Lector de Feeds

MGASA-2026-0331 - Updated bind packages fix security vulnerabilities

Mageia Security - 10 Agosto, 2026 - 20:29
Publication date: 10 Aug 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-10723 , CVE-2026-10822 , CVE-2026-11331 , CVE-2026-11605 , CVE-2026-11721 , CVE-2026-12617 , CVE-2026-13204 , CVE-2026-13321 Description
Updated bind packages fix security vulnerabilities: Incorrect acceptance of NSEC3 records. (CVE-2026-10723) Key Record using PRIVATEDNS algorithm may lead to unexpected exit. (CVE-2026-10822) Potential wildcard CNAME RPZ policy bypass. (CVE-2026-11331) Unnecessary validation of DNSSEC signed records. (CVE-2026-11605) Cache poisoning possible with label count discrepancy, RRSIG, and wildcards. (CVE-2026-11721) Record ordering based unexpected exit with CNAME or DNAME. (CVE-2026-12617) Unexpected exit in certain situations with NSEC and NSEC3 both present. (CVE-2026-13204) DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field. (CVE-2026-13321) References
SRPMS 10/core
  • bind-9.20.26-1.mga10

MGASA-2026-0329 - Updated php8.4 packages fix security vulnerabilities

Mageia Security - 10 Agosto, 2026 - 20:29
Publication date: 10 Aug 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-17544 , CVE-2026-9672 , CVE-2026-17543 , CVE-2026-7260 Description
The updated php 8.4 packages fix some security vulnerabilities. See the references for more information. References
SRPMS 10/core
  • php8.4-8.4.24-1.1.mga10

MGASA-2026-0328 - Updated openslide packages fix a security vulnerability

Mageia Security - 10 Agosto, 2026 - 20:29
Publication date: 10 Aug 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-48977 Description
Arbitrary memory write with crafted Ventana BIF file. (CVE-2026-48977) References
SRPMS 10/core
  • openslide-4.0.0-1.1.mga10

MGAA-2026-0085 - Updated rawtherapee package fixes bugs

Mageia Security - 10 Agosto, 2026 - 20:29
Publication date: 10 Aug 2026
Type: bugfix
Affected Mageia releases : 10
Description
This is rawtherapee version 5.13, the latest from upstream. It is a bugfix and features release. References
SRPMS 10/core
  • rawtherapee-5.13-1.mga10

MGAA-2026-0084 - Updated remotebox package fixes dependency on Gtk3

Mageia Security - 10 Agosto, 2026 - 20:29
Publication date: 10 Aug 2026
Type: bugfix
Affected Mageia releases : 10
Description
Upstream ported RemoteBox to Gtk3 long ago, but we still let the package depend on Gtk2. This update fixes the issue. References
SRPMS 10/core
  • remotebox-3.7-1.1.mga10

MGAA-2026-0083 - Updated mock-core-configs & mock-mageia-configs packages fix bug

Mageia Security - 10 Agosto, 2026 - 20:29
Publication date: 10 Aug 2026
Type: bugfix
Affected Mageia releases : 9
Description
mock chroots for mageia 10 still are using the cauldron configuration and don't produce rpm files for mageia 10. This update fixes the reported issue. References
SRPMS 9/core
  • mock-core-configs-39.1-2.4.mga9
  • mock-mageia-configs-9-1.2.mga9

MGASA-2026-0327 - Updated python-starlette package fixes security vulnerabilities

Mageia Security - 9 Agosto, 2026 - 07:02
Publication date: 09 Aug 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2024-28849 , CVE-2025-62727 , CVE-2026-48710 Description
The updated package fixes security vulnerabilities: Proxy-Authorization header kept across hosts. (CVE-2024-28849) Starlette vulnerable to O(n^2) DoS via Range header merging in starlette.responses.FileResponse. (CVE-2025-62727) Security restriction bypass via malformed HTTP Host header. (CVE-2026-48710) References
SRPMS 10/core
  • python-starlette-0.46.0-3.1.mga10
Feed