Lector de Feeds
MGASA-2026-0294 - Updated libevent packages fix security vulnerabilities
Publication date: 24 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-63379 , CVE-2026-63381 , CVE-2026-63382 , CVE-2026-63382 , CVE-2026-63383 , CVE-2026-63384 , CVE-2026-63385 , CVE-2026-63387 , CVE-2026-63388 Description The updated packages fix some security vulnerabilities. References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-63379 , CVE-2026-63381 , CVE-2026-63382 , CVE-2026-63382 , CVE-2026-63383 , CVE-2026-63384 , CVE-2026-63385 , CVE-2026-63387 , CVE-2026-63388 Description The updated packages fix some security vulnerabilities. References
- https://bugs.mageia.org/show_bug.cgi?id=35801
- https://www.openwall.com/lists/oss-security/2026/07/01/8
- https://www.cve.org/CVERecord?id=CVE-2026-63379
- https://www.cve.org/CVERecord?id=CVE-2026-63381
- https://www.cve.org/CVERecord?id=CVE-2026-63382
- https://www.cve.org/CVERecord?id=CVE-2026-63382
- https://www.cve.org/CVERecord?id=CVE-2026-63383
- https://www.cve.org/CVERecord?id=CVE-2026-63384
- https://www.cve.org/CVERecord?id=CVE-2026-63385
- https://www.cve.org/CVERecord?id=CVE-2026-63387
- https://www.cve.org/CVERecord?id=CVE-2026-63388
- libevent-2.1.13-1.mga10
- libevent-2.1.13-1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0293 - Updated transmission packages fix a security vulnerability
Publication date: 24 Jul 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-38978 Description The updated packages fix a security vulnerability: Transmission through 4.1.1 was found to have a clickjacking weakness in the browser-facing WebUI and RPC response paths. (CVE-2026-38978) References
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-38978 Description The updated packages fix a security vulnerability: Transmission through 4.1.1 was found to have a clickjacking weakness in the browser-facing WebUI and RPC response paths. (CVE-2026-38978) References
- https://bugs.mageia.org/show_bug.cgi?id=35638
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BSYWZMPQ6XPS66NXRF3SE4HICNOOEP64/
- https://github.com/transmission/transmission/issues/8726
- https://www.cve.org/CVERecord?id=CVE-2026-38978
- transmission-4.1.3-1.mga10
Categorías: Actualizaciones de Seguridad
MGASA-2026-0292 - Updated lrzip package fixes security vulnerabilities
Publication date: 24 Jul 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2025-15570 , CVE-2025-9396 Description The updated package fixes security vulnerabilities: ckolivas lrzip stream.c lzma_decompress_buf use after free. (CVE-2025-15570) ckolivas lrzip strtol_l.c __GI_____strtol_l_internal null pointer dereference. (CVE-2025-9396) References
Type: security
Affected Mageia releases : 10
CVE: CVE-2025-15570 , CVE-2025-9396 Description The updated package fixes security vulnerabilities: ckolivas lrzip stream.c lzma_decompress_buf use after free. (CVE-2025-15570) ckolivas lrzip strtol_l.c __GI_____strtol_l_internal null pointer dereference. (CVE-2025-9396) References
- https://bugs.mageia.org/show_bug.cgi?id=35760
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/JSNIFYQRLND7PULS3ODEDTISSERCMKIQ/
- https://github.com/ckolivas/lrzip/issues/262
- https://github.com/ckolivas/lrzip/issues/264
- https://www.cve.org/CVERecord?id=CVE-2025-15570
- https://www.cve.org/CVERecord?id=CVE-2025-9396
- lrzip-0.660-1.mga10
Categorías: Actualizaciones de Seguridad
MGAA-2026-0064 - Updated rpm-mageia-setup packages fix incompatibility with emacs
Publication date: 24 Jul 2026
Type: bugfix
Affected Mageia releases : 10
Description Opening a spec file with emacs on mga10 did no longer provide syntax highlighting. This update fixes the issue. References SRPMS 10/core
Type: bugfix
Affected Mageia releases : 10
Description Opening a spec file with emacs on mga10 did no longer provide syntax highlighting. This update fixes the issue. References SRPMS 10/core
- rpm-mageia-setup-2.84-1.mga10
Categorías: Actualizaciones de Seguridad
MGAA-2026-0063 - Updated xonotic packages fix broken online statistics support
Publication date: 24 Jul 2026
Type: bugfix
Affected Mageia releases : 10
Description Updated Xonotic packages to fix broken online statistics support. References SRPMS 10/core
Type: bugfix
Affected Mageia releases : 10
Description Updated Xonotic packages to fix broken online statistics support. References SRPMS 10/core
- xonotic-0.8.6-2.1.mga10
Categorías: Actualizaciones de Seguridad
MGASA-2026-0291 - Updated cifs-utils packages fix a security vulnerability
Publication date: 23 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-12505 Description The updated packages fix a security vulnerability: Local privilege escalation via forged cifs.spnego key description in cifs.upcall. (CVE-2026-12505) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-12505 Description The updated packages fix a security vulnerability: Local privilege escalation via forged cifs.spnego key description in cifs.upcall. (CVE-2026-12505) References
- https://bugs.mageia.org/show_bug.cgi?id=35813
- https://ubuntu.com/security/notices/USN-8496-1
- https://bugzilla.redhat.com/show_bug.cgi?id=2489805
- https://ubuntu.com/security/notices/USN-8496-2
- https://ubuntu.com/security/notices/USN-8496-3
- https://www.cve.org/CVERecord?id=CVE-2026-12505
- cifs-utils-7.5-1.1.mga10
- cifs-utils-7.0-1.2.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0290 - Updated socat package fixes a security vulnerability
Publication date: 23 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-56123 Description The updated package fixes a security vulnerability: Heap Buffer Overflow via SOCKS5 Reply Parser. (CVE-2026-56123) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-56123 Description The updated package fixes a security vulnerability: Heap Buffer Overflow via SOCKS5 Reply Parser. (CVE-2026-56123) References
- https://bugs.mageia.org/show_bug.cgi?id=35794
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/F6FLUO6FYZ6TSE43PLY7QJGUX4N2JXWW/
- https://ubuntu.com/security/notices/USN-8511-1
- https://www.cve.org/CVERecord?id=CVE-2026-56123
- socat-1.8.1.0-1.1.mga10
- socat-1.8.0.2-1.1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0289 - Updated apache packages fix security vulnerabilities
Publication date: 23 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-29167 , CVE-2026-29170 , CVE-2026-34355 , CVE-2026-34356 , CVE-2026-42535 , CVE-2026-42536 , CVE-2026-43951 , CVE-2026-44119 , CVE-2026-44185 , CVE-2026-44186 , CVE-2026-44631 , CVE-2026-48913 , CVE-2026-49975 Description The updated packages fix security vulnerabilities: Apache HTTP Server: mod_ldap per-dir use-after-free. (CVE-2026-29167) Apache HTTP Server: mod_proxy_ftp XSS. (CVE-2026-29170) Apache HTTP Server: mod_proxy_html buffer overflow. (CVE-2026-34355) Apache HTTP Server: ProxyPassReverseCookieMap buffer overflow. (CVE-2026-34356) Apache HTTP Server: mod_dav_fs protected directory access. (CVE-2026-42535) Apache HTTP Server: mod_xml2enc heap overflow. (CVE-2026-42536) Apache HTTP Server: OOB Read in `merge_response_headers` can cause crash. (CVE-2026-43951) Apache HTTP Server: escalation of privilege through expressions in .htaccess in multiple modules. (CVE-2026-44119) Apache HTTP Server: Stack Buffer Over-Read in mod_ssl OCSP `send_request`. (CVE-2026-44185) Apache HTTP Server: Loop in `proxy_ftp_handler` in mod_proxy_ftp. (CVE-2026-44186) Apache HTTP Server: Heap Underflow in `ap_regname` via Signed Char Overflow. (CVE-2026-44631) Apache HTTP Server: mod_http2 memory corruption when file handles exhausted. (CVE-2026-48913) Apache HTTP Server: mod_http2 denial of service. (CVE-2026-49975) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-29167 , CVE-2026-29170 , CVE-2026-34355 , CVE-2026-34356 , CVE-2026-42535 , CVE-2026-42536 , CVE-2026-43951 , CVE-2026-44119 , CVE-2026-44185 , CVE-2026-44186 , CVE-2026-44631 , CVE-2026-48913 , CVE-2026-49975 Description The updated packages fix security vulnerabilities: Apache HTTP Server: mod_ldap per-dir use-after-free. (CVE-2026-29167) Apache HTTP Server: mod_proxy_ftp XSS. (CVE-2026-29170) Apache HTTP Server: mod_proxy_html buffer overflow. (CVE-2026-34355) Apache HTTP Server: ProxyPassReverseCookieMap buffer overflow. (CVE-2026-34356) Apache HTTP Server: mod_dav_fs protected directory access. (CVE-2026-42535) Apache HTTP Server: mod_xml2enc heap overflow. (CVE-2026-42536) Apache HTTP Server: OOB Read in `merge_response_headers` can cause crash. (CVE-2026-43951) Apache HTTP Server: escalation of privilege through expressions in .htaccess in multiple modules. (CVE-2026-44119) Apache HTTP Server: Stack Buffer Over-Read in mod_ssl OCSP `send_request`. (CVE-2026-44185) Apache HTTP Server: Loop in `proxy_ftp_handler` in mod_proxy_ftp. (CVE-2026-44186) Apache HTTP Server: Heap Underflow in `ap_regname` via Signed Char Overflow. (CVE-2026-44631) Apache HTTP Server: mod_http2 memory corruption when file handles exhausted. (CVE-2026-48913) Apache HTTP Server: mod_http2 denial of service. (CVE-2026-49975) References
- https://bugs.mageia.org/show_bug.cgi?id=35625
- https://www.openwall.com/lists/oss-security/2026/06/03/3
- https://blog.calif.io/p/codex-discovered-a-hidden-http2-bomb
- https://lists.debian.org/debian-security-announce/2026/msg00234.html
- https://www.openwall.com/lists/oss-security/2026/06/08/4
- https://www.openwall.com/lists/oss-security/2026/06/08/5
- https://www.openwall.com/lists/oss-security/2026/06/08/6
- https://www.openwall.com/lists/oss-security/2026/06/08/7
- https://www.openwall.com/lists/oss-security/2026/06/08/8
- https://www.openwall.com/lists/oss-security/2026/06/08/9
- https://www.openwall.com/lists/oss-security/2026/06/08/10
- https://www.openwall.com/lists/oss-security/2026/06/08/11
- https://www.openwall.com/lists/oss-security/2026/06/08/12
- https://www.openwall.com/lists/oss-security/2026/06/08/13
- https://www.openwall.com/lists/oss-security/2026/06/08/14
- https://www.openwall.com/lists/oss-security/2026/06/08/15
- https://www.openwall.com/lists/oss-security/2026/06/08/16
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7R2KWQ6IEDZQHPWK66QN6DG4LW6X3OUM/
- https://www.cve.org/CVERecord?id=CVE-2026-29167
- https://www.cve.org/CVERecord?id=CVE-2026-29170
- https://www.cve.org/CVERecord?id=CVE-2026-34355
- https://www.cve.org/CVERecord?id=CVE-2026-34356
- https://www.cve.org/CVERecord?id=CVE-2026-42535
- https://www.cve.org/CVERecord?id=CVE-2026-42536
- https://www.cve.org/CVERecord?id=CVE-2026-43951
- https://www.cve.org/CVERecord?id=CVE-2026-44119
- https://www.cve.org/CVERecord?id=CVE-2026-44185
- https://www.cve.org/CVERecord?id=CVE-2026-44186
- https://www.cve.org/CVERecord?id=CVE-2026-44631
- https://www.cve.org/CVERecord?id=CVE-2026-48913
- https://www.cve.org/CVERecord?id=CVE-2026-49975
- apache-2.4.68-1.mga10
- apache-2.4.68-1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0288 - Updated dnsmasq packages fix security vulnerabilities
Publication date: 23 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-12725 , CVE-2026-12969 Description The updated dnsmasq packages fix multiple security issues: A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and query logging are both enabled, logging of DS or DNSKEY replies containing unsupported algorithm or digest types can cause dnsmasq to write past the end of an internal logging buffer. A remote attacker able to supply such a DNS response may crash the dnsmasq process, resulting in denial of service. (CVE-2026-12725) An out-of-bounds read vulnerability exists in dnsmasq's find_soa() function in src/rfc1035.c. When parsing NS section records, extract_name() is called with extrabytes=0, failing to validate that 10 additional bytes exist for fixed-length DNS record fields. A remote attacker controlling a DNS zone can exploit this via a crafted NXDOMAIN response to cause a 10-byte heap out-of-bounds read, potentially accessing stale data from prior transactions. (CVE-2026-12969) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-12725 , CVE-2026-12969 Description The updated dnsmasq packages fix multiple security issues: A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and query logging are both enabled, logging of DS or DNSKEY replies containing unsupported algorithm or digest types can cause dnsmasq to write past the end of an internal logging buffer. A remote attacker able to supply such a DNS response may crash the dnsmasq process, resulting in denial of service. (CVE-2026-12725) An out-of-bounds read vulnerability exists in dnsmasq's find_soa() function in src/rfc1035.c. When parsing NS section records, extract_name() is called with extrabytes=0, failing to validate that 10 additional bytes exist for fixed-length DNS record fields. A remote attacker controlling a DNS zone can exploit this via a crafted NXDOMAIN response to cause a 10-byte heap out-of-bounds read, potentially accessing stale data from prior transactions. (CVE-2026-12969) References
- https://bugs.mageia.org/show_bug.cgi?id=35935
- https://app.opencve.io/cve/CVE-2026-12725
- https://app.opencve.io/cve/CVE-2026-12969
- https://ubuntu.com/security/notices/USN-8542-1
- https://bugzilla.redhat.com/show_bug.cgi?id=2490763
- https://bugzilla.redhat.com/show_bug.cgi?id=2491663
- https://thekelleys.org.uk/dnsmasq/CHANGELOG
- https://www.cve.org/CVERecord?id=CVE-2026-12725
- https://www.cve.org/CVERecord?id=CVE-2026-12969
- dnsmasq-2.93-1.mga10
- dnsmasq-2.93-1.mga9
Categorías: Actualizaciones de Seguridad
MGAA-2026-0062 - Updated krita-ai-diffusion packages fix bug
Publication date: 23 Jul 2026
Type: bugfix
Affected Mageia releases : 10
Description The plugin can't connect to the server to make AI calls. This update fixes the reported issue and updates the plugin to version 1.52.1. References
Type: bugfix
Affected Mageia releases : 10
Description The plugin can't connect to the server to make AI calls. This update fixes the reported issue and updates the plugin to version 1.52.1. References
- https://bugs.mageia.org/show_bug.cgi?id=35955
- https://github.com/Acly/krita-ai-diffusion/releases/tag/v1.52.1
- https://github.com/Acly/krita-ai-diffusion/releases/tag/v1.52.0
- https://github.com/Acly/krita-ai-diffusion/releases/tag/v1.51.1
- https://github.com/Acly/krita-ai-diffusion/releases/tag/v1.51.0
- https://github.com/Acly/krita-ai-diffusion/releases/tag/v1.50.0
- https://github.com/Acly/krita-ai-diffusion/releases/tag/v1.49.1
- krita-ai-diffusion-1.52.1-1.mga10
Categorías: Actualizaciones de Seguridad
MGAA-2026-0061 - Updated nut packages fix a bug
Publication date: 23 Jul 2026
Type: bugfix
Affected Mageia releases : 10
Description nut-scanner failed to start. This update fixes the issue and also updates the nut packages to the latest maintained release. References SRPMS 10/core
Type: bugfix
Affected Mageia releases : 10
Description nut-scanner failed to start. This update fixes the issue and also updates the nut packages to the latest maintained release. References SRPMS 10/core
- nut-2.8.5-1.mga10
Categorías: Actualizaciones de Seguridad
MGAA-2026-0060 - Updated warpinator packages fix launch failure.
Publication date: 23 Jul 2026
Type: bugfix
Affected Mageia releases : 10
Description warpinator uses the grpcio module, but with a stamp of the used module version. The stamp was not in accordance with the version of the provided module in the distro, preventing launch. This update fixes that. References SRPMS 10/core
Type: bugfix
Affected Mageia releases : 10
Description warpinator uses the grpcio module, but with a stamp of the used module version. The stamp was not in accordance with the version of the provided module in the distro, preventing launch. This update fixes that. References SRPMS 10/core
- warpinator-2.0.4-1.mga10
Categorías: Actualizaciones de Seguridad
MGASA-2026-0287 - Updated tig package fixes a security vulnerability
Publication date: 21 Jul 2026
Type: security
Affected Mageia releases : 10
Description The updated package fixes a security vulnerability: editor command injection vulnerability. References
Type: security
Affected Mageia releases : 10
Description The updated package fixes a security vulnerability: editor command injection vulnerability. References
- https://bugs.mageia.org/show_bug.cgi?id=35720
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SEP2W3H6GWB2VQQATCPANKNKGGK2TGMP/
- https://github.com/jonas/tig/issues/1432
- tig-2.6.1-1.mga10
Categorías: Actualizaciones de Seguridad
MGAA-2026-0059 - Updated mageia-theme, grub2 & grub2-mageia-theme-dejavu packages fix bugs
Publication date: 21 Jul 2026
Type: bugfix
Affected Mageia releases : 10
Description The updates packages fix issues in our signature background. The images have been reworked providing a better look. Building with mock is fixed allowing the produced mageia-theme and mageia-theme-extra packages to be installed together. Fix the plymouth theme which still was the Mageia 9 version after upgrades. Behind the scenes some processes are now done at build time, avoiding recurring issues with interlaced images. References SRPMS 10/core
Type: bugfix
Affected Mageia releases : 10
Description The updates packages fix issues in our signature background. The images have been reworked providing a better look. Building with mock is fixed allowing the produced mageia-theme and mageia-theme-extra packages to be installed together. Fix the plymouth theme which still was the Mageia 9 version after upgrades. Behind the scenes some processes are now done at build time, avoiding recurring issues with interlaced images. References SRPMS 10/core
- mageia-theme-10.11-1.1.mga10
- grub2-2.12-15.1.mga10
- grub2-mageia-theme-dejavu-1.0-17.1.mga10
Categorías: Actualizaciones de Seguridad
MGAA-2026-0058 - Updated serd, sord, sratom, suil and lilv to the latest versions
Publication date: 21 Jul 2026
Type: bugfix
Affected Mageia releases : 10
Description The last versions of serd, sord, sratom, suil and lilv couldn't be submitted because of Cauldron FREEZE. References SRPMS 10/core
Type: bugfix
Affected Mageia releases : 10
Description The last versions of serd, sord, sratom, suil and lilv couldn't be submitted because of Cauldron FREEZE. References SRPMS 10/core
- serd-0.32.8-1.mga10
- sord-0.16.22-1.mga10
- sratom-0.6.22-1.mga10
- lilv-0.26.4-1.mga10
- suil-0.10.26-3.mga10
Categorías: Actualizaciones de Seguridad
MGASA-2026-0286 - Updated perl-CGI-Session package fixes a security vulnerability
Publication date: 20 Jul 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-56016 Description The updated package fixes a security vulnerability: CGI::Session::ID::md5 versions before 4.49 for Perl generate predictable session ids from low-entropy sources. (CVE-2026-56016) References
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-56016 Description The updated package fixes a security vulnerability: CGI::Session::ID::md5 versions before 4.49 for Perl generate predictable session ids from low-entropy sources. (CVE-2026-56016) References
- https://bugs.mageia.org/show_bug.cgi?id=35800
- https://www.openwall.com/lists/oss-security/2026/07/01/6
- https://metacpan.org/release/MARKSTOS/CGI-Session-4.49/changes
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/OXFQ3DBWPONO7MHLPUC3HP44MVOLIY4B/
- https://www.cve.org/CVERecord?id=CVE-2026-56016
- perl-CGI-Session-4.490.0-1.mga10
Categorías: Actualizaciones de Seguridad
MGASA-2026-0285 - Updated php8.4 and php8.5 packages fix security vulnerabilities
Publication date: 20 Jul 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-14355 Description The updated php8.4 and php8.5 packages fix several security issues, e.g. Memory corruption (zend_mm_heap corrupted) in openssl_encrypt with AES-WRAP-PAD. (CVE-2026-14355) References
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-14355 Description The updated php8.4 and php8.5 packages fix several security issues, e.g. Memory corruption (zend_mm_heap corrupted) in openssl_encrypt with AES-WRAP-PAD. (CVE-2026-14355) References
- https://bugs.mageia.org/show_bug.cgi?id=35809
- https://www.php.net/ChangeLog-8.php#8.4.23
- https://www.php.net/ChangeLog-8.php#8.5.8
- https://www.cve.org/CVERecord?id=CVE-2026-14355
- php8.4-8.4.23-1.mga10
- php8.5-8.5.8-1.mga10
Categorías: Actualizaciones de Seguridad
MGASA-2026-0284 - Updated perl-Imager package fixes security vulnerabilities
Publication date: 20 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2024-53901 , CVE-2026-13705 , CVE-2026-13708 , CVE-2026-14454 Description The updated package fixes security vulnerabilities: The Imager package before 1.025 for Perl has a heap-based buffer overflow leading to denial of service, or possibly unspecified other impact, when the trim() method is called on a crafted input image. (CVE-2024-53901) Imager versions before 1.032 for Perl have a heap out-of-bounds read in the bundled Imager::File::SGI reader via a 16-bit RLE literal run in read_rgb_16_rle. (CVE-2026-13705) Imager::File::JPEG versions before 1.003 for Perl leak heap memory when reading a JPEG with repeated APP13 markers in i_readjpeg_wiol. (CVE-2026-13708) Imager versions before 1.033 for Perl treat unsigned EXIF IFD entry counts as signed. (CVE-2026-14454) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2024-53901 , CVE-2026-13705 , CVE-2026-13708 , CVE-2026-14454 Description The updated package fixes security vulnerabilities: The Imager package before 1.025 for Perl has a heap-based buffer overflow leading to denial of service, or possibly unspecified other impact, when the trim() method is called on a crafted input image. (CVE-2024-53901) Imager versions before 1.032 for Perl have a heap out-of-bounds read in the bundled Imager::File::SGI reader via a 16-bit RLE literal run in read_rgb_16_rle. (CVE-2026-13705) Imager::File::JPEG versions before 1.003 for Perl leak heap memory when reading a JPEG with repeated APP13 markers in i_readjpeg_wiol. (CVE-2026-13708) Imager versions before 1.033 for Perl treat unsigned EXIF IFD entry counts as signed. (CVE-2026-14454) References
- https://bugs.mageia.org/show_bug.cgi?id=35848
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7QJU7MFFAP73YEH5YEG35EDMGSNOZ3O5/
- https://www.openwall.com/lists/oss-security/2026/07/08/6
- https://lists.security.metacpan.org/cve-announce/msg/41572386/
- https://lists.security.metacpan.org/cve-announce/msg/41637674/
- https://github.com/briandfoy/cpan-security-advisory/issues/167
- https://www.cve.org/CVERecord?id=CVE-2024-53901
- https://www.cve.org/CVERecord?id=CVE-2026-13705
- https://www.cve.org/CVERecord?id=CVE-2026-13708
- https://www.cve.org/CVERecord?id=CVE-2026-14454
- perl-Imager-1.33.0-1.mga10
- perl-Imager-1.19.0-2.2.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0283 - Updated perl-JavaScript-Minifier-XS package fixes security vulnerabilities
Publication date: 20 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-56017 , CVE-2026-56018 Description The updated package fixes security vulnerabilities: JavaScript::Minifier::XS versions before 0.16 for Perl crash with a NULL pointer dereference when the first meaningful token of the input is a slash. (CVE-2026-56017) JavaScript::Minifier::XS versions before 0.16 for Perl leak memory on every call to minify(), allowing unbounded memory growth. (CVE-2026-56018) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-56017 , CVE-2026-56018 Description The updated package fixes security vulnerabilities: JavaScript::Minifier::XS versions before 0.16 for Perl crash with a NULL pointer dereference when the first meaningful token of the input is a slash. (CVE-2026-56017) JavaScript::Minifier::XS versions before 0.16 for Perl leak memory on every call to minify(), allowing unbounded memory growth. (CVE-2026-56018) References
- https://bugs.mageia.org/show_bug.cgi?id=35780
- https://www.openwall.com/lists/oss-security/2026/06/29/16
- https://www.openwall.com/lists/oss-security/2026/06/29/17
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/JRQ3MRFSD4VDM6LUSDFWM5CGXIVDZXIV/
- https://www.cve.org/CVERecord?id=CVE-2026-56017
- https://www.cve.org/CVERecord?id=CVE-2026-56018
- perl-JavaScript-Minifier-XS-0.160.0-1.mga10
- perl-JavaScript-Minifier-XS-0.160.0-1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0282 - Updated graphicsmagick packages fix a security vulnerability
Publication date: 20 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-46523 Description The updated packages fix a security vulnerability: Use-After-Free in MSL decoder. (CVE-2026-46523) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-46523 Description The updated packages fix a security vulnerability: Use-After-Free in MSL decoder. (CVE-2026-46523) References
- https://bugs.mageia.org/show_bug.cgi?id=35775
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/IDMJWDSIIAL5DRGYDMBZ2JUPEQH7QCMJ/
- https://www.cve.org/CVERecord?id=CVE-2026-46523
- graphicsmagick-1.3.46-5.1.mga10
- graphicsmagick-1.3.46-5.1.mga10.tainted
- graphicsmagick-1.3.40-1.7.mga9
- graphicsmagick-1.3.40-1.7.mga9.tainted
Categorías: Actualizaciones de Seguridad




