Lector de Feeds
MGASA-2026-0443 - Updated pipewire packages fix security vulnerabilities
Publication date: 23 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-14324 , CVE-2026-14330 Description
RAOP module accepts unbounded Content-Length values and does not check the pw_array_add() return. (CVE-2026-14324) Multiple unbounded alloca() calls in the PulseAudio protocol server. (CVE-2026-14330) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-14324 , CVE-2026-14330 Description
RAOP module accepts unbounded Content-Length values and does not check the pw_array_add() return. (CVE-2026-14324) Multiple unbounded alloca() calls in the PulseAudio protocol server. (CVE-2026-14330) References
- https://bugs.mageia.org/show_bug.cgi?id=35929
- https://ubuntu.com/security/notices/USN-8535-1
- https://bugzilla.redhat.com/show_bug.cgi?id=2495903
- https://gitlab.freedesktop.org/pipewire/pipewire/-/work_items/5352
- https://bugzilla.redhat.com/show_bug.cgi?id=2495907
- https://www.cve.org/CVERecord?id=CVE-2026-14324
- https://www.cve.org/CVERecord?id=CVE-2026-14330
- pipewire-1.6.5-1.1.mga10
- pipewire-0.3.85-6.1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0442 - Updated libwebsockets packages fix a security vulnerability
Publication date: 23 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-10650 Description
warmcat libwebsockets SSH Protocol sshd.c lws_ssh_parse_plaintext resource consumption. (CVE-2026-10650) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-10650 Description
warmcat libwebsockets SSH Protocol sshd.c lws_ssh_parse_plaintext resource consumption. (CVE-2026-10650) References
- https://bugs.mageia.org/show_bug.cgi?id=36157
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KMAEZLLRGAX46TX4KZNYWZXYVIWBF3RU/
- https://github.com/biniamf/pocs/tree/main/libwebsockets_sshd-parse-ic-unbounded-alloc
- https://github.com/advisories/GHSA-23jv-8gf4-7r88
- https://www.cve.org/CVERecord?id=CVE-2026-10650
- libwebsockets-4.5.2-1.1.mga10
- libwebsockets-4.3.2-1.1.mga9
Categorías: Actualizaciones de Seguridad
MGAA-2026-0133 - Updated amavisd-new package fixes problem starting
Publication date: 23 Sep 2026
Type: bugfix
Affected Mageia releases : 10
Description
amavisd service fails to start. This update fixes the reported issue. References
SRPMS 10/core
Type: bugfix
Affected Mageia releases : 10
Description
amavisd service fails to start. This update fixes the reported issue. References
SRPMS 10/core
- amavisd-new-2.15.0-1.mga10
Categorías: Actualizaciones de Seguridad
MGASA-2026-0441 - Updated nss & firefox packages fix security vulnerabilities
Publication date: 23 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-92005 , CVE-2026-92006 , CVE-2026-92007 , CVE-2026-92008 , CVE-2026-92009 , CVE-2026-92010 , CVE-2026-92011 , CVE-2026-92012 , CVE-2026-92013 , CVE-2026-92014 , CVE-2026-92015 , CVE-2026-92016 , CVE-2026-92017 , CVE-2026-92018 , CVE-2026-92019 , CVE-2026-92020 , CVE-2026-92021 , CVE-2026-92022 , CVE-2026-92023 , CVE-2026-92024 , CVE-2026-92025 , CVE-2026-92026 , CVE-2026-92027 , CVE-2026-92028 , CVE-2026-92029 , CVE-2026-92030 , CVE-2026-92031 , CVE-2026-92032 , CVE-2026-92038 , CVE-2026-92039 , CVE-2026-92041 , CVE-2026-92042 , CVE-2026-92043 , CVE-2026-92044 , CVE-2026-92045 , CVE-2026-92046 , CVE-2026-92047 , CVE-2026-92052 , CVE-2026-92053 , CVE-2026-92054 , CVE-2026-92055 , CVE-2026-92056 , CVE-2026-92057 , CVE-2026-92058 , CVE-2026-92059 , CVE-2026-92060 , CVE-2026-92062 , CVE-2026-92064 , CVE-2026-92067 , CVE-2026-92068 , CVE-2026-92069 , CVE-2026-92070 , CVE-2026-92072 , CVE-2026-92073 , CVE-2026-92074 , CVE-2026-92075 , CVE-2026-92076 , CVE-2026-92077 , CVE-2026-92078 Description
Use-after-free in the Audio/Video: Web Codecs component. (CVE-2026-92005) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-92006) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-92007) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-92008) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-92009) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-92010) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-92011) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-92012) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-92013) Privilege escalation due to incorrect boundary conditions in the Graphics component. (CVE-2026-92014) Privilege escalation in the WebExtensions component. (CVE-2026-92015) Use-after-free in the Disability Access APIs component. (CVE-2026-92016) Privilege escalation in the DOM: Service Workers component. (CVE-2026-92017) Sandbox escape in the DOM: Core & HTML component. (CVE-2026-92018) Mitigation bypass in the Remote Settings Client component. (CVE-2026-92019) Privilege escalation due to incorrect boundary conditions in the Graphics: WebRender component. (CVE-2026-92020) Use-after-free in the JavaScript Engine: JIT component. (CVE-2026-92021) Use-after-free in the DOM: HTML Parser component. (CVE-2026-92022) Use-after-free in the XML component. (CVE-2026-92023) Use-after-free in the SVG component. (CVE-2026-92024) Use-after-free in the DOM: Navigation component. (CVE-2026-92025) Use-after-free in the Networking component. (CVE-2026-92026) Use-after-free in the DOM: Streams component. (CVE-2026-92027) Use-after-free in the DOM: Core & HTML component. (CVE-2026-92028) Use-after-free in the SVG component. (CVE-2026-92029) Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component. (CVE-2026-92030) Information disclosure in the Graphics: ImageLib component. (CVE-2026-92031) Sandbox escape due to invalid pointer in the Graphics component. (CVE-2026-92032) Mitigation bypass in the Remote Settings Client component. (CVE-2026-92038) Mitigation bypass in the DOM: Notifications component. (CVE-2026-92039) Mitigation bypass in the DOM: Networking component. (CVE-2026-92041) Race condition in the DOM: Content Processes component. (CVE-2026-92042) Privilege escalation due to incorrect boundary conditions in the Audio/Video component. (CVE-2026-92043) Information disclosure in the Networking: HTTP component. (CVE-2026-92044) Sandbox escape due to incorrect boundary conditions in the WebRTC component. (CVE-2026-92045) Use-after-free in the Graphics component. (CVE-2026-92046) Privilege escalation in the Crash Reporting component. (CVE-2026-92047) Privilege escalation due to uninitialized memory in the Graphics: CanvasWebGL component. (CVE-2026-92052) Privilege escalation in the Graphics: CanvasWebGL component. (CVE-2026-92053) Privilege escalation in the Memory component. (CVE-2026-92054) Privilege escalation in the DevTools component. (CVE-2026-92055) Use-after-free in the Graphics: Text component. (CVE-2026-92056) Mitigation bypass in the Enterprise Policies component. (CVE-2026-92057) Use-after-free in the Graphics component. (CVE-2026-92058) Incorrect boundary conditions in the DOM: Editor component. (CVE-2026-92059) Use-after-free in the Internationalization component. (CVE-2026-92060) Privilege escalation in the Session Restore component. (CVE-2026-92062) Use-after-free in the Widget: Gtk component. (CVE-2026-92067) Site isolation issue in the Reader Mode component. (CVE-2026-92068) Spoofing issue in the DOM: Navigation component. (CVE-2026-92069) Information disclosure in the Networking component. (CVE-2026-92070) Incorrect boundary conditions in the Safe Browsing component. (CVE-2026-92072) Privilege escalation in the Enterprise Policies component. (CVE-2026-92073) Mitigation bypass in the Popup Blocker component. (CVE-2026-92074) Mitigation bypass in the Networking component. (CVE-2026-92075) Incorrect boundary conditions in the Networking component. (CVE-2026-92076) Denial-of-service in the SVG component. (CVE-2026-92077) Denial-of-service in the Security component. (CVE-2026-92078) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-92005 , CVE-2026-92006 , CVE-2026-92007 , CVE-2026-92008 , CVE-2026-92009 , CVE-2026-92010 , CVE-2026-92011 , CVE-2026-92012 , CVE-2026-92013 , CVE-2026-92014 , CVE-2026-92015 , CVE-2026-92016 , CVE-2026-92017 , CVE-2026-92018 , CVE-2026-92019 , CVE-2026-92020 , CVE-2026-92021 , CVE-2026-92022 , CVE-2026-92023 , CVE-2026-92024 , CVE-2026-92025 , CVE-2026-92026 , CVE-2026-92027 , CVE-2026-92028 , CVE-2026-92029 , CVE-2026-92030 , CVE-2026-92031 , CVE-2026-92032 , CVE-2026-92038 , CVE-2026-92039 , CVE-2026-92041 , CVE-2026-92042 , CVE-2026-92043 , CVE-2026-92044 , CVE-2026-92045 , CVE-2026-92046 , CVE-2026-92047 , CVE-2026-92052 , CVE-2026-92053 , CVE-2026-92054 , CVE-2026-92055 , CVE-2026-92056 , CVE-2026-92057 , CVE-2026-92058 , CVE-2026-92059 , CVE-2026-92060 , CVE-2026-92062 , CVE-2026-92064 , CVE-2026-92067 , CVE-2026-92068 , CVE-2026-92069 , CVE-2026-92070 , CVE-2026-92072 , CVE-2026-92073 , CVE-2026-92074 , CVE-2026-92075 , CVE-2026-92076 , CVE-2026-92077 , CVE-2026-92078 Description
Use-after-free in the Audio/Video: Web Codecs component. (CVE-2026-92005) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-92006) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-92007) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-92008) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-92009) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-92010) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-92011) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-92012) Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-92013) Privilege escalation due to incorrect boundary conditions in the Graphics component. (CVE-2026-92014) Privilege escalation in the WebExtensions component. (CVE-2026-92015) Use-after-free in the Disability Access APIs component. (CVE-2026-92016) Privilege escalation in the DOM: Service Workers component. (CVE-2026-92017) Sandbox escape in the DOM: Core & HTML component. (CVE-2026-92018) Mitigation bypass in the Remote Settings Client component. (CVE-2026-92019) Privilege escalation due to incorrect boundary conditions in the Graphics: WebRender component. (CVE-2026-92020) Use-after-free in the JavaScript Engine: JIT component. (CVE-2026-92021) Use-after-free in the DOM: HTML Parser component. (CVE-2026-92022) Use-after-free in the XML component. (CVE-2026-92023) Use-after-free in the SVG component. (CVE-2026-92024) Use-after-free in the DOM: Navigation component. (CVE-2026-92025) Use-after-free in the Networking component. (CVE-2026-92026) Use-after-free in the DOM: Streams component. (CVE-2026-92027) Use-after-free in the DOM: Core & HTML component. (CVE-2026-92028) Use-after-free in the SVG component. (CVE-2026-92029) Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component. (CVE-2026-92030) Information disclosure in the Graphics: ImageLib component. (CVE-2026-92031) Sandbox escape due to invalid pointer in the Graphics component. (CVE-2026-92032) Mitigation bypass in the Remote Settings Client component. (CVE-2026-92038) Mitigation bypass in the DOM: Notifications component. (CVE-2026-92039) Mitigation bypass in the DOM: Networking component. (CVE-2026-92041) Race condition in the DOM: Content Processes component. (CVE-2026-92042) Privilege escalation due to incorrect boundary conditions in the Audio/Video component. (CVE-2026-92043) Information disclosure in the Networking: HTTP component. (CVE-2026-92044) Sandbox escape due to incorrect boundary conditions in the WebRTC component. (CVE-2026-92045) Use-after-free in the Graphics component. (CVE-2026-92046) Privilege escalation in the Crash Reporting component. (CVE-2026-92047) Privilege escalation due to uninitialized memory in the Graphics: CanvasWebGL component. (CVE-2026-92052) Privilege escalation in the Graphics: CanvasWebGL component. (CVE-2026-92053) Privilege escalation in the Memory component. (CVE-2026-92054) Privilege escalation in the DevTools component. (CVE-2026-92055) Use-after-free in the Graphics: Text component. (CVE-2026-92056) Mitigation bypass in the Enterprise Policies component. (CVE-2026-92057) Use-after-free in the Graphics component. (CVE-2026-92058) Incorrect boundary conditions in the DOM: Editor component. (CVE-2026-92059) Use-after-free in the Internationalization component. (CVE-2026-92060) Privilege escalation in the Session Restore component. (CVE-2026-92062) Use-after-free in the Widget: Gtk component. (CVE-2026-92067) Site isolation issue in the Reader Mode component. (CVE-2026-92068) Spoofing issue in the DOM: Navigation component. (CVE-2026-92069) Information disclosure in the Networking component. (CVE-2026-92070) Incorrect boundary conditions in the Safe Browsing component. (CVE-2026-92072) Privilege escalation in the Enterprise Policies component. (CVE-2026-92073) Mitigation bypass in the Popup Blocker component. (CVE-2026-92074) Mitigation bypass in the Networking component. (CVE-2026-92075) Incorrect boundary conditions in the Networking component. (CVE-2026-92076) Denial-of-service in the SVG component. (CVE-2026-92077) Denial-of-service in the Security component. (CVE-2026-92078) References
- https://bugs.mageia.org/show_bug.cgi?id=36317
- https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_129.html
- https://www.firefox.com/en-US/firefox/140.16.0/releasenotes/
- https://www.firefox.com/en-US/firefox/153.3.0/releasenotes/
- https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/
- https://www.mozilla.org/en-US/security/advisories/mfsa2026-93/
- https://www.cve.org/CVERecord?id=CVE-2026-92005
- https://www.cve.org/CVERecord?id=CVE-2026-92006
- https://www.cve.org/CVERecord?id=CVE-2026-92007
- https://www.cve.org/CVERecord?id=CVE-2026-92008
- https://www.cve.org/CVERecord?id=CVE-2026-92009
- https://www.cve.org/CVERecord?id=CVE-2026-92010
- https://www.cve.org/CVERecord?id=CVE-2026-92011
- https://www.cve.org/CVERecord?id=CVE-2026-92012
- https://www.cve.org/CVERecord?id=CVE-2026-92013
- https://www.cve.org/CVERecord?id=CVE-2026-92014
- https://www.cve.org/CVERecord?id=CVE-2026-92015
- https://www.cve.org/CVERecord?id=CVE-2026-92016
- https://www.cve.org/CVERecord?id=CVE-2026-92017
- https://www.cve.org/CVERecord?id=CVE-2026-92018
- https://www.cve.org/CVERecord?id=CVE-2026-92019
- https://www.cve.org/CVERecord?id=CVE-2026-92020
- https://www.cve.org/CVERecord?id=CVE-2026-92021
- https://www.cve.org/CVERecord?id=CVE-2026-92022
- https://www.cve.org/CVERecord?id=CVE-2026-92023
- https://www.cve.org/CVERecord?id=CVE-2026-92024
- https://www.cve.org/CVERecord?id=CVE-2026-92025
- https://www.cve.org/CVERecord?id=CVE-2026-92026
- https://www.cve.org/CVERecord?id=CVE-2026-92027
- https://www.cve.org/CVERecord?id=CVE-2026-92028
- https://www.cve.org/CVERecord?id=CVE-2026-92029
- https://www.cve.org/CVERecord?id=CVE-2026-92030
- https://www.cve.org/CVERecord?id=CVE-2026-92031
- https://www.cve.org/CVERecord?id=CVE-2026-92032
- https://www.cve.org/CVERecord?id=CVE-2026-92038
- https://www.cve.org/CVERecord?id=CVE-2026-92039
- https://www.cve.org/CVERecord?id=CVE-2026-92041
- https://www.cve.org/CVERecord?id=CVE-2026-92042
- https://www.cve.org/CVERecord?id=CVE-2026-92043
- https://www.cve.org/CVERecord?id=CVE-2026-92044
- https://www.cve.org/CVERecord?id=CVE-2026-92045
- https://www.cve.org/CVERecord?id=CVE-2026-92046
- https://www.cve.org/CVERecord?id=CVE-2026-92047
- https://www.cve.org/CVERecord?id=CVE-2026-92052
- https://www.cve.org/CVERecord?id=CVE-2026-92053
- https://www.cve.org/CVERecord?id=CVE-2026-92054
- https://www.cve.org/CVERecord?id=CVE-2026-92055
- https://www.cve.org/CVERecord?id=CVE-2026-92056
- https://www.cve.org/CVERecord?id=CVE-2026-92057
- https://www.cve.org/CVERecord?id=CVE-2026-92058
- https://www.cve.org/CVERecord?id=CVE-2026-92059
- https://www.cve.org/CVERecord?id=CVE-2026-92060
- https://www.cve.org/CVERecord?id=CVE-2026-92062
- https://www.cve.org/CVERecord?id=CVE-2026-92064
- https://www.cve.org/CVERecord?id=CVE-2026-92067
- https://www.cve.org/CVERecord?id=CVE-2026-92068
- https://www.cve.org/CVERecord?id=CVE-2026-92069
- https://www.cve.org/CVERecord?id=CVE-2026-92070
- https://www.cve.org/CVERecord?id=CVE-2026-92072
- https://www.cve.org/CVERecord?id=CVE-2026-92073
- https://www.cve.org/CVERecord?id=CVE-2026-92074
- https://www.cve.org/CVERecord?id=CVE-2026-92075
- https://www.cve.org/CVERecord?id=CVE-2026-92076
- https://www.cve.org/CVERecord?id=CVE-2026-92077
- https://www.cve.org/CVERecord?id=CVE-2026-92078
- firefox-l10n-153.3.0-1.mga10
- nss-3.129.0-1.mga10
- firefox-153.3.0-1.mga10
- firefox-l10n-140.16.0-1.mga9
- nss-3.129.0-1.mga9
- firefox-140.16.0-1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0440 - Updated borgbackup package fixes a security vulnerability
Publication date: 23 Sep 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-62268 Description
The updated package fixes a security vulnerability: CVE-2026-62268. References
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-62268 Description
The updated package fixes a security vulnerability: CVE-2026-62268. References
- https://bugs.mageia.org/show_bug.cgi?id=36163
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SHGZVBSSCWNFGJ5CQLE5BHFNNORWRSGK/
- https://www.cve.org/CVERecord?id=CVE-2026-62268
- borgbackup-1.4.5-1.mga10
Categorías: Actualizaciones de Seguridad
MGASA-2026-0439 - Updated coreutils package fixes a security vulnerability
Publication date: 23 Sep 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-56391 Description
Out‑of‑bounds Read in GNU coreutils. (CVE-2026-56391) References
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-56391 Description
Out‑of‑bounds Read in GNU coreutils. (CVE-2026-56391) References
- https://bugs.mageia.org/show_bug.cgi?id=36171
- https://www.openwall.com/lists/oss-security/2026/07/25/2
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NBV4TP2X6G6D4ITB6FA6CAPLJARRHBQS/
- https://ubuntu.com/security/notices/USN-8697-1
- https://www.cve.org/CVERecord?id=CVE-2026-56391
- coreutils-9.8-3.mga10
Categorías: Actualizaciones de Seguridad
MGASA-2026-0438 - Updated libnfs package fixes a security vulnerability
Publication date: 23 Sep 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-57918 Description
libnfs through 6.0.2 before 935b8db has an xid integer underflow in READ_IOVEC in rpc_read_from_socket in lib/socket.c during a connection to a crafted NFS server, when the expected pdu size exceeds the absolute pdu size from the xid/record-marker. (CVE-2026-57918) References
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-57918 Description
libnfs through 6.0.2 before 935b8db has an xid integer underflow in READ_IOVEC in rpc_read_from_socket in lib/socket.c during a connection to a crafted NFS server, when the expected pdu size exceeds the absolute pdu size from the xid/record-marker. (CVE-2026-57918) References
- https://bugs.mageia.org/show_bug.cgi?id=36185
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DOJLZCLBA4FYYVRVR6YGNNEBZAVEEQ3G/
- https://www.cve.org/CVERecord?id=CVE-2026-57918
- libnfs-6.0.2-2.2.mga10
Categorías: Actualizaciones de Seguridad
MGAA-2026-0132 - Updated fonts-ttf-bitstream-vera, fira-code-fonts & fonts-ttf-urw packages fix bug
Publication date: 23 Sep 2026
Type: bugfix
Affected Mageia releases : 10
Description
Type 1 fonts have been deprecated, we are replacing Type 1 fonts by True Type fonts. References
Type: bugfix
Affected Mageia releases : 10
Description
Type 1 fonts have been deprecated, we are replacing Type 1 fonts by True Type fonts. References
- https://bugs.mageia.org/show_bug.cgi?id=36095
- https://helpx.adobe.com/fonts/web/kb/postscript-type-1-fonts-end-of-support.html
- fonts-ttf-bitstream-vera-1.10-20.1.mga10
- fira-code-fonts-6.2-3.1.mga10
- fonts-ttf-urw-1-7.git20170804.1.mga10
Categorías: Actualizaciones de Seguridad
MGAA-2026-0131 - Updated bibletime package fixes bug
Publication date: 23 Sep 2026
Type: bugfix
Affected Mageia releases : 10
Description
bibletime is updated to version 3.2.0 References
SRPMS 10/core
Type: bugfix
Affected Mageia releases : 10
Description
bibletime is updated to version 3.2.0 References
SRPMS 10/core
- bibletime-3.2.0-1.mga10
- clucene-2.3.3.4-16.1.mga10
Categorías: Actualizaciones de Seguridad
MGASA-2026-0437 - Updated perl-Dancer2 packages fix a security vulnerability
Publication date: 23 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-13577 Description
Dancer2 versions through 2.1.0 for Perl generate insecure session ids when required CSPRNG modules are unavailable. (CVE-2026-13577) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-13577 Description
Dancer2 versions through 2.1.0 for Perl generate insecure session ids when required CSPRNG modules are unavailable. (CVE-2026-13577) References
- https://bugs.mageia.org/show_bug.cgi?id=35967
- https://www.openwall.com/lists/oss-security/2026/07/20/5
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PXWK3ODXBSRKU5P4JUADGHFPAH5I42DO/
- https://www.cve.org/CVERecord?id=CVE-2026-13577
- perl-Dancer2-2.0.1-1.2.mga10
- perl-Dancer2-0.400.1-1.2.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0436 - Updated rest packages fix a security vulnerability
Publication date: 23 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-16615 Description
Weak random number generation in pkce implementation. (CVE-2026-16615) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-16615 Description
Weak random number generation in pkce implementation. (CVE-2026-16615) References
- https://bugs.mageia.org/show_bug.cgi?id=36176
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/6Q63SLBWJIJZVOY6R6AXMKGOBBO26LVB/
- https://bugzilla.redhat.com/show_bug.cgi?id=2504432
- https://gitlab.gnome.org/GNOME/librest/-/issues/25
- https://www.cve.org/CVERecord?id=CVE-2026-16615
- rest-0.10.2-2.1.mga10
- rest-0.9.1-2.1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0435 - Updated cpio packages fix security vulnerabilities
Publication date: 23 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-66484 , CVE-2026-66485 , CVE-2026-66486 Description
Path Traversal in GNU cpio. (CVE-2026-66484) Uncontrolled Memory Allocation in GNU cpio. (CVE-2026-66485) Improper Output Encoding in GNU cpio. (CVE-2026-66486) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-66484 , CVE-2026-66485 , CVE-2026-66486 Description
Path Traversal in GNU cpio. (CVE-2026-66484) Uncontrolled Memory Allocation in GNU cpio. (CVE-2026-66485) Improper Output Encoding in GNU cpio. (CVE-2026-66486) References
- https://bugs.mageia.org/show_bug.cgi?id=36242
- https://ubuntu.com/security/notices/USN-8704-1
- https://www.cve.org/CVERecord?id=CVE-2026-66484
- https://www.cve.org/CVERecord?id=CVE-2026-66485
- https://www.cve.org/CVERecord?id=CVE-2026-66486
- cpio-2.15-3.1.mga10
- cpio-2.14-1.1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0434 - Updated diffutils packages fix a security vulnerability
Publication date: 23 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-53910 Description
Heap-based Buffer Overflow in GNU diffutils. (CVE-2026-53910) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-53910 Description
Heap-based Buffer Overflow in GNU diffutils. (CVE-2026-53910) References
- https://bugs.mageia.org/show_bug.cgi?id=36243
- https://ubuntu.com/security/notices/USN-8692-1
- https://www.cve.org/CVERecord?id=CVE-2026-53910
- diffutils-3.12-1.1.mga10
- diffutils-3.10-1.1.mga9
Categorías: Actualizaciones de Seguridad
MGAA-2026-0130 - Updated twinkle packages fix bug
Publication date: 23 Sep 2026
Type: bugfix
Affected Mageia releases : 10 , 9
Description
twinkle is updated to version 1.11.0 to fix a crash in the application. References
SRPMS 10/core
Type: bugfix
Affected Mageia releases : 10 , 9
Description
twinkle is updated to version 1.11.0 to fix a crash in the application. References
SRPMS 10/core
- twinkle-1.11.0-1.mga10
- twinkle-1.11.0-1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0433 - Updated nmap packages fix a security vulnerability
Publication date: 21 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-72712 Description
Denial of Service via Zero-Length TCP Option Packet. (CVE-2026-72712) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-72712 Description
Denial of Service via Zero-Length TCP Option Packet. (CVE-2026-72712) References
- https://bugs.mageia.org/show_bug.cgi?id=36129
- https://www.openwall.com/lists/oss-security/2026/07/29/4
- https://github.com/nmap/nmap/issues/3368
- https://www.vulncheck.com/advisories/nmap-denial-of-service-via-zero-length-tcp-option-packet
- https://www.cve.org/CVERecord?id=CVE-2026-72712
- nmap-7.98-1.2.mga10
- nmap-7.95-1.2.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0432 - Updated vim packages fix security vulnerabilities
Publication date: 21 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
Description
Out-of-bounds Access in libvterm Resize Handling in Vim < 9.2.1013 Integer Overflow in Undo File Entry Size Check in Vim < v9.2.1014 && Vim >= v8.1.0688 References
Type: security
Affected Mageia releases : 10 , 9
Description
Out-of-bounds Access in libvterm Resize Handling in Vim < 9.2.1013 Integer Overflow in Undo File Entry Size Check in Vim < v9.2.1014 && Vim >= v8.1.0688 References
- https://bugs.mageia.org/show_bug.cgi?id=36204
- https://www.openwall.com/lists/oss-security/2026/08/26/17
- https://www.openwall.com/lists/oss-security/2026/08/26/18
- https://github.com/vim/vim/security/advisories/GHSA-vfc7-mhvm-gjp8
- https://github.com/vim/vim/security/advisories/GHSA-cvc5-p4x9-3f9f
- vim-9.2.1054-1.mga10
- vim-9.2.1054-1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0431 - Updated pcre2 packages fix a security vulnerability
Publication date: 21 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-86145 Description
Out-of-bounds write in pcre2_dfa_match() with recursive patterns under a low heap limit (CVE-2026-86145). References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-86145 Description
Out-of-bounds write in pcre2_dfa_match() with recursive patterns under a low heap limit (CVE-2026-86145). References
- https://bugs.mageia.org/show_bug.cgi?id=36263
- https://www.openwall.com/lists/oss-security/2026/09/04/7
- https://www.openwall.com/lists/oss-security/2026/09/05/3
- https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-2p8c-ff85-vh9x
- https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-3r4p-g7gg-ppmf
- https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-q8g2-wprr-34m9
- https://www.cve.org/CVERecord?id=CVE-2026-86145
- pcre2-10.48-1.mga10
- pcre2-10.48-1.mga9
Categorías: Actualizaciones de Seguridad
MGAA-2026-0129 - Updated conda, python-msgpack & python-pluggy packages fixes bug
Publication date: 21 Sep 2026
Type: bugfix
Affected Mageia releases : 10
Description
The conda version we had was not ready for Python 3.13. This update allows it to be compatible, with updates of msgpack and pluggy too. References
SRPMS 10/core
Type: bugfix
Affected Mageia releases : 10
Description
The conda version we had was not ready for Python 3.13. This update allows it to be compatible, with updates of msgpack and pluggy too. References
SRPMS 10/core
- conda-26.5.3-1.mga10
- python-msgpack-1.2.2-1.mga10
- python-pluggy-1.6.0-1.mga10
Categorías: Actualizaciones de Seguridad




