Lector de Feeds

MGASA-2026-0395 - Updated java-21-openjdk & java-17-openjdk packages fix security vulnerabilities

Mageia Security - Hace 15 horas 25 minutos
Publication date: 12 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-46968 , CVE-2026-46917 , CVE-2026-47010 , CVE-2026-47021 , CVE-2026-47027 , CVE-2026-60147 , CVE-2026-47059 , CVE-2026-47063 , CVE-2026-60589 , CVE-2026-61308 , CVE-2026-70907 Description
Enhance TLS certificate handling. (CVE-2026-46968) Improve DTLS handshaking. (CVE-2026-46917) Enhance JPEG handling. (CVE-2026-47010) Enhance XBM image support. (CVE-2026-47021) Enhance Jar file processing. (CVE-2026-47027) Improve certification checking. (CVE-2026-60147) Enhance AWT ImagingLib. (CVE-2026-47059) Enhance Jar handling. (CVE-2026-47063) Improve Resource Resolving. (CVE-2026-60589) Enhance HTTP Connections. (CVE-2026-61308) Enhance TLS server. (CVE-2026-70907) References
SRPMS 10/core
  • java-21-openjdk-21.0.12.1.1-1.mga10
9/core
  • java-17-openjdk-17.0.20.1.1-1.mga9

MGASA-2026-0394 - Updated perl-Imager packages fix a security vulnerability

Mageia Security - Hace 15 horas 25 minutos
Publication date: 12 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-19082 Description
Imager versions from 0.45_02 before 1.034 for Perl may expose adjacent heap bytes via strlen() over-read from zero-count ASCII EXIF entries in copy_string_tags References
SRPMS 10/core
  • perl-Imager-1.34.0-1.1.mga10
9/core
  • perl-Imager-1.34.0-1.1.mga9

MGASA-2026-0393 - Updated perl-Catalyst-Plugin-Static-Simple packages fix a security vulnerability

Mageia Security - Hace 15 horas 25 minutos
Publication date: 12 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-15743 Description
Catalyst::Plugin::Static::Simple versions through 0.38 for Perl mark responses as publicly cacheable References
SRPMS 10/core
  • perl-Catalyst-Plugin-Static-Simple-0.370.0-4.mga10
9/core
  • perl-Catalyst-Plugin-Static-Simple-0.370.0-3.mga9

MGASA-2026-0392 - Updated tor packages fix security vulnerabilities

Mageia Security - Hace 20 horas 38 minutos
Publication date: 11 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-87724 Description
Tor before 0.4.9.12 interprets the CC_RESPONSE extension even when CC_REQUEST was not sent, which allows remote attackers to cause a denial of service (crash) because of corrupted congestion-control state(CVE-2026-87724) Do not purge memory for OOM from within low-level code (TROVE-2026-043). A hostile cache could trick a client into falsely believing that certain relays' microdescriptors or router descriptors were unusable (TROVE-2026-034). Fix a use-after-free error (TROVE-2026-036). Limit the size of consensus diffs, in bytes and in lines, to prevent a class of memory-based denial-of-service attacks (TROVE-2026-042). Negotiate CGO cryptography with every hop that supports it (TROVE-2026-033). Validate DNS names for complience whenever providing or receiving them from evdns, to limit exposure to a class of application and library bugs (TROVE-2026-035). References
SRPMS 10/core
  • tor-0.4.9.12-1.mga10
9/core
  • tor-0.4.9.12-1.mga9

MGASA-2026-0391 - Updated glibc package fixes security vulnerabilities

Mageia Security - 11 Septiembre, 2026 - 18:26
Publication date: 11 Sep 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-5435 , CVE-2026-6238 , CVE-2026-6368 , CVE-2026-6791 , CVE-2026-19499 , CVE-2026-77117 , CVE-2026-80489 Description
Potential buffer overflow in ns_sprintrrf TSIG handling path. (CVE-2026-5435) Buffer overread in ns_printrrf with corrupted RDATA field. (CVE-2026-6238) wordexp with WRDE_APPEND can return or use invalid memory. (CVE-2026-6368) Potential stack-based buffer clash during tilde expansion in wordexp. (CVE-2026-6791) Fix right-justification in strfmon. (CVE-2026-19499) SHIFT_JISX0213 decoding lacks pending character reset. (CVE-2026-77117) EUC_JISX0213 decoding lacks pending character reset. (CVE-2026-80489) References
SRPMS 10/core
  • glibc-2.42-10.mga10

MGAA-2026-0123 - Updated simgear, flightgear, flightgear-data packages fix bug

Mageia Security - 11 Septiembre, 2026 - 18:26
Publication date: 11 Sep 2026
Type: bugfix
Affected Mageia releases : 10
Description
Updated simgear, flightgear and flightgear-data packages to new stable release version 2024.1.7 References
SRPMS 10/core
  • simgear-2024.1.7-1.mga10
  • flightgear-2024.1.7-1.mga10
  • flightgear-data-2024.1.7-1.mga10

MGASA-2026-0390 - Updated perl-DBI packages fix security vulnerabilities

Mageia Security - 10 Septiembre, 2026 - 00:52
Publication date: 09 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-73193 , CVE-2026-73194 Description
DBI versions before 1.652 for Perl allow a heap out-of-bounds write on 32-bit perl via an integer wraparound in the output buffer size computed by preparse. DBI versions before 1.652 for Perl allow a heap out-of-bounds write via an unvalidated numeric placeholder that sets the binder counter in preparse. References
SRPMS 10/core
  • perl-DBI-1.652.0-2.mga10
9/core
  • perl-DBI-1.652.0-1.1.mga9

MGASA-2026-0389 - Updated ceph packages fix security vulnerabilities

Mageia Security - 10 Septiembre, 2026 - 00:52
Publication date: 09 Sep 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2025-30156 , CVE-2026-50152 , CVE-2026-54330 , CVE-2026-39944 Description
Updated ceph packages fix various security issues allowing authentication bypasses to gain admin privileges on the OSD, MDS, and MGR services. Notice that some of the fixes require kernel support for aes256k (introduced in kernel 7). This update will not break installs using the old (and insecure) AES keys; warnings will appear to migrate all keys (check out "ceph health detail" or "ceph status"). References
SRPMS 10/core
  • ceph-20.2.4-1.mga10

MGASA-2026-0388 - Updated thunderbird packages fix security vulnerabilities

Mageia Security - 9 Septiembre, 2026 - 19:01
Publication date: 09 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-84637 , CVE-2026-84639 , CVE-2026-84640 , CVE-2026-84641 , CVE-2026-84642 , CVE-2026-75874 , CVE-2026-16365 , CVE-2026-84118 , CVE-2026-84119 , CVE-2026-84120 , CVE-2026-84121 , CVE-2026-84122 , CVE-2026-84123 , CVE-2026-84124 , CVE-2026-84125 , CVE-2026-74952 , CVE-2026-84129 , CVE-2026-16371 , CVE-2026-84130 , CVE-2026-84131 , CVE-2026-84132 , CVE-2026-84133 , CVE-2026-84134 , CVE-2026-84136 , CVE-2026-84137 , CVE-2026-84139 , CVE-2026-84140 , CVE-2026-84141 , CVE-2026-84143 , CVE-2026-84144 , CVE-2026-84145 Description
Uninitialized memory in MIME parsing. (CVE-2026-84639) One byte overflow read in mail parser. (CVE-2026-84640) Information disclosure due to malicious IMAP server response. (CVE-2026-84641) Calendar invitation attachments could launch local executables. (CVE-2026-84637) Allowed UNC hostnames for attachments interpreted as a regular expression. (CVE-2026-84642) Sandbox escape in the Remote Settings Client component. (CVE-2026-75874) Privilege escalation in the DOM: Workers component. (CVE-2026-16365) Use-after-free in the JavaScript: GC component. (CVE-2026-84118) Sandbox escape due to use-after-free in the DOM: Navigation component. (CVE-2026-84119) Use-after-free in the Audio/Video component. (CVE-2026-84120) Sandbox escape due to use-after-free in the DOM: Security component. (CVE-2026-84121) Use-after-free in the Audio/Video component. (CVE-2026-84122) Privilege escalation due to use-after-free in the Graphics: WebGPU component. (CVE-2026-84123) Use-after-free in the DOM: Core & HTML component. (CVE-2026-84124) Use-after-free in the DOM: Core & HTML component. (CVE-2026-84125) Privilege escalation in the DOM: Navigation component. (CVE-2026-16371) Privilege escalation in the Application Update component. (CVE-2026-74952) Site isolation issue in the DOM: Navigation component. (CVE-2026-84129) Information disclosure in the Graphics: WebGPU component. (CVE-2026-84130) Privilege escalation due to invalid pointer in the Graphics component. (CVE-2026-84131) Information disclosure in the Networking: HTTP component. (CVE-2026-84132) Site isolation issue in the DOM: Push Subscriptions component. (CVE-2026-84133) Other issue in the Profile Backup component. (CVE-2026-84134) Other issue in the DOM: Navigation component. (CVE-2026-84136) Spoofing issue in the DOM: Core & HTML component. (CVE-2026-84137) Clickjacking issue in the DOM: Events component. (CVE-2026-84139) Site isolation issue in the DOM: Navigation component. (CVE-2026-84140) Integer overflow in the Graphics: ImageLib component. (CVE-2026-84141) Internally found bugs fixed in Thunderbird 155, Thunderbird ESR 153.2 and Thunderbird ESR 140.15. (CVE-2026-84143) Internally found bugs fixed in Thunderbird 155 and Thunderbird ESR 153.2. (CVE-2026-84144) Internally found bugs fixed in Thunderbird 155, Thunderbird ESR 153.2 and Thunderbird ESR 140.15. (CVE-2026-84145) References
SRPMS 10/core
  • thunderbird-153.2.0-1.mga10
  • thunderbird-l10n-153.2.0-1.mga10
9/core
  • thunderbird-140.15.0-1.mga9
  • thunderbird-l10n-140.15.0-1.mga9

MGASA-2026-0387 - Updated firefox & nss packages fix security vulnerabilities

Mageia Security - 9 Septiembre, 2026 - 19:01
Publication date: 09 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-75874 , CVE-2026-16365 , CVE-2026-84118 , CVE-2026-84119 , CVE-2026-84120 , CVE-2026-84121 , CVE-2026-84122 , CVE-2026-84123 , CVE-2026-84124 , CVE-2026-84125 , CVE-2026-74952 , CVE-2026-84129 , CVE-2026-16371 , CVE-2026-84130 , CVE-2026-84131 , CVE-2026-84132 , CVE-2026-84133 , CVE-2026-84134 , CVE-2026-84136 , CVE-2026-84137 , CVE-2026-84139 , CVE-2026-84140 , CVE-2026-84141 , CVE-2026-84143 , CVE-2026-84144 , CVE-2026-84145 Description
Sandbox escape in the Remote Settings Client component. (CVE-2026-75874) Privilege escalation in the DOM: Workers component. (CVE-2026-16365) Use-after-free in the JavaScript: GC component. (CVE-2026-84118) Sandbox escape due to use-after-free in the DOM: Navigation component. (CVE-2026-84119) Use-after-free in the Audio/Video component. (CVE-2026-84120) Sandbox escape due to use-after-free in the DOM: Security component. (CVE-2026-84121) Use-after-free in the Audio/Video component. (CVE-2026-84122) Privilege escalation due to use-after-free in the Graphics: WebGPU component. (CVE-2026-84123) Use-after-free in the DOM: Core & HTML component. (CVE-2026-84124) Use-after-free in the DOM: Core & HTML component. (CVE-2026-84125) Privilege escalation in the DOM: Navigation component. (CVE-2026-16371) Privilege escalation in the Application Update component. (CVE-2026-74952) Site isolation issue in the DOM: Navigation component. (CVE-2026-84129) Information disclosure in the Graphics: WebGPU component. (CVE-2026-84130) Privilege escalation due to invalid pointer in the Graphics component. (CVE-2026-84131) Information disclosure in the Networking: HTTP component. (CVE-2026-84132) Site isolation issue in the DOM: Push Subscriptions component. (CVE-2026-84133) Other issue in the Profile Backup component. (CVE-2026-84134) Other issue in the DOM: Navigation component. (CVE-2026-84136) Spoofing issue in the DOM: Core & HTML component. (CVE-2026-84137) Clickjacking issue in the DOM: Events component. (CVE-2026-84139) Site isolation issue in the DOM: Navigation component. (CVE-2026-84140) Integer overflow in the Graphics: ImageLib component. (CVE-2026-84141) Internally found bugs fixed in Firefox 155, Firefox ESR 153.2 and Firefox ESR 140.15. (CVE-2026-84143) Internally found bugs fixed in Firefox 155 and Firefox ESR 153.2. (CVE-2026-84144) Internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox ESR 140.15 and Firefox ESR 115.40. (CVE-2026-84145) References
SRPMS 10/core
  • firefox-l10n-153.2.0-1.mga10
  • firefox-153.2.0-1.mga10
  • nss-3.128.0-1.mga10
9/core
  • firefox-l10n-140.15.0-1.mga9
  • firefox-140.15.0-1.mga9
  • nss-3.128.0-1.mga9

MGASA-2026-0386 - Updated wget packages fix a security vulnerability

Mageia Security - 9 Septiembre, 2026 - 19:01
Publication date: 09 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-16599 Description
Denial of Service in GNU wget. (CVE-2026-16599) References
SRPMS 10/core
  • wget-1.25.0-2.3.mga10
9/core
  • wget-1.21.4-1.5.mga9

MGASA-2026-0385 - Updated dovecot package fixes security vulnerabilities

Mageia Security - 9 Septiembre, 2026 - 05:15
Publication date: 09 Sep 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-33263 , CVE-2026-33607 , CVE-2026-27852 , CVE-2026-33606 , CVE-2026-33604 , CVE-2026-40014 , CVE-2026-40013 , CVE-2026-33605 , CVE-2026-40018 , CVE-2026-40019 , CVE-2026-40015 , CVE-2026-40017 , CVE-2026-40203 , CVE-2026-42007 , CVE-2026-40204 , CVE-2026-40205 , CVE-2026-42008 , CVE-2026-42395 , CVE-2026-42393 , CVE-2026-52681 , CVE-2026-42392 , CVE-2026-73208 , CVE-2026-73209 , CVE-2026-42391 , CVE-2026-52687 Description
submission-login: Panic when mail_max_userip_connections is reached: Panic: epoll_ctl(del, 8) failed: Bad file descriptor. (CVE-2026-33263) Dovecot IMAP LIST match_sub() Exponential Backtracking — CPU Denial of Service. (CVE-2026-33607) DoS by sending mail with bad header. (CVE-2026-27852) dsync: Mail content can cause dsync protocol injection. (CVE-2026-33606) SMTP Smuggling via Missing Dot-Stuffing After Bare Carriage Return. (CVE-2026-33604) IMAP THREAD REFERENCES O(N²) CPU DoS via Crafted References Header
(index-thread-links.c). (CVE-2026-40014) pigeonhole: Stack Buffer Underflow in Pigeonhole ManageSieve CHECKSCRIPT/PUTSCRIPT. (CVE-2026-40013) managesieve-login: Pre-auth crash. (CVE-2026-33605) MySQL multi-byte escaping wrong. (CVE-2026-40018) v2.4.3 regression: managesieve-login pre-auth infinite loop. (CVE-2026-40019) imap-hibernate can be crashed. (CVE-2026-40015) IMAP THREAD O(M³) CPU DoS via CRC32 Hash Collision in strmap (mail-index-strmap.c / hash2.c). (CVE-2026-40017) IMAP Compression Can Reveal Whether a Small Synced Email Body Matches Sender-Chosen Text. (CVE-2026-40203) Sieve editheader RCE. (CVE-2026-42007) acl: lda_mailbox_autocreate can bypass acl restrictions. (CVE-2026-40204) OAuth2 passdb scope enforcement bypass via OR semantics in remote validation path. (CVE-2026-40205) XCLIENT FORWARD= bare token not namespaced, allows nopassword injection via trusted proxy. (CVE-2026-42008) Single NUL-Byte XCLIENT FORWARD Payload Crashes. (CVE-2026-42395) doveadm_password or api key length can still be leaked with timing comparisons. (CVE-2026-42393) Sieve resource usage tracking lost when active script changes. (CVE-2026-52681) imap-urlauth leaks memory into user-visible error messages. (CVE-2026-42392) auth: db-oauth2: aud claim used as fallback for missing scope claim. (CVE-2026-73208) imap-login crash: Self-recursion on zero-output decompress chunks. (CVE-2026-73209) imap: Pre-login memory/CPU growth with ID command. (CVE-2026-42391) IMAP: COMPRESS ZSTD can cause excessive memory usage. (CVE-2026-52687) References
SRPMS 10/core
  • dovecot-2.4.5-2.mga10

MGASA-2026-0384 - Updated spice-vdagent packages fix security vulnerabilities

Mageia Security - 9 Septiembre, 2026 - 05:15
Publication date: 09 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-57965 , CVE-2026-57966 Description
Integer overflow in udscs_write() leading to heap buffer overflow. (CVE-2026-57965) Path traversal in file transfer via unsanitized filename. (CVE-2026-57966) References
SRPMS 10/core
  • spice-vdagent-0.23.0-1.1.mga10
9/core
  • spice-vdagent-0.22.1-2.1.mga9

MGAA-2026-0122 - Updated python-intervaltree package fixes bug

Mageia Security - 9 Septiembre, 2026 - 05:15
Publication date: 09 Sep 2026
Type: bugfix
Affected Mageia releases : 10
Description
python3-intervaltree have a missing requirement on python3-sortedcontainers, this produce that the python IDE Spyder crash at start. This update fixes the reported issue. References
SRPMS 10/core
  • python-intervaltree-3.2.0-1.1.mga10

MGASA-2026-0383 - Updated freerdp packages fix security vulnerabilities

Mageia Security - 8 Septiembre, 2026 - 03:47
Publication date: 08 Sep 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-22851 , CVE-2026-22853 , CVE-2026-22858 , CVE-2026-25941 , CVE-2026-25942 , CVE-2026-25952 , CVE-2026-25953 , CVE-2026-25954 , CVE-2026-25955 , CVE-2026-25959 , CVE-2026-25997 , CVE-2026-26952 , CVE-2026-33977 , CVE-2026-33982 , CVE-2026-33983 , CVE-2026-33984 , CVE-2026-33985 , CVE-2026-33986 , CVE-2026-33987 , CVE-2026-33995 , CVE-2026-27015 , CVE-2026-27951 , CVE-2026-40033 , CVE-2026-44420 , CVE-2026-44421 , CVE-2026-44422 , CVE-2026-45700 , CVE-2026-55191 , CVE-2026-55192 , CVE-2026-55193 , CVE-2026-55194 , CVE-2026-55648 Description
Updated packages bring lot of security fixes. Please see the links for additional information. References
SRPMS 10/core
  • freerdp-3.31.0-1.mga10

MGASA-2026-0382 - Updated tor packages fix security vulnerabilities

Mageia Security - 8 Septiembre, 2026 - 03:47
Publication date: 08 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-77584 , CVE-2026-77587 , CVE-2026-77638 , CVE-2026-77639 , CVE-2026-77640 , CVE-2026-77641 , CVE-2026-77642 Description
An out-of-bounds write when parsing a consensus or detached signature with unexpected signature digest type (CVE-2026-77642). A NULL write after free when sending a CONFLUX_SWITCH cell fails, resulting in a crash (CVE-2026-77641). An infinite loop when decompressing a truncated zlib/gzip stream with done=1 (CVE-2026-77640). A compression bomb bypass where an attacker could concatenate many gzip or zlib sub-streams (CVE-2026-77639). A race condition where in just the right circumstances a rendezvous point could man-in-the-middle (impersonate) the onion service that the client was trying to reach (CVE-2026-77638). A use-after-free that a malicious exit node could use to crash a client (CVE-2026-77587). Tor before 0.4.9.10 did not reject a CONFLUX_LINK cell that arrives on a circuit which already has attached streams (CVE-2026-77584). References
SRPMS 10/core
  • tor-0.4.9.11-1.mga10
9/core
  • tor-0.4.9.11-1.mga9

MGASA-2026-0381 - Updated apache-mod_auth_openidc packages fix a security vulnerability

Mageia Security - 7 Septiembre, 2026 - 19:46
Publication date: 07 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-54789 Description
Out-of-bounds read and write in state cookie parsing. (CVE-2026-54789) References
SRPMS 10/core
  • apache-mod_auth_openidc-2.4.20.2-1.mga10
9/core
  • apache-mod_auth_openidc-2.4.20.2-1.mga9

MGASA-2026-0380 - Updated python-pyasn1 packages fix security vulnerabilities

Mageia Security - 7 Septiembre, 2026 - 19:46
Publication date: 07 Sep 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-59884 , CVE-2026-59885 , CVE-2026-59886 Description
The BER decoder (shared by the CER and DER codecs) parses long-form tags by accumulating continuation octets in a loop with no upper bound on the size of the tag ID. A crafted input can force the decoder to build an arbitrarily large integer, with CPU cost growing quadratically in input size — a ~1 MB input consumes over a minute of CPU. On Python 3.11+, the oversized tag ID can also trigger an unhandled ValueError (integer string conversion limit) while the decoder formats error messages, violating the documented PyAsn1Error contract and potentially bypassing caller error handling. References
SRPMS 10/core
  • python-pyasn1-0.6.4-1.mga10

MGAA-2026-0121 - Updated radiotray-ng package fixes bug

Mageia Security - 7 Septiembre, 2026 - 19:46
Publication date: 07 Sep 2026
Type: bugfix
Affected Mageia releases : 10
Description
Update the stream links for "KDFC", "CINEMIX", "Radio Paradise", and remove the offline "WNAR-AM Radio" station. References
SRPMS 10/core
  • radiotray-ng-0.2.10-1.mga10
Feed