Lector de Feeds
MGASA-2026-0345 - Updated nspr, nss, & firefox packages fix security vulnerabilities
Publication date: 31 Aug 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-74934 , CVE-2026-74935 , CVE-2026-74936 , CVE-2026-74937 , CVE-2026-74938 , CVE-2026-74939 , CVE-2026-74940 , CVE-2026-74941 , CVE-2026-74942 , CVE-2026-74943 , CVE-2026-74944 , CVE-2026-74945 , CVE-2026-74946 , CVE-2026-74947 , CVE-2026-74948 , CVE-2026-74950 , CVE-2026-74953 , CVE-2026-74954 , CVE-2026-74955 , CVE-2026-74956 , CVE-2026-74957 , CVE-2026-74958 , CVE-2026-74959 , CVE-2026-74960 , CVE-2026-74961 , CVE-2026-74962 , CVE-2026-74963 , CVE-2026-74964 , CVE-2026-74965 , CVE-2026-74966 , CVE-2026-74967 , CVE-2026-74968 , CVE-2026-74969 , CVE-2026-74970 , CVE-2026-74971 , CVE-2026-74972 , CVE-2026-74949 , CVE-2026-74973 , CVE-2026-74974 , CVE-2026-74976 , CVE-2026-74977 , CVE-2026-74978 , CVE-2026-74979 , CVE-2026-74981 , CVE-2026-74982 , CVE-2026-74983 , CVE-2026-74984 , CVE-2026-74985 , CVE-2026-74986 , CVE-2026-74987 , CVE-2026-74988 , CVE-2026-74990 Description
Site isolation issue in the Graphics: CanvasWebGL component. (CVE-2026-74934) Privilege escalation in the DOM: Networking component. (CVE-2026-74935) Use-after-free in the JavaScript: WebAssembly component. (CVE-2026-74936) Use-after-free in the JavaScript: GC component. (CVE-2026-74937) Mitigation bypass in the JavaScript: GC component. (CVE-2026-74938) Privilege escalation in the DOM: Navigation component. (CVE-2026-74939) Use-after-free in the Graphics: Text component. (CVE-2026-74940) Privilege escalation in the Graphics: CanvasWebGL component. (CVE-2026-74941) Privilege escalation in the Remote Settings Client component. (CVE-2026-74942) Use-after-free in the Graphics: ImageLib component. (CVE-2026-74943) Use-after-free in the DOM: Core & HTML component. (CVE-2026-74944) Information disclosure in the Graphics: Text component. (CVE-2026-74945) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-74946) Privilege escalation due to invalid pointer in the Graphics component. (CVE-2026-74947) Information disclosure in the Graphics component. (CVE-2026-74948) Privilege escalation in the Downloads API component. (CVE-2026-74950) Privilege escalation in the Networking: Cookies component. (CVE-2026-74953) Information disclosure due to side-channel in the Storage: Cache API component. (CVE-2026-74954) Privilege escalation in the Request Handling component. (CVE-2026-74955) Same-origin policy bypass in the DOM: Service Workers component. (CVE-2026-74956) Mitigation bypass in the Safe Browsing component. (CVE-2026-74957) Information disclosure in the WebRTC component. (CVE-2026-74958) Mitigation bypass in the Storage: Cache API component. (CVE-2026-74959) Site isolation issue in the WebExtensions component. (CVE-2026-74960) Side-channel in the Web Audio component. (CVE-2026-74961) Site isolation issue in the Networking: Cookies component. (CVE-2026-74962) Same-origin policy bypass in the Networking: Cookies component. (CVE-2026-74963) Integer overflow in the Graphics component. (CVE-2026-74964) Privilege escalation in the Shell Integration component. (CVE-2026-74965) Information disclosure in the Form Autofill component. (CVE-2026-74966) Same-origin policy bypass in the Audio/Video: Playback component. (CVE-2026-74967) Site isolation issue in the Graphics: WebRender component. (CVE-2026-74968) Use-after-free in the Layout: Text and Fonts component. (CVE-2026-74969) Site isolation issue in the Graphics component. (CVE-2026-74970) Information disclosure in the DOM: UI Events & Focus Handling component. (CVE-2026-74971) Information disclosure in the DOM: Push Subscriptions component. (CVE-2026-74972) Use-after-free in the Graphics: Canvas2D component. (CVE-2026-74949) Race condition, use-after-free in the Graphics component. (CVE-2026-74973) Same-origin policy bypass in the Graphics: ImageLib component. (CVE-2026-74974) JIT miscompilation in the JavaScript Engine: JIT component. (CVE-2026-74976) Integer overflow in the Graphics component. (CVE-2026-74977) Clickjacking issue in the Widget component. (CVE-2026-74978) Mitigation bypass in the Add-ons Manager component. (CVE-2026-74979) Site isolation issue in the Audio/Video: Web Codecs component. (CVE-2026-74981) Denial-of-service in the Widget component. (CVE-2026-74982) Mitigation bypass in the Data Loss Prevention component. (CVE-2026-74983) Race condition in the JavaScript Engine component. (CVE-2026-74984) Privilege escalation in the Enterprise Policies component. (CVE-2026-74985) Site isolation issue in the CSS Parsing and Computation component. (CVE-2026-74986) Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154. (CVE-2026-74987) Internally found bugs fixed in Firefox ESR 153.1 and Firefox 154. (CVE-2026-74988) Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154. (CVE-2026-74990) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-74934 , CVE-2026-74935 , CVE-2026-74936 , CVE-2026-74937 , CVE-2026-74938 , CVE-2026-74939 , CVE-2026-74940 , CVE-2026-74941 , CVE-2026-74942 , CVE-2026-74943 , CVE-2026-74944 , CVE-2026-74945 , CVE-2026-74946 , CVE-2026-74947 , CVE-2026-74948 , CVE-2026-74950 , CVE-2026-74953 , CVE-2026-74954 , CVE-2026-74955 , CVE-2026-74956 , CVE-2026-74957 , CVE-2026-74958 , CVE-2026-74959 , CVE-2026-74960 , CVE-2026-74961 , CVE-2026-74962 , CVE-2026-74963 , CVE-2026-74964 , CVE-2026-74965 , CVE-2026-74966 , CVE-2026-74967 , CVE-2026-74968 , CVE-2026-74969 , CVE-2026-74970 , CVE-2026-74971 , CVE-2026-74972 , CVE-2026-74949 , CVE-2026-74973 , CVE-2026-74974 , CVE-2026-74976 , CVE-2026-74977 , CVE-2026-74978 , CVE-2026-74979 , CVE-2026-74981 , CVE-2026-74982 , CVE-2026-74983 , CVE-2026-74984 , CVE-2026-74985 , CVE-2026-74986 , CVE-2026-74987 , CVE-2026-74988 , CVE-2026-74990 Description
Site isolation issue in the Graphics: CanvasWebGL component. (CVE-2026-74934) Privilege escalation in the DOM: Networking component. (CVE-2026-74935) Use-after-free in the JavaScript: WebAssembly component. (CVE-2026-74936) Use-after-free in the JavaScript: GC component. (CVE-2026-74937) Mitigation bypass in the JavaScript: GC component. (CVE-2026-74938) Privilege escalation in the DOM: Navigation component. (CVE-2026-74939) Use-after-free in the Graphics: Text component. (CVE-2026-74940) Privilege escalation in the Graphics: CanvasWebGL component. (CVE-2026-74941) Privilege escalation in the Remote Settings Client component. (CVE-2026-74942) Use-after-free in the Graphics: ImageLib component. (CVE-2026-74943) Use-after-free in the DOM: Core & HTML component. (CVE-2026-74944) Information disclosure in the Graphics: Text component. (CVE-2026-74945) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-74946) Privilege escalation due to invalid pointer in the Graphics component. (CVE-2026-74947) Information disclosure in the Graphics component. (CVE-2026-74948) Privilege escalation in the Downloads API component. (CVE-2026-74950) Privilege escalation in the Networking: Cookies component. (CVE-2026-74953) Information disclosure due to side-channel in the Storage: Cache API component. (CVE-2026-74954) Privilege escalation in the Request Handling component. (CVE-2026-74955) Same-origin policy bypass in the DOM: Service Workers component. (CVE-2026-74956) Mitigation bypass in the Safe Browsing component. (CVE-2026-74957) Information disclosure in the WebRTC component. (CVE-2026-74958) Mitigation bypass in the Storage: Cache API component. (CVE-2026-74959) Site isolation issue in the WebExtensions component. (CVE-2026-74960) Side-channel in the Web Audio component. (CVE-2026-74961) Site isolation issue in the Networking: Cookies component. (CVE-2026-74962) Same-origin policy bypass in the Networking: Cookies component. (CVE-2026-74963) Integer overflow in the Graphics component. (CVE-2026-74964) Privilege escalation in the Shell Integration component. (CVE-2026-74965) Information disclosure in the Form Autofill component. (CVE-2026-74966) Same-origin policy bypass in the Audio/Video: Playback component. (CVE-2026-74967) Site isolation issue in the Graphics: WebRender component. (CVE-2026-74968) Use-after-free in the Layout: Text and Fonts component. (CVE-2026-74969) Site isolation issue in the Graphics component. (CVE-2026-74970) Information disclosure in the DOM: UI Events & Focus Handling component. (CVE-2026-74971) Information disclosure in the DOM: Push Subscriptions component. (CVE-2026-74972) Use-after-free in the Graphics: Canvas2D component. (CVE-2026-74949) Race condition, use-after-free in the Graphics component. (CVE-2026-74973) Same-origin policy bypass in the Graphics: ImageLib component. (CVE-2026-74974) JIT miscompilation in the JavaScript Engine: JIT component. (CVE-2026-74976) Integer overflow in the Graphics component. (CVE-2026-74977) Clickjacking issue in the Widget component. (CVE-2026-74978) Mitigation bypass in the Add-ons Manager component. (CVE-2026-74979) Site isolation issue in the Audio/Video: Web Codecs component. (CVE-2026-74981) Denial-of-service in the Widget component. (CVE-2026-74982) Mitigation bypass in the Data Loss Prevention component. (CVE-2026-74983) Race condition in the JavaScript Engine component. (CVE-2026-74984) Privilege escalation in the Enterprise Policies component. (CVE-2026-74985) Site isolation issue in the CSS Parsing and Computation component. (CVE-2026-74986) Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154. (CVE-2026-74987) Internally found bugs fixed in Firefox ESR 153.1 and Firefox 154. (CVE-2026-74988) Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154. (CVE-2026-74990) References
- https://bugs.mageia.org/show_bug.cgi?id=36123
- https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_127.html
- https://github.com/mozilla/nspr/releases/tag/NSPR_4_40_RTM
- https://www.firefox.com/en-US/firefox/140.14.0/releasenotes/
- https://www.firefox.com/en-US/firefox/153.1.0/releasenotes/
- https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/
- https://www.mozilla.org/en-US/security/advisories/mfsa2026-77/
- https://www.cve.org/CVERecord?id=CVE-2026-74934
- https://www.cve.org/CVERecord?id=CVE-2026-74935
- https://www.cve.org/CVERecord?id=CVE-2026-74936
- https://www.cve.org/CVERecord?id=CVE-2026-74937
- https://www.cve.org/CVERecord?id=CVE-2026-74938
- https://www.cve.org/CVERecord?id=CVE-2026-74939
- https://www.cve.org/CVERecord?id=CVE-2026-74940
- https://www.cve.org/CVERecord?id=CVE-2026-74941
- https://www.cve.org/CVERecord?id=CVE-2026-74942
- https://www.cve.org/CVERecord?id=CVE-2026-74943
- https://www.cve.org/CVERecord?id=CVE-2026-74944
- https://www.cve.org/CVERecord?id=CVE-2026-74945
- https://www.cve.org/CVERecord?id=CVE-2026-74946
- https://www.cve.org/CVERecord?id=CVE-2026-74947
- https://www.cve.org/CVERecord?id=CVE-2026-74948
- https://www.cve.org/CVERecord?id=CVE-2026-74950
- https://www.cve.org/CVERecord?id=CVE-2026-74953
- https://www.cve.org/CVERecord?id=CVE-2026-74954
- https://www.cve.org/CVERecord?id=CVE-2026-74955
- https://www.cve.org/CVERecord?id=CVE-2026-74956
- https://www.cve.org/CVERecord?id=CVE-2026-74957
- https://www.cve.org/CVERecord?id=CVE-2026-74958
- https://www.cve.org/CVERecord?id=CVE-2026-74959
- https://www.cve.org/CVERecord?id=CVE-2026-74960
- https://www.cve.org/CVERecord?id=CVE-2026-74961
- https://www.cve.org/CVERecord?id=CVE-2026-74962
- https://www.cve.org/CVERecord?id=CVE-2026-74963
- https://www.cve.org/CVERecord?id=CVE-2026-74964
- https://www.cve.org/CVERecord?id=CVE-2026-74965
- https://www.cve.org/CVERecord?id=CVE-2026-74966
- https://www.cve.org/CVERecord?id=CVE-2026-74967
- https://www.cve.org/CVERecord?id=CVE-2026-74968
- https://www.cve.org/CVERecord?id=CVE-2026-74969
- https://www.cve.org/CVERecord?id=CVE-2026-74970
- https://www.cve.org/CVERecord?id=CVE-2026-74971
- https://www.cve.org/CVERecord?id=CVE-2026-74972
- https://www.cve.org/CVERecord?id=CVE-2026-74949
- https://www.cve.org/CVERecord?id=CVE-2026-74973
- https://www.cve.org/CVERecord?id=CVE-2026-74974
- https://www.cve.org/CVERecord?id=CVE-2026-74976
- https://www.cve.org/CVERecord?id=CVE-2026-74977
- https://www.cve.org/CVERecord?id=CVE-2026-74978
- https://www.cve.org/CVERecord?id=CVE-2026-74979
- https://www.cve.org/CVERecord?id=CVE-2026-74981
- https://www.cve.org/CVERecord?id=CVE-2026-74982
- https://www.cve.org/CVERecord?id=CVE-2026-74983
- https://www.cve.org/CVERecord?id=CVE-2026-74984
- https://www.cve.org/CVERecord?id=CVE-2026-74985
- https://www.cve.org/CVERecord?id=CVE-2026-74986
- https://www.cve.org/CVERecord?id=CVE-2026-74987
- https://www.cve.org/CVERecord?id=CVE-2026-74988
- https://www.cve.org/CVERecord?id=CVE-2026-74990
- nspr-4.40.0-1.mga10
- nss-3.127.0-1.mga10
- firefox-153.1.0-1.mga10
- firefox-l10n-153.1.0-1.mga10
- nspr-4.40.0-1.mga9
- nss-3.127.0-1.mga9
- firefox-140.14.0-1.mga9
- firefox-l10n-140.14.0-1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0344 - Updated jbig2dec packages fix security vulnerabilities
Publication date: 31 Aug 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2023-46361 , CVE-2026-38076 Description
Artifex Software jbig2dec v0.20 was discovered to contain a SEGV vulnerability via jbig2_error at /jbig2dec/jbig2.c. (CVE-2023-46361) An integer overflow in the jbig2_arith_iaid_ctx_new() function of Artifex commit cc37d0 allows attackers to cause a Denial of Service (DoS) via a crafted input. (CVE-2026-38076) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2023-46361 , CVE-2026-38076 Description
Artifex Software jbig2dec v0.20 was discovered to contain a SEGV vulnerability via jbig2_error at /jbig2dec/jbig2.c. (CVE-2023-46361) An integer overflow in the jbig2_arith_iaid_ctx_new() function of Artifex commit cc37d0 allows attackers to cause a Denial of Service (DoS) via a crafted input. (CVE-2026-38076) References
- https://bugs.mageia.org/show_bug.cgi?id=35994
- https://ubuntu.com/security/notices/USN-8582-1
- https://github.com/Frank-Z7/z-vulnerabilitys/blob/main/jbig2dec-SEGV/jbig2dec-SEGV.md
- https://bugs.ghostscript.com/show_bug.cgi?id=707308
- https://bugs.ghostscript.com/show_bug.cgi?id=705041
- https://www.cve.org/CVERecord?id=CVE-2023-46361
- https://www.cve.org/CVERecord?id=CVE-2026-38076
- jbig2dec-0.20-2.1.mga10
- jbig2dec-0.19-4.1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0343 - Updated c-ares packages fix security vulnerabilities
Publication date: 31 Aug 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-33630 , CVE-2026-69184 , CVE-2026-69186 Description
Use-after-free / double-free in c-ares query-completion handling, remotely triggerable via ares_getaddrinfo() over TCP. (CVE-2026-33630) CPU-exhaustion denial of service via unbounded DNS name compression pointer chains. (CVE-2026-69184) Memory-amplification denial of service via unvalidated DNS header record counts. (CVE-2026-69186) References
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-33630 , CVE-2026-69184 , CVE-2026-69186 Description
Use-after-free / double-free in c-ares query-completion handling, remotely triggerable via ares_getaddrinfo() over TCP. (CVE-2026-33630) CPU-exhaustion denial of service via unbounded DNS name compression pointer chains. (CVE-2026-69184) Memory-amplification denial of service via unvalidated DNS header record counts. (CVE-2026-69186) References
- https://bugs.mageia.org/show_bug.cgi?id=35847
- https://www.openwall.com/lists/oss-security/2026/07/06/8
- https://github.com/c-ares/c-ares/security/advisories/GHSA-6wfj-rwm7-3542
- https://github.com/c-ares/c-ares/security/advisories/GHSA-pjmc-gx33-gc76
- https://github.com/c-ares/c-ares/security/advisories/GHSA-jv8r-gqr9-68wj
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RP4OX63ZTYCCB4UK6HI4BFEPQEPSNLOJ/
- https://www.cve.org/CVERecord?id=CVE-2026-33630
- https://www.cve.org/CVERecord?id=CVE-2026-69184
- https://www.cve.org/CVERecord?id=CVE-2026-69186
- c-ares-1.34.8-1.mga10
Categorías: Actualizaciones de Seguridad
MGASA-2026-0342 - Updated flatpak package fixes security vulnerabilities
Publication date: 31 Aug 2026
Type: security
Affected Mageia releases : 10
Description
Updated flatpak package fixes security vulnerabilities. Please see the links for additional information. References
Type: security
Affected Mageia releases : 10
Description
Updated flatpak package fixes security vulnerabilities. Please see the links for additional information. References
- https://bugs.mageia.org/show_bug.cgi?id=36137
- https://www.openwall.com/lists/oss-security/2026/08/11/9
- https://lists.debian.org/debian-security-announce/2026/msg00343.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BT77VPU5W2JAF2LEXVLX6Q33HJJAOLTH/
- https://github.com/flatpak/flatpak/security/advisories/GHSA-8688-9x26-hhxj
- https://github.com/flatpak/flatpak/security/advisories/GHSA-qrwq-7qwx-q9rp
- https://github.com/flatpak/flatpak/security/advisories/GHSA-fqx6-vh4p-42cg
- https://github.com/flatpak/flatpak/security/advisories/GHSA-8qxj-x646-phcm
- https://github.com/flatpak/flatpak/security/advisories/GHSA-9rww-v4mm-x4jg
- https://github.com/flatpak/flatpak/security/advisories/GHSA-v2gw-v9h5-9q4x
- https://github.com/flatpak/flatpak/security/advisories/GHSA-jr92-2v97-wgvc
- https://github.com/flatpak/flatpak/security/advisories/GHSA-99wv-m8rp-g58x
- https://github.com/flatpak/flatpak/security/advisories/GHSA-w69g-9x8j-7p8f
- https://github.com/flatpak/flatpak/security/advisories/GHSA-q4gr-vc25-57m5
- flatpak-1.16.6-1.1.mga10
Categorías: Actualizaciones de Seguridad
MGASA-2026-0341 - Updated golang packages fix security vulnerabilities
Publication date: 30 Aug 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-56865 , CVE-2026-56864 , CVE-2026-56859 , CVE-2026-56853 , CVE-2026-56860 , CVE-2026-46600 , CVE-2026-56862 , CVE-2026-56858 , CVE-2026-39821 , CVE-2026-33818 Description
CVE-2026-56865 A malicious GOPROXY was previously capable of forging up to two sumdb tiles that allow for a requested module to bypass the GOSUMDB check and persist attacker-controlled module content to a local Go module cache. CVE-2026-56864 A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log. CVE-2026-56859 Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion. CVE-2026-56853 When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. Previously, this was being done with no timeout applied. ReadHeaderTimeout is now applied for this. CVE-2026-56860 Previously, resolving relative paths containing parent directory (|..|) segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. CVE-2026-4660 Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer. CVE-2026-56862 Previously, we always counted handshake messages, such as KeyUpdate, as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely. CVE-2026-56858 Previously, pathological inputs could close an unescaped |/| early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS. CVE-2026-39821 The ToASCII and ToUnicode functions incorrectly accepted Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returned the name "example.com" rather than an error. CVE-2026-33818 Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures. References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-56865 , CVE-2026-56864 , CVE-2026-56859 , CVE-2026-56853 , CVE-2026-56860 , CVE-2026-46600 , CVE-2026-56862 , CVE-2026-56858 , CVE-2026-39821 , CVE-2026-33818 Description
CVE-2026-56865 A malicious GOPROXY was previously capable of forging up to two sumdb tiles that allow for a requested module to bypass the GOSUMDB check and persist attacker-controlled module content to a local Go module cache. CVE-2026-56864 A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log. CVE-2026-56859 Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion. CVE-2026-56853 When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. Previously, this was being done with no timeout applied. ReadHeaderTimeout is now applied for this. CVE-2026-56860 Previously, resolving relative paths containing parent directory (|..|) segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. CVE-2026-4660 Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer. CVE-2026-56862 Previously, we always counted handshake messages, such as KeyUpdate, as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely. CVE-2026-56858 Previously, pathological inputs could close an unescaped |/| early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS. CVE-2026-39821 The ToASCII and ToUnicode functions incorrectly accepted Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returned the name "example.com" rather than an error. CVE-2026-33818 Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures. References
- https://bugs.mageia.org/show_bug.cgi?id=36142
- https://www.openwall.com/lists/oss-security/2026/08/13/13
- https://www.cve.org/CVERecord?id=CVE-2026-56865
- https://www.cve.org/CVERecord?id=CVE-2026-56864
- https://www.cve.org/CVERecord?id=CVE-2026-56859
- https://www.cve.org/CVERecord?id=CVE-2026-56853
- https://www.cve.org/CVERecord?id=CVE-2026-56860
- https://www.cve.org/CVERecord?id=CVE-2026-46600
- https://www.cve.org/CVERecord?id=CVE-2026-56862
- https://www.cve.org/CVERecord?id=CVE-2026-56858
- https://www.cve.org/CVERecord?id=CVE-2026-39821
- https://www.cve.org/CVERecord?id=CVE-2026-33818
- golang-1.25.13-1.mga10
- golang-1.25.13-1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0340 - Updated python-nltk packages fix security vulnerabilities
Publication date: 29 Aug 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-62383 , CVE-2026-62384 , CVE-2026-62385 , CVE-2026-62388 , CVE-2026-63311 , CVE-2026-63312 , CVE-2026-63315 , CVE-2026-71513 , CVE-2026-71514 , CVE-2026-71518 , CVE-2026-78680 , CVE-2026-78681 , CVE-2026-78682 , CVE-2026-78683 , CVE-2026-79657 , CVE-2026-79674 , CVE-2026-79675 , CVE-2026-79676 Description
Updated packages fix security vulnerabilities. Please see the links. References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-62383 , CVE-2026-62384 , CVE-2026-62385 , CVE-2026-62388 , CVE-2026-63311 , CVE-2026-63312 , CVE-2026-63315 , CVE-2026-71513 , CVE-2026-71514 , CVE-2026-71518 , CVE-2026-78680 , CVE-2026-78681 , CVE-2026-78682 , CVE-2026-78683 , CVE-2026-79657 , CVE-2026-79674 , CVE-2026-79675 , CVE-2026-79676 Description
Updated packages fix security vulnerabilities. Please see the links. References
- https://bugs.mageia.org/show_bug.cgi?id=36186
- https://github.com/nltk/nltk/releases#release-v3.10.0
- https://github.com/nltk/nltk/releases#release-v3.10.2
- https://github.com/nltk/nltk/releases#release-v3.10.3
- https://www.cve.org/CVERecord?id=CVE-2026-62383
- https://www.cve.org/CVERecord?id=CVE-2026-62384
- https://www.cve.org/CVERecord?id=CVE-2026-62385
- https://www.cve.org/CVERecord?id=CVE-2026-62388
- https://www.cve.org/CVERecord?id=CVE-2026-63311
- https://www.cve.org/CVERecord?id=CVE-2026-63312
- https://www.cve.org/CVERecord?id=CVE-2026-63315
- https://www.cve.org/CVERecord?id=CVE-2026-71513
- https://www.cve.org/CVERecord?id=CVE-2026-71514
- https://www.cve.org/CVERecord?id=CVE-2026-71518
- https://www.cve.org/CVERecord?id=CVE-2026-78680
- https://www.cve.org/CVERecord?id=CVE-2026-78681
- https://www.cve.org/CVERecord?id=CVE-2026-78682
- https://www.cve.org/CVERecord?id=CVE-2026-78683
- https://www.cve.org/CVERecord?id=CVE-2026-79657
- https://www.cve.org/CVERecord?id=CVE-2026-79674
- https://www.cve.org/CVERecord?id=CVE-2026-79675
- https://www.cve.org/CVERecord?id=CVE-2026-79676
- python-nltk-3.10.3-1.mga10
- python-nltk-3.10.3-1.mga9
Categorías: Actualizaciones de Seguridad




