Lector de Feeds

MGASA-2026-0341 - Updated golang packages fix security vulnerabilities

Mageia Security - 30 Agosto, 2026 - 05:17
Publication date: 30 Aug 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-56865 , CVE-2026-56864 , CVE-2026-56859 , CVE-2026-56853 , CVE-2026-56860 , CVE-2026-46600 , CVE-2026-56862 , CVE-2026-56858 , CVE-2026-39821 , CVE-2026-33818 Description
CVE-2026-56865 A malicious GOPROXY was previously capable of forging up to two sumdb tiles that allow for a requested module to bypass the GOSUMDB check and persist attacker-controlled module content to a local Go module cache. CVE-2026-56864 A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log. CVE-2026-56859 Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion. CVE-2026-56853 When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. Previously, this was being done with no timeout applied. ReadHeaderTimeout is now applied for this. CVE-2026-56860 Previously, resolving relative paths containing parent directory (|..|) segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. CVE-2026-4660 Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer. CVE-2026-56862 Previously, we always counted handshake messages, such as KeyUpdate, as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely. CVE-2026-56858 Previously, pathological inputs could close an unescaped |/| early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS. CVE-2026-39821 The ToASCII and ToUnicode functions incorrectly accepted Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returned the name "example.com" rather than an error. CVE-2026-33818 Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures. References
SRPMS 10/core
  • golang-1.25.13-1.mga10
9/core
  • golang-1.25.13-1.mga9

MGASA-2026-0340 - Updated python-nltk packages fix security vulnerabilities

Mageia Security - 29 Agosto, 2026 - 16:47
Publication date: 29 Aug 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-62383 , CVE-2026-62384 , CVE-2026-62385 , CVE-2026-62388 , CVE-2026-63311 , CVE-2026-63312 , CVE-2026-63315 , CVE-2026-71513 , CVE-2026-71514 , CVE-2026-71518 , CVE-2026-78680 , CVE-2026-78681 , CVE-2026-78682 , CVE-2026-78683 , CVE-2026-79657 , CVE-2026-79674 , CVE-2026-79675 , CVE-2026-79676 Description
Updated packages fix security vulnerabilities. Please see the links. References
SRPMS 10/core
  • python-nltk-3.10.3-1.mga10
9/core
  • python-nltk-3.10.3-1.mga9

MGASA-2026-0339 - Updated python-django packages fix security vulnerabilities

Mageia Security - 27 Agosto, 2026 - 20:15
Publication date: 27 Aug 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-15307 , CVE-2026-15337 , CVE-2026-15830 , CVE-2026-15920 Description
CVE-2026-15307: Server-side file-write and request forgery via spatial lookups CVE-2026-15337: Potential denial-of-service vulnerability in `check_for_language()` CVE-2026-15830: Potential denial-of-service vulnerability via nested geometry collections CVE-2026-15920: Potential cross-site scripting via `URLField` values in the admin References
SRPMS 10/core
  • python-django-5.2.17-1.mga10

MGASA-2026-0338 - Updated avahi packages fix security vulnerabilities

Mageia Security - 27 Agosto, 2026 - 20:15
Publication date: 27 Aug 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2025-59529 , CVE-2026-24401 , CVE-2026-34933 Description
Simple protocol server ignores accepts unlimited connections and logs failures without limit. (CVE-2025-59529) Avahi has Uncontrolled Recursion in lookup_handle_cname function. (CVE-2026-24401) Reachable assertion in `transport_flags_from_domain()` via conflicting publish flags crashes avahi-daemon. (CVE-2026-34933) References
SRPMS 10/core
  • avahi-0.8-18.1.mga10
9/core
  • avahi-0.8-10.4.mga9

MGAA-2026-0114 - Updated yt-dlp packages fix bug

Mageia Security - 27 Agosto, 2026 - 20:15
Publication date: 27 Aug 2026
Type: bugfix
Affected Mageia releases : 10 , 9
Description
YouTube videos are no longer loaded and instead terminated with error 'forbidden'. This update fixes the reported issue. References
SRPMS 10/core
  • yt-dlp-2026.08.19-1.1.mga10
9/core
  • yt-dlp-2026.08.19-1.1.mga9
Feed