Lector de Feeds
Rock
Rock (OMLx 6.0) is the home and workstation edition published by the OpenMandriva Association. Also for individual users who do not want many updates, be it because they prefer their system to remain the same or because of slow internet connection. Releases are scheduled around once a year.
It would be the most stable and suitable for users that like things to stay as they are and just work. Package upgrades will be limited mostly to bug fixes, and security updates.
ROME
ROME is the rolling edition, designed for individual users.
It is designed to be a working, usable system and will have the most up to date packages.
ROME users should be familiar with the command line or terminal (Konsole) and be able to use it at times.
-
arrow_drop_downPlasma 6
The Plasma Extended version is basically a complete desktop for most non-technical users. It features software from KDE.org and other Qt based software. It includes software for most day to day tasks.
Server
OpenMandriva Rock/ROME for servers is a fully independent and flexible Linux distribution, installable with only the necessary programs for starting a server environment (eg: no GUI, no desktop apps, but you can of course add them later)
It can run on bare metal as well as inside containers and VMs, such as OpenStack, Docker, or OCI
It supports AArch64, x86, and znver1 (specially optimized x86 build for Ryzen/EPYC processors) and scales from a Raspberry Pi all the way to a 160-core Ampere server
Spins
Spins is Community alternative desktop proof of concept.
OpenMandriva default desktop environment is the complete, modern KDE Plasma. If you prefer an alternative desktop such as GNOME, LXQt, Xfce or other you can download a Spin.
Do not expect everything to work “out of the box”. They are mainly supported by their maintainers or currently no dedicated maintainers. Bug fixing is not high priority. Any help is welcome.
Which release should I pick?
computer
ROCKRock (OMLx 6.0) is the home and workstation edition
home
ROMEROME is the rolling edition, designed for individual users
developer_mode
COOKERCooker is the OpenMandriva Lx development branch
group
SPINSCommunity alternative desktop proof of concept
MGAA-2026-0135 - Updated zoneminder package fixes zmsetup failure
Type: bugfix
Affected Mageia releases : 10
Description
This update fixes two issues causing zmsetup to fail due to mysql compatibility commands having been removed from mariadb. These commands are now replaced with the native mariadb equivalents. References
SRPMS 10/tainted
- zoneminder-1.38.0-1.1.mga10.tainted
MGASA-2026-0449 - Updated thunderbird & thunderbird-l10n packages fix security vulnerabilities
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-92238 , CVE-2026-92239 , CVE-2026-92240 , CVE-2026-92005 , CVE-2026-92006 , CVE-2026-92007 , CVE-2026-92008 , CVE-2026-92009 , CVE-2026-92010 , CVE-2026-92011 , CVE-2026-92012 , CVE-2026-92013 , CVE-2026-92014 , CVE-2026-92015 , CVE-2026-92016 , CVE-2026-92017 , CVE-2026-92018 , CVE-2026-92019 , CVE-2026-92020 , CVE-2026-92021 , CVE-2026-92022 , CVE-2026-92023 , CVE-2026-92024 , CVE-2026-92025 , CVE-2026-92026 , CVE-2026-92027 , CVE-2026-92028 , CVE-2026-92029 , CVE-2026-92030 , CVE-2026-92031 , CVE-2026-92032 , CVE-2026-92038 , CVE-2026-92039 , CVE-2026-92041 , CVE-2026-92042 , CVE-2026-92043 , CVE-2026-92044 , CVE-2026-92045 , CVE-2026-92046 , CVE-2026-92047 , CVE-2026-92052 , CVE-2026-92053 , CVE-2026-92054 , CVE-2026-92055 , CVE-2026-92056 , CVE-2026-92057 , CVE-2026-92058 , CVE-2026-92059 , CVE-2026-92060 , CVE-2026-92062 , CVE-2026-92064 , CVE-2026-92067 , CVE-2026-92068 , CVE-2026-92069 , CVE-2026-92070 , CVE-2026-92072 , CVE-2026-92073 , CVE-2026-92074 , CVE-2026-92075 , CVE-2026-92076 , CVE-2026-92077 , CVE-2026-92078 Description
Ambiguous parsing of mail headers. (CVE-2026-92238) Buffer overrun in IMAP. (CVE-2026-92239) Out-of-bounds read in IMAP response parser. (CVE-2026-92240) Use-after-free in the Audio/Video: Web Codecs component. (CVE-2026-92005) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-92006) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-92007) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-92008) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-92009) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-92010) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-92011) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-92012) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-92013) Privilege escalation due to incorrect boundary conditions in the Graphics component. (CVE-2026-92014) Privilege escalation in the WebExtensions component. (CVE-2026-92015) Use-after-free in the Disability Access APIs component. (CVE-2026-92016) Privilege escalation in the DOM: Service Workers component. (CVE-2026-92017) Sandbox escape in the DOM: Core & HTML component. (CVE-2026-92018) Mitigation bypass in the Remote Settings Client component. (CVE-2026-92019) Privilege escalation due to incorrect boundary conditions in the Graphics: WebRender component. (CVE-2026-92020) Use-after-free in the JavaScript Engine: JIT component. (CVE-2026-92021) Use-after-free in the DOM: HTML Parser component. (CVE-2026-92022) Use-after-free in the XML component. (CVE-2026-92023) Use-after-free in the SVG component. (CVE-2026-92024) Use-after-free in the DOM: Navigation component. (CVE-2026-92025) Use-after-free in the Networking component. (CVE-2026-92026) Use-after-free in the DOM: Streams component. (CVE-2026-92027) Use-after-free in the DOM: Core & HTML component. (CVE-2026-92028) Use-after-free in the SVG component. (CVE-2026-92029) Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component. (CVE-2026-92030) Information disclosure in the Graphics: ImageLib component. (CVE-2026-92031) Sandbox escape due to invalid pointer in the Graphics component. (CVE-2026-92032) Mitigation bypass in the Remote Settings Client component. (CVE-2026-92038) Mitigation bypass in the DOM: Notifications component. (CVE-2026-92039) Mitigation bypass in the DOM: Networking component. (CVE-2026-92041) Race condition in the DOM: Content Processes component. (CVE-2026-92042) Privilege escalation due to incorrect boundary conditions in the Audio/Video component. (CVE-2026-92043) Information disclosure in the Networking: HTTP component. (CVE-2026-92044) Sandbox escape due to incorrect boundary conditions in the WebRTC component. (CVE-2026-92045) Use-after-free in the Graphics component. (CVE-2026-92046) Privilege escalation in the Crash Reporting component. (CVE-2026-92047) Privilege escalation due to uninitialized memory in the Graphics: CanvasWebGL component. (CVE-2026-92052) Privilege escalation in the Graphics: CanvasWebGL component. (CVE-2026-92053) Privilege escalation in the Memory component. (CVE-2026-92054) Privilege escalation in the DevTools component. (CVE-2026-92055) Use-after-free in the Graphics: Text component. (CVE-2026-92056) Mitigation bypass in the Enterprise Policies component. (CVE-2026-92057) Use-after-free in the Graphics component. (CVE-2026-92058) Incorrect boundary conditions in the DOM: Editor component. (CVE-2026-92059) Use-after-free in the Internationalization component. (CVE-2026-92060) Privilege escalation in the Session Restore component. (CVE-2026-92062) Use-after-free in the Widget: Gtk component. (CVE-2026-92067) Site isolation issue in the Reader Mode component. (CVE-2026-92068) Spoofing issue in the DOM: Navigation component. (CVE-2026-92069) Information disclosure in the Networking component. (CVE-2026-92070) Incorrect boundary conditions in the Safe Browsing component. (CVE-2026-92072) Privilege escalation in the Enterprise Policies component. (CVE-2026-92073) Mitigation bypass in the Popup Blocker component. (CVE-2026-92074) Mitigation bypass in the Networking component. (CVE-2026-92075) Incorrect boundary conditions in the Networking component. (CVE-2026-92076) Denial-of-service in the SVG component. (CVE-2026-92077) Denial-of-service in the Security component. (CVE-2026-92078) References
- https://bugs.mageia.org/show_bug.cgi?id=36318
- https://www.thunderbird.net/en-US/thunderbird/140.16.0esr/releasenotes/
- https://www.thunderbird.net/en-US/thunderbird/153.3.0esr/releasenotes/
- https://www.mozilla.org/en-US/security/advisories/mfsa2026-95/
- https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/
- https://www.cve.org/CVERecord?id=CVE-2026-92238
- https://www.cve.org/CVERecord?id=CVE-2026-92239
- https://www.cve.org/CVERecord?id=CVE-2026-92240
- https://www.cve.org/CVERecord?id=CVE-2026-92005
- https://www.cve.org/CVERecord?id=CVE-2026-92006
- https://www.cve.org/CVERecord?id=CVE-2026-92007
- https://www.cve.org/CVERecord?id=CVE-2026-92008
- https://www.cve.org/CVERecord?id=CVE-2026-92009
- https://www.cve.org/CVERecord?id=CVE-2026-92010
- https://www.cve.org/CVERecord?id=CVE-2026-92011
- https://www.cve.org/CVERecord?id=CVE-2026-92012
- https://www.cve.org/CVERecord?id=CVE-2026-92013
- https://www.cve.org/CVERecord?id=CVE-2026-92014
- https://www.cve.org/CVERecord?id=CVE-2026-92015
- https://www.cve.org/CVERecord?id=CVE-2026-92016
- https://www.cve.org/CVERecord?id=CVE-2026-92017
- https://www.cve.org/CVERecord?id=CVE-2026-92018
- https://www.cve.org/CVERecord?id=CVE-2026-92019
- https://www.cve.org/CVERecord?id=CVE-2026-92020
- https://www.cve.org/CVERecord?id=CVE-2026-92021
- https://www.cve.org/CVERecord?id=CVE-2026-92022
- https://www.cve.org/CVERecord?id=CVE-2026-92023
- https://www.cve.org/CVERecord?id=CVE-2026-92024
- https://www.cve.org/CVERecord?id=CVE-2026-92025
- https://www.cve.org/CVERecord?id=CVE-2026-92026
- https://www.cve.org/CVERecord?id=CVE-2026-92027
- https://www.cve.org/CVERecord?id=CVE-2026-92028
- https://www.cve.org/CVERecord?id=CVE-2026-92029
- https://www.cve.org/CVERecord?id=CVE-2026-92030
- https://www.cve.org/CVERecord?id=CVE-2026-92031
- https://www.cve.org/CVERecord?id=CVE-2026-92032
- https://www.cve.org/CVERecord?id=CVE-2026-92038
- https://www.cve.org/CVERecord?id=CVE-2026-92039
- https://www.cve.org/CVERecord?id=CVE-2026-92041
- https://www.cve.org/CVERecord?id=CVE-2026-92042
- https://www.cve.org/CVERecord?id=CVE-2026-92043
- https://www.cve.org/CVERecord?id=CVE-2026-92044
- https://www.cve.org/CVERecord?id=CVE-2026-92045
- https://www.cve.org/CVERecord?id=CVE-2026-92046
- https://www.cve.org/CVERecord?id=CVE-2026-92047
- https://www.cve.org/CVERecord?id=CVE-2026-92052
- https://www.cve.org/CVERecord?id=CVE-2026-92053
- https://www.cve.org/CVERecord?id=CVE-2026-92054
- https://www.cve.org/CVERecord?id=CVE-2026-92055
- https://www.cve.org/CVERecord?id=CVE-2026-92056
- https://www.cve.org/CVERecord?id=CVE-2026-92057
- https://www.cve.org/CVERecord?id=CVE-2026-92058
- https://www.cve.org/CVERecord?id=CVE-2026-92059
- https://www.cve.org/CVERecord?id=CVE-2026-92060
- https://www.cve.org/CVERecord?id=CVE-2026-92062
- https://www.cve.org/CVERecord?id=CVE-2026-92064
- https://www.cve.org/CVERecord?id=CVE-2026-92067
- https://www.cve.org/CVERecord?id=CVE-2026-92068
- https://www.cve.org/CVERecord?id=CVE-2026-92069
- https://www.cve.org/CVERecord?id=CVE-2026-92070
- https://www.cve.org/CVERecord?id=CVE-2026-92072
- https://www.cve.org/CVERecord?id=CVE-2026-92073
- https://www.cve.org/CVERecord?id=CVE-2026-92074
- https://www.cve.org/CVERecord?id=CVE-2026-92075
- https://www.cve.org/CVERecord?id=CVE-2026-92076
- https://www.cve.org/CVERecord?id=CVE-2026-92077
- https://www.cve.org/CVERecord?id=CVE-2026-92078
- thunderbird-153.3.0-1.mga10
- thunderbird-l10n-153.3.0-1.mga10
- thunderbird-140.16.0-1.mga9
- thunderbird-l10n-140.16.0-1.mga9
MGASA-2026-0448 - Updated perl-Net-DNS packages fix security vulnerabilities
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-64193 , CVE-2026-64194 , CVE-2026-81928 Description
Net::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTENDED ERROR. (CVE-2026-64193) Net::DNS versions through 1.55 for Perl allow Denial of Service via deep DNS compression pointer chains. (CVE-2026-64194) Net::DNS versions before 1.57 for Perl allow memory exhaustion via unbounded recursion in sig_data when re-encoding a message with a misplaced TSIG record. (CVE-2026-81928) References
- https://bugs.mageia.org/show_bug.cgi?id=35968
- https://www.openwall.com/lists/oss-security/2026/07/20/12
- https://www.openwall.com/lists/oss-security/2026/07/20/13
- https://www.net-dns.org/blog/#release-candidate-for-netdns-1.56
- https://rt.cpan.org/Ticket/Display.html?id=179945
- https://rt.cpan.org/Ticket/Display.html?id=179946
- https://metacpan.org/release/NLNETLABS/Net-DNS-1.55_01/changes
- https://lists.debian.org/debian-security-announce/2026/msg00370.html
- https://www.openwall.com/lists/oss-security/2026/09/02/1
- https://metacpan.org/release/NLNETLABS/Net-DNS-1.56/source/lib/Net/DNS/RR/TSIG.pm#L245-262
- https://metacpan.org/release/NLNETLABS/Net-DNS-1.56/source/lib/Net/DNS/RR/TSIG.pm#L62-73
- https://datatracker.ietf.org/doc/html/rfc8945#section-5.2
- https://rt.cpan.org/Ticket/Display.html?id=181125
- https://metacpan.org/release/NLNETLABS/Net-DNS-1.57/changes
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5TS4YPB3LGX5Q5VWSYLSIQZWXJU4UMZN/
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/GGGP7EQRAUOGLVT6K5VJ7U3KCA7YMNZZ/
- https://www.cve.org/CVERecord?id=CVE-2026-64193
- https://www.cve.org/CVERecord?id=CVE-2026-64194
- https://www.cve.org/CVERecord?id=CVE-2026-81928
- perl-Net-DNS-1.570.0-1.mga10
- perl-Net-DNS-1.360.0-1.1.mga9
MGASA-2026-0447 - Updated fuse3 package fixes security vulnerabilities
Type: security
Affected Mageia releases : 10
Description
This update brings security fixes provided by upstream. References
- https://bugs.mageia.org/show_bug.cgi?id=36285
- https://www.openwall.com/lists/oss-security/2026/09/09/1
- fuse3-3.18.3-1.mga10
MGAA-2026-0134 - Updated geogebra package fixes bug
Type: bugfix
Affected Mageia releases : 10
Description
geogebra is updated to version 5.4.929.3 References
SRPMS 10/nonfree
- geogebra-5.4.929.3-1.mga10.nonfree
MGASA-2026-0446 - Updated xdg-dbus-proxy packages fix security vulnerabilities
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-93676 Description
filtering for broadcast messages bypassing path/interface/member checks References
- https://bugs.mageia.org/show_bug.cgi?id=36136
- https://www.openwall.com/lists/oss-security/2026/08/11/10
- https://github.com/flatpak/xdg-dbus-proxy/security/advisories/GHSA-r7hp-698j-2h6c
- https://lists.debian.org/debian-security-announce/2026/msg00346.html
- https://www.cve.org/CVERecord?id=CVE-2026-93676
- xdg-dbus-proxy-0.1.8-1.mga10
- xdg-dbus-proxy-0.1.8-1.mga9
MGASA-2026-0445 - Updated perl-URI packages fix a security vulnerability
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-19953 Description
Apply Unicode NFC normalization in URI::_idna nameprep so IDNA host encoding matches other clients instead of emitting a non-standard, non-round-tripping A-label (CVE-2026-19953) References
- https://bugs.mageia.org/show_bug.cgi?id=36193
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LMFMV7L7KSZWQ7ABCQNPAG65XHUR276O/
- https://www.cve.org/CVERecord?id=CVE-2026-19953
- perl-URI-5.360.0-1.mga10
- perl-URI-5.360.0-1.mga9
MGASA-2026-0444 - Updated kbd packages fix a security vulnerability
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-72693 Description
Local privilege escalation in openvt via incorrect process owner verification allowing passwordless root login. (CVE-2026-72693) References
- https://bugs.mageia.org/show_bug.cgi?id=36239
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ROE6W66CNK3GP7353HAME3NKIXGBUZ64/
- https://bugzilla.redhat.com/show_bug.cgi?id=2462115
- https://www.cve.org/CVERecord?id=CVE-2026-72693
- kbd-2.9.0-1.1.mga10
- kbd-2.5.1-1.1.mga9
MGASA-2026-0443 - Updated pipewire packages fix security vulnerabilities
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-14324 , CVE-2026-14330 Description
RAOP module accepts unbounded Content-Length values and does not check the pw_array_add() return. (CVE-2026-14324) Multiple unbounded alloca() calls in the PulseAudio protocol server. (CVE-2026-14330) References
- https://bugs.mageia.org/show_bug.cgi?id=35929
- https://ubuntu.com/security/notices/USN-8535-1
- https://bugzilla.redhat.com/show_bug.cgi?id=2495903
- https://gitlab.freedesktop.org/pipewire/pipewire/-/work_items/5352
- https://bugzilla.redhat.com/show_bug.cgi?id=2495907
- https://www.cve.org/CVERecord?id=CVE-2026-14324
- https://www.cve.org/CVERecord?id=CVE-2026-14330
- pipewire-1.6.5-1.1.mga10
- pipewire-0.3.85-6.1.mga9
MGASA-2026-0442 - Updated libwebsockets packages fix a security vulnerability
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-10650 Description
warmcat libwebsockets SSH Protocol sshd.c lws_ssh_parse_plaintext resource consumption. (CVE-2026-10650) References
- https://bugs.mageia.org/show_bug.cgi?id=36157
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KMAEZLLRGAX46TX4KZNYWZXYVIWBF3RU/
- https://github.com/biniamf/pocs/tree/main/libwebsockets_sshd-parse-ic-unbounded-alloc
- https://github.com/advisories/GHSA-23jv-8gf4-7r88
- https://www.cve.org/CVERecord?id=CVE-2026-10650
- libwebsockets-4.5.2-1.1.mga10
- libwebsockets-4.3.2-1.1.mga9
MGAA-2026-0133 - Updated amavisd-new package fixes problem starting
Type: bugfix
Affected Mageia releases : 10
Description
amavisd service fails to start. This update fixes the reported issue. References
SRPMS 10/core
- amavisd-new-2.15.0-1.mga10
MGASA-2026-0441 - Updated nss & firefox packages fix security vulnerabilities
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-92005 , CVE-2026-92006 , CVE-2026-92007 , CVE-2026-92008 , CVE-2026-92009 , CVE-2026-92010 , CVE-2026-92011 , CVE-2026-92012 , CVE-2026-92013 , CVE-2026-92014 , CVE-2026-92015 , CVE-2026-92016 , CVE-2026-92017 , CVE-2026-92018 , CVE-2026-92019 , CVE-2026-92020 , CVE-2026-92021 , CVE-2026-92022 , CVE-2026-92023 , CVE-2026-92024 , CVE-2026-92025 , CVE-2026-92026 , CVE-2026-92027 , CVE-2026-92028 , CVE-2026-92029 , CVE-2026-92030 , CVE-2026-92031 , CVE-2026-92032 , CVE-2026-92038 , CVE-2026-92039 , CVE-2026-92041 , CVE-2026-92042 , CVE-2026-92043 , CVE-2026-92044 , CVE-2026-92045 , CVE-2026-92046 , CVE-2026-92047 , CVE-2026-92052 , CVE-2026-92053 , CVE-2026-92054 , CVE-2026-92055 , CVE-2026-92056 , CVE-2026-92057 , CVE-2026-92058 , CVE-2026-92059 , CVE-2026-92060 , CVE-2026-92062 , CVE-2026-92064 , CVE-2026-92067 , CVE-2026-92068 , CVE-2026-92069 , CVE-2026-92070 , CVE-2026-92072 , CVE-2026-92073 , CVE-2026-92074 , CVE-2026-92075 , CVE-2026-92076 , CVE-2026-92077 , CVE-2026-92078 Description
Use-after-free in the Audio/Video: Web Codecs component. (CVE-2026-92005) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-92006) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-92007) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-92008) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-92009) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-92010) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-92011) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-92012) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-92013) Privilege escalation due to incorrect boundary conditions in the Graphics component. (CVE-2026-92014) Privilege escalation in the WebExtensions component. (CVE-2026-92015) Use-after-free in the Disability Access APIs component. (CVE-2026-92016) Privilege escalation in the DOM: Service Workers component. (CVE-2026-92017) Sandbox escape in the DOM: Core & HTML component. (CVE-2026-92018) Mitigation bypass in the Remote Settings Client component. (CVE-2026-92019) Privilege escalation due to incorrect boundary conditions in the Graphics: WebRender component. (CVE-2026-92020) Use-after-free in the JavaScript Engine: JIT component. (CVE-2026-92021) Use-after-free in the DOM: HTML Parser component. (CVE-2026-92022) Use-after-free in the XML component. (CVE-2026-92023) Use-after-free in the SVG component. (CVE-2026-92024) Use-after-free in the DOM: Navigation component. (CVE-2026-92025) Use-after-free in the Networking component. (CVE-2026-92026) Use-after-free in the DOM: Streams component. (CVE-2026-92027) Use-after-free in the DOM: Core & HTML component. (CVE-2026-92028) Use-after-free in the SVG component. (CVE-2026-92029) Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component. (CVE-2026-92030) Information disclosure in the Graphics: ImageLib component. (CVE-2026-92031) Sandbox escape due to invalid pointer in the Graphics component. (CVE-2026-92032) Mitigation bypass in the Remote Settings Client component. (CVE-2026-92038) Mitigation bypass in the DOM: Notifications component. (CVE-2026-92039) Mitigation bypass in the DOM: Networking component. (CVE-2026-92041) Race condition in the DOM: Content Processes component. (CVE-2026-92042) Privilege escalation due to incorrect boundary conditions in the Audio/Video component. (CVE-2026-92043) Information disclosure in the Networking: HTTP component. (CVE-2026-92044) Sandbox escape due to incorrect boundary conditions in the WebRTC component. (CVE-2026-92045) Use-after-free in the Graphics component. (CVE-2026-92046) Privilege escalation in the Crash Reporting component. (CVE-2026-92047) Privilege escalation due to uninitialized memory in the Graphics: CanvasWebGL component. (CVE-2026-92052) Privilege escalation in the Graphics: CanvasWebGL component. (CVE-2026-92053) Privilege escalation in the Memory component. (CVE-2026-92054) Privilege escalation in the DevTools component. (CVE-2026-92055) Use-after-free in the Graphics: Text component. (CVE-2026-92056) Mitigation bypass in the Enterprise Policies component. (CVE-2026-92057) Use-after-free in the Graphics component. (CVE-2026-92058) Incorrect boundary conditions in the DOM: Editor component. (CVE-2026-92059) Use-after-free in the Internationalization component. (CVE-2026-92060) Privilege escalation in the Session Restore component. (CVE-2026-92062) Use-after-free in the Widget: Gtk component. (CVE-2026-92067) Site isolation issue in the Reader Mode component. (CVE-2026-92068) Spoofing issue in the DOM: Navigation component. (CVE-2026-92069) Information disclosure in the Networking component. (CVE-2026-92070) Incorrect boundary conditions in the Safe Browsing component. (CVE-2026-92072) Privilege escalation in the Enterprise Policies component. (CVE-2026-92073) Mitigation bypass in the Popup Blocker component. (CVE-2026-92074) Mitigation bypass in the Networking component. (CVE-2026-92075) Incorrect boundary conditions in the Networking component. (CVE-2026-92076) Denial-of-service in the SVG component. (CVE-2026-92077) Denial-of-service in the Security component. (CVE-2026-92078) References
- https://bugs.mageia.org/show_bug.cgi?id=36317
- https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_129.html
- https://www.firefox.com/en-US/firefox/140.16.0/releasenotes/
- https://www.firefox.com/en-US/firefox/153.3.0/releasenotes/
- https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/
- https://www.mozilla.org/en-US/security/advisories/mfsa2026-93/
- https://www.cve.org/CVERecord?id=CVE-2026-92005
- https://www.cve.org/CVERecord?id=CVE-2026-92006
- https://www.cve.org/CVERecord?id=CVE-2026-92007
- https://www.cve.org/CVERecord?id=CVE-2026-92008
- https://www.cve.org/CVERecord?id=CVE-2026-92009
- https://www.cve.org/CVERecord?id=CVE-2026-92010
- https://www.cve.org/CVERecord?id=CVE-2026-92011
- https://www.cve.org/CVERecord?id=CVE-2026-92012
- https://www.cve.org/CVERecord?id=CVE-2026-92013
- https://www.cve.org/CVERecord?id=CVE-2026-92014
- https://www.cve.org/CVERecord?id=CVE-2026-92015
- https://www.cve.org/CVERecord?id=CVE-2026-92016
- https://www.cve.org/CVERecord?id=CVE-2026-92017
- https://www.cve.org/CVERecord?id=CVE-2026-92018
- https://www.cve.org/CVERecord?id=CVE-2026-92019
- https://www.cve.org/CVERecord?id=CVE-2026-92020
- https://www.cve.org/CVERecord?id=CVE-2026-92021
- https://www.cve.org/CVERecord?id=CVE-2026-92022
- https://www.cve.org/CVERecord?id=CVE-2026-92023
- https://www.cve.org/CVERecord?id=CVE-2026-92024
- https://www.cve.org/CVERecord?id=CVE-2026-92025
- https://www.cve.org/CVERecord?id=CVE-2026-92026
- https://www.cve.org/CVERecord?id=CVE-2026-92027
- https://www.cve.org/CVERecord?id=CVE-2026-92028
- https://www.cve.org/CVERecord?id=CVE-2026-92029
- https://www.cve.org/CVERecord?id=CVE-2026-92030
- https://www.cve.org/CVERecord?id=CVE-2026-92031
- https://www.cve.org/CVERecord?id=CVE-2026-92032
- https://www.cve.org/CVERecord?id=CVE-2026-92038
- https://www.cve.org/CVERecord?id=CVE-2026-92039
- https://www.cve.org/CVERecord?id=CVE-2026-92041
- https://www.cve.org/CVERecord?id=CVE-2026-92042
- https://www.cve.org/CVERecord?id=CVE-2026-92043
- https://www.cve.org/CVERecord?id=CVE-2026-92044
- https://www.cve.org/CVERecord?id=CVE-2026-92045
- https://www.cve.org/CVERecord?id=CVE-2026-92046
- https://www.cve.org/CVERecord?id=CVE-2026-92047
- https://www.cve.org/CVERecord?id=CVE-2026-92052
- https://www.cve.org/CVERecord?id=CVE-2026-92053
- https://www.cve.org/CVERecord?id=CVE-2026-92054
- https://www.cve.org/CVERecord?id=CVE-2026-92055
- https://www.cve.org/CVERecord?id=CVE-2026-92056
- https://www.cve.org/CVERecord?id=CVE-2026-92057
- https://www.cve.org/CVERecord?id=CVE-2026-92058
- https://www.cve.org/CVERecord?id=CVE-2026-92059
- https://www.cve.org/CVERecord?id=CVE-2026-92060
- https://www.cve.org/CVERecord?id=CVE-2026-92062
- https://www.cve.org/CVERecord?id=CVE-2026-92064
- https://www.cve.org/CVERecord?id=CVE-2026-92067
- https://www.cve.org/CVERecord?id=CVE-2026-92068
- https://www.cve.org/CVERecord?id=CVE-2026-92069
- https://www.cve.org/CVERecord?id=CVE-2026-92070
- https://www.cve.org/CVERecord?id=CVE-2026-92072
- https://www.cve.org/CVERecord?id=CVE-2026-92073
- https://www.cve.org/CVERecord?id=CVE-2026-92074
- https://www.cve.org/CVERecord?id=CVE-2026-92075
- https://www.cve.org/CVERecord?id=CVE-2026-92076
- https://www.cve.org/CVERecord?id=CVE-2026-92077
- https://www.cve.org/CVERecord?id=CVE-2026-92078
- firefox-l10n-153.3.0-1.mga10
- nss-3.129.0-1.mga10
- firefox-153.3.0-1.mga10
- firefox-l10n-140.16.0-1.mga9
- nss-3.129.0-1.mga9
- firefox-140.16.0-1.mga9
MGASA-2026-0440 - Updated borgbackup package fixes a security vulnerability
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-62268 Description
The updated package fixes a security vulnerability: CVE-2026-62268. References
- https://bugs.mageia.org/show_bug.cgi?id=36163
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SHGZVBSSCWNFGJ5CQLE5BHFNNORWRSGK/
- https://www.cve.org/CVERecord?id=CVE-2026-62268
- borgbackup-1.4.5-1.mga10
MGASA-2026-0439 - Updated coreutils package fixes a security vulnerability
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-56391 Description
Out‑of‑bounds Read in GNU coreutils. (CVE-2026-56391) References
- https://bugs.mageia.org/show_bug.cgi?id=36171
- https://www.openwall.com/lists/oss-security/2026/07/25/2
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NBV4TP2X6G6D4ITB6FA6CAPLJARRHBQS/
- https://ubuntu.com/security/notices/USN-8697-1
- https://www.cve.org/CVERecord?id=CVE-2026-56391
- coreutils-9.8-3.mga10
MGASA-2026-0438 - Updated libnfs package fixes a security vulnerability
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-57918 Description
libnfs through 6.0.2 before 935b8db has an xid integer underflow in READ_IOVEC in rpc_read_from_socket in lib/socket.c during a connection to a crafted NFS server, when the expected pdu size exceeds the absolute pdu size from the xid/record-marker. (CVE-2026-57918) References
- https://bugs.mageia.org/show_bug.cgi?id=36185
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DOJLZCLBA4FYYVRVR6YGNNEBZAVEEQ3G/
- https://www.cve.org/CVERecord?id=CVE-2026-57918
- libnfs-6.0.2-2.2.mga10




