Lector de Feeds

MGASA-2026-0305 - Updated sqlite3 packages fix security vulnerabilities

Mageia Security - 28 Julio, 2026 - 08:15
Publication date: 28 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-50812 , CVE-2026-50813 Description CVE-2026-50812: A NULL pointer dereference in the SQLite Session Extension in SQLite 3.53.1 and SQLite trunk builds before check-in e807d4e3798efd53 allows an attacker who can supply a malformed changeset blob to cause a denial of service. The issue occurs when sqlite3changeset_apply_v3() applies a corrupt changeset and reaches sqlite3_value_type() with a NULL sqlite3_value pointer. CVE-2026-50813: An issue in SQLite before Fossil check-in 869a51ae84df allows a local attacker to obtain sensitive information via the Session Extension changeset concat/changegroup merge path. References SRPMS 10/core
  • sqlite3-3.51.3-1.2.mga10
9/core
  • sqlite3-3.40.1-1.10.mga9

MGASA-2026-0304 - Updated memcached packages fix security and other issues

Mageia Security - 28 Julio, 2026 - 08:15
Publication date: 28 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
Description The updated packages fix bugs including security ones. References SRPMS 10/core
  • memcached-1.6.45-1.mga10
9/core
  • memcached-1.6.45-1.mga9

MGAA-2026-0073 - Updated gscan2pdf packages fix bug

Mageia Security - 28 Julio, 2026 - 08:15
Publication date: 28 Jul 2026
Type: bugfix
Affected Mageia releases : 10
Description perl-Gtk2-Ex-PodViewer depends on perl-Gtk2-Ex-Simple-List, but upstream gscan2pdf now explicitly depends on Gtk3::SimpleList, so this dependency seems to be indeed obsolete. Yjis update removes the dependency on perl-Gtk2-Ex-PodViewer. References SRPMS 10/core
  • gscan2pdf-2.13.5-2.1.mga10

MGASA-2026-0303 - Updated x11-server x11-server-xwayland tigervnc packages fix security vulnerabilities

Mageia Security - 27 Julio, 2026 - 23:45
Publication date: 27 Jul 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-55999 , CVE-2026-56000 Description The updated packages fix security vulnerabilities: glamor Font Atlas Heap Buffer Overflow. (CVE-2026-55999) GLX contextTags Use-After-Free in CommonMakeCurrent(). (CVE-2026-56000) References SRPMS 10/core
  • x11-server-21.1.24-1.mga10
  • x11-server-xwayland-24.1.13-1.mga10
  • tigervnc-1.15.0-7.1.mga10

MGASA-2026-0302 - Updated libyang packages fix a security vulnerability

Mageia Security - 27 Julio, 2026 - 23:45
Publication date: 27 Jul 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-41401 Description The updated packages fix a security vulnerability: Heap Use-After-Free Write in XML Metadata Parsing. (CVE-2026-41401) References SRPMS 10/core
  • libyang-3.13.5-1.1.mga10

MGASA-2026-0301 - Updated nginx packages fix security vulnerabilities

Mageia Security - 27 Julio, 2026 - 23:45
Publication date: 27 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-42533 , CVE-2026-56434 , CVE-2026-60005 Description CVE-2026-42533: Heap buffer overflow might occur in a worker process when using the map directive with regex matching if the map variable was included in a string expression after a capture affected by this map; a similar issue might happen when using a non-cacheable variable in a string expression. Thanks to Mufeed VH of Winfunc Research and Maxim Dounin. . CVE-2026-60005: Uninitialized memory access might occur when using unnamed regex captures with the "slice" directive or background cache update, which could result in worker process memory disclosure or worker process termination. . CVE-2026-56434: Use-after-free might occur when processing a specially crafted proxied backend response with the ngx_http_ssi_filter_module. Thanks to P4P3R-HAK. References SRPMS 10/core
  • nginx-1.30.4-1.mga10
9/core
  • nginx-1.30.4-1.mga9

MGAA-2026-0072 - Updated tdlib & purple-telegram-tdlib packages fix bugs

Mageia Security - 27 Julio, 2026 - 23:45
Publication date: 27 Jul 2026
Type: bugfix
Affected Mageia releases : 10 , 9
Description purple-telegram-tdlib has been migrated to a new active fork and updated to version 1.1.1. purple-telegram-tdlib updated packages fix an issue where administrators of telegram's groups can't open a chat in the group tdlib has been updated to version 1.8.65, required to build the new version of purple-telegram-tdlib References SRPMS 10/core
  • tdlib-1.8.65-1.git20260613.mga10
  • purple-telegram-tdlib-1.1.1-1.mga10
9/core
  • tdlib-1.8.65-1.git20260613.mga9
  • purple-telegram-tdlib-1.1.1-1.mga9

MGAA-2026-0071 - Updated amarok packages fix a bug

Mageia Security - 27 Julio, 2026 - 23:45
Publication date: 27 Jul 2026
Type: bugfix
Affected Mageia releases : 10
Description After right clicking on a music file in Dolphin and selecting to open it with Amarok, Amarok failed to load the file. This update fixes the issue. References SRPMS 10/core
  • amarok-3.3.3-1.mga10

MGAA-2026-0070 - Updated neochat package fixes missing dependency

Mageia Security - 27 Julio, 2026 - 23:45
Publication date: 27 Jul 2026
Type: bugfix
Affected Mageia releases : 10
Description If purpose wasn't installed, neochat would not start. This update adds the missing dependency on the purpose package. References SRPMS 10/core
  • neochat-25.12.1-1.1.mga10

MGAA-2026-0069 - Updated ocrfeeder package makes it start again

Mageia Security - 27 Julio, 2026 - 23:45
Publication date: 27 Jul 2026
Type: bugfix
Affected Mageia releases : 10
Description The OCRFeeder package wouldn't start since python3.13. This update fixes the issue. References SRPMS 10/core
  • ocrfeeder-0.8.5-4.1.mga10

MGAA-2026-0068 - Updated byobu package fixes missing desktop entry

Mageia Security - 27 Julio, 2026 - 23:45
Publication date: 27 Jul 2026
Type: bugfix
Affected Mageia releases : 10
Description The byobu package failed to install its desktop menu entry. This update fixes the issue. References SRPMS 10/core
  • byobu-6.13-1.1.mga10

MGAA-2026-0067 - Updated phonon-vlc packages fix an upgrade conflict

Mageia Security - 27 Julio, 2026 - 23:45
Publication date: 27 Jul 2026
Type: bugfix
Affected Mageia releases : 10
Description When doing a command line upgrade from Mageia 9 to Mageia 10, there were conflicts between phonon-vlc-i18n-0.12.0-2.mga10.noarch and phonon4qt5-vlc-0.11.3-2.mga9.x86_64. This Mageia 10 update fixes the issue. References SRPMS 10/core
  • phonon-vlc-0.12.0-2.1.mga10

MGASA-2026-0300 - Updated wget packages fix security vulnerabilities

Mageia Security - 25 Julio, 2026 - 19:04
Publication date: 25 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-58469 , CVE-2026-58470 , CVE-2026-58471 , CVE-2026-58472 , CVE-2026-15146 Description Updated wget packages fix security vulnerabilities: -CVE-2026-58469 Wget incorrectly handled Metalink documents containing a whitespace-only URL. A remote attacker could possibly use this issue to cause a denial of service. This issue only affected Mageia 9 and Mageia 10. -CVE-2026-58470 : Wget incorrectly handled Content-Range header values, leading to an integer overflow. A remote attacker could possibly use this issue to cause download desynchronization. -CVE-2026-58471 : Wget incorrectly handled character set conversion of server-supplied filenames. A remote attacker could possibly use this issue to cause a denial of service or possibly execute arbitrary code. This issue affected Mageia9 and Mageia 10. -CVE-2026-58472: It was discovered that Wget incorrectly handled HTML attributes requiring entity encoding. A remote attacker could possibly use this issue to cause a denial of service or possibly execute arbitrary code. -CVE-2026-15146: GNU Wget did not validate the IP address provided by an FTP PASV response while operating in FTP passive mode. A malicious FTP server, or an HTTP server that redirects to an FTP URL, could exploit this behavior to redirect Wget's data connection to an arbitrary IP address and port. This allowed an attacker to forge server-side requests (SSRF) from the machine running Wget, potentially accessing localhost services or internal network resources. References SRPMS 10/core
  • wget-1.25.0-2.2.mga10
9/core
  • wget-1.21.4-1.4.mga9

MGASA-2026-0299 - Updated libnfs packages fix a security vulnerability

Mageia Security - 25 Julio, 2026 - 19:04
Publication date: 25 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-53689 Description The updated packages fix a security vulnerability: libnfs through 6.0.2 before 55c18ea does not validate a string size, leading to an integer overflow during a connection to a crafted NFS server. This occurs in libnfs_zdr_string in lib/libnfs-zdr.c. (CVE-2026-53689) References SRPMS 10/core
  • libnfs-6.0.2-2.1.mga10
9/core
  • libnfs-5.0.2-1.1.mga9

MGASA-2026-0298 - Updated graphite2 packages fix a security vulnerability

Mageia Security - 25 Julio, 2026 - 19:04
Publication date: 25 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-50593 Description The updated packages fix a security vulnerability: Graphite before 1.3.15 has an integer underflow and resultant out-of-bounds write via Graphite actions, because slotat does not ensure that an offset is within the allowed slot-map range. (CVE-2026-50593) References SRPMS 10/core
  • graphite2-1.3.14-4.1.mga10
9/core
  • graphite2-1.3.14-2.1.mga9

MGASA-2026-0297 - Updated vorbis-tools package fixes a security vulnerability

Mageia Security - 25 Julio, 2026 - 19:04
Publication date: 25 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-34253 Description The updated package fixes a security vulnerability: A buffer underflow vulnerability has been identified in the ogg123 utility from the vorbis-tools 1.4.3 package in function remotethread in remote.c. This vulnerability occurs in the remote control functionality when processing malformed input, leading to a stack buffer underflow that can cause application crashes and potentially allow code execution. (CVE-2026-34253) References SRPMS 10/core
  • vorbis-tools-1.4.3-2.1.mga10
9/core
  • vorbis-tools-1.4.2-3.2.mga9

MGASA-2026-0296 - Updated yelp packages fix a security vulnerability

Mageia Security - 25 Julio, 2026 - 19:04
Publication date: 25 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-13601 Description The updated packages fix a security vulnerability: Yelp: yelp-xsl: overly permissive content security policy in yelp allows host file disclosure from flatpak applications. (CVE-2026-13601) References SRPMS 10/core
  • yelp-49.0-2.1.mga10
9/core
  • yelp-42.2-1.2.mga9

MGASA-2026-0295 - Updated giflib packages fix a security vulnerability

Mageia Security - 25 Julio, 2026 - 19:04
Publication date: 25 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-26740 Description The updated packages fix a security vulnerability: Buffer Overflow vulnerability in giflib v.5.2.2 allows a remote attacker to cause a denial of service via the EGifGCBToExtension overwriting an existing Graphic Control Extension block without validating its allocated size. (CVE-2026-26740) References SRPMS 10/core
  • giflib-5.2.2-4.1.mga10
9/core
  • giflib-5.2.1-7.4.mga9

MGAA-2026-0066 - Updated python-zstandard package fixes a bug

Mageia Security - 25 Julio, 2026 - 01:31
Publication date: 25 Jul 2026
Type: bugfix
Affected Mageia releases : 9
Description The previous update was released with the use of the shared library libzstd1, which is now at version 1.5.7 in Mageia 9. However, python-zstandard supported only version 1.5.5. This update patches python-zstandard to use libzstd version 1.5.7. References SRPMS 9/core
  • python-zstandard-0.21.0-1.3.mga9

MGAA-2026-0065 - Updated suricata packages fix the service not starting

Mageia Security - 25 Julio, 2026 - 01:31
Publication date: 25 Jul 2026
Type: bugfix
Affected Mageia releases : 10 , 9
Description The suricata server did not start in Mageia 9 and Mageia 10. The updated suricata packages fix the issue. References SRPMS 10/core
  • suricata-7.0.10-3.2.mga10
9/core
  • suricata-7.0.10-1.2.mga9
Feed