Lector de Feeds

MGAA-2026-0145 - Updated php8.5 & php8.4 packages fix bugs

Mageia Security - 2 Octubre, 2026 - 16:50
Publication date: 02 Oct 2026
Type: bugfix
Affected Mageia releases : 10
Description
Bug fix releases for php 8.4 and php 8.5 References
SRPMS 10/core
  • php8.5-8.5.11-1.mga10
  • php8.4-8.4.26-1.1.mga10

MGASA-2026-0467 - Updated python-tornado packages fix security vulnerabilities

Mageia Security - 2 Octubre, 2026 - 07:40
Publication date: 02 Oct 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-49853 , CVE-2026-49854 , CVE-2026-49855 Description
Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient Tornado has out-of-bounds memory access via C extension tornado AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb) References
SRPMS 10/core
  • python-tornado-6.5.10-1.1.mga10

MGASA-2026-0465 - Updated wireshark package fixes security vulnerabilities

Mageia Security - 2 Octubre, 2026 - 07:40
Publication date: 02 Oct 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-15163 , CVE-2026-15164 , CVE-2026-15165 , CVE-2026-15166 , CVE-2026-15167 , CVE-2026-15168 , CVE-2026-15169 , CVE-2026-15170 , CVE-2026-15171 , CVE-2026-15172 , CVE-2026-15173 , CVE-2026-15174 Description
Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark. (CVE-2026-15163) Heap-based Buffer Overflow in ciscodump. (CVE-2026-15164) Heap-based Buffer Overflow in Wireshark. (CVE-2026-15165) Stack-based Buffer Overflow in Wireshark. (CVE-2026-15166) Stack-based Buffer Overflow in Wireshark. (CVE-2026-15167) Use of Uninitialized Variable in Wireshark. (CVE-2026-15168) Heap-based Buffer Overflow in Wireshark. (CVE-2026-15169) Heap-based Buffer Overflow in Wireshark. (CVE-2026-15170) NULL Pointer Dereference in Wireshark. (CVE-2026-15171) Unchecked Input for Loop Condition in Wireshark. (CVE-2026-15172) Heap-based Buffer Overflow in Wireshark. (CVE-2026-15173) Heap-based Buffer Overflow in Wireshark. (CVE-2026-15174) References
SRPMS 10/core
  • wireshark-4.6.8-1.mga10

MGASA-2026-0463 - Updated python-pillow packages fix security vulnerabilities

Mageia Security - 1 Octubre, 2026 - 01:08
Publication date: 01 Oct 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-55380 , CVE-2026-54060 , CVE-2026-54059 , CVE-2026-55379 , CVE-2026-59205 , CVE-2026-59199 , CVE-2026-59197 , CVE-2026-59198 , CVE-2026-54058 , CVE-2026-59204 , CVE-2026-59203 Description
Prevent decompression bomb when parsing PDF WindowsViewer.get_command injection EPS image infinite loop JPEG2000 image memory usage McIdas out-of-bounds (OOB) read Out-of-bounds (OOB) read when saving 1 mode TGA images Out-of-bounds (OOB) write from large RankFilter sizes Out-of-bounds (OOB) write from Image.paste() Out-of-bounds (OOB) write in ImageCmsTransform Prevent FontFile decompression bomb Prevent GD decompression bomb References
SRPMS 10/core
  • python-pillow-12.3.0-1.mga10

MGAA-2026-0144 - Updated glabels & glabels-qt packages fixes bug

Mageia Security - 1 Octubre, 2026 - 01:08
Publication date: 01 Oct 2026
Type: bugfix
Affected Mageia releases : 10
Description
glabels can't open previously-created glabels files. We have added a patch to fix the issue but the project is dead upstream and its developer is now focussing on glabels-qt. We are releasing glabels-qt as an alternative. Both versions fix the reported issue; it is your decision what tool to use. References
SRPMS 10/core
  • glabels-3.4.1-12.1.mga10
  • glabels-qt-3.99-0.2.2026.08.27git554c9f0.mga10
Feed