Lector de Feeds

MGASA-2026-0471 - Updated libxfont2 package fixes security vulnerabilities

Mageia Security - 8 Octubre, 2026 - 17:23
Publication date: 08 Oct 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-59679 , CVE-2026-44950 Description
fs_read_glyphs() heap buffer overflow via cumulative glyph data overflow in libXfont2. (CVE-2026-44950) fs_read_glyphs() heap OOB read/write via encoding array index mismatch in libXfont2. (CVE-2026-59679) References
SRPMS 10/core
  • libxfont2-2.0.9-1.mga10

MGAA-2026-0154 - Updated nfs-utils package fixes bug

Mageia Security - 8 Octubre, 2026 - 17:23
Publication date: 08 Oct 2026
Type: bugfix
Affected Mageia releases : 10
Description
nfsdclnts requires python3-pyyaml to work. This update add the missing requirement to nfs-utils References
SRPMS 10/core
  • nfs-utils-2.8.3-2.1.mga10

MGAA-2026-0153 - Updated marnav package fixes bugs

Mageia Security - 8 Octubre, 2026 - 17:23
Publication date: 08 Oct 2026
Type: bugfix
Affected Mageia releases : 10
Description
marnav is updated to version 0.14.1. References
SRPMS 10/core
  • marnav-0.14.1-1.mga10

MGAA-2026-0152 - Updated opencpn packages fix bug

Mageia Security - 8 Octubre, 2026 - 17:23
Publication date: 08 Oct 2026
Type: bugfix
Affected Mageia releases : 10
Description
This version 5.14.2 of OpenCPN is a maintenance release of the previous version 5.14.0 as usually such a maintenance release is provided some time after the main release has been published. It brings some corrections and improvements needed after user reports. References
SRPMS 10/core
  • opencpn-5.14.2-1.mga10

MGAA-2026-0151 - Updated lsp-plugins package fixes bug

Mageia Security - 8 Octubre, 2026 - 17:23
Publication date: 08 Oct 2026
Type: bugfix
Affected Mageia releases : 10
Description
This new version 1.2.35 now allows the use of jack with pipewire in addition to the use with pulseaudio (the previous version 1.2.34 allowed only the use of jack with pulseaudio). References
SRPMS 10/core
  • lsp-plugins-1.2.35-1.mga10

MGAA-2026-0150 - Updated rust-gst-plugin-gif, noopenh264, vokoscreenNG & gstreamer1.0-plugins-bad packages fix bug

Mageia Security - 7 Octubre, 2026 - 22:03
Publication date: 07 Oct 2026
Type: bugfix
Affected Mageia releases : 10
Description
vokoscreenNG requires the openh264 & gif gstreamer components. We now provide openh264 packages from the noopenh264 sources, packages generated from rust-gst-plugin-gif and update gstreamer1.0-plugins-bad to generate the missing components. Note: gstreamer1.0-openh264 should be installed by hand if you do not have tainted repositories enabled before the update. References
SRPMS 10/core
  • rust-gst-plugin-gif-0.14.5-1.1.mga10
  • vokoscreenNG-4.8.3-1.1.mga10
  • gstreamer1.0-plugins-bad-1.26.11-3.1.mga10
10/tainted
  • noopenh264-2.6.0-1.mga10.tainted
  • gstreamer1.0-plugins-bad-1.26.11-3.1.mga10.tainted

MGAA-2026-0149 - Updated zrythm package fixes bug

Mageia Security - 7 Octubre, 2026 - 22:03
Publication date: 07 Oct 2026
Type: bugfix
Affected Mageia releases : 10
Description
The zrythm package has a build id that matches one in the carla package. This prevents both packages from being installed together and causes migrations from Mageia 9 to Mageia 10 to fail if both packages were installed before the migration. This update fixes the reported issue. References
SRPMS 10/core
  • zrythm-1.0.0-3.1.mga10

MGASA-2026-0470 - Updated tesseract packages fix security vulnerabilities

Mageia Security - 7 Octubre, 2026 - 18:19
Publication date: 07 Oct 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-73067 , CVE-2026-88047 , CVE-2026-88048 , CVE-2026-88049 , CVE-2026-88050 , CVE-2026-88051 , CVE-2026-88052 , CVE-2026-88053 , CVE-2026-88054 Description
This is a security update. It fixes nine vulnerabilities in tesseract, the OCR (text recognition) engine. All nine can be triggered only by feeding tesseract a maliciously crafted input file: either a specially crafted recognition/language data file (.traineddata) or a crafted word-list file. Depending on the specific flaw, this can cause a crash (denial of service) or memory corruption. CVE-2026-73067: out-of-bounds read when loading a crafted word-list file. CVE-2026-73066: out-of-bounds write when loading a crafted recognition model file. CVE-2026-88047: stack buffer overflow when loading a crafted language-normalisation file. CVE-2026-88048: out-of-bounds read/write from a crafted neural-network layer in a recognition model file. CVE-2026-88049: out-of-bounds write from a crafted neural-network layer in a recognition model file. CVE-2026-88050: out-of-bounds write from invalid character-encoding values in a crafted recognition model file. CVE-2026-88051: out-of-bounds write when loading a malformed internal data structure from a crafted recognition model file. CVE-2026-88052: out-of-bounds write when loading a crafted character-set file. CVE-2026-88053: out-of-bounds write when loading a crafted legacy recognition template file. CVE-2026-88054: crash (denial of service) when loading a crafted recognition model with an empty internal network. The tesseract package is updated to version 5.5.3, which on its own fixes CVE-2026-73067 and CVE-2026-73066. The remaining seven issues (CVE-2026-88047 to CVE-2026-88054) are not yet fixed in any upstream release, so nine patches taken from upstream's main development branch are also applied. Reported by Tristan Madani (CVE-2026-88047) and Zhixi "Jace" Sun (CVE-2026-88048 to CVE-2026-88054); see the individual advisories below for full credits, including CVE-2026-73067 and CVE-2026-73066. References
SRPMS 10/core
  • tesseract-5.5.3-1.mga10

MGASA-2026-0468 - Updated tor package fixes security vulnerabilities

Mageia Security - 6 Octubre, 2026 - 17:25
Publication date: 06 Oct 2026
Type: security
Affected Mageia releases : 10
Description
Avoid a set of possible memory corruption, double-free, and null pointer dereference bugs that could occur with some reverse DNS virtual address configurations. TROVE-2026-051. Avoid cacheing DNS PTR responses when DNS caching is disabled. Previous code to prevent this caching parsed the response addresses incorrectly, and defaulted to caching when the address could not be parsed. TROVE-2026-050 References
SRPMS 10/core
  • tor-0.4.9.13-1.mga10

MGAA-2026-0148 - Updated drakwizard package fixes bug

Mageia Security - 4 Octubre, 2026 - 00:15
Publication date: 03 Oct 2026
Type: bugfix
Affected Mageia releases : 10
Description
/sbin/route is deprecated and drakwizard should use ip (from iproute2) instead. This will let us remove the dependency on the unmaintained Net::Route::Table module, which has not been updated upstream since 2009. This update fixes the reported issue. References
SRPMS 10/core
  • drakwizard-4.13-1.mga10

MGAA-2026-0147 - Updated task-cinnamon package fixes bugs

Mageia Security - 4 Octubre, 2026 - 00:15
Publication date: 03 Oct 2026
Type: bugfix
Affected Mageia releases : 10
Description
xdg-desktop-portal-xapp package is missing in the requirements. lxdm should not be recommended as display manager for cinnamon. This update fixes the reported issues. References
SRPMS 10/core
  • task-cinnamon-6.6-1.2.mga10

MGAA-2026-0146 - Updated guayadeque package fixes bugs

Mageia Security - 4 Octubre, 2026 - 00:15
Publication date: 03 Oct 2026
Type: bugfix
Affected Mageia releases : 10
Description
This last version 0.7.7 corrects some bugs and brings an offline help: - Fixed a long standing bug that causes the grids (like Media Library Songs Panel) to not update the screen on horizontal scroll. - Fixed a bug in the playlist vertical scrolling when the playing track is out of view. - The first track out of view in the bottom of the playlist wasn't scrolled to follow the player current track. - Playlist "Select" context-menu fixes - Fixed selections failing when a Directory panel filter was active. - Fixed saving and restoring the last directory path selected in Directory Panel. - Fixed the "enable volume" preference saving the wrong value. - Fixed build for gtk2 based distros. - Added missing Serbian (Latin) language to preferences. - Corrected several translations (Portuguese (Brasil), French, Italian, Catalan, Spanish, Greek, German...) References
SRPMS 10/core
  • guayadeque-0.7.7-1.mga10
Feed