Lector de Feeds

MGASA-2026-0443 - Updated pipewire packages fix security vulnerabilities

Mageia Security - Hace 12 horas 18 minutos
Publication date: 23 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-14324 , CVE-2026-14330 Description
RAOP module accepts unbounded Content-Length values and does not check the pw_array_add() return. (CVE-2026-14324) Multiple unbounded alloca() calls in the PulseAudio protocol server. (CVE-2026-14330) References
SRPMS 10/core
  • pipewire-1.6.5-1.1.mga10
9/core
  • pipewire-0.3.85-6.1.mga9

MGASA-2026-0442 - Updated libwebsockets packages fix a security vulnerability

Mageia Security - Hace 12 horas 18 minutos
Publication date: 23 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-10650 Description
warmcat libwebsockets SSH Protocol sshd.c lws_ssh_parse_plaintext resource consumption. (CVE-2026-10650) References
SRPMS 10/core
  • libwebsockets-4.5.2-1.1.mga10
9/core
  • libwebsockets-4.3.2-1.1.mga9

MGAA-2026-0133 - Updated amavisd-new package fixes problem starting

Mageia Security - Hace 12 horas 18 minutos
Publication date: 23 Sep 2026
Type: bugfix
Affected Mageia releases : 10
Description
amavisd service fails to start. This update fixes the reported issue. References
SRPMS 10/core
  • amavisd-new-2.15.0-1.mga10

MGASA-2026-0441 - Updated nss & firefox packages fix security vulnerabilities

Mageia Security - 23 Septiembre, 2026 - 17:56
Publication date: 23 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-92005 , CVE-2026-92006 , CVE-2026-92007 , CVE-2026-92008 , CVE-2026-92009 , CVE-2026-92010 , CVE-2026-92011 , CVE-2026-92012 , CVE-2026-92013 , CVE-2026-92014 , CVE-2026-92015 , CVE-2026-92016 , CVE-2026-92017 , CVE-2026-92018 , CVE-2026-92019 , CVE-2026-92020 , CVE-2026-92021 , CVE-2026-92022 , CVE-2026-92023 , CVE-2026-92024 , CVE-2026-92025 , CVE-2026-92026 , CVE-2026-92027 , CVE-2026-92028 , CVE-2026-92029 , CVE-2026-92030 , CVE-2026-92031 , CVE-2026-92032 , CVE-2026-92038 , CVE-2026-92039 , CVE-2026-92041 , CVE-2026-92042 , CVE-2026-92043 , CVE-2026-92044 , CVE-2026-92045 , CVE-2026-92046 , CVE-2026-92047 , CVE-2026-92052 , CVE-2026-92053 , CVE-2026-92054 , CVE-2026-92055 , CVE-2026-92056 , CVE-2026-92057 , CVE-2026-92058 , CVE-2026-92059 , CVE-2026-92060 , CVE-2026-92062 , CVE-2026-92064 , CVE-2026-92067 , CVE-2026-92068 , CVE-2026-92069 , CVE-2026-92070 , CVE-2026-92072 , CVE-2026-92073 , CVE-2026-92074 , CVE-2026-92075 , CVE-2026-92076 , CVE-2026-92077 , CVE-2026-92078 Description
Use-after-free in the Audio/Video: Web Codecs component. (CVE-2026-92005) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-92006) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-92007) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-92008) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-92009) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-92010) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-92011) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-92012) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-92013) Privilege escalation due to incorrect boundary conditions in the Graphics component. (CVE-2026-92014) Privilege escalation in the WebExtensions component. (CVE-2026-92015) Use-after-free in the Disability Access APIs component. (CVE-2026-92016) Privilege escalation in the DOM: Service Workers component. (CVE-2026-92017) Sandbox escape in the DOM: Core & HTML component. (CVE-2026-92018) Mitigation bypass in the Remote Settings Client component. (CVE-2026-92019) Privilege escalation due to incorrect boundary conditions in the Graphics: WebRender component. (CVE-2026-92020) Use-after-free in the JavaScript Engine: JIT component. (CVE-2026-92021) Use-after-free in the DOM: HTML Parser component. (CVE-2026-92022) Use-after-free in the XML component. (CVE-2026-92023) Use-after-free in the SVG component. (CVE-2026-92024) Use-after-free in the DOM: Navigation component. (CVE-2026-92025) Use-after-free in the Networking component. (CVE-2026-92026) Use-after-free in the DOM: Streams component. (CVE-2026-92027) Use-after-free in the DOM: Core & HTML component. (CVE-2026-92028) Use-after-free in the SVG component. (CVE-2026-92029) Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component. (CVE-2026-92030) Information disclosure in the Graphics: ImageLib component. (CVE-2026-92031) Sandbox escape due to invalid pointer in the Graphics component. (CVE-2026-92032) Mitigation bypass in the Remote Settings Client component. (CVE-2026-92038) Mitigation bypass in the DOM: Notifications component. (CVE-2026-92039) Mitigation bypass in the DOM: Networking component. (CVE-2026-92041) Race condition in the DOM: Content Processes component. (CVE-2026-92042) Privilege escalation due to incorrect boundary conditions in the Audio/Video component. (CVE-2026-92043) Information disclosure in the Networking: HTTP component. (CVE-2026-92044) Sandbox escape due to incorrect boundary conditions in the WebRTC component. (CVE-2026-92045) Use-after-free in the Graphics component. (CVE-2026-92046) Privilege escalation in the Crash Reporting component. (CVE-2026-92047) Privilege escalation due to uninitialized memory in the Graphics: CanvasWebGL component. (CVE-2026-92052) Privilege escalation in the Graphics: CanvasWebGL component. (CVE-2026-92053) Privilege escalation in the Memory component. (CVE-2026-92054) Privilege escalation in the DevTools component. (CVE-2026-92055) Use-after-free in the Graphics: Text component. (CVE-2026-92056) Mitigation bypass in the Enterprise Policies component. (CVE-2026-92057) Use-after-free in the Graphics component. (CVE-2026-92058) Incorrect boundary conditions in the DOM: Editor component. (CVE-2026-92059) Use-after-free in the Internationalization component. (CVE-2026-92060) Privilege escalation in the Session Restore component. (CVE-2026-92062) Use-after-free in the Widget: Gtk component. (CVE-2026-92067) Site isolation issue in the Reader Mode component. (CVE-2026-92068) Spoofing issue in the DOM: Navigation component. (CVE-2026-92069) Information disclosure in the Networking component. (CVE-2026-92070) Incorrect boundary conditions in the Safe Browsing component. (CVE-2026-92072) Privilege escalation in the Enterprise Policies component. (CVE-2026-92073) Mitigation bypass in the Popup Blocker component. (CVE-2026-92074) Mitigation bypass in the Networking component. (CVE-2026-92075) Incorrect boundary conditions in the Networking component. (CVE-2026-92076) Denial-of-service in the SVG component. (CVE-2026-92077) Denial-of-service in the Security component. (CVE-2026-92078) References
SRPMS 10/core
  • firefox-l10n-153.3.0-1.mga10
  • nss-3.129.0-1.mga10
  • firefox-153.3.0-1.mga10
9/core
  • firefox-l10n-140.16.0-1.mga9
  • nss-3.129.0-1.mga9
  • firefox-140.16.0-1.mga9

MGASA-2026-0440 - Updated borgbackup package fixes a security vulnerability

Mageia Security - 23 Septiembre, 2026 - 17:56
Publication date: 23 Sep 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-62268 Description
The updated package fixes a security vulnerability: CVE-2026-62268. References
SRPMS 10/core
  • borgbackup-1.4.5-1.mga10

MGASA-2026-0438 - Updated libnfs package fixes a security vulnerability

Mageia Security - 23 Septiembre, 2026 - 17:56
Publication date: 23 Sep 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-57918 Description
libnfs through 6.0.2 before 935b8db has an xid integer underflow in READ_IOVEC in rpc_read_from_socket in lib/socket.c during a connection to a crafted NFS server, when the expected pdu size exceeds the absolute pdu size from the xid/record-marker. (CVE-2026-57918) References
SRPMS 10/core
  • libnfs-6.0.2-2.2.mga10

MGAA-2026-0132 - Updated fonts-ttf-bitstream-vera, fira-code-fonts & fonts-ttf-urw packages fix bug

Mageia Security - 23 Septiembre, 2026 - 17:56
Publication date: 23 Sep 2026
Type: bugfix
Affected Mageia releases : 10
Description
Type 1 fonts have been deprecated, we are replacing Type 1 fonts by True Type fonts. References
SRPMS 10/core
  • fonts-ttf-bitstream-vera-1.10-20.1.mga10
  • fira-code-fonts-6.2-3.1.mga10
  • fonts-ttf-urw-1-7.git20170804.1.mga10

MGAA-2026-0131 - Updated bibletime package fixes bug

Mageia Security - 23 Septiembre, 2026 - 17:56
Publication date: 23 Sep 2026
Type: bugfix
Affected Mageia releases : 10
Description
bibletime is updated to version 3.2.0 References
SRPMS 10/core
  • bibletime-3.2.0-1.mga10
  • clucene-2.3.3.4-16.1.mga10

MGASA-2026-0437 - Updated perl-Dancer2 packages fix a security vulnerability

Mageia Security - 23 Septiembre, 2026 - 02:45
Publication date: 23 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-13577 Description
Dancer2 versions through 2.1.0 for Perl generate insecure session ids when required CSPRNG modules are unavailable. (CVE-2026-13577) References
SRPMS 10/core
  • perl-Dancer2-2.0.1-1.2.mga10
9/core
  • perl-Dancer2-0.400.1-1.2.mga9

MGASA-2026-0435 - Updated cpio packages fix security vulnerabilities

Mageia Security - 23 Septiembre, 2026 - 02:45
Publication date: 23 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-66484 , CVE-2026-66485 , CVE-2026-66486 Description
Path Traversal in GNU cpio. (CVE-2026-66484) Uncontrolled Memory Allocation in GNU cpio. (CVE-2026-66485) Improper Output Encoding in GNU cpio. (CVE-2026-66486) References
SRPMS 10/core
  • cpio-2.15-3.1.mga10
9/core
  • cpio-2.14-1.1.mga9

MGASA-2026-0434 - Updated diffutils packages fix a security vulnerability

Mageia Security - 23 Septiembre, 2026 - 02:45
Publication date: 23 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-53910 Description
Heap-based Buffer Overflow in GNU diffutils. (CVE-2026-53910) References
SRPMS 10/core
  • diffutils-3.12-1.1.mga10
9/core
  • diffutils-3.10-1.1.mga9

MGAA-2026-0130 - Updated twinkle packages fix bug

Mageia Security - 23 Septiembre, 2026 - 02:45
Publication date: 23 Sep 2026
Type: bugfix
Affected Mageia releases : 10 , 9
Description
twinkle is updated to version 1.11.0 to fix a crash in the application. References
SRPMS 10/core
  • twinkle-1.11.0-1.mga10
9/core
  • twinkle-1.11.0-1.mga9

MGASA-2026-0433 - Updated nmap packages fix a security vulnerability

Mageia Security - 21 Septiembre, 2026 - 21:22
Publication date: 21 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-72712 Description
Denial of Service via Zero-Length TCP Option Packet. (CVE-2026-72712) References
SRPMS 10/core
  • nmap-7.98-1.2.mga10
9/core
  • nmap-7.95-1.2.mga9

MGASA-2026-0432 - Updated vim packages fix security vulnerabilities

Mageia Security - 21 Septiembre, 2026 - 21:22
Publication date: 21 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
Description
Out-of-bounds Access in libvterm Resize Handling in Vim < 9.2.1013 Integer Overflow in Undo File Entry Size Check in Vim < v9.2.1014 && Vim >= v8.1.0688 References
SRPMS 10/core
  • vim-9.2.1054-1.mga10
9/core
  • vim-9.2.1054-1.mga9

MGAA-2026-0129 - Updated conda, python-msgpack & python-pluggy packages fixes bug

Mageia Security - 21 Septiembre, 2026 - 21:22
Publication date: 21 Sep 2026
Type: bugfix
Affected Mageia releases : 10
Description
The conda version we had was not ready for Python 3.13. This update allows it to be compatible, with updates of msgpack and pluggy too. References
SRPMS 10/core
  • conda-26.5.3-1.mga10
  • python-msgpack-1.2.2-1.mga10
  • python-pluggy-1.6.0-1.mga10
Feed