Lector de Feeds

End of Support for Mageia 9

Blog de Mageia (English) - 25 Septiembre, 2026 - 08:07

At Mageia, we have reached a significant milestone with the release of Mageia 10 on 30 June 2026. It has been a major step towards modernising our system in many respects, and our cauldron is already beginning to simmer as we prepare our next release, Mageia 11!

Mageia 9 has been rock-solid, with 24,008 updates to date, providing security fixes for our users. This is down to the hard work of all our teams, who ensure that Mageia remains easy to use and secure.

The time has come to say goodbye to our ninth release and focus on the new challenges posed by the maintenance of Mageia 10, the development of Mageia 11, and adapting our software to the changing times so that it supports the latest additions in both hardware and third-party software packaged for our Mageia users.

We hope that all the work carried out by our contributors will result in a great open-source system that is user-friendly, modern and up-to-date for our entire community. You can find the full list of features for Mageia 10 in the release notes.

Support for previous versions extends to 3 months after the release of the latest version, so Mageia 9 will no longer be supported as of September 30. We therefore ask that, if you have not already done so, you consider upgrading to Mageia 10, as support for Mageia 9 will end with the latest validated updates.

Migration can be carried out using:

  • The update application for major versions of Mageia in the system tray (currently the blue update icon).
  • Using the command line as described in the notes.

It is also possible to migrate to Mageia 10 with a clean install using the classic installation images. Live images can be used to try out Mageia 10 or perform a clean install, but they are not compatible for migrating to or upgrading to the new version of Mageia.

Please note that when performing a clean install, any data not stored on a separate partition or backed up to an external device will be deleted. Please ensure you have made the necessary backups.

If you have any questions or need help with the migration, you can visit our forums, which cover most languages, or the Mageia wiki.

Categorías: Blogs Oficiales

MGASA-2026-0452 - Updated python-webob packages fix a security vulnerability

Mageia Security - 25 Septiembre, 2026 - 06:02
Publication date: 25 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-44889 Description
Location header normalization during redirect leads to open redirect - again References
SRPMS 10/core
  • python-webob-1.8.11-1.mga10
9/core
  • python-webob-1.8.11-1.mga9

MGASA-2026-0451 - Updated unbound packages fixes security vulnerabilities

Mageia Security - 25 Septiembre, 2026 - 06:02
Publication date: 25 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-14586 , CVE-2026-32665 , CVE-2026-40622 , CVE-2026-40691 , CVE-2026-41637 , CVE-2026-42955 , CVE-2026-44621 , CVE-2026-44687 , CVE-2026-44690 , CVE-2026-46582 , CVE-2026-50045 , CVE-2026-50046 , CVE-2026-50243 , CVE-2026-50248 , CVE-2026-50251 , CVE-2026-50252 , CVE-2026-52863 , CVE-2026-54478 , CVE-2026-55708 , CVE-2026-55717 , CVE-2026-55973 , CVE-2026-55990 , CVE-2026-55991 , CVE-2026-56416 , CVE-2026-56444 , CVE-2026-77860 , CVE-2026-77955 , CVE-2026-78227 , CVE-2026-80225 , CVE-2026-81634 , CVE-2026-81642 , CVE-2026-82717 , CVE-2026-82720 , CVE-2026-85501 Description
Heap buffer overflow and possible Remote Code Execution when digesting DNSKEY Possible heap buffer overflow during DNSSEC canonicalization CNAME synthesis could lead to heap corruption Possible ZONEMD verification bypass window Use-after-free in DoQ stream output buffer on reset re-transmission Possible degradation of service from continuous queries on the same TCP/DoT connection Use-after-free in DoH stream cleanup code path Retrap: Novel Vulnerabilities to launch Algorithmic Complexity Attacks on DNSSEC 'serve-expired' can bypass Unbound 'wait-limit' Remote DNS-over-QUIC denial of service due to 'quic-size' budget bypass Packet of death for DNSCrypt over TCP Cross-zone wildcard cache poisoning via RRSIG.labels manipulation 'dns-error-reporting: yes' leads to stack buffer overflow Assertion in libngtcp2 when under pressure in high concurrency DNS-over-QUIC environments Libunbound applications configured with 'unwanted-reply-threshold' could eventually be abruptly terminated 'max-global-quota' reset by DNSSEC validation restarts Possible heap use-after-free in an error path when a DoT forwarded query is jostled out 'response-ip'/'rpz' can rewrite BOGUS answers instead of returning SERVFAIL BOGUS configured primary hostname accepted for XFR in auth/rpz zones Date: Attacker supplied '0.0.0.0'/'::' glue triggers defensive full-cache flush Possible cache poisoning attack by mapping source port population per thread Memory corruption could lead to crash and denial of service 'serve-expired-client-timeout' and 'response-ip' CNAME redirect could lead to a crash Packet of death for a DNSCrypt misconfigured Unbound Remote DNS-over-QUIC (DoQ) flow-control assertion failure in libngtcp2 Possible heap buffer overflow when validator canonicalizes RDATA that contains domain name Degradation of resolution service when 'discard-timeout' and 'serve-expired-client-timeout' are combined in unusual configuration Degradation of resolution service from improperly accounted client-terminated DNS-over-QUIC queries Extra fix for CVE-2026-40622 to also clamp the TTL of A/AAAA records disallowing a one-time 'ghost domain' delegation renewal via glue records Off-by-one error in 'harden-below-nxdomain' logic can shadow a stub/forward zone by a legitimate parent's NXDOMAIN A wildcard replay, as another piece of data, triggers poisoning in the serve expired reply path DNS Cookie bypass when combined with proxy-protocol use Privacy/configuration issue when adding local data in views through 'unbound-control' Possible arbitrary code execution during DNSSEC validation Heap overflow with multiple NSID, COOKIE, PADDING EDNS options Crash during DNSSEC validation of malicious content Date: Packet of death with DNSCrypt Another "ghost domain names" attack variant Long list of incoming EDNS options degrades performance Jostle logic bypass degrades resolution performance Degradation of service with unbounded NSEC3 hash calculations Possible cache poisoning via promiscuous records for the authority section Unbounded name compression in certain cases causes degradation of service Use after free and crash under special conditions in RPZ code Possible domain hijacking via promiscuous records in the authority section Cache poisoning via the ECS-enabled Rebirthday Attack Unbounded name compression could lead to Denial of Service Unbound vulnerable to the "DNSBomb" pulsing DoS amplification attack Denial of service when trimming EDE text on positive replies DNSSEC verification complexity can be exploited to exhaust CPU resources and stall DNS resolvers NSEC3 closest encloser proof can exhaust CPU Non-Responsive Delegation Attack Novel "ghost domain names" attack by updating almost expired delegation information Novel "ghost domain names" attack by introducing subdomain delegations Local symlink attack Vulnerability in Domain Parse NXNSAttack Vulnerability in IPSEC module Vulnerability in parsing NOTIFY queries Vulnerability in the processing of wildcard synthesized NSEC records No limit to delegation chaining Ghost domain names attack Incorrect proof processing for NSEC3-signed zone Processing of duplicate CNAME records in a signed zone Empty error packet handling assertion failure References
SRPMS 10/core
  • unbound-1.26.1-1.mga10
9/core
  • unbound-1.26.1-1.mga9

MGASA-2026-0450 - Updated python-gitpython packages fix security vulnerabilities

Mageia Security - 25 Septiembre, 2026 - 06:02
Publication date: 25 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-87819 Description
Denial of Service via catastrophic backtracking (ReDoS) in Actor.name_email_regex — commit author/committer field parsing Repository content can impersonate the git directory, leading to arbitrary code execution Residual of GHSA-hmq2-w58f-27jc: the fix validates the `.gitmodules` **name** but the sibling **path** field still reaches `os.makedirs()` unguarded, although GitPython already owns the containment guard References
SRPMS 10/core
  • python-gitpython-3.1.62-1.mga10
9/core
  • python-gitpython-3.1.62-1.mga9

MGAA-2026-0136 - Updated discover package fixes start-up bug

Mageia Security - 25 Septiembre, 2026 - 06:02
Publication date: 25 Sep 2026
Type: bugfix
Affected Mageia releases : 10
Description
In systems that don't have plasma as the desktop discover fails to start. This update fixes the reported issue. References
SRPMS 10/core
  • discover-6.5.5-4.1.mga10

Cooker

Blog de OpenMandriva - 25 Septiembre, 2026 - 00:58
Cooker (development)

Cooker is the OpenMandriva Lx development branch.

This is where developers do the actual work of developing packages and the distro itself. Because of the nature of this continual work process Cooker breaks at times.

If you are not used to problem solving on computers at a very high level Cooker is not for you.

  • arrow_drop_downCOOKER Plasma

    The Plasma Extended version is basically a complete desktop for most non-technical users. It features software from KDE.org and other Qt based software. It includes software for most day to day tasks.

Donate

Blog de OpenMandriva - 25 Septiembre, 2026 - 00:58
Welcome to OpenMandriva!

We are a community-driven initiative dedicated to fostering open source innovation in the realm of operating systems. Since our inception, we have been committed to creating a user-friendly, cutting-edge Linux distribution that empowers users worldwide. However, to continue our mission and enhance our offerings, we need your support.

Why Donate?

Your donations play a crucial role in sustaining and advancing the OpenMandriva project. With your generous contributions, we can:

Downloads

Blog de OpenMandriva - 25 Septiembre, 2026 - 00:58

OpenMandriva flagship release is ROME (rolling)

Current Rock release is OpenMandriva Lx 6.0

Development release is Cooker

Spins are alternative desktops environments

Choose your release The OpenMandriva project offers different image types available for download.
If in doubt, use the full featured Plasma6 x86_64 ISO image. Download the ISO file

Mirror download (sourceforge.net)
Enter the folders, select the release in the list, it should automatically open a download page from a mirror nearby your location.
If in doubt, go to OpenMandriva homepage at SourceForge and click the big green button “Download”

Frequently asked questions

Blog de OpenMandriva - 25 Septiembre, 2026 - 00:58
Questions and Answers
  • arrow_drop_downTell readers about the founding of Open Mandriva This is essentially just old history - maybe the most interesting part is that it means we are one of the oldest distributions still alive today.
    When Mandriva (previously Mandrake) went out of business, the community didn’t want to let the distribution die, so it was turned over to a team consisting of previous contributors, and people from related similar projects (Unity Linux, Ark Linux) joined forces to form OpenMandriva.
    We agreed with what remained of Mandriva on terms for all further development:
    License
  • arrow_drop_downWhat does OpenMandriva inherit from Mandrake? Technology? Organization? Philosophy? The original source code;
    The initial team, or part of it;
    The idea of building an operating system that is simple enough for someone who has never seen Linux to get productive with, without dumbing it down to the point that it stops being useful to experts.
    OpenMandriva philosophy is inspired by the Open Source principles philosophy.
  • arrow_drop_downAny stats about downloads, commits, developers? Given we are an Open Source project with quite a few mirrors and bittorrent downloads, and we have no idea how many people share their download with others, it is impossible to get accurate numbers.
    We can get documented stats only from SourceForge mirror. Maybe worth to mention that many users and/or newcomers are invited to download and test the latest ISO images snapshots, during development cycle in-between the officially announced releases, directly from our build server, ABF (cf. Forum topics Most recent Cooker ISO and Most recent ROME (rolling) ISO which we keep constantly up-to-date).
    Of course we have more accurate numbers about developers and commits.
    There are 7 main developers, and a few people who submit a patch once in a while.
    There have been 82350 commits in the last year, out of which 7323 were in the last month.
    The commits go to our repositories OpenMandriva Association and OpenMandriva Software and the packages are built on ABF: [1] [2]
  • arrow_drop_downHow is OpenMandriva organized, and how are decisions made? OpenMandriva has 2 main entities:
    Council for what concerning the legal/paperworks, PR and organization side;
    Technical Committee for what concerning the products’ technical development side.
    The decisions are made depending on the specific subject however more often than not they are virtually identical pertaining to both sides.
    When at all possible we aim to reach consensus for final decisions. Crucial help is provided by the shared target and common sense.
    People who have been contributing consistently over some time are invited into the relevant entities.
  • arrow_drop_downHow does the Association interact with the community?
    • Main website /
      (News)

Get involved

Blog de OpenMandriva - 25 Septiembre, 2026 - 00:58
Give time

If you have time, we welcome your help in various areas:

Development

Check the developers documentation, join the conversation, and have a look at the bug-tracking system and to get in touch with the developers community and get things done

Writing

Help us improve the documentation, materials and communication

Translation

Translators, help us translate web materials, OpenMandriva Lx and other projects

Keep the Community alive

Participate in the forum, write your experience with Rock or ROME, share your knowledge, publish your desktop screenshots, help the other users, or even just chat

Rock

Blog de OpenMandriva - 25 Septiembre, 2026 - 00:58

Rock (OMLx 6.0) is the home and workstation edition published by the OpenMandriva Association. Also for individual users who do not want many updates, be it because they prefer their system to remain the same or because of slow internet connection. Releases are scheduled around once a year.

It would be the most stable and suitable for users that like things to stay as they are and just work. Package upgrades will be limited mostly to bug fixes, and security updates.

ROME

Blog de OpenMandriva - 25 Septiembre, 2026 - 00:58

ROME is the rolling edition, designed for individual users.

It is designed to be a working, usable system and will have the most up to date packages.

ROME users should be familiar with the command line or terminal (Konsole) and be able to use it at times.

  • arrow_drop_downPlasma 6

    The Plasma Extended version is basically a complete desktop for most non-technical users. It features software from KDE.org and other Qt based software. It includes software for most day to day tasks.

Server

Blog de OpenMandriva - 25 Septiembre, 2026 - 00:58

OpenMandriva Rock/ROME for servers is a fully independent and flexible Linux distribution, installable with only the necessary programs for starting a server environment (eg: no GUI, no desktop apps, but you can of course add them later)

It can run on bare metal as well as inside containers and VMs, such as OpenStack, Docker, or OCI

It supports AArch64, x86, and znver1 (specially optimized x86 build for Ryzen/EPYC processors) and scales from a Raspberry Pi all the way to a 160-core Ampere server

Spins

Blog de OpenMandriva - 25 Septiembre, 2026 - 00:58

Spins is Community alternative desktop proof of concept.

OpenMandriva default desktop environment is the complete, modern KDE Plasma. If you prefer an alternative desktop such as GNOME, LXQt, Xfce or other you can download a Spin.

Do not expect everything to work “out of the box”. They are mainly supported by their maintainers or currently no dedicated maintainers. Bug fixing is not high priority. Any help is welcome.

Which release should I pick?

Blog de OpenMandriva - 25 Septiembre, 2026 - 00:58

ROCK

Rock (OMLx 6.0) is the home and workstation edition

ROME

ROME is the rolling edition, designed for individual users

COOKER

Cooker is the OpenMandriva Lx development branch

SPINS

Community alternative desktop proof of concept

MGAA-2026-0135 - Updated zoneminder package fixes zmsetup failure

Mageia Security - 24 Septiembre, 2026 - 18:59
Publication date: 24 Sep 2026
Type: bugfix
Affected Mageia releases : 10
Description
This update fixes two issues causing zmsetup to fail due to mysql compatibility commands having been removed from mariadb. These commands are now replaced with the native mariadb equivalents. References
SRPMS 10/tainted
  • zoneminder-1.38.0-1.1.mga10.tainted

MGASA-2026-0449 - Updated thunderbird & thunderbird-l10n packages fix security vulnerabilities

Mageia Security - 24 Septiembre, 2026 - 17:06
Publication date: 24 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-92238 , CVE-2026-92239 , CVE-2026-92240 , CVE-2026-92005 , CVE-2026-92006 , CVE-2026-92007 , CVE-2026-92008 , CVE-2026-92009 , CVE-2026-92010 , CVE-2026-92011 , CVE-2026-92012 , CVE-2026-92013 , CVE-2026-92014 , CVE-2026-92015 , CVE-2026-92016 , CVE-2026-92017 , CVE-2026-92018 , CVE-2026-92019 , CVE-2026-92020 , CVE-2026-92021 , CVE-2026-92022 , CVE-2026-92023 , CVE-2026-92024 , CVE-2026-92025 , CVE-2026-92026 , CVE-2026-92027 , CVE-2026-92028 , CVE-2026-92029 , CVE-2026-92030 , CVE-2026-92031 , CVE-2026-92032 , CVE-2026-92038 , CVE-2026-92039 , CVE-2026-92041 , CVE-2026-92042 , CVE-2026-92043 , CVE-2026-92044 , CVE-2026-92045 , CVE-2026-92046 , CVE-2026-92047 , CVE-2026-92052 , CVE-2026-92053 , CVE-2026-92054 , CVE-2026-92055 , CVE-2026-92056 , CVE-2026-92057 , CVE-2026-92058 , CVE-2026-92059 , CVE-2026-92060 , CVE-2026-92062 , CVE-2026-92064 , CVE-2026-92067 , CVE-2026-92068 , CVE-2026-92069 , CVE-2026-92070 , CVE-2026-92072 , CVE-2026-92073 , CVE-2026-92074 , CVE-2026-92075 , CVE-2026-92076 , CVE-2026-92077 , CVE-2026-92078 Description
Ambiguous parsing of mail headers. (CVE-2026-92238) Buffer overrun in IMAP. (CVE-2026-92239) Out-of-bounds read in IMAP response parser. (CVE-2026-92240) Use-after-free in the Audio/Video: Web Codecs component. (CVE-2026-92005) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-92006) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-92007) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-92008) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-92009) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-92010) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-92011) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-92012) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-92013) Privilege escalation due to incorrect boundary conditions in the Graphics component. (CVE-2026-92014) Privilege escalation in the WebExtensions component. (CVE-2026-92015) Use-after-free in the Disability Access APIs component. (CVE-2026-92016) Privilege escalation in the DOM: Service Workers component. (CVE-2026-92017) Sandbox escape in the DOM: Core & HTML component. (CVE-2026-92018) Mitigation bypass in the Remote Settings Client component. (CVE-2026-92019) Privilege escalation due to incorrect boundary conditions in the Graphics: WebRender component. (CVE-2026-92020) Use-after-free in the JavaScript Engine: JIT component. (CVE-2026-92021) Use-after-free in the DOM: HTML Parser component. (CVE-2026-92022) Use-after-free in the XML component. (CVE-2026-92023) Use-after-free in the SVG component. (CVE-2026-92024) Use-after-free in the DOM: Navigation component. (CVE-2026-92025) Use-after-free in the Networking component. (CVE-2026-92026) Use-after-free in the DOM: Streams component. (CVE-2026-92027) Use-after-free in the DOM: Core & HTML component. (CVE-2026-92028) Use-after-free in the SVG component. (CVE-2026-92029) Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component. (CVE-2026-92030) Information disclosure in the Graphics: ImageLib component. (CVE-2026-92031) Sandbox escape due to invalid pointer in the Graphics component. (CVE-2026-92032) Mitigation bypass in the Remote Settings Client component. (CVE-2026-92038) Mitigation bypass in the DOM: Notifications component. (CVE-2026-92039) Mitigation bypass in the DOM: Networking component. (CVE-2026-92041) Race condition in the DOM: Content Processes component. (CVE-2026-92042) Privilege escalation due to incorrect boundary conditions in the Audio/Video component. (CVE-2026-92043) Information disclosure in the Networking: HTTP component. (CVE-2026-92044) Sandbox escape due to incorrect boundary conditions in the WebRTC component. (CVE-2026-92045) Use-after-free in the Graphics component. (CVE-2026-92046) Privilege escalation in the Crash Reporting component. (CVE-2026-92047) Privilege escalation due to uninitialized memory in the Graphics: CanvasWebGL component. (CVE-2026-92052) Privilege escalation in the Graphics: CanvasWebGL component. (CVE-2026-92053) Privilege escalation in the Memory component. (CVE-2026-92054) Privilege escalation in the DevTools component. (CVE-2026-92055) Use-after-free in the Graphics: Text component. (CVE-2026-92056) Mitigation bypass in the Enterprise Policies component. (CVE-2026-92057) Use-after-free in the Graphics component. (CVE-2026-92058) Incorrect boundary conditions in the DOM: Editor component. (CVE-2026-92059) Use-after-free in the Internationalization component. (CVE-2026-92060) Privilege escalation in the Session Restore component. (CVE-2026-92062) Use-after-free in the Widget: Gtk component. (CVE-2026-92067) Site isolation issue in the Reader Mode component. (CVE-2026-92068) Spoofing issue in the DOM: Navigation component. (CVE-2026-92069) Information disclosure in the Networking component. (CVE-2026-92070) Incorrect boundary conditions in the Safe Browsing component. (CVE-2026-92072) Privilege escalation in the Enterprise Policies component. (CVE-2026-92073) Mitigation bypass in the Popup Blocker component. (CVE-2026-92074) Mitigation bypass in the Networking component. (CVE-2026-92075) Incorrect boundary conditions in the Networking component. (CVE-2026-92076) Denial-of-service in the SVG component. (CVE-2026-92077) Denial-of-service in the Security component. (CVE-2026-92078) References
SRPMS 10/core
  • thunderbird-153.3.0-1.mga10
  • thunderbird-l10n-153.3.0-1.mga10
9/core
  • thunderbird-140.16.0-1.mga9
  • thunderbird-l10n-140.16.0-1.mga9

MGASA-2026-0448 - Updated perl-Net-DNS packages fix security vulnerabilities

Mageia Security - 24 Septiembre, 2026 - 17:06
Publication date: 24 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-64193 , CVE-2026-64194 , CVE-2026-81928 Description
Net::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTENDED ERROR. (CVE-2026-64193) Net::DNS versions through 1.55 for Perl allow Denial of Service via deep DNS compression pointer chains. (CVE-2026-64194) Net::DNS versions before 1.57 for Perl allow memory exhaustion via unbounded recursion in sig_data when re-encoding a message with a misplaced TSIG record. (CVE-2026-81928) References
SRPMS 10/core
  • perl-Net-DNS-1.570.0-1.mga10
9/core
  • perl-Net-DNS-1.360.0-1.1.mga9

MGASA-2026-0447 - Updated fuse3 package fixes security vulnerabilities

Mageia Security - 24 Septiembre, 2026 - 17:06
Publication date: 24 Sep 2026
Type: security
Affected Mageia releases : 10
Description
This update brings security fixes provided by upstream. References
SRPMS 10/core
  • fuse3-3.18.3-1.mga10

MGAA-2026-0134 - Updated geogebra package fixes bug

Mageia Security - 24 Septiembre, 2026 - 17:06
Publication date: 24 Sep 2026
Type: bugfix
Affected Mageia releases : 10
Description
geogebra is updated to version 5.4.929.3 References
SRPMS 10/nonfree
  • geogebra-5.4.929.3-1.mga10.nonfree
Feed