Lector de Feeds
MGASA-2026-0281 - Updated python-nltk packages fix security vulnerability
Publication date: 20 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-54293 Description URL-Encoded Path Traversal in nltk.data.load() Allows Arbitrary Local File Read. (CVE-2026-54293) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-54293 Description URL-Encoded Path Traversal in nltk.data.load() Allows Arbitrary Local File Read. (CVE-2026-54293) References
- https://bugs.mageia.org/show_bug.cgi?id=35762
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/WMWF7SLMCGEL35KSK5ERA7U5CKTU5Z57/
- https://github.com/nltk/nltk/security/advisories/GHSA-p4gq-832x-fm9v
- https://www.cve.org/CVERecord?id=CVE-2026-54293
- python-nltk-3.9.4-1.1.mga10
- python-nltk-3.9.4-1.1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0280 - Updated nilfs-utils packages fix security vulnerability
Publication date: 20 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-55392 Description Undefined Behavior and Out-of-Memory via Unvalidated s_log_block_size. (CVE-2026-55392) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-55392 Description Undefined Behavior and Out-of-Memory via Unvalidated s_log_block_size. (CVE-2026-55392) References
- https://bugs.mageia.org/show_bug.cgi?id=35759
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/547QU7QRINNSB7HMT4YKQIJSKLUMGGKV/
- https://github.com/nilfs-dev/nilfs-utils/issues/26
- https://www.cve.org/CVERecord?id=CVE-2026-55392
- nilfs-utils-2.2.11-3.1.mga10
- nilfs-utils-2.2.9-1.1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0279 - Updated nginx packages fix security vulnerabilities
Publication date: 20 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-42055 , CVE-2026-48142 Description ngx_http_proxy_v2_module and ngx_http_grpc_module vulnerability. (CVE-2026-42055) ngx_http_charset_module vulnerability. (CVE-2026-48142) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-42055 , CVE-2026-48142 Description ngx_http_proxy_v2_module and ngx_http_grpc_module vulnerability. (CVE-2026-42055) ngx_http_charset_module vulnerability. (CVE-2026-48142) References
- https://bugs.mageia.org/show_bug.cgi?id=35750
- https://ubuntu.com/security/notices/USN-8458-1
- https://my.f5.com/manage/s/article/K000161584
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WLAG3KT4JVKUFDRLDTUDAIB4KDUXBVGU/
- https://lists.debian.org/debian-security-announce/2026/msg00285.html
- https://www.cve.org/CVERecord?id=CVE-2026-42055
- https://www.cve.org/CVERecord?id=CVE-2026-48142
- nginx-1.30.3-1.mga10
- nginx-1.30.3-1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0278 - Updated sqlite3 packages fix security vulnerabilities
Publication date: 20 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-11822 , CVE-2026-11824 Description The updated packages fix security vulnerabilities: SQLite before 3.53.2 Memory Corruption in FTS5 Extension. (CVE-2026-11822) SQLite before 3.53.2 Heap Buffer Overflow via FTS5 fts5ChunkIterate. (CVE-2026-11824) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-11822 , CVE-2026-11824 Description The updated packages fix security vulnerabilities: SQLite before 3.53.2 Memory Corruption in FTS5 Extension. (CVE-2026-11822) SQLite before 3.53.2 Heap Buffer Overflow via FTS5 fts5ChunkIterate. (CVE-2026-11824) References
- https://bugs.mageia.org/show_bug.cgi?id=35740
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/WSARHTYMOLWR6EKE3FP43GM4U37WSA2O/
- https://ubuntu.com/security/notices/USN-8480-1
- https://www.cve.org/CVERecord?id=CVE-2026-11822
- https://www.cve.org/CVERecord?id=CVE-2026-11824
- sqlite3-3.51.3-1.1.mga10
- sqlite3-3.40.1-1.9.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0277 - Updated xmlstarlet package fixes a security vulnerability
Publication date: 20 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
Description The updated package fixes a security vulnerability: XML external entity vulnerability. References: https://lists.fedoraproject.org/archives/list/package-announce@lists.fed oraproject.org/message/KDR5XRMVBCDZ4HWDCGLKDVKGSCWACG33/ References
Type: security
Affected Mageia releases : 10 , 9
Description The updated package fixes a security vulnerability: XML external entity vulnerability. References: https://lists.fedoraproject.org/archives/list/package-announce@lists.fed oraproject.org/message/KDR5XRMVBCDZ4HWDCGLKDVKGSCWACG33/ References
- https://bugs.mageia.org/show_bug.cgi?id=35671
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KDR5XRMVBCDZ4HWDCGLKDVKGSCWACG33/
- xmlstarlet-1.6.1-12.1.mga10
- xmlstarlet-1.6.1-9.1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0276 - Updated golang packages fix security vulnerabilities
Publication date: 20 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-42504 , CVE-2026-42507 , CVE-2026-27145 , CVE-2026-39822 , CVE-2026-42505 Description The updated packages fix security vulnerabilities: mime: quadratic complexity in WordDecoder.DecodeHeader. (CVE-2026-42504) net/textproto: arbitrary input are included in errors without any escaping. (CVE-2026-42507) crypto/x509: split candidate hostname only once. (CVE-2026-27145) os: Root escape via symlink plus trailing slash. (CVE-2026-39822) crypto/tls: Encrypted Client Hello privacy leak. (CVE-2026-42505) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-42504 , CVE-2026-42507 , CVE-2026-27145 , CVE-2026-39822 , CVE-2026-42505 Description The updated packages fix security vulnerabilities: mime: quadratic complexity in WordDecoder.DecodeHeader. (CVE-2026-42504) net/textproto: arbitrary input are included in errors without any escaping. (CVE-2026-42507) crypto/x509: split candidate hostname only once. (CVE-2026-27145) os: Root escape via symlink plus trailing slash. (CVE-2026-39822) crypto/tls: Encrypted Client Hello privacy leak. (CVE-2026-42505) References
- https://bugs.mageia.org/show_bug.cgi?id=35624
- https://www.openwall.com/lists/oss-security/2026/06/03/2
- https://www.openwall.com/lists/oss-security/2026/07/08/10
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/PHOAHESABWDZPEWFOMKYQVZYR2MQH3RA/
- https://www.cve.org/CVERecord?id=CVE-2026-42504
- https://www.cve.org/CVERecord?id=CVE-2026-42507
- https://www.cve.org/CVERecord?id=CVE-2026-27145
- https://www.cve.org/CVERecord?id=CVE-2026-39822
- https://www.cve.org/CVERecord?id=CVE-2026-42505
- golang-1.25.12-1.mga10
- golang-1.25.12-1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0275 - Updated haveged package fixes a security vulnerability
Publication date: 20 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-41054 Description The updated package fixes a security vulnerability: Privilege escalation via command socket. (CVE-2026-41054) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-41054 Description The updated package fixes a security vulnerability: Privilege escalation via command socket. (CVE-2026-41054) References
- https://bugs.mageia.org/show_bug.cgi?id=35550
- https://www.openwall.com/lists/oss-security/2026/05/19/3
- https://www.cve.org/CVERecord?id=CVE-2026-41054
- haveged-1.9.21-2.mga10
- haveged-1.9.21-2.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0274 - Updated php packages fix a security vulnerability
Publication date: 20 Jul 2026
Type: security
Affected Mageia releases : 9
CVE: CVE-2026-14355 Description The updated php packages fix a security issue: Memory corruption (zend_mm_heap corrupted) in openssl_encrypt with AES-WRAP-PAD. (CVE-2026-14355) References
Type: security
Affected Mageia releases : 9
CVE: CVE-2026-14355 Description The updated php packages fix a security issue: Memory corruption (zend_mm_heap corrupted) in openssl_encrypt with AES-WRAP-PAD. (CVE-2026-14355) References
- https://bugs.mageia.org/show_bug.cgi?id=35807
- https://www.php.net/ChangeLog-8.php#8.2.32
- https://www.cve.org/CVERecord?id=CVE-2026-14355
- php-8.2.32-1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0273 - Updated libssh2 packages fix security vulnerabilities
Publication date: 20 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2025-15661 , CVE-2026-7598 , CVE-2026-55199 , CVE-2026-55200 , CVE-2026-58050 , CVE-2026-58051 Description The updated packages fix security vulnerabilities: Heap Buffer Over-read via sftp_symlink() in sftp.c. (CVE-2025-15661) libssh2 userauth.c userauth_password integer overflow. (CVE-2026-7598) Pre-Authentication DoS via SSH_MSG_EXT_INFO Handler. (CVE-2026-55199) Out-of-Bounds Write via Unchecked packet_length in transport.c. (CVE-2026-55200) Integer Overflow in publickey Subsystem Attribute Allocation. (CVE-2026-58050) Free of Uninitialized Pointer in publickey List Cleanup. (CVE-2026-58051) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2025-15661 , CVE-2026-7598 , CVE-2026-55199 , CVE-2026-55200 , CVE-2026-58050 , CVE-2026-58051 Description The updated packages fix security vulnerabilities: Heap Buffer Over-read via sftp_symlink() in sftp.c. (CVE-2025-15661) libssh2 userauth.c userauth_password integer overflow. (CVE-2026-7598) Pre-Authentication DoS via SSH_MSG_EXT_INFO Handler. (CVE-2026-55199) Out-of-Bounds Write via Unchecked packet_length in transport.c. (CVE-2026-55200) Integer Overflow in publickey Subsystem Attribute Allocation. (CVE-2026-58050) Free of Uninitialized Pointer in publickey List Cleanup. (CVE-2026-58051) References
- https://bugs.mageia.org/show_bug.cgi?id=35616
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NRU63FODXZBBO73NFWUI32A2A36ETDQZ/
- https://www.openwall.com/lists/oss-security/2026/06/23/10
- https://www.openwall.com/lists/oss-security/2026/06/23/11
- https://lists.debian.org/debian-security-announce/2026/msg00276.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZREI4LITT4U2ZXPEEVVNALFKPLXGLAFM/
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/SRBHQ76PA4ZHTWY5F4ESYPYF3G2NLGWI/
- https://ubuntu.com/security/notices/USN-8486-1
- https://ubuntu.com/security/notices/USN-8532-1
- https://www.cve.org/CVERecord?id=CVE-2025-15661
- https://www.cve.org/CVERecord?id=CVE-2026-7598
- https://www.cve.org/CVERecord?id=CVE-2026-55199
- https://www.cve.org/CVERecord?id=CVE-2026-55200
- https://www.cve.org/CVERecord?id=CVE-2026-58050
- https://www.cve.org/CVERecord?id=CVE-2026-58051
- libssh2-1.11.1-2.1.mga10
- libssh2-1.11.0-1.1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0272 - Updated perl-String-Util package fixes a security vulnerability
Publication date: 19 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-14895 Description The updated package fixes a security vulnerability: String::Util versions before 1.36 for Perl are susceptible to a regular expression denial of service. (CVE-2026-14895) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-14895 Description The updated package fixes a security vulnerability: String::Util versions before 1.36 for Perl are susceptible to a regular expression denial of service. (CVE-2026-14895) References
- https://bugs.mageia.org/show_bug.cgi?id=35858
- https://www.openwall.com/lists/oss-security/2026/07/07/18
- https://www.cve.org/CVERecord?id=CVE-2026-14895
- perl-String-Util-1.350.0-2.1.mga10
- perl-String-Util-1.340.0-1.1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0271 - Updated clamav packages fix security vulnerabilities
Publication date: 19 Jul 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-20213 , CVE-2026-20214 , CVE-2026-20215 , CVE-2026-20216 , CVE-2026-20217 , CVE-2026-20243 , CVE-2026-20244 Description The updated packages fix security vulnerabilities: PE File Format Processing Out-of-Bounds Memory Corruption Vulnerability. (CVE-2026-20213) FSG File Format Processing Out-of-Bounds Memory Corruption Vulnerability. (CVE-2026-20214) 7Zip File Format Processing Out-of-Bounds Memory Corruption Vulnerability. (CVE-2026-20215) InstallShield File Format Processing Resource Exhaustion Vulnerability. (CVE-2026-20216) PESpin File Format Processing Out-of-Bounds Memory Corruption Vulnerability. (CVE-2026-20217) ALZ Archive Processing Denial of Service Vulnerability. (CVE-2026-20243) DMG File Processing Denial of Service Vulnerability. (CVE-2026-20244) References
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-20213 , CVE-2026-20214 , CVE-2026-20215 , CVE-2026-20216 , CVE-2026-20217 , CVE-2026-20243 , CVE-2026-20244 Description The updated packages fix security vulnerabilities: PE File Format Processing Out-of-Bounds Memory Corruption Vulnerability. (CVE-2026-20213) FSG File Format Processing Out-of-Bounds Memory Corruption Vulnerability. (CVE-2026-20214) 7Zip File Format Processing Out-of-Bounds Memory Corruption Vulnerability. (CVE-2026-20215) InstallShield File Format Processing Resource Exhaustion Vulnerability. (CVE-2026-20216) PESpin File Format Processing Out-of-Bounds Memory Corruption Vulnerability. (CVE-2026-20217) ALZ Archive Processing Denial of Service Vulnerability. (CVE-2026-20243) DMG File Processing Denial of Service Vulnerability. (CVE-2026-20244) References
- https://bugs.mageia.org/show_bug.cgi?id=35841
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/N4HZVOZRQX4MIQVALYKDCGBZUHHVH4QN/
- https://github.com/Cisco-Talos/clamav/releases/tag/clamav-1.4.5
- https://www.cve.org/CVERecord?id=CVE-2026-20213
- https://www.cve.org/CVERecord?id=CVE-2026-20214
- https://www.cve.org/CVERecord?id=CVE-2026-20215
- https://www.cve.org/CVERecord?id=CVE-2026-20216
- https://www.cve.org/CVERecord?id=CVE-2026-20217
- https://www.cve.org/CVERecord?id=CVE-2026-20243
- https://www.cve.org/CVERecord?id=CVE-2026-20244
- clamav-1.4.5-1.mga10
Categorías: Actualizaciones de Seguridad
MGASA-2026-0270 - Updated erlang packages fix a security vulnerability
Publication date: 19 Jul 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-48855 Description The updated packages fix a security vulnerability: SFTP READLINK response leaks absolute backend filesystem path when root is configured. (CVE-2026-48855) References
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-48855 Description The updated packages fix a security vulnerability: SFTP READLINK response leaks absolute backend filesystem path when root is configured. (CVE-2026-48855) References
- https://bugs.mageia.org/show_bug.cgi?id=35839
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/O2CL6CSAYWT3KK6GLRNIWD7YDNMWHJ4N/
- https://github.com/erlang/otp/security/advisories/GHSA-pv7g-pjrq-x2fh
- https://cna.erlef.org/cves/CVE-2026-48855.html
- https://osv.dev/vulnerability/EEF-CVE-2026-48855
- https://www.cve.org/CVERecord?id=CVE-2026-48855
- erlang-27.3.4.13-1.mga10
Categorías: Actualizaciones de Seguridad
MGASA-2026-0269 - Updated perl-Mojolicious package fixes a security vulnerability
Publication date: 19 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-14803 Description The updated package fixes a security vulnerability: Mojo::JSON versions before 9.47 for Perl allow memory exhaustion via unbounded recursion in the pure-Perl decoder. (CVE-2026-14803) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-14803 Description The updated package fixes a security vulnerability: Mojo::JSON versions before 9.47 for Perl allow memory exhaustion via unbounded recursion in the pure-Perl decoder. (CVE-2026-14803) References
- https://bugs.mageia.org/show_bug.cgi?id=35835
- https://www.openwall.com/lists/oss-security/2026/07/06/2
- https://metacpan.org/release/SRI/Mojolicious-9.47/changes
- https://www.cve.org/CVERecord?id=CVE-2026-14803
- perl-Mojolicious-9.420.0-1.1.mga10
- perl-Mojolicious-9.310.0-1.1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0268 - Updated nmap packages fix a security vulnerability
Publication date: 19 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-58058 Description The updated packages fix a security vulnerability: Integer Underflow in IPv6 Extension Header Parsing. (CVE-2026-58058) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-58058 Description The updated packages fix a security vulnerability: Integer Underflow in IPv6 Extension Header Parsing. (CVE-2026-58058) References
- https://bugs.mageia.org/show_bug.cgi?id=35812
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MIIROUN7QWWO22LUS5B4KPZ4DNYFQYJZ/
- https://github.com/bikini/exploitarium/tree/main/nmap-ipv6-extlen-wrap-poc
- https://www.cve.org/CVERecord?id=CVE-2026-58058
- nmap-7.98-1.1.mga10
- nmap-7.95-1.1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0267 - Updated perl-CSS-Minifier-XS package fixes a security vulnerability
Publication date: 19 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-13593 Description The updated package fixes a security vulnerability: CSS::Minifier::XS versions before 0.14 for Perl have a memory leak when the entire document is minified away. (CVE-2026-13593) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-13593 Description The updated package fixes a security vulnerability: CSS::Minifier::XS versions before 0.14 for Perl have a memory leak when the entire document is minified away. (CVE-2026-13593) References
- https://bugs.mageia.org/show_bug.cgi?id=35781
- https://www.openwall.com/lists/oss-security/2026/06/29/18
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/3PEXBYM5REIQMMQ2BZA2J2AXW7M4U673/
- https://www.cve.org/CVERecord?id=CVE-2026-13593
- perl-CSS-Minifier-XS-0.150.0-1.mga10
- perl-CSS-Minifier-XS-0.150.0-1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0266 - Updated perl-Bytes-Random-Secure package fixes a security vulnerability
Publication date: 19 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-11625 Description The updated package fixes a security vulnerability: Bytes::Random::Secure versions through 0.29 for Perl share internal state across forked processes. (CVE-2026-11625) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-11625 Description The updated package fixes a security vulnerability: Bytes::Random::Secure versions through 0.29 for Perl share internal state across forked processes. (CVE-2026-11625) References
- https://bugs.mageia.org/show_bug.cgi?id=35767
- https://www.openwall.com/lists/oss-security/2026/06/26/5
- https://github.com/daoswald/Bytes-Random-Secure/issues/3
- https://www.cve.org/CVERecord?id=CVE-2026-11625
- perl-Bytes-Random-Secure-0.290.0-7.1.mga10
- perl-Bytes-Random-Secure-0.290.0-6.1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0265 - Updated rsync package fixes security vulnerabilities
Publication date: 18 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-29518 , CVE-2026-43617 , CVE-2026-43618 , CVE-2026-43619 , CVE-2026-43620 , CVE-2026-45232 Description The updated package fixes security vulnerabilities: Rsync < 3.4.3 TOCTOU Race Condition Allows Symlink-Based Arbitrary File Write. (CVE-2026-29518) Rsync < 3.4.3 Authorization Bypass via Hostname Resolution. (CVE-2026-43617) Rsync < 3.4.3 Integer Overflow Information Disclosure. (CVE-2026-43618) Rsync < 3.4.3 Symlink Race Condition via Path-Based Syscalls. (CVE-2026-43619) Rsync < 3.4.3 Out-of-Bounds Array Read via recv_files(). (CVE-2026-43620) Rsync < 3.4.3 Off-by-One Stack Write via HTTP Proxy. (CVE-2026-45232) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-29518 , CVE-2026-43617 , CVE-2026-43618 , CVE-2026-43619 , CVE-2026-43620 , CVE-2026-45232 Description The updated package fixes security vulnerabilities: Rsync < 3.4.3 TOCTOU Race Condition Allows Symlink-Based Arbitrary File Write. (CVE-2026-29518) Rsync < 3.4.3 Authorization Bypass via Hostname Resolution. (CVE-2026-43617) Rsync < 3.4.3 Integer Overflow Information Disclosure. (CVE-2026-43618) Rsync < 3.4.3 Symlink Race Condition via Path-Based Syscalls. (CVE-2026-43619) Rsync < 3.4.3 Out-of-Bounds Array Read via recv_files(). (CVE-2026-43620) Rsync < 3.4.3 Off-by-One Stack Write via HTTP Proxy. (CVE-2026-45232) References
- https://bugs.mageia.org/show_bug.cgi?id=35562
- https://www.openwall.com/lists/oss-security/2026/05/20/6
- https://lists.debian.org/debian-security-announce/2026/msg00193.html
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/FBOANNVT2JXHE24DJ2WIYE2BNCWRGT24/
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/4RPOIF6TVE233FKZN5TAC6XTNQ5WVFYL/
- https://www.openwall.com/lists/oss-security/2026/06/08/1
- https://ubuntu.com/security/notices/USN-8349-1
- https://ubuntu.com/security/notices/USN-8349-2
- https://www.cve.org/CVERecord?id=CVE-2026-29518
- https://www.cve.org/CVERecord?id=CVE-2026-43617
- https://www.cve.org/CVERecord?id=CVE-2026-43618
- https://www.cve.org/CVERecord?id=CVE-2026-43619
- https://www.cve.org/CVERecord?id=CVE-2026-43620
- https://www.cve.org/CVERecord?id=CVE-2026-45232
- rsync-3.4.1-4.1.mga10
- rsync-3.2.7-1.5.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0264 - Updated perl-HTML-Parser packages fix security vulnerability
Publication date: 18 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-8829 Description HTML::Entities versions before 3.84 for Perl read freed heap memory in _decode_entities. (CVE-2026-8829) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-8829 Description HTML::Entities versions before 3.84 for Perl read freed heap memory in _decode_entities. (CVE-2026-8829) References
- https://bugs.mageia.org/show_bug.cgi?id=35632
- https://www.openwall.com/lists/oss-security/2026/06/04/2
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/CNUNI2FWJG22SMHLLF6L6BGYNBH6YI52/
- https://www.cve.org/CVERecord?id=CVE-2026-8829
- perl-HTML-Parser-3.830.0-3.1.mga10
- perl-HTML-Parser-3.810.0-1.1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0263 - Updated perl-Config-IniFiles package fixes a security vulnerability
Publication date: 18 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-11527 Description The updated package fixes a security vulnerability: Config::IniFiles versions before 3.001000 for Perl allow OS command injection and file overwrite via a 2-arg open() of the -file argument in _make_filehandle. (CVE-2026-11527) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-11527 Description The updated package fixes a security vulnerability: Config::IniFiles versions before 3.001000 for Perl allow OS command injection and file overwrite via a 2-arg open() of the -file argument in _make_filehandle. (CVE-2026-11527) References
- https://bugs.mageia.org/show_bug.cgi?id=35701
- https://www.openwall.com/lists/oss-security/2026/06/14/5
- https://metacpan.org/release/SHLOMIF/Config-IniFiles-3.001000/changes
- https://ubuntu.com/security/notices/USN-8445-1
- https://lists.debian.org/debian-security-announce/2026/msg00265.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KNV5NUG6UF4JCFTI7P253PPUETZTA4HE/
- https://www.cve.org/CVERecord?id=CVE-2026-11527
- perl-Config-IniFiles-3.0.3-3.1.mga10
- perl-Config-IniFiles-3.0.3-2.1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0262 - Updated libidn packages fix security vulnerability
Publication date: 18 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-57053 Description GNU libidn before 1.44 is prone to out-of-bounds reads of uninitialized memory in the ToUnicode APIs because of mishandling in idna_to_unicode_internal. The affected code is not present in libidn2. (CVE-2026-57053) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-57053 Description GNU libidn before 1.44 is prone to out-of-bounds reads of uninitialized memory in the ToUnicode APIs because of mishandling in idna_to_unicode_internal. The affected code is not present in libidn2. (CVE-2026-57053) References
- https://bugs.mageia.org/show_bug.cgi?id=35726
- http://www.slackware.com/security/viewer.php?l=slackware-security&y=2026&m=slackware-security.355846
- https://lists.gnu.org/archive/html/help-libidn/2026-05/msg00000.html
- https://lists.gnu.org/archive/html/help-libidn/2025-06/msg00000.html
- https://ubuntu.com/security/notices/USN-8521-1
- https://www.cve.org/CVERecord?id=CVE-2026-57053
- libidn-1.43-2.1.mga10
- libidn-1.41-2.1.mga9
Categorías: Actualizaciones de Seguridad




