Lector de Feeds
Cooker
Cooker is the OpenMandriva Lx development branch.
This is where developers do the actual work of developing packages and the distro itself. Because of the nature of this continual work process Cooker breaks at times.
If you are not used to problem solving on computers at a very high level Cooker is not for you.
-
arrow_drop_downCOOKER Plasma
The Plasma Extended version is basically a complete desktop for most non-technical users. It features software from KDE.org and other Qt based software. It includes software for most day to day tasks.
Donate
We are a community-driven initiative dedicated to fostering open source innovation in the realm of operating systems. Since our inception, we have been committed to creating a user-friendly, cutting-edge Linux distribution that empowers users worldwide. However, to continue our mission and enhance our offerings, we need your support.
Why Donate?Your donations play a crucial role in sustaining and advancing the OpenMandriva project. With your generous contributions, we can:
Downloads
OpenMandriva flagship release is ROME (rolling)
Current Rock release is OpenMandriva Lx 6.0
Development release is Cooker
Spins are alternative desktops environments
Choose your release The OpenMandriva project offers different image types available for download.If in doubt, use the full featured Plasma6 x86_64 ISO image. Download the ISO file
Mirror download (sourceforge.net)
Enter the folders, select the release in the list, it should automatically open a download page from a mirror nearby your location.
If in doubt, go to OpenMandriva homepage at SourceForge and click the big green button “Download”
Frequently asked questions
-
arrow_drop_downTell readers about the founding of Open Mandriva
This is essentially just old history - maybe the most interesting part is that it means we are one of the oldest distributions still alive today.
When Mandriva (previously Mandrake) went out of business, the community didn’t want to let the distribution die, so it was turned over to a team consisting of previous contributors, and people from related similar projects (Unity Linux, Ark Linux) joined forces to form OpenMandriva.
We agreed with what remained of Mandriva on terms for all further development:
License -
arrow_drop_downWhat does OpenMandriva inherit from Mandrake? Technology? Organization? Philosophy?
The original source code;
The initial team, or part of it;
The idea of building an operating system that is simple enough for someone who has never seen Linux to get productive with, without dumbing it down to the point that it stops being useful to experts.
OpenMandriva philosophy is inspired by the Open Source principles philosophy. -
arrow_drop_downAny stats about downloads, commits, developers?
Given we are an Open Source project with quite a few mirrors and bittorrent downloads, and we have no idea how many people share their download with others, it is impossible to get accurate numbers.
We can get documented stats only from SourceForge mirror. Maybe worth to mention that many users and/or newcomers are invited to download and test the latest ISO images snapshots, during development cycle in-between the officially announced releases, directly from our build server, ABF (cf. Forum topics Most recent Cooker ISO and Most recent ROME (rolling) ISO which we keep constantly up-to-date).
Of course we have more accurate numbers about developers and commits.
There are 7 main developers, and a few people who submit a patch once in a while.
There have been 82350 commits in the last year, out of which 7323 were in the last month.
The commits go to our repositories OpenMandriva Association and OpenMandriva Software and the packages are built on ABF: [1] [2] -
arrow_drop_downHow is OpenMandriva organized, and how are decisions made?
OpenMandriva has 2 main entities:
Council for what concerning the legal/paperworks, PR and organization side;
Technical Committee for what concerning the products’ technical development side.
The decisions are made depending on the specific subject however more often than not they are virtually identical pertaining to both sides.
When at all possible we aim to reach consensus for final decisions. Crucial help is provided by the shared target and common sense.
People who have been contributing consistently over some time are invited into the relevant entities. -
arrow_drop_downHow does the Association interact with the community?
-
Main website /
(News)
-
Get involved
If you have time, we welcome your help in various areas:
DevelopmentCheck the developers documentation, join the conversation, and have a look at the bug-tracking system and to get in touch with the developers community and get things done
WritingHelp us improve the documentation, materials and communication
TranslationTranslators, help us translate web materials, OpenMandriva Lx and other projects
Keep the Community aliveParticipate in the forum, write your experience with Rock or ROME, share your knowledge, publish your desktop screenshots, help the other users, or even just chat
Rock
Rock (OMLx 6.0) is the home and workstation edition published by the OpenMandriva Association. Also for individual users who do not want many updates, be it because they prefer their system to remain the same or because of slow internet connection. Releases are scheduled around once a year.
It would be the most stable and suitable for users that like things to stay as they are and just work. Package upgrades will be limited mostly to bug fixes, and security updates.
ROME
ROME is the rolling edition, designed for individual users.
It is designed to be a working, usable system and will have the most up to date packages.
ROME users should be familiar with the command line or terminal (Konsole) and be able to use it at times.
-
arrow_drop_downPlasma 6
The Plasma Extended version is basically a complete desktop for most non-technical users. It features software from KDE.org and other Qt based software. It includes software for most day to day tasks.
Server
OpenMandriva Rock/ROME for servers is a fully independent and flexible Linux distribution, installable with only the necessary programs for starting a server environment (eg: no GUI, no desktop apps, but you can of course add them later)
It can run on bare metal as well as inside containers and VMs, such as OpenStack, Docker, or OCI
It supports AArch64, x86, and znver1 (specially optimized x86 build for Ryzen/EPYC processors) and scales from a Raspberry Pi all the way to a 160-core Ampere server
Spins
Spins is Community alternative desktop proof of concept.
OpenMandriva default desktop environment is the complete, modern KDE Plasma. If you prefer an alternative desktop such as GNOME, LXQt, Xfce or other you can download a Spin.
Do not expect everything to work “out of the box”. They are mainly supported by their maintainers or currently no dedicated maintainers. Bug fixing is not high priority. Any help is welcome.
Which release should I pick?
computer
ROCKRock (OMLx 6.0) is the home and workstation edition
home
ROMEROME is the rolling edition, designed for individual users
developer_mode
COOKERCooker is the OpenMandriva Lx development branch
group
SPINSCommunity alternative desktop proof of concept
MGASA-2026-0443 - Updated pipewire packages fix security vulnerabilities
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-14324 , CVE-2026-14330 Description
RAOP module accepts unbounded Content-Length values and does not check the pw_array_add() return. (CVE-2026-14324) Multiple unbounded alloca() calls in the PulseAudio protocol server. (CVE-2026-14330) References
- https://bugs.mageia.org/show_bug.cgi?id=35929
- https://ubuntu.com/security/notices/USN-8535-1
- https://bugzilla.redhat.com/show_bug.cgi?id=2495903
- https://gitlab.freedesktop.org/pipewire/pipewire/-/work_items/5352
- https://bugzilla.redhat.com/show_bug.cgi?id=2495907
- https://www.cve.org/CVERecord?id=CVE-2026-14324
- https://www.cve.org/CVERecord?id=CVE-2026-14330
- pipewire-1.6.5-1.1.mga10
- pipewire-0.3.85-6.1.mga9
MGASA-2026-0442 - Updated libwebsockets packages fix a security vulnerability
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-10650 Description
warmcat libwebsockets SSH Protocol sshd.c lws_ssh_parse_plaintext resource consumption. (CVE-2026-10650) References
- https://bugs.mageia.org/show_bug.cgi?id=36157
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KMAEZLLRGAX46TX4KZNYWZXYVIWBF3RU/
- https://github.com/biniamf/pocs/tree/main/libwebsockets_sshd-parse-ic-unbounded-alloc
- https://github.com/advisories/GHSA-23jv-8gf4-7r88
- https://www.cve.org/CVERecord?id=CVE-2026-10650
- libwebsockets-4.5.2-1.1.mga10
- libwebsockets-4.3.2-1.1.mga9
MGAA-2026-0133 - Updated amavisd-new package fixes problem starting
Type: bugfix
Affected Mageia releases : 10
Description
amavisd service fails to start. This update fixes the reported issue. References
SRPMS 10/core
- amavisd-new-2.15.0-1.mga10
MGASA-2026-0441 - Updated nss & firefox packages fix security vulnerabilities
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-92005 , CVE-2026-92006 , CVE-2026-92007 , CVE-2026-92008 , CVE-2026-92009 , CVE-2026-92010 , CVE-2026-92011 , CVE-2026-92012 , CVE-2026-92013 , CVE-2026-92014 , CVE-2026-92015 , CVE-2026-92016 , CVE-2026-92017 , CVE-2026-92018 , CVE-2026-92019 , CVE-2026-92020 , CVE-2026-92021 , CVE-2026-92022 , CVE-2026-92023 , CVE-2026-92024 , CVE-2026-92025 , CVE-2026-92026 , CVE-2026-92027 , CVE-2026-92028 , CVE-2026-92029 , CVE-2026-92030 , CVE-2026-92031 , CVE-2026-92032 , CVE-2026-92038 , CVE-2026-92039 , CVE-2026-92041 , CVE-2026-92042 , CVE-2026-92043 , CVE-2026-92044 , CVE-2026-92045 , CVE-2026-92046 , CVE-2026-92047 , CVE-2026-92052 , CVE-2026-92053 , CVE-2026-92054 , CVE-2026-92055 , CVE-2026-92056 , CVE-2026-92057 , CVE-2026-92058 , CVE-2026-92059 , CVE-2026-92060 , CVE-2026-92062 , CVE-2026-92064 , CVE-2026-92067 , CVE-2026-92068 , CVE-2026-92069 , CVE-2026-92070 , CVE-2026-92072 , CVE-2026-92073 , CVE-2026-92074 , CVE-2026-92075 , CVE-2026-92076 , CVE-2026-92077 , CVE-2026-92078 Description
Use-after-free in the Audio/Video: Web Codecs component. (CVE-2026-92005) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-92006) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-92007) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-92008) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-92009) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-92010) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-92011) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-92012) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-92013) Privilege escalation due to incorrect boundary conditions in the Graphics component. (CVE-2026-92014) Privilege escalation in the WebExtensions component. (CVE-2026-92015) Use-after-free in the Disability Access APIs component. (CVE-2026-92016) Privilege escalation in the DOM: Service Workers component. (CVE-2026-92017) Sandbox escape in the DOM: Core & HTML component. (CVE-2026-92018) Mitigation bypass in the Remote Settings Client component. (CVE-2026-92019) Privilege escalation due to incorrect boundary conditions in the Graphics: WebRender component. (CVE-2026-92020) Use-after-free in the JavaScript Engine: JIT component. (CVE-2026-92021) Use-after-free in the DOM: HTML Parser component. (CVE-2026-92022) Use-after-free in the XML component. (CVE-2026-92023) Use-after-free in the SVG component. (CVE-2026-92024) Use-after-free in the DOM: Navigation component. (CVE-2026-92025) Use-after-free in the Networking component. (CVE-2026-92026) Use-after-free in the DOM: Streams component. (CVE-2026-92027) Use-after-free in the DOM: Core & HTML component. (CVE-2026-92028) Use-after-free in the SVG component. (CVE-2026-92029) Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component. (CVE-2026-92030) Information disclosure in the Graphics: ImageLib component. (CVE-2026-92031) Sandbox escape due to invalid pointer in the Graphics component. (CVE-2026-92032) Mitigation bypass in the Remote Settings Client component. (CVE-2026-92038) Mitigation bypass in the DOM: Notifications component. (CVE-2026-92039) Mitigation bypass in the DOM: Networking component. (CVE-2026-92041) Race condition in the DOM: Content Processes component. (CVE-2026-92042) Privilege escalation due to incorrect boundary conditions in the Audio/Video component. (CVE-2026-92043) Information disclosure in the Networking: HTTP component. (CVE-2026-92044) Sandbox escape due to incorrect boundary conditions in the WebRTC component. (CVE-2026-92045) Use-after-free in the Graphics component. (CVE-2026-92046) Privilege escalation in the Crash Reporting component. (CVE-2026-92047) Privilege escalation due to uninitialized memory in the Graphics: CanvasWebGL component. (CVE-2026-92052) Privilege escalation in the Graphics: CanvasWebGL component. (CVE-2026-92053) Privilege escalation in the Memory component. (CVE-2026-92054) Privilege escalation in the DevTools component. (CVE-2026-92055) Use-after-free in the Graphics: Text component. (CVE-2026-92056) Mitigation bypass in the Enterprise Policies component. (CVE-2026-92057) Use-after-free in the Graphics component. (CVE-2026-92058) Incorrect boundary conditions in the DOM: Editor component. (CVE-2026-92059) Use-after-free in the Internationalization component. (CVE-2026-92060) Privilege escalation in the Session Restore component. (CVE-2026-92062) Use-after-free in the Widget: Gtk component. (CVE-2026-92067) Site isolation issue in the Reader Mode component. (CVE-2026-92068) Spoofing issue in the DOM: Navigation component. (CVE-2026-92069) Information disclosure in the Networking component. (CVE-2026-92070) Incorrect boundary conditions in the Safe Browsing component. (CVE-2026-92072) Privilege escalation in the Enterprise Policies component. (CVE-2026-92073) Mitigation bypass in the Popup Blocker component. (CVE-2026-92074) Mitigation bypass in the Networking component. (CVE-2026-92075) Incorrect boundary conditions in the Networking component. (CVE-2026-92076) Denial-of-service in the SVG component. (CVE-2026-92077) Denial-of-service in the Security component. (CVE-2026-92078) References
- https://bugs.mageia.org/show_bug.cgi?id=36317
- https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_129.html
- https://www.firefox.com/en-US/firefox/140.16.0/releasenotes/
- https://www.firefox.com/en-US/firefox/153.3.0/releasenotes/
- https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/
- https://www.mozilla.org/en-US/security/advisories/mfsa2026-93/
- https://www.cve.org/CVERecord?id=CVE-2026-92005
- https://www.cve.org/CVERecord?id=CVE-2026-92006
- https://www.cve.org/CVERecord?id=CVE-2026-92007
- https://www.cve.org/CVERecord?id=CVE-2026-92008
- https://www.cve.org/CVERecord?id=CVE-2026-92009
- https://www.cve.org/CVERecord?id=CVE-2026-92010
- https://www.cve.org/CVERecord?id=CVE-2026-92011
- https://www.cve.org/CVERecord?id=CVE-2026-92012
- https://www.cve.org/CVERecord?id=CVE-2026-92013
- https://www.cve.org/CVERecord?id=CVE-2026-92014
- https://www.cve.org/CVERecord?id=CVE-2026-92015
- https://www.cve.org/CVERecord?id=CVE-2026-92016
- https://www.cve.org/CVERecord?id=CVE-2026-92017
- https://www.cve.org/CVERecord?id=CVE-2026-92018
- https://www.cve.org/CVERecord?id=CVE-2026-92019
- https://www.cve.org/CVERecord?id=CVE-2026-92020
- https://www.cve.org/CVERecord?id=CVE-2026-92021
- https://www.cve.org/CVERecord?id=CVE-2026-92022
- https://www.cve.org/CVERecord?id=CVE-2026-92023
- https://www.cve.org/CVERecord?id=CVE-2026-92024
- https://www.cve.org/CVERecord?id=CVE-2026-92025
- https://www.cve.org/CVERecord?id=CVE-2026-92026
- https://www.cve.org/CVERecord?id=CVE-2026-92027
- https://www.cve.org/CVERecord?id=CVE-2026-92028
- https://www.cve.org/CVERecord?id=CVE-2026-92029
- https://www.cve.org/CVERecord?id=CVE-2026-92030
- https://www.cve.org/CVERecord?id=CVE-2026-92031
- https://www.cve.org/CVERecord?id=CVE-2026-92032
- https://www.cve.org/CVERecord?id=CVE-2026-92038
- https://www.cve.org/CVERecord?id=CVE-2026-92039
- https://www.cve.org/CVERecord?id=CVE-2026-92041
- https://www.cve.org/CVERecord?id=CVE-2026-92042
- https://www.cve.org/CVERecord?id=CVE-2026-92043
- https://www.cve.org/CVERecord?id=CVE-2026-92044
- https://www.cve.org/CVERecord?id=CVE-2026-92045
- https://www.cve.org/CVERecord?id=CVE-2026-92046
- https://www.cve.org/CVERecord?id=CVE-2026-92047
- https://www.cve.org/CVERecord?id=CVE-2026-92052
- https://www.cve.org/CVERecord?id=CVE-2026-92053
- https://www.cve.org/CVERecord?id=CVE-2026-92054
- https://www.cve.org/CVERecord?id=CVE-2026-92055
- https://www.cve.org/CVERecord?id=CVE-2026-92056
- https://www.cve.org/CVERecord?id=CVE-2026-92057
- https://www.cve.org/CVERecord?id=CVE-2026-92058
- https://www.cve.org/CVERecord?id=CVE-2026-92059
- https://www.cve.org/CVERecord?id=CVE-2026-92060
- https://www.cve.org/CVERecord?id=CVE-2026-92062
- https://www.cve.org/CVERecord?id=CVE-2026-92064
- https://www.cve.org/CVERecord?id=CVE-2026-92067
- https://www.cve.org/CVERecord?id=CVE-2026-92068
- https://www.cve.org/CVERecord?id=CVE-2026-92069
- https://www.cve.org/CVERecord?id=CVE-2026-92070
- https://www.cve.org/CVERecord?id=CVE-2026-92072
- https://www.cve.org/CVERecord?id=CVE-2026-92073
- https://www.cve.org/CVERecord?id=CVE-2026-92074
- https://www.cve.org/CVERecord?id=CVE-2026-92075
- https://www.cve.org/CVERecord?id=CVE-2026-92076
- https://www.cve.org/CVERecord?id=CVE-2026-92077
- https://www.cve.org/CVERecord?id=CVE-2026-92078
- firefox-l10n-153.3.0-1.mga10
- nss-3.129.0-1.mga10
- firefox-153.3.0-1.mga10
- firefox-l10n-140.16.0-1.mga9
- nss-3.129.0-1.mga9
- firefox-140.16.0-1.mga9
MGASA-2026-0440 - Updated borgbackup package fixes a security vulnerability
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-62268 Description
The updated package fixes a security vulnerability: CVE-2026-62268. References
- https://bugs.mageia.org/show_bug.cgi?id=36163
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SHGZVBSSCWNFGJ5CQLE5BHFNNORWRSGK/
- https://www.cve.org/CVERecord?id=CVE-2026-62268
- borgbackup-1.4.5-1.mga10
MGASA-2026-0439 - Updated coreutils package fixes a security vulnerability
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-56391 Description
Out‑of‑bounds Read in GNU coreutils. (CVE-2026-56391) References
- https://bugs.mageia.org/show_bug.cgi?id=36171
- https://www.openwall.com/lists/oss-security/2026/07/25/2
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NBV4TP2X6G6D4ITB6FA6CAPLJARRHBQS/
- https://ubuntu.com/security/notices/USN-8697-1
- https://www.cve.org/CVERecord?id=CVE-2026-56391
- coreutils-9.8-3.mga10
MGASA-2026-0438 - Updated libnfs package fixes a security vulnerability
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-57918 Description
libnfs through 6.0.2 before 935b8db has an xid integer underflow in READ_IOVEC in rpc_read_from_socket in lib/socket.c during a connection to a crafted NFS server, when the expected pdu size exceeds the absolute pdu size from the xid/record-marker. (CVE-2026-57918) References
- https://bugs.mageia.org/show_bug.cgi?id=36185
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DOJLZCLBA4FYYVRVR6YGNNEBZAVEEQ3G/
- https://www.cve.org/CVERecord?id=CVE-2026-57918
- libnfs-6.0.2-2.2.mga10
MGAA-2026-0132 - Updated fonts-ttf-bitstream-vera, fira-code-fonts & fonts-ttf-urw packages fix bug
Type: bugfix
Affected Mageia releases : 10
Description
Type 1 fonts have been deprecated, we are replacing Type 1 fonts by True Type fonts. References
- https://bugs.mageia.org/show_bug.cgi?id=36095
- https://helpx.adobe.com/fonts/web/kb/postscript-type-1-fonts-end-of-support.html
- fonts-ttf-bitstream-vera-1.10-20.1.mga10
- fira-code-fonts-6.2-3.1.mga10
- fonts-ttf-urw-1-7.git20170804.1.mga10
MGAA-2026-0131 - Updated bibletime package fixes bug
Type: bugfix
Affected Mageia releases : 10
Description
bibletime is updated to version 3.2.0 References
SRPMS 10/core
- bibletime-3.2.0-1.mga10
- clucene-2.3.3.4-16.1.mga10




