-74981 , CVE-2026-74982 , CVE-2026-74983 , CVE-2026-74984 , CVE-2026-74985 , CVE-2026-74986 , CVE-2026-74987 , CVE-2026-74988 , CVE-2026-74990 Description
Site isolation issue in the Graphics: CanvasWebGL component. (CVE-2026-74934) Privilege escalation in the DOM: Networking component. (CVE-2026-74935) Use-after-free in the JavaScript: WebAssembly component. (CVE-2026-74936) Use-after-free in the JavaScript: GC component. (CVE-2026-74937) Mitigation bypass in the JavaScript: GC component. (CVE-2026-74938) Privilege escalation in the DOM: Navigation component. (CVE-2026-74939) Use-after-free in the Graphics: Text component. (CVE-2026-74940) Privilege escalation in the Graphics: CanvasWebGL component. (CVE-2026-74941) Privilege escalation in the Remote Settings Client component. (CVE-2026-74942) Use-after-free in the Graphics: ImageLib component. (CVE-2026-74943) Use-after-free in the DOM: Core & HTML component. (CVE-2026-74944) Information disclosure in the Graphics: Text component. (CVE-2026-74945) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-74946) Privilege escalation due to invalid pointer in the Graphics component. (CVE-2026-74947) Information disclosure in the Graphics component. (CVE-2026-74948) Privilege escalation in the Downloads API component. (CVE-2026-74950) Privilege escalation in the Networking: Cookies component. (CVE-2026-74953) Information disclosure due to side-channel in the Storage: Cache API component. (CVE-2026-74954) Privilege escalation in the Request Handling component. (CVE-2026-74955) Same-origin policy bypass in the DOM: Service Workers component. (CVE-2026-74956) Mitigation bypass in the Safe Browsing component. (CVE-2026-74957) Information disclosure in the WebRTC component. (CVE-2026-74958) Mitigation bypass in the Storage: Cache API component. (CVE-2026-74959) Site isolation issue in the WebExtensions component. (CVE-2026-74960) Side-channel in the Web Audio component. (CVE-2026-74961) Site isolation issue in the Networking: Cookies component. (CVE-2026-74962) Same-origin policy bypass in the Networking: Cookies component. (CVE-2026-74963) Integer overflow in the Graphics component. (CVE-2026-74964) Privilege escalation in the Shell Integration component. (CVE-2026-74965) Information disclosure in the Form Autofill component. (CVE-2026-74966) Same-origin policy bypass in the Audio/Video: Playback component. (CVE-2026-74967) Site isolation issue in the Graphics: WebRender component. (CVE-2026-74968) Use-after-free in the Layout: Text and Fonts component. (CVE-2026-74969) Site isolation issue in the Graphics component. (CVE-2026-74970) Information disclosure in the DOM: UI Events & Focus Handling component. (CVE-2026-74971) Information disclosure in the DOM: Push Subscriptions component. (CVE-2026-74972) Use-after-free in the Graphics: Canvas2D component. (CVE-2026-74949) Race condition, use-after-free in the Graphics component. (CVE-2026-74973) Same-origin policy bypass in the Graphics: ImageLib component. (CVE-2026-74974) JIT miscompilation in the JavaScript Engine: JIT component. (CVE-2026-74976) Integer overflow in the Graphics component. (CVE-2026-74977) Clickjacking issue in the Widget component. (CVE-2026-74978) Mitigation bypass in the Add-ons Manager component. (CVE-2026-74979) Site isolation issue in the Audio/Video: Web Codecs component. (CVE-2026-74981) Denial-of-service in the Widget component. (CVE-2026-74982) Mitigation bypass in the Data Loss Prevention component. (CVE-2026-74983) Race condition in the JavaScript Engine component. (CVE-2026-74984) Privilege escalation in the Enterprise Policies component. (CVE-2026-74985) Site isolation issue in the CSS Parsing and Computation component. (CVE-2026-74986) Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154. (CVE-2026-74987) Internally found bugs fixed in Firefox ESR 153.1 and Firefox 154. (CVE-2026-74988) Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154. (CVE-2026-74990) References
- https://bugs.mageia.org/show_bug.cgi?id=36123
- https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_127.html
- https://github.com/mozilla/nspr/releases/tag/NSPR_4_40_RTM
- https://www.firefox.com/en-US/firefox/140.14.0/releasenotes/
- https://www.firefox.com/en-US/firefox/153.1.0/releasenotes/
- https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/
- https://www.mozilla.org/en-US/security/advisories/mfsa2026-77/
- https://www.cve.org/CVERecord?id=CVE-2026-74934
- https://www.cve.org/CVERecord?id=CVE-2026-74935
- https://www.cve.org/CVERecord?id=CVE-2026-74936
- https://www.cve.org/CVERecord?id=CVE-2026-74937
- https://www.cve.org/CVERecord?id=CVE-2026-74938
- https://www.cve.org/CVERecord?id=CVE-2026-74939
- https://www.cve.org/CVERecord?id=CVE-2026-74940
- https://www.cve.org/CVERecord?id=CVE-2026-74941
- https://www.cve.org/CVERecord?id=CVE-2026-74942
- https://www.cve.org/CVERecord?id=CVE-2026-74943
- https://www.cve.org/CVERecord?id=CVE-2026-74944
- https://www.cve.org/CVERecord?id=CVE-2026-74945
- https://www.cve.org/CVERecord?id=CVE-2026-74946
- https://www.cve.org/CVERecord?id=CVE-2026-74947
- https://www.cve.org/CVERecord?id=CVE-2026-74948
- https://www.cve.org/CVERecord?id=CVE-2026-74950
- https://www.cve.org/CVERecord?id=CVE-2026-74953
- https://www.cve.org/CVERecord?id=CVE-2026-74954
- https://www.cve.org/CVERecord?id=CVE-2026-74955
- https://www.cve.org/CVERecord?id=CVE-2026-74956
- https://www.cve.org/CVERecord?id=CVE-2026-74957
- https://www.cve.org/CVERecord?id=CVE-2026-74958
- https://www.cve.org/CVERecord?id=CVE-2026-74959
- https://www.cve.org/CVERecord?id=CVE-2026-74960
- https://www.cve.org/CVERecord?id=CVE-2026-74961
- https://www.cve.org/CVERecord?id=CVE-2026-74962
- https://www.cve.org/CVERecord?id=CVE-2026-74963
- https://www.cve.org/CVERecord?id=CVE-2026-74964
- https://www.cve.org/CVERecord?id=CVE-2026-74965
- https://www.cve.org/CVERecord?id=CVE-2026-74966
- https://www.cve.org/CVERecord?id=CVE-2026-74967
- https://www.cve.org/CVERecord?id=CVE-2026-74968
- https://www.cve.org/CVERecord?id=CVE-2026-74969
- https://www.cve.org/CVERecord?id=CVE-2026-74970
- https://www.cve.org/CVERecord?id=CVE-2026-74971
- https://www.cve.org/CVERecord?id=CVE-2026-74972
- https://www.cve.org/CVERecord?id=CVE-2026-74949
- https://www.cve.org/CVERecord?id=CVE-2026-74973
- https://www.cve.org/CVERecord?id=CVE-2026-74974
- https://www.cve.org/CVERecord?id=CVE-2026-74976
- https://www.cve.org/CVERecord?id=CVE-2026-74977
- https://www.cve.org/CVERecord?id=CVE-2026-74978
- https://www.cve.org/CVERecord?id=CVE-2026-74979
- https://www.cve.org/CVERecord?id=CVE-2026-74981
- https://www.cve.org/CVERecord?id=CVE-2026-74982
- https://www.cve.org/CVERecord?id=CVE-2026-74983
- https://www.cve.org/CVERecord?id=CVE-2026-74984
- https://www.cve.org/CVERecord?id=CVE-2026-74985
- https://www.cve.org/CVERecord?id=CVE-2026-74986
- https://www.cve.org/CVERecord?id=CVE-2026-74987
- https://www.cve.org/CVERecord?id=CVE-2026-74988
- https://www.cve.org/CVERecord?id=CVE-2026-74990
- nspr-4.40.0-1.mga10
- nss-3.127.0-1.mga10
- firefox-153.1.0-1.mga10
- firefox-l10n-153.1.0-1.mga10
- nspr-4.40.0-1.mga9
- nss-3.127.0-1.mga9
- firefox-140.14.0-1.mga9
- firefox-l10n-140.14.0-1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0344 - Updated jbig2dec packages fix security vulnerabilities
Publication date: 31 Aug 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2023-46361 , CVE-2026-38076 Description
Artifex Software jbig2dec v0.20 was discovered to contain a SEGV vulnerability via jbig2_error at /jbig2dec/jbig2.c. (CVE-2023-46361) An integer overflow in the jbig2_arith_iaid_ctx_new() function of Artifex commit cc37d0 allows attackers to cause a Denial of Service (DoS) via a crafted input. (CVE-2026-38076) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2023-46361 , CVE-2026-38076 Description
Artifex Software jbig2dec v0.20 was discovered to contain a SEGV vulnerability via jbig2_error at /jbig2dec/jbig2.c. (CVE-2023-46361) An integer overflow in the jbig2_arith_iaid_ctx_new() function of Artifex commit cc37d0 allows attackers to cause a Denial of Service (DoS) via a crafted input. (CVE-2026-38076) References
- https://bugs.mageia.org/show_bug.cgi?id=35994
- https://ubuntu.com/security/notices/USN-8582-1
- https://github.com/Frank-Z7/z-vulnerabilitys/blob/main/jbig2dec-SEGV/jbig2dec-SEGV.md
- https://bugs.ghostscript.com/show_bug.cgi?id=707308
- https://bugs.ghostscript.com/show_bug.cgi?id=705041
- https://www.cve.org/CVERecord?id=CVE-2023-46361
- https://www.cve.org/CVERecord?id=CVE-2026-38076
- jbig2dec-0.20-2.1.mga10
- jbig2dec-0.19-4.1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0343 - Updated c-ares packages fix security vulnerabilities
Publication date: 31 Aug 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-33630 , CVE-2026-69184 , CVE-2026-69186 Description
Use-after-free / double-free in c-ares query-completion handling, remotely triggerable via ares_getaddrinfo() over TCP. (CVE-2026-33630) CPU-exhaustion denial of service via unbounded DNS name compression pointer chains. (CVE-2026-69184) Memory-amplification denial of service via unvalidated DNS header record counts. (CVE-2026-69186) References
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-33630 , CVE-2026-69184 , CVE-2026-69186 Description
Use-after-free / double-free in c-ares query-completion handling, remotely triggerable via ares_getaddrinfo() over TCP. (CVE-2026-33630) CPU-exhaustion denial of service via unbounded DNS name compression pointer chains. (CVE-2026-69184) Memory-amplification denial of service via unvalidated DNS header record counts. (CVE-2026-69186) References
- https://bugs.mageia.org/show_bug.cgi?id=35847
- https://www.openwall.com/lists/oss-security/2026/07/06/8
- https://github.com/c-ares/c-ares/security/advisories/GHSA-6wfj-rwm7-3542
- https://github.com/c-ares/c-ares/security/advisories/GHSA-pjmc-gx33-gc76
- https://github.com/c-ares/c-ares/security/advisories/GHSA-jv8r-gqr9-68wj
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RP4OX63ZTYCCB4UK6HI4BFEPQEPSNLOJ/
- https://www.cve.org/CVERecord?id=CVE-2026-33630
- https://www.cve.org/CVERecord?id=CVE-2026-69184
- https://www.cve.org/CVERecord?id=CVE-2026-69186
- c-ares-1.34.8-1.mga10
Categorías: Actualizaciones de Seguridad
MGASA-2026-0342 - Updated flatpak package fixes security vulnerabilities
Publication date: 31 Aug 2026
Type: security
Affected Mageia releases : 10
Description
Updated flatpak package fixes security vulnerabilities. Please see the links for additional information. References
Type: security
Affected Mageia releases : 10
Description
Updated flatpak package fixes security vulnerabilities. Please see the links for additional information. References
- https://bugs.mageia.org/show_bug.cgi?id=36137
- https://www.openwall.com/lists/oss-security/2026/08/11/9
- https://lists.debian.org/debian-security-announce/2026/msg00343.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BT77VPU5W2JAF2LEXVLX6Q33HJJAOLTH/
- https://github.com/flatpak/flatpak/security/advisories/GHSA-8688-9x26-hhxj
- https://github.com/flatpak/flatpak/security/advisories/GHSA-qrwq-7qwx-q9rp
- https://github.com/flatpak/flatpak/security/advisories/GHSA-fqx6-vh4p-42cg
- https://github.com/flatpak/flatpak/security/advisories/GHSA-8qxj-x646-phcm
- https://github.com/flatpak/flatpak/security/advisories/GHSA-9rww-v4mm-x4jg
- https://github.com/flatpak/flatpak/security/advisories/GHSA-v2gw-v9h5-9q4x
- https://github.com/flatpak/flatpak/security/advisories/GHSA-jr92-2v97-wgvc
- https://github.com/flatpak/flatpak/security/advisories/GHSA-99wv-m8rp-g58x
- https://github.com/flatpak/flatpak/security/advisories/GHSA-w69g-9x8j-7p8f
- https://github.com/flatpak/flatpak/security/advisories/GHSA-q4gr-vc25-57m5
- flatpak-1.16.6-1.1.mga10
Categorías: Actualizaciones de Seguridad




