Lector de Feeds

MGASA-2026-0430 - Updated ntpsec packages fix a security vulnerability

Mageia Security - 20 Septiembre, 2026 - 05:25
Publication date: 20 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-18321 Description
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') in ntpsec. (CVE-2026-18321) References
SRPMS 10/core
  • ntpsec-1.2.4-3.2.mga10
9/core
  • ntpsec-1.2.2-5.1.mga9

MGASA-2026-0428 - Updated mpg123 package fixes security vulnerabilities

Mageia Security - 20 Septiembre, 2026 - 05:25
Publication date: 20 Sep 2026
Type: security
Affected Mageia releases : 10
Description
Updated packages fix security vulnerabilities, please se the reference. References
SRPMS 10/core
  • mpg123-1.33.7-1.mga10

MGASA-2026-0427 - Updated gawk packages fix security vulnerabilities

Mageia Security - 20 Septiembre, 2026 - 05:25
Publication date: 20 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-40467 , CVE-2026-40468 , CVE-2026-40469 , CVE-2026-40553 Description
Use after free in gawk. (CVE-2026-40467) Heap buffer overflow in gawk. (CVE-2026-40468) Heap buffer overflow in gawk. (CVE-2026-40469) Stack-based buffer overflow in gawk. (CVE-2026-40553) References
SRPMS 10/core
  • gawk-5.3.2-2.1.mga10
9/core
  • gawk-5.2.2-1.1.mga9

MGASA-2026-0426 - Updated perl-YAML packages fix a security vulnerability

Mageia Security - 20 Septiembre, 2026 - 05:25
Publication date: 20 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-63676 Description
Updated packages fixes CVE-2026-63676 References
SRPMS 10/core
  • perl-YAML-1.310.0-2.1.mga10
9/core
  • perl-YAML-1.300.0-3.1.mga9

MGASA-2026-0425 - Updated libssh packages fix security vulnerabilities

Mageia Security - 20 Septiembre, 2026 - 05:25
Publication date: 20 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-15370 , CVE-2026-59843 , CVE-2026-59844 , CVE-2026-59845 , CVE-2026-59846 , CVE-2026-59847 , CVE-2026-59848 , CVE-2026-59849 , CVE-2026-59850 Description
Stack buffer overflow in SFTP server longname construction. (CVE-2026-15370) Denial of service via zero advertised channel packet size. (CVE-2026-59843) Denial of service via oversized SFTP read length. (CVE-2026-59844) Denial of service via unchecked ProxyCommand fork() failure. (CVE-2026-59845) Information disclosure via ProxyCommand %r username expansion. (CVE-2026-59846) Integrity downgrade via OpenSSL AES-GCM tag verification. (CVE-2026-59847) Denial of service via SFTP responses with unknown request IDs. (CVE-2026-59848) Denial of service via automatic certificate authentication loop. (CVE-2026-59849) Use-after-free via data callbacks on closed channels. (CVE-2026-59850) References
SRPMS 10/core
  • libssh-0.11.5-1.mga10
9/core
  • libssh-0.10.6-1.3.mga9

MGASA-2026-0424 - Updated ntfs-3g packages fix security vulnerabilities

Mageia Security - 20 Septiembre, 2026 - 05:25
Publication date: 20 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-42616 , CVE-2026-42617 , CVE-2026-42618 , CVE-2026-46569 , CVE-2026-46570 , CVE-2026-46571 , CVE-2026-46572 , CVE-2026-56135 , CVE-2026-56136 Description
Heap memory corruption when processing a corrupt or maliciously crafted filesystem. (CVE-2026-42616) Heap memory corruption when copying index data from root to an index block in a corrupt or maliciously crafted filesystem. (CVE-2026-42617) Single-byte heap buffer overflow when decompressing maliciously crafted compressed file data. (CVE-2026-42618) Heap buffer overflow when copying the tail data of an index block to a freshly allocated block. (CVE-2026-46569) Heap memory corruption for maliciously crafted or corrupt index data descending to an out-of-bounds tree depth. (CVE-2026-46570) Out-of-bounds read when processing symlink reparse data in a corrupt or maliciously crafted filesystem. (CVE-2026-46571) Heap buffer overflow for maliciously crafted or corrupt index data during a node split. (CVE-2026-46572) Heap buffer overflow when building inherited ACL data. (CVE-2026-56135) Out of bounds access when clearing an index root in maliciously crafted or corrupt index data. (CVE-2026-56136) References
SRPMS 10/core
  • ntfs-3g-2026.2.25-1.1.mga10
9/core
  • ntfs-3g-2022.10.3-1.3.mga9

MGASA-2026-0423 - Updated patch package fixes security vulnerabilities

Mageia Security - 20 Septiembre, 2026 - 05:25
Publication date: 20 Sep 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-56288 , CVE-2026-56289 Description
NULL Pointer Dereference in GNU patch. (CVE-2026-56288) Loop with Unreachable Exit Condition in GNU patch. (CVE-2026-56289) References
SRPMS 10/core
  • patch-2.8-1.1.mga10

MGASA-2026-0422 - Updated bind package fixes security vulnerabilities

Mageia Security - 20 Septiembre, 2026 - 05:25
Publication date: 20 Sep 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-19033 , CVE-2026-19662 , CVE-2026-19666 , CVE-2026-19667 , CVE-2026-19668 , CVE-2026-19941 , CVE-2026-75029 , CVE-2026-76163 , CVE-2026-77119 , CVE-2026-77692 , CVE-2026-78301 , CVE-2026-80274 , CVE-2026-81563 , CVE-2026-81736 Description
Unauthenticated IXFR deltas are applied to the live zone before TSIG verification (CVE-2026-19033). qpcache NOQNAME proof use-after-free crashes recursive resolver (CVE-2026-19662). Use-after-free in query_addnoqnameproof() via the DNS64 filter64 path (CVE-2026-19666). Remote assertion failure via 16-bit length truncation in dns_ncache_add() (CVE-2026-19667). Resource Exhaustion via Excessive DNSSEC Cryptographic Material Matching (CVE-2026-19668). checkwildcard() accepts an out-of-zone NSEC as a wildcard-nonexistence proof (CVE-2026-19941). Message parser retains every identical singleton RDATA, enabling wire-to-work amplification (CVE-2026-75029). named aborts on a TKEY query when the user configuration has no global options statement (CVE-2026-76163). NSEC3 insecure-referral proof can use unrelated cached NSEC3 RRsets (CVE-2026-77119). Unauthenticated remote crash of named via a single DoH SIG(0) request (CVE-2026-77692). Out-of-zone database nodes can become authoritative zone cuts (CVE-2026-78301). Validating resolver can abort while caching a mismatched NOQNAME proof (CVE-2026-80274). SVCB AliasMode additional-data error leaks qpcache references (CVE-2026-81563). Remote CPU denial of service through cached SVCB/HTTPS AliasMode trees (CVE-2026-81736). References
SRPMS 10/core
  • bind-9.20.29-1.mga10

MGASA-2026-0421 - Updated python-configargparse packages fix security vulnerabilities

Mageia Security - 20 Septiembre, 2026 - 05:25
Publication date: 20 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
Description
Config file or environment variable can trigger writing out a config file, overwriting an arbitrary file and disclosing configuration values References
SRPMS 10/core
  • python-configargparse-1.7.7-1.mga10
9/core
  • python-configargparse-1.7.7-1.mga9

MGASA-2026-0420 - Updated libde265 package fixes security vulnerabilities

Mageia Security - 20 Septiembre, 2026 - 05:25
Publication date: 20 Sep 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2024-38949 , CVE-2024-38950 , CVE-2025-61147 , CVE-2026-33164 , CVE-2026-33165 , CVE-2026-45382 , CVE-2026-45383 , CVE-2026-49295 , CVE-2026-49337 , CVE-2026-49346 , CVE-2026-54240 , CVE-2026-54241 Description
Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attackers to crash the application via crafted payload to display444as420 function at sdl.cc. (CVE-2024-38949) Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attackers to crash the application via crafted payload to __interceptor_memcpy function. (CVE-2024-38950) strukturag libde265 commit d9fea9d wa discovered to contain a segmentation fault via the component decoder_context::compute_framedrop_table(). (CVE-2025-61147) NULL Pointer Dereference in libde265. (CVE-2026-33164) Heap out-of-bounds write in libde265 1.0.16. (CVE-2026-33165) libde265 has a heap-buffer-overflow READ in decode_slice_unit_tiles via unvalidated PPS tile geometry. (CVE-2026-45382) libde265 has a heap buffer overflow (OOB read) in decode_slice_unit_WPP() via out-of-bounds CtbAddrRStoTS access — libde265 <= v1.0.18. (CVE-2026-45383) libde265 has an out-of-bounds write in process_reference_picture_set via predicted short-term RPS. (CVE-2026-49295) libde265 has an unbounded memory leak via orphaned slice headers in `read_slice_NAL`. (CVE-2026-49337) libde265 has a heap buffer overflow in de265_image_get_buffer via SPS dimension integer overflow. (CVE-2026-49346) Pixel accessor signed integer overflow causes heap OOB read/write. (CVE-2026-54240) SAO sequential filter heap buffer overflow via signed integer overflow. (CVE-2026-54241) References
SRPMS 10/core
  • libde265-1.0.16-4.1.mga10
10/tainted
  • libde265-1.0.16-4.1.mga10.tainted

MGASA-2026-0419 - Updated python-httplib2 packages fix a security vulnerability

Mageia Security - 20 Septiembre, 2026 - 05:25
Publication date: 20 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-59939 Description
Decompression Bomb Denial of Service via Unbounded gzip/deflate Response Handling. (CVE-2026-59939) References
SRPMS 10/core
  • python-httplib2-0.22.0-3.1.mga10
9/core
  • python-httplib2-0.20.4-1.1.mga9

MGAA-2026-0128 - Updated system-config-printer package fixes bug

Mageia Security - 20 Septiembre, 2026 - 05:25
Publication date: 20 Sep 2026
Type: bugfix
Affected Mageia releases : 10
Description
Current system-config-printer package does not show a logo in the about dialog box. This update fixes the reported issue. References
SRPMS 10/core
  • system-config-printer-1.5.18-6.2.mga10

MGAA-2026-0127 - Updated perl-Chart package fixes bug

Mageia Security - 20 Septiembre, 2026 - 05:25
Publication date: 20 Sep 2026
Type: bugfix
Affected Mageia releases : 10
Description
perl-Chart is updated to version 2.403.9. perl-Graphics-Toolkit-Color is a new runtime requirement for perl-Chart. References
SRPMS 10/core
  • perl-Chart-2.403.9-1.mga10
  • perl-Graphics-Toolkit-Color-2.220.0-1.mga10

MGAA-2026-0126 - Updated gnome-software package fixes bug

Mageia Security - 20 Septiembre, 2026 - 05:25
Publication date: 20 Sep 2026
Type: bugfix
Affected Mageia releases : 10
Description
GUI aplications packaged by mageia are not listed in gnome-software. This updates adds libdnf5-plugin-appstream as optional requirement to allow gnome-software see the GUI applications packaged by mageia and allow to user skip the additional package if they want. References
SRPMS 10/core
  • gnome-software-49.3-2.1.mga10

MGAA-2026-0125 - Updated isodumper package fixes bugs

Mageia Security - 20 Septiembre, 2026 - 05:25
Publication date: 20 Sep 2026
Type: bugfix
Affected Mageia releases : 10
Description
When formatting a partition which was already mounted, Isodumper failed. Now, it starts to unmount the partitions on the target device Devices list is also cleaned of optical devices. References
SRPMS 10/core
  • isodumper-1.93-1.mga10

MGASA-2026-0418 - Updated gstreamer1.0-plugins-base packages fix a security vulnerability

Mageia Security - 19 Septiembre, 2026 - 08:25
Publication date: 19 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-18297 Description
GStreamer OGG File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. (CVE-2026-18297) References
SRPMS 10/core
  • gstreamer1.0-plugins-base-1.26.11-1.1.mga10
9/core
  • gstreamer1.0-plugins-base-1.22.11-1.4.mga9

MGAA-2026-0124 - Updated audacity packages fix bug

Mageia Security - 19 Septiembre, 2026 - 08:25
Publication date: 19 Sep 2026
Type: bugfix
Affected Mageia releases : 10
Description
audacity is updated to version 3.7.9 which has improvements and bugs fixed by the audacity team. References
SRPMS 10/core
  • audacity-3.7.9-1.mga10

MGASA-2026-0416 - Updated libpcap packages fix security vulnerabilities

Mageia Security - 18 Septiembre, 2026 - 18:17
Publication date: 18 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-0799 , CVE-2026-31911 , CVE-2026-31912 , CVE-2026-6244 , CVE-2026-6554 , CVE-2026-18313 , CVE-2026-18238 Description
OOBR and OOBW in libpcap before 1.10.7. (CVE-2026-0799) abort() in libpcap before 1.10.7 on an invalid BPF opcode. (CVE-2026-31911) OOBR in libpcap before 1.10.7. (CVE-2026-31912) Division by zero in libpcap before 1.10.7. (CVE-2026-6244) Infinte loop in libpcap before 1.10.7. (CVE-2026-6554) rpcapd memory leak in libpcap before 1.10.7. (CVE-2026-18313) OOBR in rpcap client in libpcap before 1.10.7. (CVE-2026-18238) References
SRPMS 10/core
  • libpcap-1.10.7-1.mga10
9/core
  • libpcap-1.10.7-1.mga9
Feed