Lector de Feeds

MGASA-2026-0364 - Updated apr-util packages fix security vulnerabilities

Mageia Security - 2 Septiembre, 2026 - 17:59
Publication date: 02 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2025-49506 , CVE-2026-32327 , CVE-2026-34191 , CVE-2026-34501 , CVE-2026-34502 Description
Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack. (CVE-2025-49506) Apache Portable Runtime Utility: apr-util XML stack recursion crash. (CVE-2026-32327) Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracle. (CVE-2026-34191) Apache Portable Runtime Utility: Heap buffer overflow in APR redis client. (CVE-2026-34501) Apache Portable Runtime Utility: Heap buffer overflow in APR memcached client. (CVE-2026-34502) References
SRPMS 10/core
  • apr-util-1.6.3-3.1.mga10
9/core
  • apr-util-1.6.3-1.1.mga9

MGAA-2026-0118 - Updated opencpn-climatology-plugin package fixes bug

Mageia Security - 2 Septiembre, 2026 - 17:59
Publication date: 02 Sep 2026
Type: bugfix
Affected Mageia releases : 10
Description
Updated package provides more recent climatology data (data from 2026) than the previous version (data from 2019). References
SRPMS 10/core
  • opencpn-climatology-plugin-1.6.37.0-1.git20260510.mga10

MGASA-2026-0362 - Updated perl-HTTP-Date packages fix a security vulnerability

Mageia Security - 1 Septiembre, 2026 - 08:04
Publication date: 01 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-14741 Description
HTTP::Date versions before 6.08 for Perl allow CPU exhaustion via polynomial regex backtracking in parse_date References
SRPMS 10/core
  • perl-HTTP-Date-6.80.0-1.mga10
9/core
  • perl-HTTP-Date-6.80.0-1.mga9

MGASA-2026-0361 - Updated perl-Date-Manip packages fix security vulnerabilities

Mageia Security - 1 Septiembre, 2026 - 08:04
Publication date: 01 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-60074 , CVE-2026-60075 Description
Date::Manip versions through 6.99 for Perl return corrupted dates via non-ASCII decimal digits that pass the numeric range tests in check Date::Manip versions through 6.99 for Perl allow CPU exhaustion via quadratic backtracking in the unanchored time substitution in _parse_time References
SRPMS 10/core
  • perl-Date-Manip-6.990.0-1.mga10
9/core
  • perl-Date-Manip-6.990.0-1.mga9

MGASA-2026-0360 - Updated perl-HTML-FormHandler packages fix a security vulnerability

Mageia Security - 1 Septiembre, 2026 - 08:04
Publication date: 01 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2022-4993 Description
HTML::FormHandler versions through 0.40068 for Perl allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notation template References
SRPMS 10/core
  • perl-HTML-FormHandler-0.400.680-8.mga10
9/core
  • perl-HTML-FormHandler-0.400.680-6.mga9

MGASA-2026-0359 - Updated nodejs packages fix security vulnerabilities

Mageia Security - 1 Septiembre, 2026 - 04:06
Publication date: 01 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-56846 , CVE-2026-56848 , CVE-2026-58043 , CVE-2026-56850 , CVE-2026-58040 , CVE-2026-58042 , CVE-2026-58045 , CVE-2026-56847 , CVE-2026-58039 , CVE-2026-58044 Description
http2: retain header memory in session accounting. (CVE-2026-56846) http2: defer rst stream while in scope. (CVE-2026-56848) permission: avoid granting radix split nodes. (CVE-2026-58043) https: distinguish PFX object-array agent keys. (CVE-2026-56850) https: bind identity checks to session reuse. (CVE-2026-58040) dns: handle large resolveAny address replies. (CVE-2026-58042) zlib: throw on out-of-bounds write buffers. (CVE-2026-58045) permission: enforce fs write permission for trace events. (CVE-2026-56847) permission: check final report output path. (CVE-2026-58039) http: reject requests exceeding max header count. (CVE-2026-58044) References
SRPMS 10/core
  • nodejs-22.23.2-1.mga10
9/core
  • nodejs-22.23.2-1.mga9

MGASA-2026-0358 - Updated roundcubemail packages fix security vulnerabilities

Mageia Security - 1 Septiembre, 2026 - 04:06
Publication date: 01 Sep 2026
Type: security
Affected Mageia releases : 9
Description
* Add basic validation for content proxied by the css proxy acta2.jpg acta.jpg advisories avatar.jpg avatar.png bdk-key.bkup bdk-mga9.txt bdk-new.key bdkpackagers.key bdkpackagers.sec bdkpass bin blogdrake.net bookmarks.html BRF Descargas Desktop diagrana.pdf discover-missing Documentos download Dragon Quest: Dai no Daibouken - Bravest Full OP Sub Español [2MZON1ev9DE].mkv ejemplo añadir_archivo1.spec ejemplo añadir_archivo2.spec google-chrome.spec html i18n.pdf Imágenes index.php kernel-backport kernel-cves.enc kernel-cves.txt lqshell-stylesheet.css mageia-advisories MANOLO MUÑOZ VS ALBERTO VAZQUEZ MANO A MANO 24 EXITAZOS RANCHEROS CON MARIACHI.opus MEGA megasync-10.tar.gz #*message*-20260914-112747# mgaadv-error.txt mgarepo mirrorbdk mock Música origen.rss out.pnm PDF pdfbooklet-3.1.2-all_64.tar.gz Plantillas Precure News - Star Detective PreCure! OP (Movie Footage Edition) [2099120870992310272].mp4 Proyectos qatest qa-testing qphotorec.desktop qphotorec.log reinstall.sh repodkfix.sh repositorio rpm rss Sailor Moon Cosmos AMV - Makenai (Sailor Star Song).mp4 sshrc style.html Taylor Swift, les coulisses du succès [120464-000-A].mp4 test.jpg tmp update-bdkkey.sh urpm-ng-distupgrade-orphans vdhcoapp-2.0.19 Ventoy Backup Vídeos VirtualBox VMs xen test xen-mga#33082 YAML-LibYAML-Test-dir zekemx Fix SSRF bypass via specific local address URLs using 100.64.0.0/10 and fe80::/10 nets, reported by Dmytro Ivanenko acta2.jpg acta.jpg advisories avatar.jpg avatar.png bdk-key.bkup bdk-mga9.txt bdk-new.key bdkpackagers.key bdkpackagers.sec bdkpass bin blogdrake.net bookmarks.html BRF Descargas Desktop diagrana.pdf discover-missing Documentos download Dragon Quest: Dai no Daibouken - Bravest Full OP Sub Español [2MZON1ev9DE].mkv ejemplo añadir_archivo1.spec ejemplo añadir_archivo2.spec google-chrome.spec html i18n.pdf Imágenes index.php kernel-backport kernel-cves.enc kernel-cves.txt lqshell-stylesheet.css mageia-advisories MANOLO MUÑOZ VS ALBERTO VAZQUEZ MANO A MANO 24 EXITAZOS RANCHEROS CON MARIACHI.opus MEGA megasync-10.tar.gz #*message*-20260914-112747# mgaadv-error.txt mgarepo mirrorbdk mock Música origen.rss out.pnm PDF pdfbooklet-3.1.2-all_64.tar.gz Plantillas Precure News - Star Detective PreCure! OP (Movie Footage Edition) [2099120870992310272].mp4 Proyectos qatest qa-testing qphotorec.desktop qphotorec.log reinstall.sh repodkfix.sh repositorio rpm rss Sailor Moon Cosmos AMV - Makenai (Sailor Star Song).mp4 sshrc style.html Taylor Swift, les coulisses du succès [120464-000-A].mp4 test.jpg tmp update-bdkkey.sh urpm-ng-distupgrade-orphans vdhcoapp-2.0.19 Ventoy Backup Vídeos VirtualBox VMs xen test xen-mga#33082 YAML-LibYAML-Test-dir zekemx Fix SSRF filter bypass via various forms of nip.io/sslip.io hostnames evading is_local_url() check, reported by Milan Hoppe acta2.jpg acta.jpg advisories avatar.jpg avatar.png bdk-key.bkup bdk-mga9.txt bdk-new.key bdkpackagers.key bdkpackagers.sec bdkpass bin blogdrake.net bookmarks.html BRF Descargas Desktop diagrana.pdf discover-missing Documentos download Dragon Quest: Dai no Daibouken - Bravest Full OP Sub Español [2MZON1ev9DE].mkv ejemplo añadir_archivo1.spec ejemplo añadir_archivo2.spec google-chrome.spec html i18n.pdf Imágenes index.php kernel-backport kernel-cves.enc kernel-cves.txt lqshell-stylesheet.css mageia-advisories MANOLO MUÑOZ VS ALBERTO VAZQUEZ MANO A MANO 24 EXITAZOS RANCHEROS CON MARIACHI.opus MEGA megasync-10.tar.gz #*message*-20260914-112747# mgaadv-error.txt mgarepo mirrorbdk mock Música origen.rss out.pnm PDF pdfbooklet-3.1.2-all_64.tar.gz Plantillas Precure News - Star Detective PreCure! OP (Movie Footage Edition) [2099120870992310272].mp4 Proyectos qatest qa-testing qphotorec.desktop qphotorec.log reinstall.sh repodkfix.sh repositorio rpm rss Sailor Moon Cosmos AMV - Makenai (Sailor Star Song).mp4 sshrc style.html Taylor Swift, les coulisses du succès [120464-000-A].mp4 test.jpg tmp update-bdkkey.sh urpm-ng-distupgrade-orphans vdhcoapp-2.0.19 Ventoy Backup Vídeos VirtualBox VMs xen test xen-mga#33082 YAML-LibYAML-Test-dir zekemx Fix remote content blocking bypass via unclosed url() in a FuncIRI attribute, reported by Milan Hoppe acta2.jpg acta.jpg advisories avatar.jpg avatar.png bdk-key.bkup bdk-mga9.txt bdk-new.key bdkpackagers.key bdkpackagers.sec bdkpass bin blogdrake.net bookmarks.html BRF Descargas Desktop diagrana.pdf discover-missing Documentos download Dragon Quest: Dai no Daibouken - Bravest Full OP Sub Español [2MZON1ev9DE].mkv ejemplo añadir_archivo1.spec ejemplo añadir_archivo2.spec google-chrome.spec html i18n.pdf Imágenes index.php kernel-backport kernel-cves.enc kernel-cves.txt lqshell-stylesheet.css mageia-advisories MANOLO MUÑOZ VS ALBERTO VAZQUEZ MANO A MANO 24 EXITAZOS RANCHEROS CON MARIACHI.opus MEGA megasync-10.tar.gz #*message*-20260914-112747# mgaadv-error.txt mgarepo mirrorbdk mock Música origen.rss out.pnm PDF pdfbooklet-3.1.2-all_64.tar.gz Plantillas Precure News - Star Detective PreCure! OP (Movie Footage Edition) [2099120870992310272].mp4 Proyectos qatest qa-testing qphotorec.desktop qphotorec.log reinstall.sh repodkfix.sh repositorio rpm rss Sailor Moon Cosmos AMV - Makenai (Sailor Star Song).mp4 sshrc style.html Taylor Swift, les coulisses du succès [120464-000-A].mp4 test.jpg tmp update-bdkkey.sh urpm-ng-distupgrade-orphans vdhcoapp-2.0.19 Ventoy Backup Vídeos VirtualBox VMs xen test xen-mga#33082 YAML-LibYAML-Test-dir zekemx Fix LDAP filter injection via unescaped %u/%fu/%d substitution into the `search_filter`, reported by Milan Hoppe acta2.jpg acta.jpg advisories avatar.jpg avatar.png bdk-key.bkup bdk-mga9.txt bdk-new.key bdkpackagers.key bdkpackagers.sec bdkpass bin blogdrake.net bookmarks.html BRF Descargas Desktop diagrana.pdf discover-missing Documentos download Dragon Quest: Dai no Daibouken - Bravest Full OP Sub Español [2MZON1ev9DE].mkv ejemplo añadir_archivo1.spec ejemplo añadir_archivo2.spec google-chrome.spec html i18n.pdf Imágenes index.php kernel-backport kernel-cves.enc kernel-cves.txt lqshell-stylesheet.css mageia-advisories MANOLO MUÑOZ VS ALBERTO VAZQUEZ MANO A MANO 24 EXITAZOS RANCHEROS CON MARIACHI.opus MEGA megasync-10.tar.gz #*message*-20260914-112747# mgaadv-error.txt mgarepo mirrorbdk mock Música origen.rss out.pnm PDF pdfbooklet-3.1.2-all_64.tar.gz Plantillas Precure News - Star Detective PreCure! OP (Movie Footage Edition) [2099120870992310272].mp4 Proyectos qatest qa-testing qphotorec.desktop qphotorec.log reinstall.sh repodkfix.sh repositorio rpm rss Sailor Moon Cosmos AMV - Makenai (Sailor Star Song).mp4 sshrc style.html Taylor Swift, les coulisses du succès [120464-000-A].mp4 test.jpg tmp update-bdkkey.sh urpm-ng-distupgrade-orphans vdhcoapp-2.0.19 Ventoy Backup Vídeos VirtualBox VMs xen test xen-mga#33082 YAML-LibYAML-Test-dir zekemx Fix arbitrary Sieve script injection via a filter rule name bypassing `managesieve_disabled_actions`, reported by Milan Hoppe acta2.jpg acta.jpg advisories avatar.jpg avatar.png bdk-key.bkup bdk-mga9.txt bdk-new.key bdkpackagers.key bdkpackagers.sec bdkpass bin blogdrake.net bookmarks.html BRF Descargas Desktop diagrana.pdf discover-missing Documentos download Dragon Quest: Dai no Daibouken - Bravest Full OP Sub Español [2MZON1ev9DE].mkv ejemplo añadir_archivo1.spec ejemplo añadir_archivo2.spec google-chrome.spec html i18n.pdf Imágenes index.php kernel-backport kernel-cves.enc kernel-cves.txt lqshell-stylesheet.css mageia-advisories MANOLO MUÑOZ VS ALBERTO VAZQUEZ MANO A MANO 24 EXITAZOS RANCHEROS CON MARIACHI.opus MEGA megasync-10.tar.gz #*message*-20260914-112747# mgaadv-error.txt mgarepo mirrorbdk mock Música origen.rss out.pnm PDF pdfbooklet-3.1.2-all_64.tar.gz Plantillas Precure News - Star Detective PreCure! OP (Movie Footage Edition) [2099120870992310272].mp4 Proyectos qatest qa-testing qphotorec.desktop qphotorec.log reinstall.sh repodkfix.sh repositorio rpm rss Sailor Moon Cosmos AMV - Makenai (Sailor Star Song).mp4 sshrc style.html Taylor Swift, les coulisses du succès [120464-000-A].mp4 test.jpg tmp update-bdkkey.sh urpm-ng-distupgrade-orphans vdhcoapp-2.0.19 Ventoy Backup Vídeos VirtualBox VMs xen test xen-mga#33082 YAML-LibYAML-Test-dir zekemx Fix RCE via cmd_learn driver of markasjunk plugin, reported by nept1337 acta2.jpg acta.jpg advisories avatar.jpg avatar.png bdk-key.bkup bdk-mga9.txt bdk-new.key bdkpackagers.key bdkpackagers.sec bdkpass bin blogdrake.net bookmarks.html BRF Descargas Desktop diagrana.pdf discover-missing Documentos download Dragon Quest: Dai no Daibouken - Bravest Full OP Sub Español [2MZON1ev9DE].mkv ejemplo añadir_archivo1.spec ejemplo añadir_archivo2.spec google-chrome.spec html i18n.pdf Imágenes index.php kernel-backport kernel-cves.enc kernel-cves.txt lqshell-stylesheet.css mageia-advisories MANOLO MUÑOZ VS ALBERTO VAZQUEZ MANO A MANO 24 EXITAZOS RANCHEROS CON MARIACHI.opus MEGA megasync-10.tar.gz #*message*-20260914-112747# mgaadv-error.txt mgarepo mirrorbdk mock Música origen.rss out.pnm PDF pdfbooklet-3.1.2-all_64.tar.gz Plantillas Precure News - Star Detective PreCure! OP (Movie Footage Edition) [2099120870992310272].mp4 Proyectos qatest qa-testing qphotorec.desktop qphotorec.log reinstall.sh repodkfix.sh repositorio rpm rss Sailor Moon Cosmos AMV - Makenai (Sailor Star Song).mp4 sshrc style.html Taylor Swift, les coulisses du succès [120464-000-A].mp4 test.jpg tmp update-bdkkey.sh urpm-ng-distupgrade-orphans vdhcoapp-2.0.19 Ventoy Backup Vídeos VirtualBox VMs xen test xen-mga#33082 YAML-LibYAML-Test-dir zekemx Fix IMAP command injection via mail search and LITERAL+ byte-count desynchronization, reported by Zach Hanley of Horizon3.ai acta2.jpg acta.jpg advisories avatar.jpg avatar.png bdk-key.bkup bdk-mga9.txt bdk-new.key bdkpackagers.key bdkpackagers.sec bdkpass bin blogdrake.net bookmarks.html BRF Descargas Desktop diagrana.pdf discover-missing Documentos download Dragon Quest: Dai no Daibouken - Bravest Full OP Sub Español [2MZON1ev9DE].mkv ejemplo añadir_archivo1.spec ejemplo añadir_archivo2.spec google-chrome.spec html i18n.pdf Imágenes index.php kernel-backport kernel-cves.enc kernel-cves.txt lqshell-stylesheet.css mageia-advisories MANOLO MUÑOZ VS ALBERTO VAZQUEZ MANO A MANO 24 EXITAZOS RANCHEROS CON MARIACHI.opus MEGA megasync-10.tar.gz #*message*-20260914-112747# mgaadv-error.txt mgarepo mirrorbdk mock Música origen.rss out.pnm PDF pdfbooklet-3.1.2-all_64.tar.gz Plantillas Precure News - Star Detective PreCure! OP (Movie Footage Edition) [2099120870992310272].mp4 Proyectos qatest qa-testing qphotorec.desktop qphotorec.log reinstall.sh repodkfix.sh repositorio rpm rss Sailor Moon Cosmos AMV - Makenai (Sailor Star Song).mp4 sshrc style.html Taylor Swift, les coulisses du succès [120464-000-A].mp4 test.jpg tmp update-bdkkey.sh urpm-ng-distupgrade-orphans vdhcoapp-2.0.19 Ventoy Backup Vídeos VirtualBox VMs xen test xen-mga#33082 YAML-LibYAML-Test-dir zekemx Fix password’s modoboa driver leak of an authentication token to a user-controlled host, reported by [meifukun](https://github.com/meifukun) acta2.jpg acta.jpg advisories avatar.jpg avatar.png bdk-key.bkup bdk-mga9.txt bdk-new.key bdkpackagers.key bdkpackagers.sec bdkpass bin blogdrake.net bookmarks.html BRF Descargas Desktop diagrana.pdf discover-missing Documentos download Dragon Quest: Dai no Daibouken - Bravest Full OP Sub Español [2MZON1ev9DE].mkv ejemplo añadir_archivo1.spec ejemplo añadir_archivo2.spec google-chrome.spec html i18n.pdf Imágenes index.php kernel-backport kernel-cves.enc kernel-cves.txt lqshell-stylesheet.css mageia-advisories MANOLO MUÑOZ VS ALBERTO VAZQUEZ MANO A MANO 24 EXITAZOS RANCHEROS CON MARIACHI.opus MEGA megasync-10.tar.gz #*message*-20260914-112747# mgaadv-error.txt mgarepo mirrorbdk mock Música origen.rss out.pnm PDF pdfbooklet-3.1.2-all_64.tar.gz Plantillas Precure News - Star Detective PreCure! OP (Movie Footage Edition) [2099120870992310272].mp4 Proyectos qatest qa-testing qphotorec.desktop qphotorec.log reinstall.sh repodkfix.sh repositorio rpm rss Sailor Moon Cosmos AMV - Makenai (Sailor Star Song).mp4 sshrc style.html Taylor Swift, les coulisses du succès [120464-000-A].mp4 test.jpg tmp update-bdkkey.sh urpm-ng-distupgrade-orphans vdhcoapp-2.0.19 Ventoy Backup Vídeos VirtualBox VMs xen test xen-mga#33082 YAML-LibYAML-Test-dir zekemx Fix stored XSS in “Add to address book” action, reported by Paulos Yibelo from pwn.ai acta2.jpg acta.jpg advisories avatar.jpg avatar.png bdk-key.bkup bdk-mga9.txt bdk-new.key bdkpackagers.key bdkpackagers.sec bdkpass bin blogdrake.net bookmarks.html BRF Descargas Desktop diagrana.pdf discover-missing Documentos download Dragon Quest: Dai no Daibouken - Bravest Full OP Sub Español [2MZON1ev9DE].mkv ejemplo añadir_archivo1.spec ejemplo añadir_archivo2.spec google-chrome.spec html i18n.pdf Imágenes index.php kernel-backport kernel-cves.enc kernel-cves.txt lqshell-stylesheet.css mageia-advisories MANOLO MUÑOZ VS ALBERTO VAZQUEZ MANO A MANO 24 EXITAZOS RANCHEROS CON MARIACHI.opus MEGA megasync-10.tar.gz #*message*-20260914-112747# mgaadv-error.txt mgarepo mirrorbdk mock Música origen.rss out.pnm PDF pdfbooklet-3.1.2-all_64.tar.gz Plantillas Precure News - Star Detective PreCure! OP (Movie Footage Edition) [2099120870992310272].mp4 Proyectos qatest qa-testing qphotorec.desktop qphotorec.log reinstall.sh repodkfix.sh repositorio rpm rss Sailor Moon Cosmos AMV - Makenai (Sailor Star Song).mp4 sshrc style.html Taylor Swift, les coulisses du succès [120464-000-A].mp4 test.jpg tmp update-bdkkey.sh urpm-ng-distupgrade-orphans vdhcoapp-2.0.19 Ventoy Backup Vídeos VirtualBox VMs xen test xen-mga#33082 YAML-LibYAML-Test-dir zekemx Fix HTML/CSS sanitization bypass via SVG animate `by` attribute, reported by vectrain References
SRPMS 9/core
  • roundcubemail-1.6.18-1.mga9

MGASA-2026-0357 - Updated varnish packages fix security vulnerabilities

Mageia Security - 1 Septiembre, 2026 - 04:06
Publication date: 01 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-34475 , CVE-2026-50052 Description
The updated packages fix security vulnerabilities: Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle URLs with a path of / for HTTP/1.1, potentially leading to cache poisoning or authentication bypass. (CVE-2026-34475) In Vinyl Cache before 9.0.1 and Varnish Cache before 9.0.3, a deficiency in HTTP/2 request parsing can be exploited to launch a backend request desync attack (request smuggling), which in turn can be used for cache poisoning, authentication bypass, or possibly even information disclosure and manipulation. The attack vector only exists if HTTP/2 support is enabled by setting the feature parameter to contain +http2. HTTP/2 support is disabled by default. (CVE-2026-50052) References
SRPMS 10/core
  • varnish-8.0.2-2.mga10
9/core
  • varnish-7.7.3-1.1.mga9

MGASA-2026-0356 - Updated perl-Mojolicious packages fix a security vulnerability

Mageia Security - 1 Septiembre, 2026 - 04:06
Publication date: 01 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-15747 Description
Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session CSRF token to a BREACH compression oracle. References
SRPMS 10/core
  • perl-Mojolicious-9.480.0-1.1.mga10
9/core
  • perl-Mojolicious-9.480.0-1.1.mga9

MGASA-2026-0355 - Updated vim packages fix security vulnerabilities

Mageia Security - 1 Septiembre, 2026 - 04:06
Publication date: 01 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-73077 , CVE-2026-73078 , CVE-2026-73074 , CVE-2026-73070 , CVE-2026-73075 , CVE-2026-73071 , CVE-2026-73073 , CVE-2026-73072 , CVE-2026-73076 Description
Arbitrary Code Execution via Shell Keyword Lookup in Vim < 9.2.0839. (CVE-2026-73077) Arbitrary Code Execution via Netrw Menu Construction in Vim < 9.2.0840. (CVE-2026-73078) Heap Buffer Overflow in Text Property Handling in Vim < 9.2.0841. (CVE-2026-73074) Stack Buffer Overflow in the Vim Socket Server in Vim < 9.2.0842. (CVE-2026-73070) Out-of-bounds Access in Popup Opacity Handling in Vim >= 9.2.0469 && Vim < 9.2.0843. (CVE-2026-73075) Use-after-free in JSON Decoding in Vim >= 9.2.0511 && Vim < 9.2.0844. (CVE-2026-73071) Arbitrary Ex Command Execution in C Omni-Completion in Vim < 9.2.0845. (CVE-2026-73073) Heap Buffer Overflow when Loading a Spell File in Vim < 9.2.0846. (CVE-2026-73072) Arbitrary Command Execution via Malicious `.VimballRecord` Entry Replay in `vimball.vim`. (CVE-2026-73076) References
SRPMS 10/core
  • vim-9.2.1011-2.mga10
9/core
  • vim-9.2.1011-2.mga9

MGASA-2026-0354 - Updated redis packages fix a security vulnerability

Mageia Security - 31 Agosto, 2026 - 20:40
Publication date: 31 Aug 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-62356 Description
The updated package fixes security vulnerabilities, including: Miscalculated buffer size in CMSketch RDB loading may lead to heap OOB write. (CVE-2026-62356) References
SRPMS 10/core
  • redis-8.6.6-1.mga10
9/core
  • redis-7.2.16-1.mga9

MGASA-2026-0353 - Updated openssl packages fix security vulnerabilities

Mageia Security - 31 Agosto, 2026 - 20:40
Publication date: 31 Aug 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-14456 , CVE-2026-18798 , CVE-2026-63072 , CVE-2026-63076 , CVE-2026-14457 , CVE-2026-54874 , CVE-2026-63073 , CVE-2026-63074 , CVE-2026-63075 , CVE-2026-75803 Description
Unbounded Memory Growth in QUIC Server Incoming Channel Queue. (CVE-2026-14456) QUIC Server May Trigger Double Free When Processing INITIAL Packet. (CVE-2026-18798) Heap Buffer Overflow in CMS Key Unwrapping. (CVE-2026-63072) Invalid Pointer Dereference in CMP Server via Crafted protectionAlg. (CVE-2026-63076) RPK Server Signature Algorithm Selection Can Dereference a Missing Certificate. (CVE-2026-14457) Excessive Memory Use Buffering DTLS Records for a Future Epoch. (CVE-2026-54874) Untrusted Sender DN Used as Format String in CMP Response Validation. (CVE-2026-63073) CMP Indefinite Cache Growth of ExtraCerts. (CVE-2026-63074) QUIC ACK-only Packet Retention Can Cause Memory Exhaustion. (CVE-2026-63075) References
SRPMS 10/core
  • openssl-3.5.8-1.mga10
9/core
  • openssl-3.0.22-1.mga9

MGASA-2026-0352 - Updated expat & mingw-expat packages fix security vulnerabilities

Mageia Security - 31 Agosto, 2026 - 20:40
Publication date: 31 Aug 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-50219 , CVE-2026-56131 , CVE-2026-56132 , CVE-2026-56403 , CVE-2026-56404 , CVE-2026-56405 , CVE-2026-56406 , CVE-2026-56407 , CVE-2026-56408 , CVE-2026-56409 , CVE-2026-56410 , CVE-2026-56411 , CVE-2026-56412 , CVE-2026-72522 Description
Missing control flow integrity checks. (CVE-2026-50219) Missing control flow integrity checks. (CVE-2026-56131) Out-of-bounds write. (CVE-2026-56132) Integer overflow. (CVE-2026-56403) Integer overflow. (CVE-2026-56404) Integer overflow. (CVE-2026-56405) Integer overflow. (CVE-2026-56406) Integer overflow. (CVE-2026-56407) Integer overflow. (CVE-2026-56408) Integer overflow. (CVE-2026-56409) Integer overflow. (CVE-2026-56410) Integer overflow. (CVE-2026-56411) Missing control flow integrity checks. (CVE-2026-56412) References
SRPMS 10/core
  • expat-2.8.3-1.mga10
  • mingw-expat-2.8.3-1.mga10

MGASA-2026-0351 - Updated perl-Catalyst-Plugin-Authentication packages fix a security vulnerability

Mageia Security - 31 Agosto, 2026 - 20:40
Publication date: 31 Aug 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2009-10007 Description
Catalyst::Plugin::Authentication versions before 0.10_027 for Perl are susceptible to session fixation attacks. (CVE-2009-10007) References
SRPMS 10/core
  • perl-Catalyst-Plugin-Authentication-0.100.280-1.mga10
9/core
  • perl-Catalyst-Plugin-Authentication-0.100.230-12.2.mga9

MGASA-2026-0350 - Updated perl-Plack packages fix a security vulnerability

Mageia Security - 31 Agosto, 2026 - 20:40
Publication date: 31 Aug 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-7381 Description
Plack::Middleware::XSendfile versions through 1.0053 for Perl can allow client-controlled path rewriting. References
SRPMS 10/core
  • perl-Plack-1.5.400-1.mga10
9/core
  • perl-Plack-1.5.400-1.mga9

MGASA-2026-0349 - Updated python-hpack packages fix a security vulnerability

Mageia Security - 31 Agosto, 2026 - 20:40
Publication date: 31 Aug 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-59980 Description
An issue was found in the python-hyper/hpack library, most commonly used as a downstream dependency of the python-hyper/h2 library (an HTTP/2 client and server implementation). Unbounded variable integer decoding can cause run-away computation on malformed input leading to O(n^2) runtime, effectively blocking further processing with large enough unsanitized input. A fix python-hyper/hpack v4.2.0 restricts variable integer decoding to uint32 to prevent run-away computation. References
SRPMS 10/core
  • python-hpack-4.2.0-1.mga10

MGASA-2026-0348 - Updated clamav packages fix security vulnerabilities

Mageia Security - 31 Agosto, 2026 - 20:40
Publication date: 31 Aug 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-20345 , CVE-2026-20339 , CVE-2026-20346 , CVE-2026-20347 , CVE-2026-20348 Description
An indexing error while converting GPT partition names that could read or write beyond a stack-allocated partition entry. (CVE-2026-20345) An integer overflow in the PESpin unpacker that could allocate an undersized buffer and then write beyond it while rebuilding a PE file. (CVE-2026-20339) An integer underflow in the PDF parser that could cause a crash while reading a malformed hex string. (CVE-2026-20346) Undefined behavior and integer overflow in the Mach-O parser that could cause a crash while scanning a malformed Mach-O file. (CVE-2026-20347) XAR parser size handling that could request an excessive allocation or exceed scan limits while decompressing a malformed table of contents. (CVE-2026-20348) References
SRPMS 10/core
  • clamav-1.4.6-1.mga10

MGAA-2026-0117 - Updated mga-advisor package fixes bugs

Mageia Security - 31 Agosto, 2026 - 20:40
Publication date: 31 Aug 2026
Type: bugfix
Affected Mageia releases : 10
Description
The updated package brings improvement to our graphic tool to make advisories, the changes include but are not limited to: Ver. 6 - Choose only the Mageia versions affected by a bug - Dedupe the package names before checking package info - Allow multiple CVEs or references to be added at once - Improve duplicate CVE warnings - Expand bracket expressions in the list of CVEs - Retrieve package info in parallel for speed - Open a URL in the references by double-clicking it - Join package names in the subject with & or , - Improve the package name regex to solve problems with dots in names - Use singular form in subject with only one package or vuln - Add a status message for each package being retrieved - Fix search in release 10 for source packages Ver. 5 - Run more data checks after loading from Bugzilla - Open a URL in the references by double-clicking it - Join package names in the subject with & or , - Improve the package name regex to solve problems with dots in names - Internal refactoring & minor changes - Use singular form in subject with only one package or vuln - Add a status message for each package being retrieved - Add a timeout when reading from Bugzilla - Display the version number on-screen Ver. 4 - Increase widths of text fields in dialogs - Fix search in release 10 for source packages Ver. 3 - Add syntax checks on package name - Add whitespace checks on subject - Use slash when displaying sources - Drop mga8 as a source and replace with mga10 - Add checks for invalid CVE IDs and URL references - Send a custom User-Agent with Bugzilla requests - Internal cleanups References
SRPMS 10/core
  • mga-advisor-6-1.mga10
Feed