Lector de Feeds

MGAA-2026-0091 - Updated perl-App-Asciio & perl-IO-Prompter packages fix bug

Mageia Security - 14 Agosto, 2026 - 19:04
Publication date: 14 Aug 2026
Type: bugfix
Affected Mageia releases : 10

The current App::Asciio perl module in Mageia 10, version 1.51.3 (released in 2015), depends on Gtk2. This update brings a new version 1.9.02 (released in 2023) which upgraded its dependencies to Gtk3. References SRPMS 10/core
  • perl-App-Asciio-1.9.2-1.3.mga10
  • perl-IO-Prompter-0.5.4-1.mga10

MGASA-2026-0335 - Updated dhcpcd packages fix security vulnerabilities

Mageia Security - 13 Agosto, 2026 - 22:59
Publication date: 13 Aug 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-56114 , CVE-2026-56116
Attackers can send a crafted DHCPv6 ADVERTISE message containing an IA_PD IAPREFIX /0 with a valid OPTION_PD_EXCLUDE using an exclude prefix length of /121 through /128 to trigger the out-of-bounds write and potentially corrupt adjacent stack memory (CVE: CVE-2026-56114). Attackers can repeatedly send Router Advertisements containing Route Information options with a lifetime of zero, triggering unfreed allocations in routeinfo_findalloc() that cause linear memory exhaustion and eventual daemon crash (CVE: CVE-2026-56116). References SRPMS 10/core
  • dhcpcd-10.5.0-1.1.mga10

MGASA-2026-0334 - Updated qemu packages fix many security vulnerabilities

Mageia Security - 13 Agosto, 2026 - 17:40

MGASA-2026-0333 - Updated roundcubemail packages fix security vulnerabilities

Mageia Security - 13 Agosto, 2026 - 17:40
Publication date: 13 Aug 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-54432 , CVE-2026-54433 , CVE-2026-62641 , CVE-2026-62642 , CVE-2026-62643 , CVE-2026-62644
Add basic validation for content proxied by the css proxy Fix SSRF bypass via specific local address URLs using 100.64.0.0/10 and fe80::/10 nets, Fix SSRF filter bypass via various forms of nip.io/sslip.io hostnames evading is_local_url() check Fix remote content blocking bypass via unclosed url() in a FuncIRI attribute Fix LDAP filter injection via unescaped %u/%fu/%d substitution into the search_filter Fix arbitrary Sieve script injection via a filter rule name bypassing managesieve_disabled_actions Fix RCE via cmd_learn driver of markasjunk plugin Fix IMAP command injection via mail search and LITERAL+ byte-count desynchronization Fix password's modoboa driver leak of an authentication token to a user-controlled host Fix stored XSS in "Add to address book" action Fix HTML/CSS sanitization bypass via SVG animate by attribute References SRPMS 10/core
  • roundcubemail-1.7.3-2.mga10

MGASA-2026-0332 - Updated roundcubemail package fixes security vulnerabilities

Mageia Security - 13 Agosto, 2026 - 17:40

MGAA-2026-0090 - Updated gdm packages fix bug

Mageia Security - 13 Agosto, 2026 - 17:40
Publication date: 13 Aug 2026
Type: bugfix
Affected Mageia releases : 10

When upgrading from Mageia 9 to Mageia 10 in a graphical session controlled by gdm, gdm restarts in the middle of the distro upgrade process and causes an incomplete/broken upgrade. This update fixes the reported issue. References SRPMS 10/core
  • gdm-49.2-2.1.mga10

MGAA-2026-0089 - Updated lightdm packages fix bug

Mageia Security - 13 Agosto, 2026 - 17:40
Publication date: 13 Aug 2026
Type: bugfix
Affected Mageia releases : 10

When upgrading from Mageia 9 to Mageia 10 in a graphical session controlled by lightdm, lightdm restarts in the middle of the distro upgrade process and causes an incomplete/broken upgrade. This update fixes the reported issue. References SRPMS 10/core
  • lightdm-1.32.0-4.1.mga10

MGAA-2026-0088 - Updated (kmod-)virtualbox(-kvm) packages fix a bug

Mageia Security - 13 Agosto, 2026 - 17:40
Publication date: 13 Aug 2026
Type: bugfix
Affected Mageia releases : 10

The updated packages fix an issue with sharing the clipboard and Plasma Wayland guests. References SRPMS 10/core
  • virtualbox-7.2.14-1.mga10
  • virtualbox-kvm-7.2.14-1.mga10
  • kmod-virtualbox-7.2.14-29.mga10

MGAA-2026-0086 - Updated (kmod-)nvidia-current(-wopengpu) packages fix bugs

Mageia Security - 13 Agosto, 2026 - 17:40
Publication date: 13 Aug 2026
Type: bugfix
Affected Mageia releases : 10

This is a bug fix release for the new 580 series. See the upstream reference for details. References SRPMS 10/nonfree
  • nvidia-current-580.173.02-1.mga10.nonfree
  • nvidia-current-wopengpu-580.173.02-1.mga10.nonfree
  • kmod-nvidia-current-wopengpu-580.173.02-38.mga10.nonfree
Feed