Lector de Feeds

MGASA-2026-0312 - Updated kernel, kmod, bluez, firmware, wireless-regdb and drakx-installer-images packages fix security vulnerabilities

Mageia Security - 1 Agosto, 2026 - 16:58
Publication date: 01 Aug 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-52908 , CVE-2026-52909 , CVE-2026-52910 , CVE-2026-52917 , CVE-2026-52924 , CVE-2026-52929 , CVE-2026-52930 , CVE-2026-52935 , CVE-2026-52939 , CVE-2026-52940 , CVE-2026-52942 , CVE-2026-52946 , CVE-2026-52947 , CVE-2026-52948 , CVE-2026-53131 , CVE-2026-53132 , CVE-2026-53133 , CVE-2026-53134 , CVE-2026-53135 , CVE-2026-53136 , CVE-2026-53137 , CVE-2026-53138 , CVE-2026-53139 , CVE-2026-53140 , CVE-2026-53141 , CVE-2026-53142 , CVE-2026-53143 , CVE-2026-53144 , CVE-2026-53145 , CVE-2026-53146 , CVE-2026-53147 , CVE-2026-53148 , CVE-2026-53149 , CVE-2026-53150 , CVE-2026-53151 , CVE-2026-53152 , CVE-2026-53153 , CVE-2026-53154 , CVE-2026-53156 , CVE-2026-53157 , CVE-2026-53158 , CVE-2026-53159 , CVE-2026-53160 , CVE-2026-53161 , CVE-2026-53162 , CVE-2026-53163 , CVE-2026-53164 , CVE-2026-53166 , CVE-2026-53167 , CVE-2026-53168 , CVE-2026-53175 , CVE-2026-53176 , CVE-2026-53177 , CVE-2026-53179 , CVE-2026-53180 , CVE-2026-53181 , CVE-2026-53182 , CVE-2026-53183 , CVE-2026-53184 , CVE-2026-53185 , CVE-2026-53186 , CVE-2026-53187 , CVE-2026-53188 , CVE-2026-53189 , CVE-2026-53190 , CVE-2026-53191 , CVE-2026-53192 , CVE-2026-53193 , CVE-2026-53194 , CVE-2026-53195 , CVE-2026-53196 , CVE-2026-53197 , CVE-2026-53198 , CVE-2026-53199 , CVE-2026-53202 , CVE-2026-53203 , CVE-2026-53205 , CVE-2026-53207 , CVE-2026-53208 , CVE-2026-53209 , CVE-2026-53210 , CVE-2026-53211 , CVE-2026-53212 , CVE-2026-53213 , CVE-2026-53214 , CVE-2026-53215 , CVE-2026-53216 , CVE-2026-53217 , CVE-2026-53218 , CVE-2026-53219 , CVE-2026-53220 , CVE-2026-53221 , CVE-2026-53223 , CVE-2026-53224 , CVE-2026-53225 , CVE-2026-53226 , CVE-2026-53227 , CVE-2026-53228 , CVE-2026-53229 , CVE-2026-53230 , CVE-2026-53233 , CVE-2026-53234 , CVE-2026-53235 , CVE-2026-53236 , CVE-2026-53237 , CVE-2026-53238 , CVE-2026-53239 , CVE-2026-53240 , CVE-2026-53241 , CVE-2026-53242 , CVE-2026-53245 , CVE-2026-53246 , CVE-2026-53247 , CVE-2026-53248 , CVE-2026-53249 , CVE-2026-53250 , CVE-2026-53251 , CVE-2026-53252 , CVE-2026-53253 , CVE-2026-53254 , CVE-2026-53255 , CVE-2026-53256 , CVE-2026-53258 , CVE-2026-53259 , CVE-2026-53261 , CVE-2026-53262 , CVE-2026-53263 , CVE-2026-53264 , CVE-2026-53265 , CVE-2026-53266 , CVE-2026-53267 , CVE-2026-53268 , CVE-2026-53269 , CVE-2026-53270 , CVE-2026-53271 , CVE-2026-53272 , CVE-2026-53273 , CVE-2026-53274 , CVE-2026-53275 , CVE-2026-53277 , CVE-2026-53325 , CVE-2026-53327 , CVE-2026-53328 , CVE-2026-53329 , CVE-2026-53330 , CVE-2026-53331 , CVE-2026-53332 , CVE-2026-53333 , CVE-2026-53334 , CVE-2026-53335 , CVE-2026-53336 , CVE-2026-53337 , CVE-2026-53338 , CVE-2026-53339 , CVE-2026-53340 , CVE-2026-53341 , CVE-2026-53342 , CVE-2026-53343 , CVE-2026-53345 , CVE-2026-53346 , CVE-2026-53347 , CVE-2026-53349 , CVE-2026-53350 , CVE-2026-53352 , CVE-2026-53353 , CVE-2026-53354 , CVE-2026-53355 , CVE-2026-53356 , CVE-2026-53359 , CVE-2026-53361 , CVE-2026-53362 , CVE-2026-53363 , CVE-2026-53366 , CVE-2026-53381 , CVE-2026-53382 , CVE-2026-53383 , CVE-2026-53384 , CVE-2026-53385 , CVE-2026-53386 , CVE-2026-53387 , CVE-2026-53388 , CVE-2026-53389 , CVE-2026-53390 , CVE-2026-53391 , CVE-2026-53392 , CVE-2026-53393 , CVE-2026-53394 , CVE-2026-53397 , CVE-2026-53398 , CVE-2026-53399 , CVE-2026-53400 , CVE-2026-53402 , CVE-2026-53403 , CVE-2026-63794 , CVE-2026-63795 , CVE-2026-63796 , CVE-2026-63797 , CVE-2026-63798 , CVE-2026-63800 , CVE-2026-63801 , CVE-2026-63802 , CVE-2026-63803 , CVE-2026-63804 , CVE-2026-63805 , CVE-2026-63806 , CVE-2026-63807 , CVE-2026-63808 , CVE-2026-63809 , CVE-2026-63810 , CVE-2026-63812 , CVE-2026-63814 , CVE-2026-63815 , CVE-2026-63816 , CVE-2026-63817 , CVE-2026-63818 , CVE-2026-63819 , CVE-2026-63821 , CVE-2026-63822 , CVE-2026-63823 , CVE-2026-63824 , CVE-2026-63825 , CVE-2026-63826 , CVE-2026-63827 , CVE-2026-63828 , CVE-2026-63829 , CVE-2026-63830 , CVE-2026-63831 , CVE-2026-63832 , CVE-2026-63833 , CVE-2026-63834 , CVE-2026-63835 , CVE-2026-63836 , CVE-2026-63867 , CVE-2026-63868 , CVE-2026-63869 , CVE-2026-63870 , CVE-2026-63871 , CVE-2026-63873 , CVE-2026-63874 , CVE-2026-64187 , CVE-2026-64188 , CVE-2026-64189 , CVE-2026-64191 , CVE-2026-64205 , CVE-2026-64206 , CVE-2026-64207 Description
Upstream kernel version 6.18.39 fixes bugs and vulnerabilities. The kmod, bluez, wireless-regdb, firmware and drakx-installer-images packages have been updated to work with this new kernel. References
SRPMS 10/core
  • kernel-6.18.39-1.mga10
  • kmod-virtualbox-7.2.8-28.mga10
  • kmod-xtables-addons-3.30-3.mga10
  • bluez-5.87-1.mga10
  • wireless-regdb-20260530-1.mga10
  • kernel-firmware-20260622-1.mga10
  • drakx-installer-images-2.94-54.mga10
10/nonfree
  • kernel-firmware-nonfree-20260622-1.mga10.nonfree
  • radeon-firmware-20260622-1.mga10.nonfree
  • drakx-installer-images-2.94-54.mga10.nonfree
  • kmod-nvidia-current-wopengpu-580.159.04-37.mga10.nonfree

MGASA-2026-0311 - Updated libxfont2 packages fix security vulnerabilities

Mageia Security - 30 Julio, 2026 - 18:03
Publication date: 30 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-56001 , CVE-2026-56002 , CVE-2026-56003 Description
The updated packages fix security vulnerabilities: BitmapScaleBitmaps Integer Overflow Heap Buffer Overflow. (CVE-2026-56001) PCF Font Parsing Heap Buffer Overflow. (CVE-2026-56002) computeProps Property Buffer Heap Buffer Overflow. (CVE-2026-56003) References
SRPMS 10/core
  • libxfont2-2.0.8-1.mga10
9/core
  • libxfont2-2.0.6-2.1.mga9

MGASA-2026-0310 - Updated 389-ds-base packages fix a security vulnerability

Mageia Security - 30 Julio, 2026 - 18:03
Publication date: 30 Jul 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-9064 Description
The updated packages fix a security vulnerability: Unbounded ldap controls count in get_ldapmessage_controls_ext() causes cpu and heap amplification (remote dos). (CVE-2026-9064) References
SRPMS 10/core
  • 389-ds-base-3.1.3-2.1.mga10

MGASA-2026-0309 - Updated nghttp2 packages fix a security vulnerability

Mageia Security - 30 Julio, 2026 - 18:03
Publication date: 30 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-58055 Description
The updated packages fix a security vulnerability: HTTP Request/Response Smuggling via Upgrade Request with Content-Length. (CVE-2026-58055) References
SRPMS 10/core
  • nghttp2-1.68.1-2.1.mga10
9/core
  • nghttp2-1.61.0-1.2.mga9

MGASA-2026-0307 - Updated gstreamer1.0-libav packages fix security vulnerability

Mageia Security - 28 Julio, 2026 - 18:06
Publication date: 28 Jul 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-52717 Description
Heap corruption in gst-libav AV protocol pipe. (CVE-2026-52717) References
SRPMS 10/core
  • gstreamer1.0-libav-1.26.11-1.1.mga10

MGASA-2026-0306 - Updated libslirp packages fix a security vulnerability

Mageia Security - 28 Julio, 2026 - 18:06
Publication date: 28 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-9539 Description
The updated packages fix a security vulnerability: TCP URG OOB Read Information Leak. (CVE-2026-9539) References
SRPMS 10/core
  • libslirp-4.8.0-2.1.mga10
9/core
  • libslirp-4.6.1-1.1.mga9

MGASA-2026-0305 - Updated sqlite3 packages fix security vulnerabilities

Mageia Security - 28 Julio, 2026 - 08:15
Publication date: 28 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-50812 , CVE-2026-50813 Description
CVE-2026-50812: A NULL pointer dereference in the SQLite Session Extension in SQLite 3.53.1 and SQLite trunk builds before check-in e807d4e3798efd53 allows an attacker who can supply a malformed changeset blob to cause a denial of service. The issue occurs when sqlite3changeset_apply_v3() applies a corrupt changeset and reaches sqlite3_value_type() with a NULL sqlite3_value pointer. CVE-2026-50813: An issue in SQLite before Fossil check-in 869a51ae84df allows a local attacker to obtain sensitive information via the Session Extension changeset concat/changegroup merge path. References
SRPMS 10/core
  • sqlite3-3.51.3-1.2.mga10
9/core
  • sqlite3-3.40.1-1.10.mga9

MGASA-2026-0304 - Updated memcached packages fix security and other issues

Mageia Security - 28 Julio, 2026 - 08:15
Publication date: 28 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
Description
The updated packages fix bugs including security ones. References
SRPMS 10/core
  • memcached-1.6.45-1.mga10
9/core
  • memcached-1.6.45-1.mga9

MGAA-2026-0073 - Updated gscan2pdf packages fix bug

Mageia Security - 28 Julio, 2026 - 08:15
Publication date: 28 Jul 2026
Type: bugfix
Affected Mageia releases : 10
Description
perl-Gtk2-Ex-PodViewer depends on perl-Gtk2-Ex-Simple-List, but upstream gscan2pdf now explicitly depends on Gtk3::SimpleList, so this dependency seems to be indeed obsolete. Yjis update removes the dependency on perl-Gtk2-Ex-PodViewer. References
SRPMS 10/core
  • gscan2pdf-2.13.5-2.1.mga10

MGASA-2026-0303 - Updated x11-server x11-server-xwayland tigervnc packages fix security vulnerabilities

Mageia Security - 27 Julio, 2026 - 23:45
Publication date: 27 Jul 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-55999 , CVE-2026-56000 Description
The updated packages fix security vulnerabilities: glamor Font Atlas Heap Buffer Overflow. (CVE-2026-55999) GLX contextTags Use-After-Free in CommonMakeCurrent(). (CVE-2026-56000) References
SRPMS 10/core
  • x11-server-21.1.24-1.mga10
  • x11-server-xwayland-24.1.13-1.mga10
  • tigervnc-1.15.0-7.1.mga10

MGASA-2026-0302 - Updated libyang packages fix a security vulnerability

Mageia Security - 27 Julio, 2026 - 23:45
Publication date: 27 Jul 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-41401 Description
The updated packages fix a security vulnerability: Heap Use-After-Free Write in XML Metadata Parsing. (CVE-2026-41401) References
SRPMS 10/core
  • libyang-3.13.5-1.1.mga10

MGASA-2026-0301 - Updated nginx packages fix security vulnerabilities

Mageia Security - 27 Julio, 2026 - 23:45
Publication date: 27 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-42533 , CVE-2026-56434 , CVE-2026-60005 Description
CVE-2026-42533: Heap buffer overflow might occur in a worker process when using the map directive with regex matching if the map variable was included in a string expression after a capture affected by this map; a similar issue might happen when using a non-cacheable variable in a string expression. Thanks to Mufeed VH of Winfunc Research and Maxim Dounin. . CVE-2026-60005: Uninitialized memory access might occur when using unnamed regex captures with the "slice" directive or background cache update, which could result in worker process memory disclosure or worker process termination. . CVE-2026-56434: Use-after-free might occur when processing a specially crafted proxied backend response with the ngx_http_ssi_filter_module. Thanks to P4P3R-HAK. References
SRPMS 10/core
  • nginx-1.30.4-1.mga10
9/core
  • nginx-1.30.4-1.mga9

MGAA-2026-0072 - Updated tdlib & purple-telegram-tdlib packages fix bugs

Mageia Security - 27 Julio, 2026 - 23:45
Publication date: 27 Jul 2026
Type: bugfix
Affected Mageia releases : 10 , 9
Description
purple-telegram-tdlib has been migrated to a new active fork and updated to version 1.1.1. purple-telegram-tdlib updated packages fix an issue where administrators of telegram's groups can't open a chat in the group tdlib has been updated to version 1.8.65, required to build the new version of purple-telegram-tdlib References
SRPMS 10/core
  • tdlib-1.8.65-1.git20260613.mga10
  • purple-telegram-tdlib-1.1.1-1.mga10
9/core
  • tdlib-1.8.65-1.git20260613.mga9
  • purple-telegram-tdlib-1.1.1-1.mga9

MGAA-2026-0071 - Updated amarok packages fix a bug

Mageia Security - 27 Julio, 2026 - 23:45
Publication date: 27 Jul 2026
Type: bugfix
Affected Mageia releases : 10
Description
After right clicking on a music file in Dolphin and selecting to open it with Amarok, Amarok failed to load the file. This update fixes the issue. References SRPMS 10/core
  • amarok-3.3.3-1.mga10

MGAA-2026-0070 - Updated neochat package fixes missing dependency

Mageia Security - 27 Julio, 2026 - 23:45
Publication date: 27 Jul 2026
Type: bugfix
Affected Mageia releases : 10
Description
If purpose wasn't installed, neochat would not start. This update adds the missing dependency on the purpose package. References SRPMS 10/core
  • neochat-25.12.1-1.1.mga10

MGAA-2026-0069 - Updated ocrfeeder package makes it start again

Mageia Security - 27 Julio, 2026 - 23:45
Publication date: 27 Jul 2026
Type: bugfix
Affected Mageia releases : 10
Description
The OCRFeeder package wouldn't start since python3.13. This update fixes the issue. References SRPMS 10/core
  • ocrfeeder-0.8.5-4.1.mga10

MGAA-2026-0068 - Updated byobu package fixes missing desktop entry

Mageia Security - 27 Julio, 2026 - 23:45
Publication date: 27 Jul 2026
Type: bugfix
Affected Mageia releases : 10
Description
The byobu package failed to install its desktop menu entry. This update fixes the issue. References SRPMS 10/core
  • byobu-6.13-1.1.mga10

MGAA-2026-0067 - Updated phonon-vlc packages fix an upgrade conflict

Mageia Security - 27 Julio, 2026 - 23:45
Publication date: 27 Jul 2026
Type: bugfix
Affected Mageia releases : 10
Description
When doing a command line upgrade from Mageia 9 to Mageia 10, there were conflicts between phonon-vlc-i18n-0.12.0-2.mga10.noarch and phonon4qt5-vlc-0.11.3-2.mga9.x86_64. This Mageia 10 update fixes the issue. References SRPMS 10/core
  • phonon-vlc-0.12.0-2.1.mga10

MGASA-2026-0300 - Updated wget packages fix security vulnerabilities

Mageia Security - 25 Julio, 2026 - 19:04
Publication date: 25 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-58469 , CVE-2026-58470 , CVE-2026-58471 , CVE-2026-58472 , CVE-2026-15146 Description
Updated wget packages fix security vulnerabilities: -CVE-2026-58469 Wget incorrectly handled Metalink documents containing a whitespace-only URL. A remote attacker could possibly use this issue to cause a denial of service. This issue only affected Mageia 9 and Mageia 10. -CVE-2026-58470 : Wget incorrectly handled Content-Range header values, leading to an integer overflow. A remote attacker could possibly use this issue to cause download desynchronization. -CVE-2026-58471 : Wget incorrectly handled character set conversion of server-supplied filenames. A remote attacker could possibly use this issue to cause a denial of service or possibly execute arbitrary code. This issue affected Mageia9 and Mageia 10. -CVE-2026-58472: It was discovered that Wget incorrectly handled HTML attributes requiring entity encoding. A remote attacker could possibly use this issue to cause a denial of service or possibly execute arbitrary code. -CVE-2026-15146: GNU Wget did not validate the IP address provided by an FTP PASV response while operating in FTP passive mode. A malicious FTP server, or an HTTP server that redirects to an FTP URL, could exploit this behavior to redirect Wget's data connection to an arbitrary IP address and port. This allowed an attacker to forge server-side requests (SSRF) from the machine running Wget, potentially accessing localhost services or internal network resources. References SRPMS 10/core
  • wget-1.25.0-2.2.mga10
9/core
  • wget-1.21.4-1.4.mga9
Feed