Lector de Feeds
MGASA-2026-0437 - Updated perl-Dancer2 packages fix a security vulnerability
Publication date: 23 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-13577 Description
Dancer2 versions through 2.1.0 for Perl generate insecure session ids when required CSPRNG modules are unavailable. (CVE-2026-13577) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-13577 Description
Dancer2 versions through 2.1.0 for Perl generate insecure session ids when required CSPRNG modules are unavailable. (CVE-2026-13577) References
- https://bugs.mageia.org/show_bug.cgi?id=35967
- https://www.openwall.com/lists/oss-security/2026/07/20/5
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PXWK3ODXBSRKU5P4JUADGHFPAH5I42DO/
- https://www.cve.org/CVERecord?id=CVE-2026-13577
- perl-Dancer2-2.0.1-1.2.mga10
- perl-Dancer2-0.400.1-1.2.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0436 - Updated rest packages fix a security vulnerability
Publication date: 23 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-16615 Description
Weak random number generation in pkce implementation. (CVE-2026-16615) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-16615 Description
Weak random number generation in pkce implementation. (CVE-2026-16615) References
- https://bugs.mageia.org/show_bug.cgi?id=36176
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/6Q63SLBWJIJZVOY6R6AXMKGOBBO26LVB/
- https://bugzilla.redhat.com/show_bug.cgi?id=2504432
- https://gitlab.gnome.org/GNOME/librest/-/issues/25
- https://www.cve.org/CVERecord?id=CVE-2026-16615
- rest-0.10.2-2.1.mga10
- rest-0.9.1-2.1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0435 - Updated cpio packages fix security vulnerabilities
Publication date: 23 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-66484 , CVE-2026-66485 , CVE-2026-66486 Description
Path Traversal in GNU cpio. (CVE-2026-66484) Uncontrolled Memory Allocation in GNU cpio. (CVE-2026-66485) Improper Output Encoding in GNU cpio. (CVE-2026-66486) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-66484 , CVE-2026-66485 , CVE-2026-66486 Description
Path Traversal in GNU cpio. (CVE-2026-66484) Uncontrolled Memory Allocation in GNU cpio. (CVE-2026-66485) Improper Output Encoding in GNU cpio. (CVE-2026-66486) References
- https://bugs.mageia.org/show_bug.cgi?id=36242
- https://ubuntu.com/security/notices/USN-8704-1
- https://www.cve.org/CVERecord?id=CVE-2026-66484
- https://www.cve.org/CVERecord?id=CVE-2026-66485
- https://www.cve.org/CVERecord?id=CVE-2026-66486
- cpio-2.15-3.1.mga10
- cpio-2.14-1.1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0434 - Updated diffutils packages fix a security vulnerability
Publication date: 23 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-53910 Description
Heap-based Buffer Overflow in GNU diffutils. (CVE-2026-53910) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-53910 Description
Heap-based Buffer Overflow in GNU diffutils. (CVE-2026-53910) References
- https://bugs.mageia.org/show_bug.cgi?id=36243
- https://ubuntu.com/security/notices/USN-8692-1
- https://www.cve.org/CVERecord?id=CVE-2026-53910
- diffutils-3.12-1.1.mga10
- diffutils-3.10-1.1.mga9
Categorías: Actualizaciones de Seguridad
MGAA-2026-0130 - Updated twinkle packages fix bug
Publication date: 23 Sep 2026
Type: bugfix
Affected Mageia releases : 10 , 9
Description
twinkle is updated to version 1.11.0 to fix a crash in the application. References
SRPMS 10/core
Type: bugfix
Affected Mageia releases : 10 , 9
Description
twinkle is updated to version 1.11.0 to fix a crash in the application. References
SRPMS 10/core
- twinkle-1.11.0-1.mga10
- twinkle-1.11.0-1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0433 - Updated nmap packages fix a security vulnerability
Publication date: 21 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-72712 Description
Denial of Service via Zero-Length TCP Option Packet. (CVE-2026-72712) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-72712 Description
Denial of Service via Zero-Length TCP Option Packet. (CVE-2026-72712) References
- https://bugs.mageia.org/show_bug.cgi?id=36129
- https://www.openwall.com/lists/oss-security/2026/07/29/4
- https://github.com/nmap/nmap/issues/3368
- https://www.vulncheck.com/advisories/nmap-denial-of-service-via-zero-length-tcp-option-packet
- https://www.cve.org/CVERecord?id=CVE-2026-72712
- nmap-7.98-1.2.mga10
- nmap-7.95-1.2.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0432 - Updated vim packages fix security vulnerabilities
Publication date: 21 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
Description
Out-of-bounds Access in libvterm Resize Handling in Vim < 9.2.1013 Integer Overflow in Undo File Entry Size Check in Vim < v9.2.1014 && Vim >= v8.1.0688 References
Type: security
Affected Mageia releases : 10 , 9
Description
Out-of-bounds Access in libvterm Resize Handling in Vim < 9.2.1013 Integer Overflow in Undo File Entry Size Check in Vim < v9.2.1014 && Vim >= v8.1.0688 References
- https://bugs.mageia.org/show_bug.cgi?id=36204
- https://www.openwall.com/lists/oss-security/2026/08/26/17
- https://www.openwall.com/lists/oss-security/2026/08/26/18
- https://github.com/vim/vim/security/advisories/GHSA-vfc7-mhvm-gjp8
- https://github.com/vim/vim/security/advisories/GHSA-cvc5-p4x9-3f9f
- vim-9.2.1054-1.mga10
- vim-9.2.1054-1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0431 - Updated pcre2 packages fix a security vulnerability
Publication date: 21 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-86145 Description
Out-of-bounds write in pcre2_dfa_match() with recursive patterns under a low heap limit (CVE-2026-86145). References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-86145 Description
Out-of-bounds write in pcre2_dfa_match() with recursive patterns under a low heap limit (CVE-2026-86145). References
- https://bugs.mageia.org/show_bug.cgi?id=36263
- https://www.openwall.com/lists/oss-security/2026/09/04/7
- https://www.openwall.com/lists/oss-security/2026/09/05/3
- https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-2p8c-ff85-vh9x
- https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-3r4p-g7gg-ppmf
- https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-q8g2-wprr-34m9
- https://www.cve.org/CVERecord?id=CVE-2026-86145
- pcre2-10.48-1.mga10
- pcre2-10.48-1.mga9
Categorías: Actualizaciones de Seguridad
MGAA-2026-0129 - Updated conda, python-msgpack & python-pluggy packages fixes bug
Publication date: 21 Sep 2026
Type: bugfix
Affected Mageia releases : 10
Description
The conda version we had was not ready for Python 3.13. This update allows it to be compatible, with updates of msgpack and pluggy too. References
SRPMS 10/core
Type: bugfix
Affected Mageia releases : 10
Description
The conda version we had was not ready for Python 3.13. This update allows it to be compatible, with updates of msgpack and pluggy too. References
SRPMS 10/core
- conda-26.5.3-1.mga10
- python-msgpack-1.2.2-1.mga10
- python-pluggy-1.6.0-1.mga10
Categorías: Actualizaciones de Seguridad




