Lector de Feeds
MGASA-2026-0430 - Updated ntpsec packages fix a security vulnerability
Publication date: 20 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-18321 Description
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') in ntpsec. (CVE-2026-18321) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-18321 Description
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') in ntpsec. (CVE-2026-18321) References
- https://bugs.mageia.org/show_bug.cgi?id=36168
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/UTEH533TYAX7KYJMMA773F3LEQ3E2JX2/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QJWRFBL7QOCH5ZDIFCWDUMRTVPZNV7UQ/
- https://www.cve.org/CVERecord?id=CVE-2026-18321
- ntpsec-1.2.4-3.2.mga10
- ntpsec-1.2.2-5.1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0429 - Updated postfix packages fix security vulnerabilities
Publication date: 20 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
Description
Updated packages fix security issues. Please see the references. References
Type: security
Affected Mageia releases : 10 , 9
Description
Updated packages fix security issues. Please see the references. References
- https://bugs.mageia.org/show_bug.cgi?id=36153
- https://www.openwall.com/lists/oss-security/2026/08/20/5
- https://www.postfix.org/announcements/postfix-3.11.6.html
- https://www.mail-archive.com/postfix-announce@postfix.org/msg00110.html
- https://www.openwall.com/lists/oss-security/2026/09/10/8
- https://www.postfix.org/announcements/postfix-3.11.7.html
- postfix-3.9.15-1.mga10
- postfix-3.8.21-1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0428 - Updated mpg123 package fixes security vulnerabilities
Publication date: 20 Sep 2026
Type: security
Affected Mageia releases : 10
Description
Updated packages fix security vulnerabilities, please se the reference. References
Type: security
Affected Mageia releases : 10
Description
Updated packages fix security vulnerabilities, please se the reference. References
- https://bugs.mageia.org/show_bug.cgi?id=36131
- https://www.openwall.com/lists/oss-security/2026/08/03/2
- mpg123-1.33.7-1.mga10
Categorías: Actualizaciones de Seguridad
MGASA-2026-0427 - Updated gawk packages fix security vulnerabilities
Publication date: 20 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-40467 , CVE-2026-40468 , CVE-2026-40469 , CVE-2026-40553 Description
Use after free in gawk. (CVE-2026-40467) Heap buffer overflow in gawk. (CVE-2026-40468) Heap buffer overflow in gawk. (CVE-2026-40469) Stack-based buffer overflow in gawk. (CVE-2026-40553) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-40467 , CVE-2026-40468 , CVE-2026-40469 , CVE-2026-40553 Description
Use after free in gawk. (CVE-2026-40467) Heap buffer overflow in gawk. (CVE-2026-40468) Heap buffer overflow in gawk. (CVE-2026-40469) Stack-based buffer overflow in gawk. (CVE-2026-40553) References
- https://bugs.mageia.org/show_bug.cgi?id=35997
- https://ubuntu.com/security/notices/USN-8588-1
- https://www.cve.org/CVERecord?id=CVE-2026-40467
- https://www.cve.org/CVERecord?id=CVE-2026-40468
- https://www.cve.org/CVERecord?id=CVE-2026-40469
- https://www.cve.org/CVERecord?id=CVE-2026-40553
- gawk-5.3.2-2.1.mga10
- gawk-5.2.2-1.1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0426 - Updated perl-YAML packages fix a security vulnerability
Publication date: 20 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-63676 Description
Updated packages fixes CVE-2026-63676 References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-63676 Description
Updated packages fixes CVE-2026-63676 References
- https://bugs.mageia.org/show_bug.cgi?id=35996
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/J2RXBIKA5WZB2UEHKQR7MEKDH6GABEFL/
- https://www.cve.org/CVERecord?id=CVE-2026-63676
- perl-YAML-1.310.0-2.1.mga10
- perl-YAML-1.300.0-3.1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0425 - Updated libssh packages fix security vulnerabilities
Publication date: 20 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-15370 , CVE-2026-59843 , CVE-2026-59844 , CVE-2026-59845 , CVE-2026-59846 , CVE-2026-59847 , CVE-2026-59848 , CVE-2026-59849 , CVE-2026-59850 Description
Stack buffer overflow in SFTP server longname construction. (CVE-2026-15370) Denial of service via zero advertised channel packet size. (CVE-2026-59843) Denial of service via oversized SFTP read length. (CVE-2026-59844) Denial of service via unchecked ProxyCommand fork() failure. (CVE-2026-59845) Information disclosure via ProxyCommand %r username expansion. (CVE-2026-59846) Integrity downgrade via OpenSSL AES-GCM tag verification. (CVE-2026-59847) Denial of service via SFTP responses with unknown request IDs. (CVE-2026-59848) Denial of service via automatic certificate authentication loop. (CVE-2026-59849) Use-after-free via data callbacks on closed channels. (CVE-2026-59850) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-15370 , CVE-2026-59843 , CVE-2026-59844 , CVE-2026-59845 , CVE-2026-59846 , CVE-2026-59847 , CVE-2026-59848 , CVE-2026-59849 , CVE-2026-59850 Description
Stack buffer overflow in SFTP server longname construction. (CVE-2026-15370) Denial of service via zero advertised channel packet size. (CVE-2026-59843) Denial of service via oversized SFTP read length. (CVE-2026-59844) Denial of service via unchecked ProxyCommand fork() failure. (CVE-2026-59845) Information disclosure via ProxyCommand %r username expansion. (CVE-2026-59846) Integrity downgrade via OpenSSL AES-GCM tag verification. (CVE-2026-59847) Denial of service via SFTP responses with unknown request IDs. (CVE-2026-59848) Denial of service via automatic certificate authentication loop. (CVE-2026-59849) Use-after-free via data callbacks on closed channels. (CVE-2026-59850) References
- https://bugs.mageia.org/show_bug.cgi?id=35983
- https://www.openwall.com/lists/oss-security/2026/07/21/7
- https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MIVTLBAG4MPX3WGPMVYDO2UPZB6G3ESR/
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/YZ324UUCGQ4JEC4ZOJMJODWYVPSFBWUU/
- https://lists.debian.org/debian-security-announce/2026/msg00321.html
- https://ubuntu.com/security/notices/USN-8699-1
- https://www.cve.org/CVERecord?id=CVE-2026-15370
- https://www.cve.org/CVERecord?id=CVE-2026-59843
- https://www.cve.org/CVERecord?id=CVE-2026-59844
- https://www.cve.org/CVERecord?id=CVE-2026-59845
- https://www.cve.org/CVERecord?id=CVE-2026-59846
- https://www.cve.org/CVERecord?id=CVE-2026-59847
- https://www.cve.org/CVERecord?id=CVE-2026-59848
- https://www.cve.org/CVERecord?id=CVE-2026-59849
- https://www.cve.org/CVERecord?id=CVE-2026-59850
- libssh-0.11.5-1.mga10
- libssh-0.10.6-1.3.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0424 - Updated ntfs-3g packages fix security vulnerabilities
Publication date: 20 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-42616 , CVE-2026-42617 , CVE-2026-42618 , CVE-2026-46569 , CVE-2026-46570 , CVE-2026-46571 , CVE-2026-46572 , CVE-2026-56135 , CVE-2026-56136 Description
Heap memory corruption when processing a corrupt or maliciously crafted filesystem. (CVE-2026-42616) Heap memory corruption when copying index data from root to an index block in a corrupt or maliciously crafted filesystem. (CVE-2026-42617) Single-byte heap buffer overflow when decompressing maliciously crafted compressed file data. (CVE-2026-42618) Heap buffer overflow when copying the tail data of an index block to a freshly allocated block. (CVE-2026-46569) Heap memory corruption for maliciously crafted or corrupt index data descending to an out-of-bounds tree depth. (CVE-2026-46570) Out-of-bounds read when processing symlink reparse data in a corrupt or maliciously crafted filesystem. (CVE-2026-46571) Heap buffer overflow for maliciously crafted or corrupt index data during a node split. (CVE-2026-46572) Heap buffer overflow when building inherited ACL data. (CVE-2026-56135) Out of bounds access when clearing an index root in maliciously crafted or corrupt index data. (CVE-2026-56136) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-42616 , CVE-2026-42617 , CVE-2026-42618 , CVE-2026-46569 , CVE-2026-46570 , CVE-2026-46571 , CVE-2026-46572 , CVE-2026-56135 , CVE-2026-56136 Description
Heap memory corruption when processing a corrupt or maliciously crafted filesystem. (CVE-2026-42616) Heap memory corruption when copying index data from root to an index block in a corrupt or maliciously crafted filesystem. (CVE-2026-42617) Single-byte heap buffer overflow when decompressing maliciously crafted compressed file data. (CVE-2026-42618) Heap buffer overflow when copying the tail data of an index block to a freshly allocated block. (CVE-2026-46569) Heap memory corruption for maliciously crafted or corrupt index data descending to an out-of-bounds tree depth. (CVE-2026-46570) Out-of-bounds read when processing symlink reparse data in a corrupt or maliciously crafted filesystem. (CVE-2026-46571) Heap buffer overflow for maliciously crafted or corrupt index data during a node split. (CVE-2026-46572) Heap buffer overflow when building inherited ACL data. (CVE-2026-56135) Out of bounds access when clearing an index root in maliciously crafted or corrupt index data. (CVE-2026-56136) References
- https://bugs.mageia.org/show_bug.cgi?id=35940
- https://www.openwall.com/lists/oss-security/2026/07/15/6
- https://lists.debian.org/debian-security-announce/2026/msg00300.html
- https://ubuntu.com/security/notices/USN-8554-1
- https://www.cve.org/CVERecord?id=CVE-2026-42616
- https://www.cve.org/CVERecord?id=CVE-2026-42617
- https://www.cve.org/CVERecord?id=CVE-2026-42618
- https://www.cve.org/CVERecord?id=CVE-2026-46569
- https://www.cve.org/CVERecord?id=CVE-2026-46570
- https://www.cve.org/CVERecord?id=CVE-2026-46571
- https://www.cve.org/CVERecord?id=CVE-2026-46572
- https://www.cve.org/CVERecord?id=CVE-2026-56135
- https://www.cve.org/CVERecord?id=CVE-2026-56136
- ntfs-3g-2026.2.25-1.1.mga10
- ntfs-3g-2022.10.3-1.3.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0423 - Updated patch package fixes security vulnerabilities
Publication date: 20 Sep 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-56288 , CVE-2026-56289 Description
NULL Pointer Dereference in GNU patch. (CVE-2026-56288) Loop with Unreachable Exit Condition in GNU patch. (CVE-2026-56289) References
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-56288 , CVE-2026-56289 Description
NULL Pointer Dereference in GNU patch. (CVE-2026-56288) Loop with Unreachable Exit Condition in GNU patch. (CVE-2026-56289) References
- https://bugs.mageia.org/show_bug.cgi?id=35933
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/5MJXY435MLDAL5GXH6V5OY6MEMOGFEH5/
- https://cert.pl/en/posts/2026/07/CVE-2026-56288/
- https://www.cve.org/CVERecord?id=CVE-2026-56288
- https://www.cve.org/CVERecord?id=CVE-2026-56289
- patch-2.8-1.1.mga10
Categorías: Actualizaciones de Seguridad
MGASA-2026-0422 - Updated bind package fixes security vulnerabilities
Publication date: 20 Sep 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-19033 , CVE-2026-19662 , CVE-2026-19666 , CVE-2026-19667 , CVE-2026-19668 , CVE-2026-19941 , CVE-2026-75029 , CVE-2026-76163 , CVE-2026-77119 , CVE-2026-77692 , CVE-2026-78301 , CVE-2026-80274 , CVE-2026-81563 , CVE-2026-81736 Description
Unauthenticated IXFR deltas are applied to the live zone before TSIG verification (CVE-2026-19033). qpcache NOQNAME proof use-after-free crashes recursive resolver (CVE-2026-19662). Use-after-free in query_addnoqnameproof() via the DNS64 filter64 path (CVE-2026-19666). Remote assertion failure via 16-bit length truncation in dns_ncache_add() (CVE-2026-19667). Resource Exhaustion via Excessive DNSSEC Cryptographic Material Matching (CVE-2026-19668). checkwildcard() accepts an out-of-zone NSEC as a wildcard-nonexistence proof (CVE-2026-19941). Message parser retains every identical singleton RDATA, enabling wire-to-work amplification (CVE-2026-75029). named aborts on a TKEY query when the user configuration has no global options statement (CVE-2026-76163). NSEC3 insecure-referral proof can use unrelated cached NSEC3 RRsets (CVE-2026-77119). Unauthenticated remote crash of named via a single DoH SIG(0) request (CVE-2026-77692). Out-of-zone database nodes can become authoritative zone cuts (CVE-2026-78301). Validating resolver can abort while caching a mismatched NOQNAME proof (CVE-2026-80274). SVCB AliasMode additional-data error leaks qpcache references (CVE-2026-81563). Remote CPU denial of service through cached SVCB/HTTPS AliasMode trees (CVE-2026-81736). References
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-19033 , CVE-2026-19662 , CVE-2026-19666 , CVE-2026-19667 , CVE-2026-19668 , CVE-2026-19941 , CVE-2026-75029 , CVE-2026-76163 , CVE-2026-77119 , CVE-2026-77692 , CVE-2026-78301 , CVE-2026-80274 , CVE-2026-81563 , CVE-2026-81736 Description
Unauthenticated IXFR deltas are applied to the live zone before TSIG verification (CVE-2026-19033). qpcache NOQNAME proof use-after-free crashes recursive resolver (CVE-2026-19662). Use-after-free in query_addnoqnameproof() via the DNS64 filter64 path (CVE-2026-19666). Remote assertion failure via 16-bit length truncation in dns_ncache_add() (CVE-2026-19667). Resource Exhaustion via Excessive DNSSEC Cryptographic Material Matching (CVE-2026-19668). checkwildcard() accepts an out-of-zone NSEC as a wildcard-nonexistence proof (CVE-2026-19941). Message parser retains every identical singleton RDATA, enabling wire-to-work amplification (CVE-2026-75029). named aborts on a TKEY query when the user configuration has no global options statement (CVE-2026-76163). NSEC3 insecure-referral proof can use unrelated cached NSEC3 RRsets (CVE-2026-77119). Unauthenticated remote crash of named via a single DoH SIG(0) request (CVE-2026-77692). Out-of-zone database nodes can become authoritative zone cuts (CVE-2026-78301). Validating resolver can abort while caching a mismatched NOQNAME proof (CVE-2026-80274). SVCB AliasMode additional-data error leaks qpcache references (CVE-2026-81563). Remote CPU denial of service through cached SVCB/HTTPS AliasMode trees (CVE-2026-81736). References
- https://bugs.mageia.org/show_bug.cgi?id=36326
- https://kb.isc.org/docs/cve-2026-19033
- https://kb.isc.org/docs/cve-2026-19662
- https://kb.isc.org/docs/cve-2026-19666
- https://kb.isc.org/docs/cve-2026-19667
- https://kb.isc.org/docs/cve-2026-19668
- https://kb.isc.org/docs/cve-2026-19941
- https://kb.isc.org/docs/cve-2026-75029
- https://kb.isc.org/docs/cve-2026-76163
- https://kb.isc.org/docs/cve-2026-77119
- https://kb.isc.org/docs/cve-2026-77692
- https://kb.isc.org/docs/cve-2026-78301
- https://kb.isc.org/docs/cve-2026-80274
- https://kb.isc.org/docs/cve-2026-81563
- https://kb.isc.org/docs/cve-2026-81736
- https://www.cve.org/CVERecord?id=CVE-2026-19033
- https://www.cve.org/CVERecord?id=CVE-2026-19662
- https://www.cve.org/CVERecord?id=CVE-2026-19666
- https://www.cve.org/CVERecord?id=CVE-2026-19667
- https://www.cve.org/CVERecord?id=CVE-2026-19668
- https://www.cve.org/CVERecord?id=CVE-2026-19941
- https://www.cve.org/CVERecord?id=CVE-2026-75029
- https://www.cve.org/CVERecord?id=CVE-2026-76163
- https://www.cve.org/CVERecord?id=CVE-2026-77119
- https://www.cve.org/CVERecord?id=CVE-2026-77692
- https://www.cve.org/CVERecord?id=CVE-2026-78301
- https://www.cve.org/CVERecord?id=CVE-2026-80274
- https://www.cve.org/CVERecord?id=CVE-2026-81563
- https://www.cve.org/CVERecord?id=CVE-2026-81736
- bind-9.20.29-1.mga10
Categorías: Actualizaciones de Seguridad
MGASA-2026-0421 - Updated python-configargparse packages fix security vulnerabilities
Publication date: 20 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
Description
Config file or environment variable can trigger writing out a config file, overwriting an arbitrary file and disclosing configuration values References
Type: security
Affected Mageia releases : 10 , 9
Description
Config file or environment variable can trigger writing out a config file, overwriting an arbitrary file and disclosing configuration values References
- https://bugs.mageia.org/show_bug.cgi?id=36321
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UWACSE6EO43FMBJWXK22JG7C3LAOLJ3Z/
- https://github.com/bw2/ConfigArgParse/security/advisories/GHSA-6m27-337c-jcgf
- python-configargparse-1.7.7-1.mga10
- python-configargparse-1.7.7-1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0420 - Updated libde265 package fixes security vulnerabilities
Publication date: 20 Sep 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2024-38949 , CVE-2024-38950 , CVE-2025-61147 , CVE-2026-33164 , CVE-2026-33165 , CVE-2026-45382 , CVE-2026-45383 , CVE-2026-49295 , CVE-2026-49337 , CVE-2026-49346 , CVE-2026-54240 , CVE-2026-54241 Description
Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attackers to crash the application via crafted payload to display444as420 function at sdl.cc. (CVE-2024-38949) Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attackers to crash the application via crafted payload to __interceptor_memcpy function. (CVE-2024-38950) strukturag libde265 commit d9fea9d wa discovered to contain a segmentation fault via the component decoder_context::compute_framedrop_table(). (CVE-2025-61147) NULL Pointer Dereference in libde265. (CVE-2026-33164) Heap out-of-bounds write in libde265 1.0.16. (CVE-2026-33165) libde265 has a heap-buffer-overflow READ in decode_slice_unit_tiles via unvalidated PPS tile geometry. (CVE-2026-45382) libde265 has a heap buffer overflow (OOB read) in decode_slice_unit_WPP() via out-of-bounds CtbAddrRStoTS access — libde265 <= v1.0.18. (CVE-2026-45383) libde265 has an out-of-bounds write in process_reference_picture_set via predicted short-term RPS. (CVE-2026-49295) libde265 has an unbounded memory leak via orphaned slice headers in `read_slice_NAL`. (CVE-2026-49337) libde265 has a heap buffer overflow in de265_image_get_buffer via SPS dimension integer overflow. (CVE-2026-49346) Pixel accessor signed integer overflow causes heap OOB read/write. (CVE-2026-54240) SAO sequential filter heap buffer overflow via signed integer overflow. (CVE-2026-54241) References
Type: security
Affected Mageia releases : 10
CVE: CVE-2024-38949 , CVE-2024-38950 , CVE-2025-61147 , CVE-2026-33164 , CVE-2026-33165 , CVE-2026-45382 , CVE-2026-45383 , CVE-2026-49295 , CVE-2026-49337 , CVE-2026-49346 , CVE-2026-54240 , CVE-2026-54241 Description
Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attackers to crash the application via crafted payload to display444as420 function at sdl.cc. (CVE-2024-38949) Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attackers to crash the application via crafted payload to __interceptor_memcpy function. (CVE-2024-38950) strukturag libde265 commit d9fea9d wa discovered to contain a segmentation fault via the component decoder_context::compute_framedrop_table(). (CVE-2025-61147) NULL Pointer Dereference in libde265. (CVE-2026-33164) Heap out-of-bounds write in libde265 1.0.16. (CVE-2026-33165) libde265 has a heap-buffer-overflow READ in decode_slice_unit_tiles via unvalidated PPS tile geometry. (CVE-2026-45382) libde265 has a heap buffer overflow (OOB read) in decode_slice_unit_WPP() via out-of-bounds CtbAddrRStoTS access — libde265 <= v1.0.18. (CVE-2026-45383) libde265 has an out-of-bounds write in process_reference_picture_set via predicted short-term RPS. (CVE-2026-49295) libde265 has an unbounded memory leak via orphaned slice headers in `read_slice_NAL`. (CVE-2026-49337) libde265 has a heap buffer overflow in de265_image_get_buffer via SPS dimension integer overflow. (CVE-2026-49346) Pixel accessor signed integer overflow causes heap OOB read/write. (CVE-2026-54240) SAO sequential filter heap buffer overflow via signed integer overflow. (CVE-2026-54241) References
- https://bugs.mageia.org/show_bug.cgi?id=35987
- https://ubuntu.com/security/notices/USN-8573-1
- https://github.com/strukturag/libde265/issues/460
- https://github.com/strukturag/libde265/issues/484
- https://github.com/strukturag/libde265/security/advisories/GHSA-wqrf-6rf5-v78r
- https://github.com/strukturag/libde265/security/advisories/GHSA-653q-9f73-8hvg
- https://github.com/strukturag/libde265/security/advisories/GHSA-hwhx-x2mq-ccr9
- https://github.com/strukturag/libde265/security/advisories/GHSA-wg9q-ppqw-6q38
- https://github.com/strukturag/libde265/security/advisories/GHSA-g2rg-wj66-w594
- https://github.com/strukturag/libde265/security/advisories/GHSA-g5hj-rf9f-7vxm
- https://github.com/strukturag/libde265/security/advisories/GHSA-vv8h-932h-7r86
- https://github.com/strukturag/libde265/security/advisories/GHSA-ccfw-29x7-rrx3
- https://github.com/strukturag/libde265/security/advisories/GHSA-j2qq-x2xq-g9wr
- https://lists.debian.org/debian-security-announce/2026/msg00324.html
- https://lists.debian.org/debian-security-announce/2026/msg00397.html
- https://www.cve.org/CVERecord?id=CVE-2024-38949
- https://www.cve.org/CVERecord?id=CVE-2024-38950
- https://www.cve.org/CVERecord?id=CVE-2025-61147
- https://www.cve.org/CVERecord?id=CVE-2026-33164
- https://www.cve.org/CVERecord?id=CVE-2026-33165
- https://www.cve.org/CVERecord?id=CVE-2026-45382
- https://www.cve.org/CVERecord?id=CVE-2026-45383
- https://www.cve.org/CVERecord?id=CVE-2026-49295
- https://www.cve.org/CVERecord?id=CVE-2026-49337
- https://www.cve.org/CVERecord?id=CVE-2026-49346
- https://www.cve.org/CVERecord?id=CVE-2026-54240
- https://www.cve.org/CVERecord?id=CVE-2026-54241
- libde265-1.0.16-4.1.mga10
- libde265-1.0.16-4.1.mga10.tainted
Categorías: Actualizaciones de Seguridad
MGASA-2026-0419 - Updated python-httplib2 packages fix a security vulnerability
Publication date: 20 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-59939 Description
Decompression Bomb Denial of Service via Unbounded gzip/deflate Response Handling. (CVE-2026-59939) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-59939 Description
Decompression Bomb Denial of Service via Unbounded gzip/deflate Response Handling. (CVE-2026-59939) References
- https://bugs.mageia.org/show_bug.cgi?id=35936
- https://ubuntu.com/security/notices/USN-8537-1
- https://github.com/httplib2/httplib2/security/advisories/GHSA-j5g9-f88f-gfj3
- https://lists.debian.org/debian-security-announce/2026/msg00352.html
- https://www.cve.org/CVERecord?id=CVE-2026-59939
- python-httplib2-0.22.0-3.1.mga10
- python-httplib2-0.20.4-1.1.mga9
Categorías: Actualizaciones de Seguridad
MGAA-2026-0128 - Updated system-config-printer package fixes bug
Publication date: 20 Sep 2026
Type: bugfix
Affected Mageia releases : 10
Description
Current system-config-printer package does not show a logo in the about dialog box. This update fixes the reported issue. References
SRPMS 10/core
Type: bugfix
Affected Mageia releases : 10
Description
Current system-config-printer package does not show a logo in the about dialog box. This update fixes the reported issue. References
SRPMS 10/core
- system-config-printer-1.5.18-6.2.mga10
Categorías: Actualizaciones de Seguridad
MGAA-2026-0127 - Updated perl-Chart package fixes bug
Publication date: 20 Sep 2026
Type: bugfix
Affected Mageia releases : 10
Description
perl-Chart is updated to version 2.403.9. perl-Graphics-Toolkit-Color is a new runtime requirement for perl-Chart. References
SRPMS 10/core
Type: bugfix
Affected Mageia releases : 10
Description
perl-Chart is updated to version 2.403.9. perl-Graphics-Toolkit-Color is a new runtime requirement for perl-Chart. References
SRPMS 10/core
- perl-Chart-2.403.9-1.mga10
- perl-Graphics-Toolkit-Color-2.220.0-1.mga10
Categorías: Actualizaciones de Seguridad
MGAA-2026-0126 - Updated gnome-software package fixes bug
Publication date: 20 Sep 2026
Type: bugfix
Affected Mageia releases : 10
Description
GUI aplications packaged by mageia are not listed in gnome-software. This updates adds libdnf5-plugin-appstream as optional requirement to allow gnome-software see the GUI applications packaged by mageia and allow to user skip the additional package if they want. References
SRPMS 10/core
Type: bugfix
Affected Mageia releases : 10
Description
GUI aplications packaged by mageia are not listed in gnome-software. This updates adds libdnf5-plugin-appstream as optional requirement to allow gnome-software see the GUI applications packaged by mageia and allow to user skip the additional package if they want. References
SRPMS 10/core
- gnome-software-49.3-2.1.mga10
Categorías: Actualizaciones de Seguridad
MGAA-2026-0125 - Updated isodumper package fixes bugs
Publication date: 20 Sep 2026
Type: bugfix
Affected Mageia releases : 10
Description
When formatting a partition which was already mounted, Isodumper failed. Now, it starts to unmount the partitions on the target device Devices list is also cleaned of optical devices. References
SRPMS 10/core
Type: bugfix
Affected Mageia releases : 10
Description
When formatting a partition which was already mounted, Isodumper failed. Now, it starts to unmount the partitions on the target device Devices list is also cleaned of optical devices. References
SRPMS 10/core
- isodumper-1.93-1.mga10
Categorías: Actualizaciones de Seguridad
MGASA-2026-0418 - Updated gstreamer1.0-plugins-base packages fix a security vulnerability
Publication date: 19 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-18297 Description
GStreamer OGG File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. (CVE-2026-18297) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-18297 Description
GStreamer OGG File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. (CVE-2026-18297) References
- https://bugs.mageia.org/show_bug.cgi?id=36288
- https://lists.debian.org/debian-security-announce/2026/msg00400.html
- https://gstreamer.freedesktop.org/security/sa-2026-0053.html
- https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12044
- https://www.cve.org/CVERecord?id=CVE-2026-18297
- gstreamer1.0-plugins-base-1.26.11-1.1.mga10
- gstreamer1.0-plugins-base-1.22.11-1.4.mga9
Categorías: Actualizaciones de Seguridad
MGAA-2026-0124 - Updated audacity packages fix bug
Publication date: 19 Sep 2026
Type: bugfix
Affected Mageia releases : 10
Description
audacity is updated to version 3.7.9 which has improvements and bugs fixed by the audacity team. References
Type: bugfix
Affected Mageia releases : 10
Description
audacity is updated to version 3.7.9 which has improvements and bugs fixed by the audacity team. References
- https://bugs.mageia.org/show_bug.cgi?id=36271
- https://github.com/audacity/audacity/releases#release-Audacity-3.7.9
- https://github.com/audacity/audacity/releases#release-Audacity-3.7.8
- audacity-3.7.9-1.mga10
Categorías: Actualizaciones de Seguridad
MGASA-2026-0417 - Updated gdk-pixbuf2.0 packages fix security vulnerabilities
Publication date: 18 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2025-7345 , CVE-2026-16768 , CVE-2026-81893 Description
Heap‑buffer‑overflow in gdk‑pixbuf. (CVE-2025-7345) Out-of-bounds read in ico parser. (CVE-2026-16768) Invalid write in jpeg icc profile parser on error recovery. (CVE-2026-81893) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2025-7345 , CVE-2026-16768 , CVE-2026-81893 Description
Heap‑buffer‑overflow in gdk‑pixbuf. (CVE-2025-7345) Out-of-bounds read in ico parser. (CVE-2026-16768) Invalid write in jpeg icc profile parser on error recovery. (CVE-2026-81893) References
- https://bugs.mageia.org/show_bug.cgi?id=36238
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7DP4KY4CEXMYSH2LTCRQAN4JZKGOIKAV/
- https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/issues/302
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MXN4IRXYCTUM4SHIHKYCZ4F65WY26VVT/
- https://lists.debian.org/debian-lts-announce/2025/10/msg00024.html
- https://www.cve.org/CVERecord?id=CVE-2025-7345
- https://www.cve.org/CVERecord?id=CVE-2026-16768
- https://www.cve.org/CVERecord?id=CVE-2026-81893
- gdk-pixbuf2.0-2.44.4-2.1.mga10
- gdk-pixbuf2.0-2.42.10-2.4.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0416 - Updated libpcap packages fix security vulnerabilities
Publication date: 18 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-0799 , CVE-2026-31911 , CVE-2026-31912 , CVE-2026-6244 , CVE-2026-6554 , CVE-2026-18313 , CVE-2026-18238 Description
OOBR and OOBW in libpcap before 1.10.7. (CVE-2026-0799) abort() in libpcap before 1.10.7 on an invalid BPF opcode. (CVE-2026-31911) OOBR in libpcap before 1.10.7. (CVE-2026-31912) Division by zero in libpcap before 1.10.7. (CVE-2026-6244) Infinte loop in libpcap before 1.10.7. (CVE-2026-6554) rpcapd memory leak in libpcap before 1.10.7. (CVE-2026-18313) OOBR in rpcap client in libpcap before 1.10.7. (CVE-2026-18238) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-0799 , CVE-2026-31911 , CVE-2026-31912 , CVE-2026-6244 , CVE-2026-6554 , CVE-2026-18313 , CVE-2026-18238 Description
OOBR and OOBW in libpcap before 1.10.7. (CVE-2026-0799) abort() in libpcap before 1.10.7 on an invalid BPF opcode. (CVE-2026-31911) OOBR in libpcap before 1.10.7. (CVE-2026-31912) Division by zero in libpcap before 1.10.7. (CVE-2026-6244) Infinte loop in libpcap before 1.10.7. (CVE-2026-6554) rpcapd memory leak in libpcap before 1.10.7. (CVE-2026-18313) OOBR in rpcap client in libpcap before 1.10.7. (CVE-2026-18238) References
- https://bugs.mageia.org/show_bug.cgi?id=36286
- https://www.openwall.com/lists/oss-security/2026/09/09/2
- https://www.cve.org/CVERecord?id=CVE-2026-0799
- https://www.cve.org/CVERecord?id=CVE-2026-31911
- https://www.cve.org/CVERecord?id=CVE-2026-31912
- https://www.cve.org/CVERecord?id=CVE-2026-6244
- https://www.cve.org/CVERecord?id=CVE-2026-6554
- https://www.cve.org/CVERecord?id=CVE-2026-18313
- https://www.cve.org/CVERecord?id=CVE-2026-18238
- libpcap-1.10.7-1.mga10
- libpcap-1.10.7-1.mga9
Categorías: Actualizaciones de Seguridad




