Lector de Feeds
MGAA-2026-0091 - Updated perl-App-Asciio & perl-IO-Prompter packages fix bug
Publication date: 14 Aug 2026
Type: bugfix
Affected Mageia releases : 10
The current App::Asciio perl module in Mageia 10, version 1.51.3 (released in 2015), depends on Gtk2. This update brings a new version 1.9.02 (released in 2023) which upgraded its dependencies to Gtk3. References SRPMS 10/core
Type: bugfix
Affected Mageia releases : 10
The current App::Asciio perl module in Mageia 10, version 1.51.3 (released in 2015), depends on Gtk2. This update brings a new version 1.9.02 (released in 2023) which upgraded its dependencies to Gtk3. References SRPMS 10/core
- perl-App-Asciio-1.9.2-1.3.mga10
- perl-IO-Prompter-0.5.4-1.mga10
Categorías: Actualizaciones de Seguridad
MGASA-2026-0335 - Updated dhcpcd packages fix security vulnerabilities
Publication date: 13 Aug 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-56114 , CVE-2026-56116
Attackers can send a crafted DHCPv6 ADVERTISE message containing an IA_PD IAPREFIX /0 with a valid OPTION_PD_EXCLUDE using an exclude prefix length of /121 through /128 to trigger the out-of-bounds write and potentially corrupt adjacent stack memory (CVE: CVE-2026-56114). Attackers can repeatedly send Router Advertisements containing Route Information options with a lifetime of zero, triggering unfreed allocations in routeinfo_findalloc() that cause linear memory exhaustion and eventual daemon crash (CVE: CVE-2026-56116). References
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-56114 , CVE-2026-56116
Attackers can send a crafted DHCPv6 ADVERTISE message containing an IA_PD IAPREFIX /0 with a valid OPTION_PD_EXCLUDE using an exclude prefix length of /121 through /128 to trigger the out-of-bounds write and potentially corrupt adjacent stack memory (CVE: CVE-2026-56114). Attackers can repeatedly send Router Advertisements containing Route Information options with a lifetime of zero, triggering unfreed allocations in routeinfo_findalloc() that cause linear memory exhaustion and eventual daemon crash (CVE: CVE-2026-56116). References
- https://bugs.mageia.org/show_bug.cgi?id=36063
- https://github.com/NetworkConfiguration/dhcpcd/pull/676
- https://www.cve.org/CVERecord?id=CVE-2026-56114
- https://www.cve.org/CVERecord?id=CVE-2026-56116
- dhcpcd-10.5.0-1.1.mga10
Categorías: Actualizaciones de Seguridad
MGASA-2026-0334 - Updated qemu packages fix many security vulnerabilities
Publication date: 13 Aug 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-3886 , CVE-2026-3890 , CVE-2026-5744 , CVE-2026-5761 , CVE-2026-5763 , CVE-2026-6502 , CVE-2024-6519 , CVE-2026-8341 , CVE-2026-41435 , CVE-2026-41436 , CVE-2026-41437 , CVE-2026-41438 , CVE-2026-41439 , CVE-2026-41440 , CVE-2026-48004 , CVE-2026-48914
This update to qemu-10.2.4-2.mga10 fixes 14 CVEs from 10.2.3 and 2 from 10.2.4 References
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-3886 , CVE-2026-3890 , CVE-2026-5744 , CVE-2026-5761 , CVE-2026-5763 , CVE-2026-6502 , CVE-2024-6519 , CVE-2026-8341 , CVE-2026-41435 , CVE-2026-41436 , CVE-2026-41437 , CVE-2026-41438 , CVE-2026-41439 , CVE-2026-41440 , CVE-2026-48004 , CVE-2026-48914
This update to qemu-10.2.4-2.mga10 fixes 14 CVEs from 10.2.3 and 2 from 10.2.4 References
- https://bugs.mageia.org/show_bug.cgi?id=35989
- https://lists.nongnu.org/archive/html/qemu-stable/2026-05/msg00654.html
- https://lists.nongnu.org/archive/html/qemu-stable/2026-06/msg00551.html
- https://www.cve.org/CVERecord?id=CVE-2026-3886
- https://www.cve.org/CVERecord?id=CVE-2026-3890
- https://www.cve.org/CVERecord?id=CVE-2026-5744
- https://www.cve.org/CVERecord?id=CVE-2026-5761
- https://www.cve.org/CVERecord?id=CVE-2026-5763
- https://www.cve.org/CVERecord?id=CVE-2026-6502
- https://www.cve.org/CVERecord?id=CVE-2024-6519
- https://www.cve.org/CVERecord?id=CVE-2026-8341
- https://www.cve.org/CVERecord?id=CVE-2026-41435
- https://www.cve.org/CVERecord?id=CVE-2026-41436
- https://www.cve.org/CVERecord?id=CVE-2026-41437
- https://www.cve.org/CVERecord?id=CVE-2026-41438
- https://www.cve.org/CVERecord?id=CVE-2026-41439
- https://www.cve.org/CVERecord?id=CVE-2026-41440
- https://www.cve.org/CVERecord?id=CVE-2026-48004
- https://www.cve.org/CVERecord?id=CVE-2026-48914
- qemu-10.2.4-2.mga10
Categorías: Actualizaciones de Seguridad
MGASA-2026-0333 - Updated roundcubemail packages fix security vulnerabilities
Publication date: 13 Aug 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-54432 , CVE-2026-54433 , CVE-2026-62641 , CVE-2026-62642 , CVE-2026-62643 , CVE-2026-62644
Add basic validation for content proxied by the css proxy Fix SSRF bypass via specific local address URLs using 100.64.0.0/10 and fe80::/10 nets, Fix SSRF filter bypass via various forms of nip.io/sslip.io hostnames evading is_local_url() check Fix remote content blocking bypass via unclosed url() in a FuncIRI attribute Fix LDAP filter injection via unescaped %u/%fu/%d substitution into the search_filter Fix arbitrary Sieve script injection via a filter rule name bypassing managesieve_disabled_actions Fix RCE via cmd_learn driver of markasjunk plugin Fix IMAP command injection via mail search and LITERAL+ byte-count desynchronization Fix password's modoboa driver leak of an authentication token to a user-controlled host Fix stored XSS in "Add to address book" action Fix HTML/CSS sanitization bypass via SVG animate by attribute References
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-54432 , CVE-2026-54433 , CVE-2026-62641 , CVE-2026-62642 , CVE-2026-62643 , CVE-2026-62644
Add basic validation for content proxied by the css proxy Fix SSRF bypass via specific local address URLs using 100.64.0.0/10 and fe80::/10 nets, Fix SSRF filter bypass via various forms of nip.io/sslip.io hostnames evading is_local_url() check Fix remote content blocking bypass via unclosed url() in a FuncIRI attribute Fix LDAP filter injection via unescaped %u/%fu/%d substitution into the search_filter Fix arbitrary Sieve script injection via a filter rule name bypassing managesieve_disabled_actions Fix RCE via cmd_learn driver of markasjunk plugin Fix IMAP command injection via mail search and LITERAL+ byte-count desynchronization Fix password's modoboa driver leak of an authentication token to a user-controlled host Fix stored XSS in "Add to address book" action Fix HTML/CSS sanitization bypass via SVG animate by attribute References
- https://bugs.mageia.org/show_bug.cgi?id=36080
- https://github.com/roundcube/roundcubemail/releases/tag/1.7.3
- https://github.com/roundcube/roundcubemail/releases/tag/1.7.2
- https://www.cve.org/CVERecord?id=CVE-2026-54432
- https://www.cve.org/CVERecord?id=CVE-2026-54433
- https://www.cve.org/CVERecord?id=CVE-2026-62641
- https://www.cve.org/CVERecord?id=CVE-2026-62642
- https://www.cve.org/CVERecord?id=CVE-2026-62643
- https://www.cve.org/CVERecord?id=CVE-2026-62644
- roundcubemail-1.7.3-2.mga10
Categorías: Actualizaciones de Seguridad
MGASA-2026-0332 - Updated roundcubemail package fixes security vulnerabilities
Publication date: 13 Aug 2026
Type: security
Affected Mageia releases : 9
CVE: CVE-2026-54432 , CVE-2026-54433 , CVE-2026-62641 , CVE-2026-62642 , CVE-2026-62643 , CVE-2026-62644
Updated roundcubemail to the 1.6.17 version to fix security vulnerabilities: Some XSS and DoS errors have been corrected. Various vulnerabilities in the password plugin have been fixed. An infinite loop has been fixed. References
Type: security
Affected Mageia releases : 9
CVE: CVE-2026-54432 , CVE-2026-54433 , CVE-2026-62641 , CVE-2026-62642 , CVE-2026-62643 , CVE-2026-62644
Updated roundcubemail to the 1.6.17 version to fix security vulnerabilities: Some XSS and DoS errors have been corrected. Various vulnerabilities in the password plugin have been fixed. An infinite loop has been fixed. References
- https://bugs.mageia.org/show_bug.cgi?id=35944
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TL4FNTXFDUDYFIB5CESGSLF7DCZCMJT6/
- https://roundcube.net/news/2026/07/05/security-updates-1.6.17-and-1.7.2
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54432
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-54433
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-62641
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-62642
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-62643
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-62644
- https://www.cve.org/CVERecord?id=CVE-2026-54432
- https://www.cve.org/CVERecord?id=CVE-2026-54433
- https://www.cve.org/CVERecord?id=CVE-2026-62641
- https://www.cve.org/CVERecord?id=CVE-2026-62642
- https://www.cve.org/CVERecord?id=CVE-2026-62643
- https://www.cve.org/CVERecord?id=CVE-2026-62644
- roundcubemail-1.6.17-1.mga9
Categorías: Actualizaciones de Seguridad
MGAA-2026-0090 - Updated gdm packages fix bug
Publication date: 13 Aug 2026
Type: bugfix
Affected Mageia releases : 10
When upgrading from Mageia 9 to Mageia 10 in a graphical session controlled by gdm, gdm restarts in the middle of the distro upgrade process and causes an incomplete/broken upgrade. This update fixes the reported issue. References SRPMS 10/core
Type: bugfix
Affected Mageia releases : 10
When upgrading from Mageia 9 to Mageia 10 in a graphical session controlled by gdm, gdm restarts in the middle of the distro upgrade process and causes an incomplete/broken upgrade. This update fixes the reported issue. References SRPMS 10/core
- gdm-49.2-2.1.mga10
Categorías: Actualizaciones de Seguridad
MGAA-2026-0089 - Updated lightdm packages fix bug
Publication date: 13 Aug 2026
Type: bugfix
Affected Mageia releases : 10
When upgrading from Mageia 9 to Mageia 10 in a graphical session controlled by lightdm, lightdm restarts in the middle of the distro upgrade process and causes an incomplete/broken upgrade. This update fixes the reported issue. References SRPMS 10/core
Type: bugfix
Affected Mageia releases : 10
When upgrading from Mageia 9 to Mageia 10 in a graphical session controlled by lightdm, lightdm restarts in the middle of the distro upgrade process and causes an incomplete/broken upgrade. This update fixes the reported issue. References SRPMS 10/core
- lightdm-1.32.0-4.1.mga10
Categorías: Actualizaciones de Seguridad
MGAA-2026-0088 - Updated (kmod-)virtualbox(-kvm) packages fix a bug
Publication date: 13 Aug 2026
Type: bugfix
Affected Mageia releases : 10
The updated packages fix an issue with sharing the clipboard and Plasma Wayland guests. References SRPMS 10/core
Type: bugfix
Affected Mageia releases : 10
The updated packages fix an issue with sharing the clipboard and Plasma Wayland guests. References SRPMS 10/core
- virtualbox-7.2.14-1.mga10
- virtualbox-kvm-7.2.14-1.mga10
- kmod-virtualbox-7.2.14-29.mga10
Categorías: Actualizaciones de Seguridad
MGAA-2026-0087 - Updated mesa, libdrm, libva and libva-utils packages fix bugs
Publication date: 13 Aug 2026
Type: bugfix
Affected Mageia releases : 10
This is the latest bugfix release for the new mesa 26.1.x branch, that further improves stability (fixing crashes and memleaks). References
Type: bugfix
Affected Mageia releases : 10
This is the latest bugfix release for the new mesa 26.1.x branch, that further improves stability (fixing crashes and memleaks). References
- https://bugs.mageia.org/show_bug.cgi?id=36006
- https://docs.mesa3d.org/relnotes/26.1.5.html#changes
- https://docs.mesa3d.org/relnotes/26.1.4.html#changes
- https://docs.mesa3d.org/relnotes/26.1.3.html#changes
- https://docs.mesa3d.org/relnotes/26.1.2.html#changes
- https://docs.mesa3d.org/relnotes/26.1.1.html#changes
- https://docs.mesa3d.org/relnotes/26.1.0.html#changes
- https://docs.mesa3d.org/relnotes/26.1.5.html#bug-fixes
- https://docs.mesa3d.org/relnotes/26.1.4.html#bug-fixes
- https://docs.mesa3d.org/relnotes/26.1.3.html#bug-fixes
- https://docs.mesa3d.org/relnotes/26.1.2.html#bug-fixes
- https://docs.mesa3d.org/relnotes/26.1.1.html#bug-fixes
- https://docs.mesa3d.org/relnotes/26.1.0.html#bug-fixes
- libdrm-2.4.134-1.mga10
- libva-2.24.1-1.mga10
- libva-utils-2.24.0-1.mga10
- mesa-26.1.5-1.mga10
- mesa-26.1.5-1.mga10.tainted
Categorías: Actualizaciones de Seguridad
MGAA-2026-0086 - Updated (kmod-)nvidia-current(-wopengpu) packages fix bugs
Publication date: 13 Aug 2026
Type: bugfix
Affected Mageia releases : 10
This is a bug fix release for the new 580 series. See the upstream reference for details. References SRPMS 10/nonfree
Type: bugfix
Affected Mageia releases : 10
This is a bug fix release for the new 580 series. See the upstream reference for details. References SRPMS 10/nonfree
- nvidia-current-580.173.02-1.mga10.nonfree
- nvidia-current-wopengpu-580.173.02-1.mga10.nonfree
- kmod-nvidia-current-wopengpu-580.173.02-38.mga10.nonfree
Categorías: Actualizaciones de Seguridad




