Lector de Feeds
Potions in Mageia. 04 – How proper cooking makes the final recipe pleasing to our users
This time, as promised in this new phase of publications on our official sites, we’re giving a voice to one of our users from the Mageia community. Today, we’re sharing their opinion piece. We’re struck by the sincerity with which they speak about the benefits of Mageia, and also, because nothing is perfect, by some usage ideas we can improve within Mageia. Without further ado, here’s their analysis, which encourages us to continue improving our distribution!
Why and when I prefer Mageia Linux. By Ricardo Naranjo Faccini
1.- Personal reasons.
In the vast universe of Linux distributions, every user has their own preferences and reasons for choosing one over another. Today I want to talk about Mageia, a distribution that may not be the most well-known, but which offers a number of advantages that make it stand out. Here I’ll tell you why and when I prefer to use Mageia Linux, and why you might consider giving it a try.
1.a. Flexibility without Complications
One of the main reasons I choose Mageia is its incredible flexibility. This distribution allows me to set up a complete lab that seamlessly combines server tools with desktop applications. I can have an Apache server and PostgreSQL running simultaneously while using LibreOffice and GIMP. This duality is ideal for both development environments and personal use.
1.b. Package and Repository Management
Mageia stands out for its repository organization. You can opt for an extremely stable system by keeping the repositories in their default configuration, or you can enable the “testing” repositories to stay up-to-date with the latest updates. Additionally, you can activate the “debug” repositories to access source code and debugging tools. This adaptability is perfect for different needs and risk levels.
1.c. Safety during Installation and Uninstallation
One of the biggest fears of Linux users is breaking the system when installing or uninstalling software due to dependency issues. Mageia handles dependencies efficiently, allowing me to install and uninstall programs with the peace of mind that the system will continue to function correctly.
1.d. Powerful Graphics Tools
Mageia’s Control Center is one of its gems. This graphical tool allows you to manage the entire system intuitively, from hardware and network configuration to user administration and security. Not many distributions offer such comprehensive and accessible control.
Furthermore, Mageia simplifies disk partitioning during installation. I can create and manage partitions graphically, and even retain my user settings if I need to reinstall the system. This functionality is especially useful for those who are not comfortable with command-line partitioning tools.
1.e. Similarity to Red Hat
Mageia shares many similarities with Red Hat, a distribution widely used in corporate environments. This makes Mageia an excellent option for those seeking an enterprise-grade distribution without the associated costs. Furthermore, familiarity with Mageia facilitates the transition to Red Hat in the workplace.
1.f. Community and Support
Although not the most popular distribution, Mageia boasts an active and supportive community. Users can find help, share experiences, and access additional repositories. This kind of community support is invaluable, especially for new users.
1.g. Ease of Use and Diversity
Mageia is user-friendly for both beginners and advanced users. It’s easy to install and offers a wide variety of desktop environments to choose from. The full DVD version lets you try different desktops with a single click, making it easy to find the environment that best suits your needs.
Another advantage that I greatly value about Mageia is the availability of its Live versions, which allow you to boot the entire system from a USB memory without modifying the hard drive. This is perfect for both testing the distribution and verifying hardware compatibility without compromising the main equipment, or for setting up a temporary, homogeneous laboratory in minutes during a teaching session.
Furthermore, in the context of a trip, the Live version becomes an invaluable protection tool. If I need to use a rented computer at an internet cafe, just restart the computer from my USB to work in a clean environment controlled by me.
This way, I can carry out my tasks with complete peace of mind, eliminating the suspicion of interacting with malware installed on the host system and ensuring that no trace of my information or credentials is left when the machine is shut down.
2. When do I use Mageia?
I prefer to use Mageia in several scenarios:
- Laboratory or Development Environments: Its ability to combine server and desktop applications in a single system is ideal for testing and development.
- Personal Use: The stability and ease of management make Mageia an excellent choice for my daily use.
- Teaching: When I teach Linux, Mageia is a formidable educational tool thanks to its flexibility and wealth of graphical tools.
- Transition to Corporate Environments: For those interested in a career in IT, Mageia offers a solid foundation similar to Red Hat, facilitating the transition to corporate environments.
3. When I Prefer Other Distributions
Although Mageia is my preferred choice in most cases, there are very specific situations where other Linux distributions can be more suitable:
- AlmaLinux OS and Rocky Linux—the successors to CentOS—for managing standalone enterprise servers.
- Red Hat or SUSE, for corporate environments requiring support contracts and strict certifications.
- Ubuntu: while its desktop environment currently bears no resemblance to Microsoft’s system, it remains highly recommended for the transition from Windows to Linux. Much of this recommendation likely stems from a lack of awareness regarding solid, user-friendly alternatives like Mageia.
- Slackware or Gentoo: for extreme customization and absolute system control, suited for advanced Linux users who prefer terminal-based management.
- Kali Linux or Fire, for digital forensics and penetration testing, featuring specialized environments designed to run from a live version without requiring local installation.
4. Conclusion
Mageia may not be the most popular distribution, but its advantages are undeniable. From its flexibility and efficient package management to its powerful graphical tools and active community, Mageia offers a robust and accessible experience. Whether you are looking for a development environment, a stable system for personal use, or an educational tool, Mageia is an option worth considering. Give it a try, and you will likely discover why it could become your preferred Linux distribution.
That concludes the analysis by our user Ricardo Naranjo Faccini; we will continue to work towards improving Mageia and giving our users a voice. Our distribution is a community project, legally established as a not-for-profit association run by an elected board of directors, unlike some of our better-known competitors. As advocates who recognize the benefits of free software, we invite you to share your ideas about Mageia with us on our open social media channels Mageia Matrix or Mageia IRC. You can also share your experiences using Mageia on other social networks by mentioning @Mageia or #Mageia, or by posting on our page Mageia Facebook.
Pociones en Mageia. 04 – De como una buena cocción hace que la receta final guste a nuestros usuarios
En esta ocasión, y como prometimos en esta nueva etapa de publicaciones en nuestros sitios oficiales, damos voz a uno de nuestros usuarios de la comunidad Mageia. Hoy, nos hacemos eco de su artículo de opinión, nos llama la atención la sinceridad con la que habla de las bondades de Mageia, y también, porque nada es perfecto, de algunas ideas de uso que podemos mejorar desde Mageia. Sin más dilación, os mostramos su análisis que nos anima a seguir mejorando nuestra distribución!
Por qué y cuando prefiero Mageia Linux. Por Ricardo Naranjo Faccini
1.- Razones personales.
En el vasto universo de las distribuciones Linux, cada usuario tiene sus preferencias y razones para elegir una sobre otra. Hoy quiero hablar de Mageia, una distribución que quizás no sea la más conocida, pero que ofrece una serie de ventajas que la hacen destacar. Aquí te contaré por qué y cuándo prefiero usar Mageia Linux, y por qué podrías considerar darle una oportunidad.
1.a. Flexibilidad sin Complicaciones
Una de las razones principales por las que elijo Mageia es su increíble flexibilidad. Esta distribución me permite montar un completo laboratorio que combina herramientas de servidor con aplicaciones de escritorio sin ningún problema. Puedo tener un servidor Apache y PostgreSQL corriendo al mismo tiempo que utilizo LibreOffice y GIMP. Esta dualidad es ideal tanto para entornos de desarrollo como para uso personal.
1.b. Gestión de Paquetes y Repositorios
Mageia se destaca por su organización de repositorios. Puedes optar por un sistema extremadamente estable manteniendo los repositorios en su configuración predeterminada, o puedes habilitar los repositorios de «testing» para estar a la vanguardia con las últimas actualizaciones. Además, puedes activar los repositorios de «debug» para tener acceso a los fuentes y herramientas de depuración. Esta capacidad de adaptación es perfecta para diferentes necesidades y niveles de riesgo.
1.c. Seguridad al Instalar y Desinstalar
Uno de los mayores temores de los usuarios de Linux es romper el sistema al instalar o desinstalar software debido a problemas de dependencias. Mageia maneja las dependencias de manera eficiente, permitiéndome instalar y desinstalar programas con la tranquilidad de que el sistema seguirá funcionando correctamente.
1.d. Herramientas Gráficas Potentes
El Centro de Control de Mageia es una de sus joyas. Esta herramienta gráfica permite gestionar todo el sistema de manera intuitiva, desde la configuración de hardware y redes, hasta la administración de usuarios y seguridad. No muchas distribuciones ofrecen un control tan exhaustivo y accesible.
Además, Mageia facilita el particionado del disco durante la instalación. Puedo crear y gestionar particiones de manera gráfica, e incluso mantener mis configuraciones de usuario si necesito reinstalar el sistema. Esta funcionalidad es especialmente útil para aquellos que no se sienten cómodos con las herramientas de particionado en línea de comandos.
1.e. Similaridad con RedHat
Mageia comparte muchas similitudes con RedHat, una distribución ampliamente utilizada en entornos corporativos. Esto hace que Mageia sea una excelente opción para aquellos que buscan una distribución de uso empresarial sin el costo asociado. Además, conocer Mageia facilita la transición a RedHat en el entorno laboral.
1.f. Comunidad y Soporte
Aunque no es la distribución más popular, Mageia cuenta con una comunidad activa y solidaria. Los usuarios pueden encontrar ayuda, compartir experiencias y acceder a repositorios adicionales. Este tipo de soporte comunitario es invaluable, especialmente para los nuevos usuarios.
1.g. Facilidad de Uso y Diversidad
Mageia es amigable tanto para principiantes como para usuarios avanzados. Su instalación es sencilla y ofrece una gran variedad de entornos de escritorio para elegir. La versión DVD completa permite probar diferentes escritorios con un solo clic, facilitando encontrar el entorno que mejor se adapte a mis necesidades.
Otra ventaja que valoro enormemente de Mageia es la disponibilidad de sus versiones Live, las cuales permiten arrancar el sistema completo desde una memoria USB sin modificar el disco duro. Esto resulta perfecto tanto para probar la distribución y verificar la compatibilidad de hardware sin comprometer el equipo principal, como para montar en minutos un laboratorio temporal y homogéneo durante una sesión de enseñanza.
Además, en el contexto de un viaje, la versión Live se convierte en una herramienta de protección invaluable. Si necesito utilizar una computadora alquilada en un café internet, basta con reiniciar el equipo desde mi USB para trabajar en un entorno limpio y controlado por mí.
De esta manera, puedo realizar mis tareas con total tranquilidad, eliminando la sospecha de interactuar con malware instalado en el sistema anfitrión y asegurando que no quede rastro alguno de mi información ni de mis credenciales al apagar la máquina.
2. ¿Cuándo Uso Mageia?
Prefiero usar Mageia en varios escenarios:
- Laboratorio o Entornos de Desarrollo: Su capacidad para combinar aplicaciones de servidor y escritorio en un solo sistema es ideal para pruebas y desarrollo.
- Uso Personal: La estabilidad y la facilidad de gestión hacen de Mageia una excelente opción para mi uso diario.
- Enseñanza: Cuando imparto clases de Linux, Mageia es una herramienta educativa formidable gracias a su flexibilidad y la riqueza de herramientas gráficas.
- Transición a Entornos Corporativos: Para aquellos interesados en una carrera en TI, Mageia ofrece una base sólida similar a RedHat, facilitando la transición a entornos corporativos.
3. Cuándo Prefiero Otras Distribuciones
Aunque Mageia es mi elección preferida en la mayoría de los casos, existen situaciones muy específicas donde otras distribuciones de Linux pueden ser más adecuadas:
- AlmaLinux Os y Rocky Linux, los hijos de CentOS, para la gestión de servidores empresariales independientes.
- RedHat o SuSE, para entornos corporativos con requerimientos de contratos de soporte y certificaciones extrictas.
- Ubuntu, actualmente su escritorio no se parece nada al sistema de Microsoft, pero sigue siendo muy recomendada para la transición Windows-Linux. Quizás gran parte de estas recomendaciones se deban al desconocimiento de alternativas muy sólidas y fáciles para el usuario como Mageia.
- Slackware o Gentoo: para personalización extrema, control absoluto del sistema, por usuarios avanzados en linux y la gestión por terminal.
- Kali Linux o Fire, para análisis forense informático y pruebas de penetración, con entornos especializados preparados para operar desde una versión live sin instalación local.
4. Conclusión
Mageia puede no ser la distribución más popular, pero sus ventajas son innegables. Desde su flexibilidad y gestión eficiente de paquetes hasta sus poderosas herramientas gráficas y comunidad activa, Mageia ofrece una experiencia robusta y accesible. Ya sea que busques un entorno de desarrollo, un sistema estable para uso personal o una herramienta educativa, Mageia es una opción que merece ser considerada. Seguro que si le das una oportunidad descubrirás por qué puede convertirse en tu distribución de Linux preferida.
Hasta aquí el análisis de nuestro usuario Ricardo Naranjo Faccini, seguiremos avanzando para mejorar Mageia y dando voz a nuestros usuarios. Nuestra distribución es un proyecto comunitario, constituido legalmente como una asociación sin ánimo de lucro dirigida por una junta directiva elegida, a diferencia de algunos de nuestros competidores más conocidos. Siendo conscientes y promotores de las ventajas del uso de sofware libre, nos puedes contar tus ideas sobre Mageia en nuestros espacios en las redes sociales abiertas Mageia Matrix o Mageia IRC. Aunque también puedes comentar sobre tu uso de Mageia cualquiera de otras redes, haciendo mención a @Mageia, #Mageia o en nuestra página Mageia Facebook.
MGASA-2026-0407 - Updated libcupsfilters & cups-filters packages fix security vulnerabilities
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-64611 , CVE-2026-64612 Description
cpu exhaustion via infinite loop in cfieee1284normalizemakemodel(). (CVE-2026-64611) cups image filter process abort via malformed png. (CVE-2026-64612) References
- https://bugs.mageia.org/show_bug.cgi?id=36182
- https://www.cve.org/CVERecord?id=CVE-2026-64611
- https://www.cve.org/CVERecord?id=CVE-2026-64612
- libcupsfilters-2.1.1-5.1.mga10
- cups-filters-1.28.16-6.4.mga9
MGASA-2026-0406 - Updated zip packages fix a security vulnerability
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2018-13410 Description
zip test option (-T) command injection. Info-ZIP Zip 3.0, when the -T and -TT command-line options are used, allows attackers to cause a denial of service (invalid free and application crash) or possibly have unspecified other impact because of an off-by-one error. (CVE-2018-13410) References
- https://bugs.mageia.org/show_bug.cgi?id=36143
- https://www.openwall.com/lists/oss-security/2026/08/14/1
- https://sintonen.fi/advisories/infozip-test-option-command-injection.txt
- https://lists.debian.org/debian-security-announce/2026/msg00350.html
- https://www.cve.org/CVERecord?id=CVE-2018-13410
- zip-3.0-17.1.mga10
- zip-3.0-14.1.mga9
MGASA-2026-0405 - Updated unzip packages fix security vulnerabilities
Type: security
Affected Mageia releases : 10 , 9
Description
Vulnerabilities were discovered in the Info-ZIP unzip program, which could result in the execution of arbitrary code if a specially crafted file is processed. References
- https://bugs.mageia.org/show_bug.cgi?id=36184
- https://lists.debian.org/debian-security-announce/2026/msg00351.html
- unzip-6.0-8.1.mga10
- unzip-6.0-4.1.mga9
MGASA-2026-0404 - Updated perl-HTML-FormFu packages fix a security vulnerability
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-19873 Description
HTML::FormFu versions through 2.08 for Perl allow resource exhaustion via an unbounded repeat count from the query string in Repeatable elements. (CVE-2026-19873) References
- https://bugs.mageia.org/show_bug.cgi?id=36232
- https://www.openwall.com/lists/oss-security/2026/08/31/7
- https://github.com/FormFu/HTML-FormFu/issues/71
- https://www.cve.org/CVERecord?id=CVE-2026-19873
- perl-HTML-FormFu-2.60.0-5.1.mga10
- perl-HTML-FormFu-2.60.0-4.1.mga9
MGASA-2026-0403 - Updated bzip2 packages fix a security vulnerability
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-42250 Description
Off-by-One Leading to Out-of-Bounds Write in bzip2. (CVE-2026-42250 References
- https://bugs.mageia.org/show_bug.cgi?id=36240
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/5BZUFTRN4TGNACBM45SR6YO5FURLM3CM/
- https://inbox.sourceware.org/bzip2-devel/20260528145407.293768-1-mark@klomp.org/
- https://www.cve.org/CVERecord?id=CVE-2026-42250
- bzip2-1.0.8-7.1.mga10
- bzip2-1.0.8-5.1.mga9
MGASA-2026-0402 - Updated libssh2 packages fix security vulnerabilities
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-66032 , CVE-2026-66033 , CVE-2026-66035 Description
Double-Free Heap Corruption via sftp_open(). (CVE-2026-66032) Integer Underflow DoS via AES-GCM Cipher Negotiation. (CVE-2026-66033) Heap Buffer Overflow via ETM Cipher Negotiation. (CVE-2026-66035) References
- https://bugs.mageia.org/show_bug.cgi?id=36256
- https://ubuntu.com/security/notices/USN-8722-1
- https://www.cve.org/CVERecord?id=CVE-2026-66032
- https://www.cve.org/CVERecord?id=CVE-2026-66033
- https://www.cve.org/CVERecord?id=CVE-2026-66035
- libssh2-1.11.1-2.2.mga10
- libssh2-1.11.0-1.2.mga9
MGASA-2026-0401 - Updated tar packages fix security vulnerabilities
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2025-45582 , CVE-2026-18508 , CVE-2026-18477 Description
GNU Tar through 1.35 allows file overwrite via directory traversal in crafted TAR archives, with a certain two-step process. (CVE-2025-45582) Tar: toctou in incremental dumpdir 'x' rename handling allows restore path escape. (CVE-2026-18477) Tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite. (CVE-2026-18508) References
- https://bugs.mageia.org/show_bug.cgi?id=36289
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ASLMG5TUYWS2IEKBCOWN5KZ2K55V366N/
- https://www.cve.org/CVERecord?id=CVE-2025-45582
- https://www.cve.org/CVERecord?id=CVE-2026-18508
- https://www.cve.org/CVERecord?id=CVE-2026-18477
- tar-1.35-4.1.mga10
- tar-1.35-4.1.mga9
MGASA-2026-0400 - Updated perl-Authen-SASL packages fix a security vulnerability
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-86219 Description
Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept replayed authentication responses via unverified nonce in server_step. (CVE-2026-86219) References
- https://bugs.mageia.org/show_bug.cgi?id=36264
- https://www.openwall.com/lists/oss-security/2026/09/06/1
- https://metacpan.org/release/EHUELS/Authen-SASL-2.2000/source/lib/Authen/SASL/Perl/DIGEST_MD5.pm#L203-222
- https://metacpan.org/release/EHUELS/Authen-SASL-2.2000/source/lib/Authen/SASL/Perl/DIGEST_MD5.pm#L410-414
- https://datatracker.ietf.org/doc/html/rfc2831#section-2.1.2
- https://metacpan.org/release/EHUELS/Authen-SASL-2.2100/changes
- https://www.cve.org/CVERecord?id=CVE-2026-86219
- perl-Authen-SASL-2.190.0-1.1.mga10
- perl-Authen-SASL-2.160.0-13.2.mga9
MGASA-2026-0399 - Updated bind package fixes a security vulnerability
Type: security
Affected Mageia releases : 9
CVE: CVE-2026-13204 Description
It was discovered that Bind incorrectly handled DNSSEC validation when a domain was covered by both NSEC and NSEC3 records with only one type having an RRSIG. A remote attacker could possibly use this issue to cause Bind to crash, resulting in a denial of service (CVE-2026-13204). References
- https://bugs.mageia.org/show_bug.cgi?id=36241
- https://ubuntu.com/security/notices/USN-8696-1
- https://kb.isc.org/docs/cve-2026-13204
- https://www.cve.org/CVERecord?id=CVE-2026-13204
- https://www.cve.org/CVERecord?id=CVE-2026-13204
- bind-9.18.50-1.1.mga9
MGASA-2026-0398 - Updated ffmpeg package fixes security vulnerabilities
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-58049 , CVE-2026-64830 , CVE-2026-64832 , CVE-2026-64833 , CVE-2026-64834 , CVE-2026-64835 , CVE-2026-65703 , CVE-2026-65704 , CVE-2026-65705 , CVE-2026-65706 , CVE-2026-66036 , CVE-2026-66037 , CVE-2026-66038 , CVE-2026-66039 , CVE-2026-66041 , CVE-2026-70628 , CVE-2026-70629 , CVE-2026-70630 , CVE-2026-70631 , CVE-2026-70632 , CVE-2026-75141 , CVE-2026-75142 , CVE-2026-75143 , CVE-2026-75144 , CVE-2026-75146 Description
Out-of-Bounds Write in RASC Decoder decode_dlta(). (CVE-2026-58049) Heap Buffer Overflow via VobSub Subtitle Demuxer. (CVE-2026-64830) Double-Free in NVDEC Hardware Decoder via nvdec.c. (CVE-2026-64832) Out-of-Bounds Read via S/PDIF Muxer spdifenc.c. (CVE-2026-64833) Infinite Loop DoS via RTP/ASF Demuxer. (CVE-2026-64834) Out-of-Bounds Memory Access in ADX Audio Decoder. (CVE-2026-64835) Out-of-Bounds Write in TDSC Video Decoder. (CVE-2026-65703) Out-of-Bounds Write via TY Demuxer and Shorten Decoder. (CVE-2026-65704) vf_floodfill Out-of-Bounds Write via filter_frame(). (CVE-2026-65705) vf_swaprect Out-of-Bounds Write via NV12 Frame Processing. (CVE-2026-65706) Heap Out-of-Bounds Write in vf_hqdn3d Filter. (CVE-2026-66036) IAMF Demuxer Uncontrolled Resource Consumption via mix_presentation_obu(). (CVE-2026-66037) LCL/ZLIB Video Decoder Information Disclosure via lcldec.c. (CVE-2026-66038) MACE6 Audio Decoder Heap Out-of-Bounds Write via CAF File. (CVE-2026-66039) Heap Out-of-Bounds Write via vf_quirc Filter. (CVE-2026-66041) DVB Subtitle Parser Heap Buffer Overflow via WTV File. (CVE-2026-70628) Uninitialized Heap Memory Read in RSCC Decoder. (CVE-2026-70629) Uninitialized Heap Memory Read in Screenpresso Decoder. (CVE-2026-70630) Uninitialized Heap Memory Read in TIFF Decoder. (CVE-2026-70631) Heap Out-of-Bounds Write in CFHD Decoder via AVI Demuxing. (CVE-2026-70632) Heap Buffer Overflow in hvcC Box Writer via HEVC Muxing. (CVE-2026-75141) Stack Buffer Overflow in MPEG-PS Muxer via mpegenc.c. (CVE-2026-75142) Heap Buffer Overflow via RIST Protocol Reader. (CVE-2026-75143) Heap Buffer Overflow in VC-2/Dirac RTP Packetizer. (CVE-2026-75144) Out-of-Bounds Read in DASH Demuxer via dashdec.c. (CVE-2026-75146) References
- https://bugs.mageia.org/show_bug.cgi?id=36272
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/36MFOOZUWA23VQEN5YTRKBQNH32RPWZB/
- https://www.cve.org/CVERecord?id=CVE-2026-58049
- https://www.cve.org/CVERecord?id=CVE-2026-64830
- https://www.cve.org/CVERecord?id=CVE-2026-64832
- https://www.cve.org/CVERecord?id=CVE-2026-64833
- https://www.cve.org/CVERecord?id=CVE-2026-64834
- https://www.cve.org/CVERecord?id=CVE-2026-64835
- https://www.cve.org/CVERecord?id=CVE-2026-65703
- https://www.cve.org/CVERecord?id=CVE-2026-65704
- https://www.cve.org/CVERecord?id=CVE-2026-65705
- https://www.cve.org/CVERecord?id=CVE-2026-65706
- https://www.cve.org/CVERecord?id=CVE-2026-66036
- https://www.cve.org/CVERecord?id=CVE-2026-66037
- https://www.cve.org/CVERecord?id=CVE-2026-66038
- https://www.cve.org/CVERecord?id=CVE-2026-66039
- https://www.cve.org/CVERecord?id=CVE-2026-66041
- https://www.cve.org/CVERecord?id=CVE-2026-70628
- https://www.cve.org/CVERecord?id=CVE-2026-70629
- https://www.cve.org/CVERecord?id=CVE-2026-70630
- https://www.cve.org/CVERecord?id=CVE-2026-70631
- https://www.cve.org/CVERecord?id=CVE-2026-70632
- https://www.cve.org/CVERecord?id=CVE-2026-75141
- https://www.cve.org/CVERecord?id=CVE-2026-75142
- https://www.cve.org/CVERecord?id=CVE-2026-75143
- https://www.cve.org/CVERecord?id=CVE-2026-75144
- https://www.cve.org/CVERecord?id=CVE-2026-75146
- ffmpeg-7.1.5-1.1.mga10
- ffmpeg-7.1.5-1.1.mga10.tainted
MGASA-2026-0397 - Updated librabbitmq packages fix security vulnerabilities
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-59986 , CVE-2026-61547 Description
amqp_decode_bytes size_t integer overflow bypasses bounds check on 32-bit (OOB read). (CVE-2026-59986) Heap Buffer Overflow in amqp_send_frame() When Serializing Oversized AMQP_FRAME_BODY. (CVE-2026-61547) References
- https://bugs.mageia.org/show_bug.cgi?id=36189
- https://lists.debian.org/debian-security-announce/2026/msg00358.html
- https://github.com/alanxz/rabbitmq-c/security/advisories/GHSA-jgjf-7fwf-f3c7
- https://github.com/alanxz/rabbitmq-c/security/advisories/GHSA-hfjv-vcp3-39wh
- https://ubuntu.com/security/notices/USN-8724-1
- https://www.cve.org/CVERecord?id=CVE-2026-59986
- https://www.cve.org/CVERecord?id=CVE-2026-61547
- librabbitmq-0.15.0-2.2.mga10
- librabbitmq-0.11.0-1.2.mga9
MGASA-2026-0396 - Updated xz packages fix security vulnerabilities
Type: security
Affected Mageia releases : 10 , 9
Description
XZ Utils: Invalid write if a decoder is reinitialized after allocation failure References
- https://bugs.mageia.org/show_bug.cgi?id=36293
- https://www.openwall.com/lists/oss-security/2026/09/09/5
- https://tukaani.org/xz/invalid-write-after-reinit.html
- https://github.com/tukaani-project/xz/security/advisories/GHSA-5qpq-xqfv-j9pg
- xz-5.8.4-1.mga10
- xz-5.4.7-0.git20260909.1.mga9
MGASA-2026-0395 - Updated java-21-openjdk & java-17-openjdk packages fix security vulnerabilities
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-46968 , CVE-2026-46917 , CVE-2026-47010 , CVE-2026-47021 , CVE-2026-47027 , CVE-2026-60147 , CVE-2026-47059 , CVE-2026-47063 , CVE-2026-60589 , CVE-2026-61308 , CVE-2026-70907 Description
Enhance TLS certificate handling. (CVE-2026-46968) Improve DTLS handshaking. (CVE-2026-46917) Enhance JPEG handling. (CVE-2026-47010) Enhance XBM image support. (CVE-2026-47021) Enhance Jar file processing. (CVE-2026-47027) Improve certification checking. (CVE-2026-60147) Enhance AWT ImagingLib. (CVE-2026-47059) Enhance Jar handling. (CVE-2026-47063) Improve Resource Resolving. (CVE-2026-60589) Enhance HTTP Connections. (CVE-2026-61308) Enhance TLS server. (CVE-2026-70907) References
- https://bugs.mageia.org/show_bug.cgi?id=36125
- https://access.redhat.com/errata/RHSA-2026:42889
- https://access.redhat.com/errata/RHSA-2026:55782
- https://access.redhat.com/errata/RHSA-2026:42897
- https://access.redhat.com/errata/RHSA-2026:55788
- https://www.oracle.com/security-alerts/cpujul2026.html#AppendixJAVA
- https://www.oracle.com/security-alerts/cspuaug2026.html#AppendixJAVA
- https://www.cve.org/CVERecord?id=CVE-2026-46968
- https://www.cve.org/CVERecord?id=CVE-2026-46917
- https://www.cve.org/CVERecord?id=CVE-2026-47010
- https://www.cve.org/CVERecord?id=CVE-2026-47021
- https://www.cve.org/CVERecord?id=CVE-2026-47027
- https://www.cve.org/CVERecord?id=CVE-2026-60147
- https://www.cve.org/CVERecord?id=CVE-2026-47059
- https://www.cve.org/CVERecord?id=CVE-2026-47063
- https://www.cve.org/CVERecord?id=CVE-2026-60589
- https://www.cve.org/CVERecord?id=CVE-2026-61308
- https://www.cve.org/CVERecord?id=CVE-2026-70907
- java-21-openjdk-21.0.12.1.1-1.mga10
- java-17-openjdk-17.0.20.1.1-1.mga9
MGASA-2026-0394 - Updated perl-Imager packages fix a security vulnerability
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-19082 Description
Imager versions from 0.45_02 before 1.034 for Perl may expose adjacent heap bytes via strlen() over-read from zero-count ASCII EXIF entries in copy_string_tags References
- https://bugs.mageia.org/show_bug.cgi?id=36133
- https://www.openwall.com/lists/oss-security/2026/08/07/6
- https://github.com/tonycoz/imager/security/advisories/GHSA-hx46-55wp-hv6m
- https://metacpan.org/release/TONYC/Imager-1.034/changes
- https://www.cve.org/CVERecord?id=CVE-2026-19082
- perl-Imager-1.34.0-1.1.mga10
- perl-Imager-1.34.0-1.1.mga9
MGASA-2026-0393 - Updated perl-Catalyst-Plugin-Static-Simple packages fix a security vulnerability
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-15743 Description
Catalyst::Plugin::Static::Simple versions through 0.38 for Perl mark responses as publicly cacheable References
- https://bugs.mageia.org/show_bug.cgi?id=36154
- https://www.openwall.com/lists/oss-security/2026/08/20/18
- https://www.cve.org/CVERecord?id=CVE-2026-15743
- perl-Catalyst-Plugin-Static-Simple-0.370.0-4.mga10
- perl-Catalyst-Plugin-Static-Simple-0.370.0-3.mga9
MGASA-2026-0392 - Updated tor packages fix security vulnerabilities
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-87724 Description
Tor before 0.4.9.12 interprets the CC_RESPONSE extension even when CC_REQUEST was not sent, which allows remote attackers to cause a denial of service (crash) because of corrupted congestion-control state(CVE-2026-87724) Do not purge memory for OOM from within low-level code (TROVE-2026-043). A hostile cache could trick a client into falsely believing that certain relays' microdescriptors or router descriptors were unusable (TROVE-2026-034). Fix a use-after-free error (TROVE-2026-036). Limit the size of consensus diffs, in bytes and in lines, to prevent a class of memory-based denial-of-service attacks (TROVE-2026-042). Negotiate CGO cryptography with every hop that supports it (TROVE-2026-033). Validate DNS names for complience whenever providing or receiving them from evdns, to limit exposure to a class of application and library bugs (TROVE-2026-035). References
- https://bugs.mageia.org/show_bug.cgi?id=36284
- https://www.openwall.com/lists/oss-security/2026/09/08/20
- https://www.cve.org/CVERecord?id=CVE-2026-87724
- tor-0.4.9.12-1.mga10
- tor-0.4.9.12-1.mga9
MGASA-2026-0391 - Updated glibc package fixes security vulnerabilities
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-5435 , CVE-2026-6238 , CVE-2026-6368 , CVE-2026-6791 , CVE-2026-19499 , CVE-2026-77117 , CVE-2026-80489 Description
Potential buffer overflow in ns_sprintrrf TSIG handling path. (CVE-2026-5435) Buffer overread in ns_printrrf with corrupted RDATA field. (CVE-2026-6238) wordexp with WRDE_APPEND can return or use invalid memory. (CVE-2026-6368) Potential stack-based buffer clash during tilde expansion in wordexp. (CVE-2026-6791) Fix right-justification in strfmon. (CVE-2026-19499) SHIFT_JISX0213 decoding lacks pending character reset. (CVE-2026-77117) EUC_JISX0213 decoding lacks pending character reset. (CVE-2026-80489) References
- https://bugs.mageia.org/show_bug.cgi?id=35262
- https://www.openwall.com/lists/oss-security/2026/04/28/16
- https://www.openwall.com/lists/oss-security/2026/08/11/3
- https://www.cve.org/CVERecord?id=CVE-2026-5435
- https://www.cve.org/CVERecord?id=CVE-2026-6238
- https://www.cve.org/CVERecord?id=CVE-2026-6368
- https://www.cve.org/CVERecord?id=CVE-2026-6791
- https://www.cve.org/CVERecord?id=CVE-2026-19499
- https://www.cve.org/CVERecord?id=CVE-2026-77117
- https://www.cve.org/CVERecord?id=CVE-2026-80489
- glibc-2.42-10.mga10
MGAA-2026-0123 - Updated simgear, flightgear, flightgear-data packages fix bug
Type: bugfix
Affected Mageia releases : 10
Description
Updated simgear, flightgear and flightgear-data packages to new stable release version 2024.1.7 References
SRPMS 10/core
- simgear-2024.1.7-1.mga10
- flightgear-2024.1.7-1.mga10
- flightgear-data-2024.1.7-1.mga10




