Lector de Feeds

MGAA-2026-0093 - Updated soundkonverter packages fix bug

Mageia Security - 14 Agosto, 2026 - 19:04
Publication date: 14 Aug 2026
Type: bugfix
Affected Mageia releases : 10

soundkonverter can't convert audio files. This update switches to another qt6 fork of soundkonverter to fix the reported issue. Please note that command line operations are still not working. References SRPMS 10/core
  • soundkonverter-3.0.1.32-1.20260728.1.mga10

MGAA-2026-0092 - Updated php8.5-imap & php8.4-imap packages fix bug

Mageia Security - 14 Agosto, 2026 - 19:04
Publication date: 14 Aug 2026
Type: bugfix
Affected Mageia releases : 10

Due to an import error, the php[8.4,8.5]-imap package was compiled without SSL support. This update fixes this issue. Please be aware that this package was deprecated by php. Please use an alternative package instead; see the links. References SRPMS 10/core
  • php8.5-imap-1.0.3-1.1.mga10
  • php8.4-imap-1.0.3-3.1.mga10

MGAA-2026-0091 - Updated perl-App-Asciio & perl-IO-Prompter packages fix bug

Mageia Security - 14 Agosto, 2026 - 19:04
Publication date: 14 Aug 2026
Type: bugfix
Affected Mageia releases : 10

The current App::Asciio perl module in Mageia 10, version 1.51.3 (released in 2015), depends on Gtk2. This update brings a new version 1.9.02 (released in 2023) which upgraded its dependencies to Gtk3. References SRPMS 10/core
  • perl-App-Asciio-1.9.2-1.3.mga10
  • perl-IO-Prompter-0.5.4-1.mga10

MGASA-2026-0335 - Updated dhcpcd packages fix security vulnerabilities

Mageia Security - 13 Agosto, 2026 - 22:59
Publication date: 13 Aug 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-56114 , CVE-2026-56116
Attackers can send a crafted DHCPv6 ADVERTISE message containing an IA_PD IAPREFIX /0 with a valid OPTION_PD_EXCLUDE using an exclude prefix length of /121 through /128 to trigger the out-of-bounds write and potentially corrupt adjacent stack memory (CVE: CVE-2026-56114). Attackers can repeatedly send Router Advertisements containing Route Information options with a lifetime of zero, triggering unfreed allocations in routeinfo_findalloc() that cause linear memory exhaustion and eventual daemon crash (CVE: CVE-2026-56116). References SRPMS 10/core
  • dhcpcd-10.5.0-1.1.mga10

MGASA-2026-0334 - Updated qemu packages fix many security vulnerabilities

Mageia Security - 13 Agosto, 2026 - 17:40

MGASA-2026-0333 - Updated roundcubemail packages fix security vulnerabilities

Mageia Security - 13 Agosto, 2026 - 17:40
Publication date: 13 Aug 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-54432 , CVE-2026-54433 , CVE-2026-62641 , CVE-2026-62642 , CVE-2026-62643 , CVE-2026-62644
Add basic validation for content proxied by the css proxy Fix SSRF bypass via specific local address URLs using 100.64.0.0/10 and fe80::/10 nets, Fix SSRF filter bypass via various forms of nip.io/sslip.io hostnames evading is_local_url() check Fix remote content blocking bypass via unclosed url() in a FuncIRI attribute Fix LDAP filter injection via unescaped %u/%fu/%d substitution into the search_filter Fix arbitrary Sieve script injection via a filter rule name bypassing managesieve_disabled_actions Fix RCE via cmd_learn driver of markasjunk plugin Fix IMAP command injection via mail search and LITERAL+ byte-count desynchronization Fix password's modoboa driver leak of an authentication token to a user-controlled host Fix stored XSS in "Add to address book" action Fix HTML/CSS sanitization bypass via SVG animate by attribute References SRPMS 10/core
  • roundcubemail-1.7.3-2.mga10

MGASA-2026-0332 - Updated roundcubemail package fixes security vulnerabilities

Mageia Security - 13 Agosto, 2026 - 17:40

MGAA-2026-0090 - Updated gdm packages fix bug

Mageia Security - 13 Agosto, 2026 - 17:40
Publication date: 13 Aug 2026
Type: bugfix
Affected Mageia releases : 10

When upgrading from Mageia 9 to Mageia 10 in a graphical session controlled by gdm, gdm restarts in the middle of the distro upgrade process and causes an incomplete/broken upgrade. This update fixes the reported issue. References SRPMS 10/core
  • gdm-49.2-2.1.mga10

MGAA-2026-0089 - Updated lightdm packages fix bug

Mageia Security - 13 Agosto, 2026 - 17:40
Publication date: 13 Aug 2026
Type: bugfix
Affected Mageia releases : 10

When upgrading from Mageia 9 to Mageia 10 in a graphical session controlled by lightdm, lightdm restarts in the middle of the distro upgrade process and causes an incomplete/broken upgrade. This update fixes the reported issue. References SRPMS 10/core
  • lightdm-1.32.0-4.1.mga10

MGAA-2026-0088 - Updated (kmod-)virtualbox(-kvm) packages fix a bug

Mageia Security - 13 Agosto, 2026 - 17:40
Publication date: 13 Aug 2026
Type: bugfix
Affected Mageia releases : 10

The updated packages fix an issue with sharing the clipboard and Plasma Wayland guests. References SRPMS 10/core
  • virtualbox-7.2.14-1.mga10
  • virtualbox-kvm-7.2.14-1.mga10
  • kmod-virtualbox-7.2.14-29.mga10

MGAA-2026-0086 - Updated (kmod-)nvidia-current(-wopengpu) packages fix bugs

Mageia Security - 13 Agosto, 2026 - 17:40
Publication date: 13 Aug 2026
Type: bugfix
Affected Mageia releases : 10

This is a bug fix release for the new 580 series. See the upstream reference for details. References SRPMS 10/nonfree
  • nvidia-current-580.173.02-1.mga10.nonfree
  • nvidia-current-wopengpu-580.173.02-1.mga10.nonfree
  • kmod-nvidia-current-wopengpu-580.173.02-38.mga10.nonfree
Feed