Lector de Feeds
MGASA-2026-0341 - Updated golang packages fix security vulnerabilities
Publication date: 30 Aug 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-56865 , CVE-2026-56864 , CVE-2026-56859 , CVE-2026-56853 , CVE-2026-56860 , CVE-2026-46600 , CVE-2026-56862 , CVE-2026-56858 , CVE-2026-39821 , CVE-2026-33818 Description
CVE-2026-56865 A malicious GOPROXY was previously capable of forging up to two sumdb tiles that allow for a requested module to bypass the GOSUMDB check and persist attacker-controlled module content to a local Go module cache. CVE-2026-56864 A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log. CVE-2026-56859 Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion. CVE-2026-56853 When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. Previously, this was being done with no timeout applied. ReadHeaderTimeout is now applied for this. CVE-2026-56860 Previously, resolving relative paths containing parent directory (|..|) segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. CVE-2026-4660 Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer. CVE-2026-56862 Previously, we always counted handshake messages, such as KeyUpdate, as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely. CVE-2026-56858 Previously, pathological inputs could close an unescaped |/| early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS. CVE-2026-39821 The ToASCII and ToUnicode functions incorrectly accepted Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returned the name "example.com" rather than an error. CVE-2026-33818 Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures. References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-56865 , CVE-2026-56864 , CVE-2026-56859 , CVE-2026-56853 , CVE-2026-56860 , CVE-2026-46600 , CVE-2026-56862 , CVE-2026-56858 , CVE-2026-39821 , CVE-2026-33818 Description
CVE-2026-56865 A malicious GOPROXY was previously capable of forging up to two sumdb tiles that allow for a requested module to bypass the GOSUMDB check and persist attacker-controlled module content to a local Go module cache. CVE-2026-56864 A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log. CVE-2026-56859 Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion. CVE-2026-56853 When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. Previously, this was being done with no timeout applied. ReadHeaderTimeout is now applied for this. CVE-2026-56860 Previously, resolving relative paths containing parent directory (|..|) segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. CVE-2026-4660 Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer. CVE-2026-56862 Previously, we always counted handshake messages, such as KeyUpdate, as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely. CVE-2026-56858 Previously, pathological inputs could close an unescaped |/| early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS. CVE-2026-39821 The ToASCII and ToUnicode functions incorrectly accepted Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returned the name "example.com" rather than an error. CVE-2026-33818 Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures. References
- https://bugs.mageia.org/show_bug.cgi?id=36142
- https://www.openwall.com/lists/oss-security/2026/08/13/13
- https://www.cve.org/CVERecord?id=CVE-2026-56865
- https://www.cve.org/CVERecord?id=CVE-2026-56864
- https://www.cve.org/CVERecord?id=CVE-2026-56859
- https://www.cve.org/CVERecord?id=CVE-2026-56853
- https://www.cve.org/CVERecord?id=CVE-2026-56860
- https://www.cve.org/CVERecord?id=CVE-2026-46600
- https://www.cve.org/CVERecord?id=CVE-2026-56862
- https://www.cve.org/CVERecord?id=CVE-2026-56858
- https://www.cve.org/CVERecord?id=CVE-2026-39821
- https://www.cve.org/CVERecord?id=CVE-2026-33818
- golang-1.25.13-1.mga10
- golang-1.25.13-1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0340 - Updated python-nltk packages fix security vulnerabilities
Publication date: 29 Aug 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-62383 , CVE-2026-62384 , CVE-2026-62385 , CVE-2026-62388 , CVE-2026-63311 , CVE-2026-63312 , CVE-2026-63315 , CVE-2026-71513 , CVE-2026-71514 , CVE-2026-71518 , CVE-2026-78680 , CVE-2026-78681 , CVE-2026-78682 , CVE-2026-78683 , CVE-2026-79657 , CVE-2026-79674 , CVE-2026-79675 , CVE-2026-79676 Description
Updated packages fix security vulnerabilities. Please see the links. References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-62383 , CVE-2026-62384 , CVE-2026-62385 , CVE-2026-62388 , CVE-2026-63311 , CVE-2026-63312 , CVE-2026-63315 , CVE-2026-71513 , CVE-2026-71514 , CVE-2026-71518 , CVE-2026-78680 , CVE-2026-78681 , CVE-2026-78682 , CVE-2026-78683 , CVE-2026-79657 , CVE-2026-79674 , CVE-2026-79675 , CVE-2026-79676 Description
Updated packages fix security vulnerabilities. Please see the links. References
- https://bugs.mageia.org/show_bug.cgi?id=36186
- https://github.com/nltk/nltk/releases#release-v3.10.0
- https://github.com/nltk/nltk/releases#release-v3.10.2
- https://github.com/nltk/nltk/releases#release-v3.10.3
- https://www.cve.org/CVERecord?id=CVE-2026-62383
- https://www.cve.org/CVERecord?id=CVE-2026-62384
- https://www.cve.org/CVERecord?id=CVE-2026-62385
- https://www.cve.org/CVERecord?id=CVE-2026-62388
- https://www.cve.org/CVERecord?id=CVE-2026-63311
- https://www.cve.org/CVERecord?id=CVE-2026-63312
- https://www.cve.org/CVERecord?id=CVE-2026-63315
- https://www.cve.org/CVERecord?id=CVE-2026-71513
- https://www.cve.org/CVERecord?id=CVE-2026-71514
- https://www.cve.org/CVERecord?id=CVE-2026-71518
- https://www.cve.org/CVERecord?id=CVE-2026-78680
- https://www.cve.org/CVERecord?id=CVE-2026-78681
- https://www.cve.org/CVERecord?id=CVE-2026-78682
- https://www.cve.org/CVERecord?id=CVE-2026-78683
- https://www.cve.org/CVERecord?id=CVE-2026-79657
- https://www.cve.org/CVERecord?id=CVE-2026-79674
- https://www.cve.org/CVERecord?id=CVE-2026-79675
- https://www.cve.org/CVERecord?id=CVE-2026-79676
- python-nltk-3.10.3-1.mga10
- python-nltk-3.10.3-1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0339 - Updated python-django packages fix security vulnerabilities
Publication date: 27 Aug 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-15307 , CVE-2026-15337 , CVE-2026-15830 , CVE-2026-15920 Description
CVE-2026-15307: Server-side file-write and request forgery via spatial lookups CVE-2026-15337: Potential denial-of-service vulnerability in `check_for_language()` CVE-2026-15830: Potential denial-of-service vulnerability via nested geometry collections CVE-2026-15920: Potential cross-site scripting via `URLField` values in the admin References
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-15307 , CVE-2026-15337 , CVE-2026-15830 , CVE-2026-15920 Description
CVE-2026-15307: Server-side file-write and request forgery via spatial lookups CVE-2026-15337: Potential denial-of-service vulnerability in `check_for_language()` CVE-2026-15830: Potential denial-of-service vulnerability via nested geometry collections CVE-2026-15920: Potential cross-site scripting via `URLField` values in the admin References
- https://bugs.mageia.org/show_bug.cgi?id=36132
- https://www.openwall.com/lists/oss-security/2026/08/04/6
- https://docs.djangoproject.com/en/dev/releases/5.2.17/
- https://www.cve.org/CVERecord?id=CVE-2026-15307
- https://www.cve.org/CVERecord?id=CVE-2026-15337
- https://www.cve.org/CVERecord?id=CVE-2026-15830
- https://www.cve.org/CVERecord?id=CVE-2026-15920
- python-django-5.2.17-1.mga10
Categorías: Actualizaciones de Seguridad
MGASA-2026-0338 - Updated avahi packages fix security vulnerabilities
Publication date: 27 Aug 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2025-59529 , CVE-2026-24401 , CVE-2026-34933 Description
Simple protocol server ignores accepts unlimited connections and logs failures without limit. (CVE-2025-59529) Avahi has Uncontrolled Recursion in lookup_handle_cname function. (CVE-2026-24401) Reachable assertion in `transport_flags_from_domain()` via conflicting publish flags crashes avahi-daemon. (CVE-2026-34933) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2025-59529 , CVE-2026-24401 , CVE-2026-34933 Description
Simple protocol server ignores accepts unlimited connections and logs failures without limit. (CVE-2025-59529) Avahi has Uncontrolled Recursion in lookup_handle_cname function. (CVE-2026-24401) Reachable assertion in `transport_flags_from_domain()` via conflicting publish flags crashes avahi-daemon. (CVE-2026-34933) References
- https://bugs.mageia.org/show_bug.cgi?id=35044
- https://www.openwall.com/lists/oss-security/2025/12/19/1
- https://www.openwall.com/lists/oss-security/2026/04/11/9
- https://github.com/avahi/avahi/security/advisories/GHSA-w65r-6gxh-vhvc
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/LK4OWC4GTD6XELDD5SALQ5NAKJF2JEJ3/
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/QRADPW6Z7LALOMFKDKQVKGWAXCKCS226/
- https://www.cve.org/CVERecord?id=CVE-2025-59529
- https://www.cve.org/CVERecord?id=CVE-2026-24401
- https://www.cve.org/CVERecord?id=CVE-2026-34933
- avahi-0.8-18.1.mga10
- avahi-0.8-10.4.mga9
Categorías: Actualizaciones de Seguridad
MGAA-2026-0114 - Updated yt-dlp packages fix bug
Publication date: 27 Aug 2026
Type: bugfix
Affected Mageia releases : 10 , 9
Description
YouTube videos are no longer loaded and instead terminated with error 'forbidden'. This update fixes the reported issue. References
Type: bugfix
Affected Mageia releases : 10 , 9
Description
YouTube videos are no longer loaded and instead terminated with error 'forbidden'. This update fixes the reported issue. References
- https://bugs.mageia.org/show_bug.cgi?id=36119
- https://github.com/yt-dlp/yt-dlp/releases/tag/2026.08.19
- https://github.com/yt-dlp/yt-dlp/releases/tag/2026.07.04
- yt-dlp-2026.08.19-1.1.mga10
- yt-dlp-2026.08.19-1.1.mga9
Categorías: Actualizaciones de Seguridad




