Lector de Feeds

MGASA-2026-0291 - Updated cifs-utils packages fix a security vulnerability

Mageia Security - 23 Julio, 2026 - 18:45
Publication date: 23 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-12505 Description
The updated packages fix a security vulnerability: Local privilege escalation via forged cifs.spnego key description in cifs.upcall. (CVE-2026-12505) References SRPMS 10/core
  • cifs-utils-7.5-1.1.mga10
9/core
  • cifs-utils-7.0-1.2.mga9

MGASA-2026-0290 - Updated socat package fixes a security vulnerability

Mageia Security - 23 Julio, 2026 - 18:45
Publication date: 23 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-56123 Description
The updated package fixes a security vulnerability: Heap Buffer Overflow via SOCKS5 Reply Parser. (CVE-2026-56123) References SRPMS 10/core
  • socat-1.8.1.0-1.1.mga10
9/core
  • socat-1.8.0.2-1.1.mga9

MGASA-2026-0289 - Updated apache packages fix security vulnerabilities

Mageia Security - 23 Julio, 2026 - 18:45
Publication date: 23 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-29167 , CVE-2026-29170 , CVE-2026-34355 , CVE-2026-34356 , CVE-2026-42535 , CVE-2026-42536 , CVE-2026-43951 , CVE-2026-44119 , CVE-2026-44185 , CVE-2026-44186 , CVE-2026-44631 , CVE-2026-48913 , CVE-2026-49975 Description
The updated packages fix security vulnerabilities: Apache HTTP Server: mod_ldap per-dir use-after-free. (CVE-2026-29167) Apache HTTP Server: mod_proxy_ftp XSS. (CVE-2026-29170) Apache HTTP Server: mod_proxy_html buffer overflow. (CVE-2026-34355) Apache HTTP Server: ProxyPassReverseCookieMap buffer overflow. (CVE-2026-34356) Apache HTTP Server: mod_dav_fs protected directory access. (CVE-2026-42535) Apache HTTP Server: mod_xml2enc heap overflow. (CVE-2026-42536) Apache HTTP Server: OOB Read in `merge_response_headers` can cause crash. (CVE-2026-43951) Apache HTTP Server: escalation of privilege through expressions in .htaccess in multiple modules. (CVE-2026-44119) Apache HTTP Server: Stack Buffer Over-Read in mod_ssl OCSP `send_request`. (CVE-2026-44185) Apache HTTP Server: Loop in `proxy_ftp_handler` in mod_proxy_ftp. (CVE-2026-44186) Apache HTTP Server: Heap Underflow in `ap_regname` via Signed Char Overflow. (CVE-2026-44631) Apache HTTP Server: mod_http2 memory corruption when file handles exhausted. (CVE-2026-48913) Apache HTTP Server: mod_http2 denial of service. (CVE-2026-49975) References SRPMS 10/core
  • apache-2.4.68-1.mga10
9/core
  • apache-2.4.68-1.mga9

MGASA-2026-0288 - Updated dnsmasq packages fix security vulnerabilities

Mageia Security - 23 Julio, 2026 - 18:45
Publication date: 23 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-12725 , CVE-2026-12969 Description
The updated dnsmasq packages fix multiple security issues: A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and query logging are both enabled, logging of DS or DNSKEY replies containing unsupported algorithm or digest types can cause dnsmasq to write past the end of an internal logging buffer. A remote attacker able to supply such a DNS response may crash the dnsmasq process, resulting in denial of service. (CVE-2026-12725) An out-of-bounds read vulnerability exists in dnsmasq's find_soa() function in src/rfc1035.c. When parsing NS section records, extract_name() is called with extrabytes=0, failing to validate that 10 additional bytes exist for fixed-length DNS record fields. A remote attacker controlling a DNS zone can exploit this via a crafted NXDOMAIN response to cause a 10-byte heap out-of-bounds read, potentially accessing stale data from prior transactions. (CVE-2026-12969) References SRPMS 10/core
  • dnsmasq-2.93-1.mga10
9/core
  • dnsmasq-2.93-1.mga9

MGAA-2026-0061 - Updated nut packages fix a bug

Mageia Security - 23 Julio, 2026 - 18:45
Publication date: 23 Jul 2026
Type: bugfix
Affected Mageia releases : 10
Description
nut-scanner failed to start. This update fixes the issue and also updates the nut packages to the latest maintained release. References SRPMS 10/core
  • nut-2.8.5-1.mga10

MGAA-2026-0060 - Updated warpinator packages fix launch failure.

Mageia Security - 23 Julio, 2026 - 18:45
Publication date: 23 Jul 2026
Type: bugfix
Affected Mageia releases : 10
Description
warpinator uses the grpcio module, but with a stamp of the used module version. The stamp was not in accordance with the version of the provided module in the distro, preventing launch. This update fixes that. References SRPMS 10/core
  • warpinator-2.0.4-1.mga10

MGASA-2026-0287 - Updated tig package fixes a security vulnerability

Mageia Security - 21 Julio, 2026 - 16:19
Publication date: 21 Jul 2026
Type: security
Affected Mageia releases : 10
Description
The updated package fixes a security vulnerability: editor command injection vulnerability. References SRPMS 10/core
  • tig-2.6.1-1.mga10

MGAA-2026-0059 - Updated mageia-theme, grub2 & grub2-mageia-theme-dejavu packages fix bugs

Mageia Security - 21 Julio, 2026 - 16:19
Publication date: 21 Jul 2026
Type: bugfix
Affected Mageia releases : 10
Description
The updates packages fix issues in our signature background. The images have been reworked providing a better look. Building with mock is fixed allowing the produced mageia-theme and mageia-theme-extra packages to be installed together. Fix the plymouth theme which still was the Mageia 9 version after upgrades. Behind the scenes some processes are now done at build time, avoiding recurring issues with interlaced images. References SRPMS 10/core
  • mageia-theme-10.11-1.1.mga10
  • grub2-2.12-15.1.mga10
  • grub2-mageia-theme-dejavu-1.0-17.1.mga10

MGAA-2026-0058 - Updated serd, sord, sratom, suil and lilv to the latest versions

Mageia Security - 21 Julio, 2026 - 04:53
Publication date: 21 Jul 2026
Type: bugfix
Affected Mageia releases : 10
Description
The last versions of serd, sord, sratom, suil and lilv couldn't be submitted because of Cauldron FREEZE. References SRPMS 10/core
  • serd-0.32.8-1.mga10
  • sord-0.16.22-1.mga10
  • sratom-0.6.22-1.mga10
  • lilv-0.26.4-1.mga10
  • suil-0.10.26-3.mga10

MGASA-2026-0286 - Updated perl-CGI-Session package fixes a security vulnerability

Mageia Security - 20 Julio, 2026 - 20:06
Publication date: 20 Jul 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-56016 Description
The updated package fixes a security vulnerability: CGI::Session::ID::md5 versions before 4.49 for Perl generate predictable session ids from low-entropy sources. (CVE-2026-56016) References SRPMS 10/core
  • perl-CGI-Session-4.490.0-1.mga10
Feed