Actualizaciones de Seguridad
MGASA-2026-0327 - Updated python-starlette package fixes security vulnerabilities
Publication date: 09 Aug 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2024-28849 , CVE-2025-62727 , CVE-2026-48710
The updated package fixes security vulnerabilities: Proxy-Authorization header kept across hosts. (CVE-2024-28849) Starlette vulnerable to O(n^2) DoS via Range header merging in starlette.responses.FileResponse. (CVE-2025-62727) Security restriction bypass via malformed HTTP Host header. (CVE-2026-48710) References
Type: security
Affected Mageia releases : 10
CVE: CVE-2024-28849 , CVE-2025-62727 , CVE-2026-48710
The updated package fixes security vulnerabilities: Proxy-Authorization header kept across hosts. (CVE-2024-28849) Starlette vulnerable to O(n^2) DoS via Range header merging in starlette.responses.FileResponse. (CVE-2025-62727) Security restriction bypass via malformed HTTP Host header. (CVE-2026-48710) References
- https://bugs.mageia.org/show_bug.cgi?id=35637
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HWLLKAJQCNBN46LPLDAYBM2FU65WBX72/
- https://lists.debian.org/debian-security-announce/2026/msg00213.html
- https://github.com/follow-redirects/follow-redirects/security/advisories/GHSA-cxjh-pqwp-8mfp
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/FET4KWO46IN64G35ZF7HGJJBIM4OF3YC/
- https://www.cve.org/CVERecord?id=CVE-2024-28849
- https://www.cve.org/CVERecord?id=CVE-2025-62727
- https://www.cve.org/CVERecord?id=CVE-2026-48710
- python-starlette-0.46.0-3.1.mga10
Categorías: Actualizaciones de Seguridad
MGAA-2026-0082 - Updated wine and wine-wow64 packages fix a bug
Publication date: 09 Aug 2026
Type: bugfix
Affected Mageia releases : 10
Fix command line launching for some of the common Wine tools. References SRPMS 10/core
Type: bugfix
Affected Mageia releases : 10
Fix command line launching for some of the common Wine tools. References SRPMS 10/core
- wine-11.0-2.1.mga10
- wine-wow64-11.0-1.1.mga10
Categorías: Actualizaciones de Seguridad
MGAA-2026-0081 - Updated unoconv packages fix bug
Publication date: 09 Aug 2026
Type: bugfix
Affected Mageia releases : 10
unoconv can't perform file conversions. This update fixes the reported issue. References
Type: bugfix
Affected Mageia releases : 10
unoconv can't perform file conversions. This update fixes the reported issue. References
- https://bugs.mageia.org/show_bug.cgi?id=36046
- https://ask.libreoffice.org/t/is-this-unoconv-issue-a-regression-in-libreoffice/131807/2
- unoconv-0.9.0-4.1.mga10
Categorías: Actualizaciones de Seguridad
MGAA-2026-0080 - Updated urpmi packages fix a missing dependency
Publication date: 09 Aug 2026
Type: bugfix
Affected Mageia releases : 10
When xz was missing, urpmi and rpmdrake were unable to display information about packages, because they could read neither the description, nor the file list, nor the history. This update fixes the issue by making urpmi depend on xz. References SRPMS 10/core
Type: bugfix
Affected Mageia releases : 10
When xz was missing, urpmi and rpmdrake were unable to display information about packages, because they could read neither the description, nor the file list, nor the history. This update fixes the issue by making urpmi depend on xz. References SRPMS 10/core
- urpmi-8.136-2.1.mga10
Categorías: Actualizaciones de Seguridad
MGASA-2026-0326 - Updated thunderbird packages fix security vulnerabilities
Publication date: 07 Aug 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-14899 , CVE-2026-15718 , CVE-2026-15719 , CVE-2026-16349 , CVE-2026-16350 , CVE-2026-16351 , CVE-2026-16352 , CVE-2026-16353 , CVE-2026-16354 , CVE-2026-16355 , CVE-2026-16356 , CVE-2026-16357 , CVE-2026-16358 , CVE-2026-16359 , CVE-2026-16360 , CVE-2026-16361 , CVE-2026-16362 , CVE-2026-16363 , CVE-2026-16368 , CVE-2026-16369 , CVE-2026-16371 , CVE-2026-16374 , CVE-2026-16375 , CVE-2026-16377 , CVE-2026-16379 , CVE-2026-16381 , CVE-2026-16383 , CVE-2026-16387 , CVE-2026-16390 , CVE-2026-16391 , CVE-2026-16396 , CVE-2026-16405 , CVE-2026-16412 , CVE-2026-12289 , CVE-2026-12290 , CVE-2026-12291 , CVE-2026-12292 , CVE-2026-12294 , CVE-2026-12295 , CVE-2026-12296 , CVE-2026-12297 , CVE-2026-12298 , CVE-2026-12299 , CVE-2026-12302 , CVE-2026-12304 , CVE-2026-12305 , CVE-2026-12306 , CVE-2026-12307 , CVE-2026-12308 , CVE-2026-12309 , CVE-2026-12310 , CVE-2026-12311 , CVE-2026-12312 , CVE-2026-12313 , CVE-2026-12314 , CVE-2026-12315 , CVE-2026-12324 , CVE-2026-12325 , CVE-2026-12327 , CVE-2026-12328 , CVE-2026-12329 , CVE-2026-12330 , CVE-2026-57962 , CVE-2026-57963
Updated thunderbird packages fix various security issues. See the links to get complete information of each issue. References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-14899 , CVE-2026-15718 , CVE-2026-15719 , CVE-2026-16349 , CVE-2026-16350 , CVE-2026-16351 , CVE-2026-16352 , CVE-2026-16353 , CVE-2026-16354 , CVE-2026-16355 , CVE-2026-16356 , CVE-2026-16357 , CVE-2026-16358 , CVE-2026-16359 , CVE-2026-16360 , CVE-2026-16361 , CVE-2026-16362 , CVE-2026-16363 , CVE-2026-16368 , CVE-2026-16369 , CVE-2026-16371 , CVE-2026-16374 , CVE-2026-16375 , CVE-2026-16377 , CVE-2026-16379 , CVE-2026-16381 , CVE-2026-16383 , CVE-2026-16387 , CVE-2026-16390 , CVE-2026-16391 , CVE-2026-16396 , CVE-2026-16405 , CVE-2026-16412 , CVE-2026-12289 , CVE-2026-12290 , CVE-2026-12291 , CVE-2026-12292 , CVE-2026-12294 , CVE-2026-12295 , CVE-2026-12296 , CVE-2026-12297 , CVE-2026-12298 , CVE-2026-12299 , CVE-2026-12302 , CVE-2026-12304 , CVE-2026-12305 , CVE-2026-12306 , CVE-2026-12307 , CVE-2026-12308 , CVE-2026-12309 , CVE-2026-12310 , CVE-2026-12311 , CVE-2026-12312 , CVE-2026-12313 , CVE-2026-12314 , CVE-2026-12315 , CVE-2026-12324 , CVE-2026-12325 , CVE-2026-12327 , CVE-2026-12328 , CVE-2026-12329 , CVE-2026-12330 , CVE-2026-57962 , CVE-2026-57963
Updated thunderbird packages fix various security issues. See the links to get complete information of each issue. References
- https://bugs.mageia.org/show_bug.cgi?id=35982
- https://bugs.mageia.org/show_bug.cgi?id=35863
- https://www.thunderbird.net/en-US/thunderbird/140.13.0esr/releasenotes/
- https://www.mozilla.org/en-US/security/known-vulnerabilities/thunderbird/#thunderbird140.13
- https://www.thunderbird.net/en-US/thunderbird/140.12.0esr/releasenotes/
- https://www.mozilla.org/en-US/security/advisories/mfsa2026-61/
- https://www.thunderbird.net/en-US/thunderbird/140.12.1esr/releasenotes/
- https://www.mozilla.org/en-US/security/advisories/mfsa2026-64/
- https://www.cve.org/CVERecord?id=CVE-2026-14899
- https://www.cve.org/CVERecord?id=CVE-2026-15718
- https://www.cve.org/CVERecord?id=CVE-2026-15719
- https://www.cve.org/CVERecord?id=CVE-2026-16349
- https://www.cve.org/CVERecord?id=CVE-2026-16350
- https://www.cve.org/CVERecord?id=CVE-2026-16351
- https://www.cve.org/CVERecord?id=CVE-2026-16352
- https://www.cve.org/CVERecord?id=CVE-2026-16353
- https://www.cve.org/CVERecord?id=CVE-2026-16354
- https://www.cve.org/CVERecord?id=CVE-2026-16355
- https://www.cve.org/CVERecord?id=CVE-2026-16356
- https://www.cve.org/CVERecord?id=CVE-2026-16357
- https://www.cve.org/CVERecord?id=CVE-2026-16358
- https://www.cve.org/CVERecord?id=CVE-2026-16359
- https://www.cve.org/CVERecord?id=CVE-2026-16360
- https://www.cve.org/CVERecord?id=CVE-2026-16361
- https://www.cve.org/CVERecord?id=CVE-2026-16362
- https://www.cve.org/CVERecord?id=CVE-2026-16363
- https://www.cve.org/CVERecord?id=CVE-2026-16368
- https://www.cve.org/CVERecord?id=CVE-2026-16369
- https://www.cve.org/CVERecord?id=CVE-2026-16371
- https://www.cve.org/CVERecord?id=CVE-2026-16374
- https://www.cve.org/CVERecord?id=CVE-2026-16375
- https://www.cve.org/CVERecord?id=CVE-2026-16377
- https://www.cve.org/CVERecord?id=CVE-2026-16379
- https://www.cve.org/CVERecord?id=CVE-2026-16381
- https://www.cve.org/CVERecord?id=CVE-2026-16383
- https://www.cve.org/CVERecord?id=CVE-2026-16387
- https://www.cve.org/CVERecord?id=CVE-2026-16390
- https://www.cve.org/CVERecord?id=CVE-2026-16391
- https://www.cve.org/CVERecord?id=CVE-2026-16396
- https://www.cve.org/CVERecord?id=CVE-2026-16405
- https://www.cve.org/CVERecord?id=CVE-2026-16412
- https://www.cve.org/CVERecord?id=CVE-2026-12289
- https://www.cve.org/CVERecord?id=CVE-2026-12290
- https://www.cve.org/CVERecord?id=CVE-2026-12291
- https://www.cve.org/CVERecord?id=CVE-2026-12292
- https://www.cve.org/CVERecord?id=CVE-2026-12294
- https://www.cve.org/CVERecord?id=CVE-2026-12295
- https://www.cve.org/CVERecord?id=CVE-2026-12296
- https://www.cve.org/CVERecord?id=CVE-2026-12297
- https://www.cve.org/CVERecord?id=CVE-2026-12298
- https://www.cve.org/CVERecord?id=CVE-2026-12299
- https://www.cve.org/CVERecord?id=CVE-2026-12302
- https://www.cve.org/CVERecord?id=CVE-2026-12304
- https://www.cve.org/CVERecord?id=CVE-2026-12305
- https://www.cve.org/CVERecord?id=CVE-2026-12306
- https://www.cve.org/CVERecord?id=CVE-2026-12307
- https://www.cve.org/CVERecord?id=CVE-2026-12308
- https://www.cve.org/CVERecord?id=CVE-2026-12309
- https://www.cve.org/CVERecord?id=CVE-2026-12310
- https://www.cve.org/CVERecord?id=CVE-2026-12311
- https://www.cve.org/CVERecord?id=CVE-2026-12312
- https://www.cve.org/CVERecord?id=CVE-2026-12313
- https://www.cve.org/CVERecord?id=CVE-2026-12314
- https://www.cve.org/CVERecord?id=CVE-2026-12315
- https://www.cve.org/CVERecord?id=CVE-2026-12324
- https://www.cve.org/CVERecord?id=CVE-2026-12325
- https://www.cve.org/CVERecord?id=CVE-2026-12327
- https://www.cve.org/CVERecord?id=CVE-2026-12328
- https://www.cve.org/CVERecord?id=CVE-2026-12329
- https://www.cve.org/CVERecord?id=CVE-2026-12330
- https://www.cve.org/CVERecord?id=CVE-2026-57962
- https://www.cve.org/CVERecord?id=CVE-2026-57963
- thunderbird-140.13.0-1.mga10
- thunderbird-l10n-140.13.0-1.mga10
- thunderbird-140.13.0-1.mga9
- thunderbird-l10n-140.13.0-1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0325 - Updated rootcerts, nss & firefox packages fix security vulnerabilities
Publication date: 07 Aug 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-15718 , CVE-2026-15719 , CVE-2026-16349 , CVE-2026-16350 , CVE-2026-16351 , CVE-2026-16352 , CVE-2026-16353 , CVE-2026-16354 , CVE-2026-16355 , CVE-2026-16356 , CVE-2026-16357 , CVE-2026-16358 , CVE-2026-16359 , CVE-2026-16360 , CVE-2026-16361 , CVE-2026-16362 , CVE-2026-16363 , CVE-2026-16368 , CVE-2026-16369 , CVE-2026-16371 , CVE-2026-16374 , CVE-2026-16375 , CVE-2026-16377 , CVE-2026-16379 , CVE-2026-16381 , CVE-2026-16383 , CVE-2026-16387 , CVE-2026-16390 , CVE-2026-16391 , CVE-2026-16396 , CVE-2026-16405 , CVE-2026-16412
Updated rootcerts, nss & firefox packages fixes various vulnerabilities. Please see the links for detailed information of each one. References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-15718 , CVE-2026-15719 , CVE-2026-16349 , CVE-2026-16350 , CVE-2026-16351 , CVE-2026-16352 , CVE-2026-16353 , CVE-2026-16354 , CVE-2026-16355 , CVE-2026-16356 , CVE-2026-16357 , CVE-2026-16358 , CVE-2026-16359 , CVE-2026-16360 , CVE-2026-16361 , CVE-2026-16362 , CVE-2026-16363 , CVE-2026-16368 , CVE-2026-16369 , CVE-2026-16371 , CVE-2026-16374 , CVE-2026-16375 , CVE-2026-16377 , CVE-2026-16379 , CVE-2026-16381 , CVE-2026-16383 , CVE-2026-16387 , CVE-2026-16390 , CVE-2026-16391 , CVE-2026-16396 , CVE-2026-16405 , CVE-2026-16412
Updated rootcerts, nss & firefox packages fixes various vulnerabilities. Please see the links for detailed information of each one. References
- https://bugs.mageia.org/show_bug.cgi?id=35981
- https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_126.html
- https://www.firefox.com/en-US/firefox/140.13.0/releasenotes/
- https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/
- https://www.cve.org/CVERecord?id=CVE-2026-15718
- https://www.cve.org/CVERecord?id=CVE-2026-15719
- https://www.cve.org/CVERecord?id=CVE-2026-16349
- https://www.cve.org/CVERecord?id=CVE-2026-16350
- https://www.cve.org/CVERecord?id=CVE-2026-16351
- https://www.cve.org/CVERecord?id=CVE-2026-16352
- https://www.cve.org/CVERecord?id=CVE-2026-16353
- https://www.cve.org/CVERecord?id=CVE-2026-16354
- https://www.cve.org/CVERecord?id=CVE-2026-16355
- https://www.cve.org/CVERecord?id=CVE-2026-16356
- https://www.cve.org/CVERecord?id=CVE-2026-16357
- https://www.cve.org/CVERecord?id=CVE-2026-16358
- https://www.cve.org/CVERecord?id=CVE-2026-16359
- https://www.cve.org/CVERecord?id=CVE-2026-16360
- https://www.cve.org/CVERecord?id=CVE-2026-16361
- https://www.cve.org/CVERecord?id=CVE-2026-16362
- https://www.cve.org/CVERecord?id=CVE-2026-16363
- https://www.cve.org/CVERecord?id=CVE-2026-16368
- https://www.cve.org/CVERecord?id=CVE-2026-16369
- https://www.cve.org/CVERecord?id=CVE-2026-16371
- https://www.cve.org/CVERecord?id=CVE-2026-16374
- https://www.cve.org/CVERecord?id=CVE-2026-16375
- https://www.cve.org/CVERecord?id=CVE-2026-16377
- https://www.cve.org/CVERecord?id=CVE-2026-16379
- https://www.cve.org/CVERecord?id=CVE-2026-16381
- https://www.cve.org/CVERecord?id=CVE-2026-16383
- https://www.cve.org/CVERecord?id=CVE-2026-16387
- https://www.cve.org/CVERecord?id=CVE-2026-16390
- https://www.cve.org/CVERecord?id=CVE-2026-16391
- https://www.cve.org/CVERecord?id=CVE-2026-16396
- https://www.cve.org/CVERecord?id=CVE-2026-16405
- https://www.cve.org/CVERecord?id=CVE-2026-16412
- rootcerts-20260714.00-1.mga10
- nss-3.126.0-1.mga10
- firefox-140.13.0-1.mga10
- firefox-l10n-140.13.0-1.mga10
- rootcerts-20260714.00-1.mga9
- nss-3.126.0-1.mga9
- firefox-140.13.0-1.mga9
- firefox-l10n-140.13.0-1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0324 - Updated python-django packages fix security vulnerabilities
Publication date: 07 Aug 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-6873 , CVE-2026-7666 , CVE-2026-8404 , CVE-2026-35193 , CVE-2026-48587 , CVE-2026-48588 , CVE-2026-53877 , CVE-2026-53878
The updated package fixes security vulnerabilities: Signed cookie salt namespace collision in `django.http.HttpRequest.get_signed_cookie`. (CVE-2026-6873) Potential unencrypted email transmission via `STARTTLS` in the SMTP backend. (CVE-2026-7666) Potential exposure of private data via case-sensitive `Cache-Control` directives in `UpdateCacheMiddleware`. (CVE-2026-8404) Potential exposure of private data via missing `Vary: Authorization` in `UpdateCacheMiddleware`. (CVE-2026-35193) Potential exposure of private data via whitespace padding in `Vary` header. (CVE-2026-48587) Potential exposure of private data via cached `Set-Cookie` response. (CVE-2026-48588) Heap buffer over-read in `GDALRaster`. (CVE-2026-53877) Header injection possibility since `DomainNameValidator` accepted newlines in input. (CVE-2026-53878) References
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-6873 , CVE-2026-7666 , CVE-2026-8404 , CVE-2026-35193 , CVE-2026-48587 , CVE-2026-48588 , CVE-2026-53877 , CVE-2026-53878
The updated package fixes security vulnerabilities: Signed cookie salt namespace collision in `django.http.HttpRequest.get_signed_cookie`. (CVE-2026-6873) Potential unencrypted email transmission via `STARTTLS` in the SMTP backend. (CVE-2026-7666) Potential exposure of private data via case-sensitive `Cache-Control` directives in `UpdateCacheMiddleware`. (CVE-2026-8404) Potential exposure of private data via missing `Vary: Authorization` in `UpdateCacheMiddleware`. (CVE-2026-35193) Potential exposure of private data via whitespace padding in `Vary` header. (CVE-2026-48587) Potential exposure of private data via cached `Set-Cookie` response. (CVE-2026-48588) Heap buffer over-read in `GDALRaster`. (CVE-2026-53877) Header injection possibility since `DomainNameValidator` accepted newlines in input. (CVE-2026-53878) References
- https://bugs.mageia.org/show_bug.cgi?id=35870
- https://www.openwall.com/lists/oss-security/2026/06/03/10
- https://www.openwall.com/lists/oss-security/2026/07/07/10
- https://www.djangoproject.com/weblog/2026/jul/07/security-releases/
- https://www.cve.org/CVERecord?id=CVE-2026-6873
- https://www.cve.org/CVERecord?id=CVE-2026-7666
- https://www.cve.org/CVERecord?id=CVE-2026-8404
- https://www.cve.org/CVERecord?id=CVE-2026-35193
- https://www.cve.org/CVERecord?id=CVE-2026-48587
- https://www.cve.org/CVERecord?id=CVE-2026-48588
- https://www.cve.org/CVERecord?id=CVE-2026-53877
- https://www.cve.org/CVERecord?id=CVE-2026-53878
- python-django-5.2.16-1.mga10
Categorías: Actualizaciones de Seguridad
MGAA-2026-0079 - Updated purple-telegram-tdlib packages fix bugs
Publication date: 06 Aug 2026
Type: bugfix
Affected Mageia releases : 10 , 9
In telegram groups with topics, the conversations from all the topics end in the Unique chat tab in pidgin and messages from pidgin end in the General topic, making it hard to follow the conversations. If the session for the plugin is closed from the phone client, in the next pidgin start you can't login. This update fixes the reported issues. Please note that the icon for the protocol has changed and is now listed as Unofficial Telegram. References
Type: bugfix
Affected Mageia releases : 10 , 9
In telegram groups with topics, the conversations from all the topics end in the Unique chat tab in pidgin and messages from pidgin end in the General topic, making it hard to follow the conversations. If the session for the plugin is closed from the phone client, in the next pidgin start you can't login. This update fixes the reported issues. Please note that the icon for the protocol has changed and is now listed as Unofficial Telegram. References
- https://bugs.mageia.org/show_bug.cgi?id=36048
- https://github.com/adrighem/tdlib-purple/issues/8
- https://github.com/adrighem/tdlib-purple/issues/19
- https://github.com/adrighem/tdlib-purple/releases/tag/tdlib-purple-v2.0.2
- https://github.com/adrighem/tdlib-purple/releases/tag/tdlib-purple-v2.0.1
- https://github.com/adrighem/tdlib-purple/releases/tag/tdlib-purple-v2.0.0
- https://github.com/adrighem/tdlib-purple/releases/tag/tdlib-purple-v1.2.2
- https://github.com/adrighem/tdlib-purple/releases/tag/tdlib-purple-v1.2.1
- https://github.com/adrighem/tdlib-purple/releases/tag/tdlib-purple-v1.2.0
- purple-telegram-tdlib-2.0.2-1.mga10
- purple-telegram-tdlib-2.0.2-1.mga9
Categorías: Actualizaciones de Seguridad
MGAA-2026-0078 - Updated font-tools packages fix two bugs
Publication date: 06 Aug 2026
Type: bugfix
Affected Mageia releases : 10 , 9
pfm2afm crashed on 64-bit machines and did not accept absolute path names to files. Both these issues have been fixed. References SRPMS 10/core
Type: bugfix
Affected Mageia releases : 10 , 9
pfm2afm crashed on 64-bit machines and did not accept absolute path names to files. Both these issues have been fixed. References SRPMS 10/core
- font-tools-0.1-34.mga10
- font-tools-0.1-34.mga9
Categorías: Actualizaciones de Seguridad
MGAA-2026-0077 - Updated steam, steam-udevrules packages add requires
Publication date: 06 Aug 2026
Type: bugfix
Affected Mageia releases : 10
Steam is updated to 1.0.0.87 and Requires: are added for libmesavulkan-drivers and libvulkan-loader1, needed for some games on Intel and AMD gpus. Note that steam-udevrules is required by steam and will be automatically pulled in by steam. However, it is available as a separate package so it can be used by folks with the libre steamcontroller without having to install all of steam to get it. References SRPMS 10/core
Type: bugfix
Affected Mageia releases : 10
Steam is updated to 1.0.0.87 and Requires: are added for libmesavulkan-drivers and libvulkan-loader1, needed for some games on Intel and AMD gpus. Note that steam-udevrules is required by steam and will be automatically pulled in by steam. However, it is available as a separate package so it can be used by folks with the libre steamcontroller without having to install all of steam to get it. References SRPMS 10/core
- steam-udevrules-1.0.0.87-1.mga10
- steam-1.0.0.87-1.mga10.nonfree
Categorías: Actualizaciones de Seguridad
MGAA-2026-0075 - Updated woeusb-ng packages fix bug
Publication date: 05 Aug 2026
Type: bugfix
Affected Mageia releases : 10
woeusb-ng did not mark the 7zip package as a required dependency. This update fixes the reported issue. References SRPMS 10/core
Type: bugfix
Affected Mageia releases : 10
woeusb-ng did not mark the 7zip package as a required dependency. This update fixes the reported issue. References SRPMS 10/core
- woeusb-ng-0.2.12-4.1.mga10
Categorías: Actualizaciones de Seguridad
MGASA-2026-0323 - Updated tomcat packages fix security vulnerabilities
Publication date: 05 Aug 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-50229 , CVE-2026-53404 , CVE-2026-53434 , CVE-2026-55276 , CVE-2026-55955 , CVE-2026-55956 , CVE-2026-55957
The updated packages fix security vulnerabilities: XSS in number guess example. (CVE-2026-50229) Bad ornext processing in RewriteValve. (CVE-2026-53404) Invalid CRL configuration doesn't trigger failure for FFM Connector. (CVE-2026-53434) Logged effective web.xml is incomplete. (CVE-2026-55276) EncryptInterceptor not protected against replay attacks. (CVE-2026-55955) Security constraints for default servlet ignored method. (CVE-2026-55956) Authentication bypass with JNDIRealm and GSSAPI authenticated bind. (CVE-2026-55957) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-50229 , CVE-2026-53404 , CVE-2026-53434 , CVE-2026-55276 , CVE-2026-55955 , CVE-2026-55956 , CVE-2026-55957
The updated packages fix security vulnerabilities: XSS in number guess example. (CVE-2026-50229) Bad ornext processing in RewriteValve. (CVE-2026-53404) Invalid CRL configuration doesn't trigger failure for FFM Connector. (CVE-2026-53434) Logged effective web.xml is incomplete. (CVE-2026-55276) EncryptInterceptor not protected against replay attacks. (CVE-2026-55955) Security constraints for default servlet ignored method. (CVE-2026-55956) Authentication bypass with JNDIRealm and GSSAPI authenticated bind. (CVE-2026-55957) References
- https://bugs.mageia.org/show_bug.cgi?id=35783
- https://www.openwall.com/lists/oss-security/2026/06/29/20
- https://www.openwall.com/lists/oss-security/2026/06/29/21
- https://www.openwall.com/lists/oss-security/2026/06/29/22
- https://www.openwall.com/lists/oss-security/2026/06/29/23
- https://www.openwall.com/lists/oss-security/2026/06/29/24
- https://www.openwall.com/lists/oss-security/2026/06/29/25
- https://www.openwall.com/lists/oss-security/2026/06/29/26
- https://www.cve.org/CVERecord?id=CVE-2026-50229
- https://www.cve.org/CVERecord?id=CVE-2026-53404
- https://www.cve.org/CVERecord?id=CVE-2026-53434
- https://www.cve.org/CVERecord?id=CVE-2026-55276
- https://www.cve.org/CVERecord?id=CVE-2026-55955
- https://www.cve.org/CVERecord?id=CVE-2026-55956
- https://www.cve.org/CVERecord?id=CVE-2026-55957
- tomcat-9.0.119-1.mga10
- tomcat-9.0.119-1.mga9
Categorías: Actualizaciones de Seguridad
MGAA-2026-0076 - Updated php-fpdf package fixes two issues.
Publication date: 05 Aug 2026
Type: bugfix
Affected Mageia releases : 10
Updating php-fpdf to version 1.9.0 suppresses deprecated warnings in php 8.5. This update also fixes a bug related to the PDF creation date. References SRPMS 10/core
Type: bugfix
Affected Mageia releases : 10
Updating php-fpdf to version 1.9.0 suppresses deprecated warnings in php 8.5. This update also fixes a bug related to the PDF creation date. References SRPMS 10/core
- php-fpdf-1.9.0-1.mga10
Categorías: Actualizaciones de Seguridad
MGAA-2026-0074 - Updated netprofile packages fix a bug
Publication date: 05 Aug 2026
Type: bugfix
Affected Mageia releases : 10 , 9
netprofile sent messages to com.mandriva.user instead of org.mageia.user. This update fixes the issue. References SRPMS 10/core
Type: bugfix
Affected Mageia releases : 10 , 9
netprofile sent messages to com.mandriva.user instead of org.mageia.user. This update fixes the issue. References SRPMS 10/core
- netprofile-0.29.1-1.mga10
- netprofile-0.29.1-1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0322 - Updated php packages fix security vulnerabilities
Publication date: 04 Aug 2026
Type: security
Affected Mageia releases : 9
CVE: CVE-2026-7260 , CVE-2026-17543
This update brings the latest version of php 8.2 and fixes some security vulnerabilities. References
Type: security
Affected Mageia releases : 9
CVE: CVE-2026-7260 , CVE-2026-17543
This update brings the latest version of php 8.2 and fixes some security vulnerabilities. References
- https://bugs.mageia.org/show_bug.cgi?id=36034
- https://www.php.net/ChangeLog-8.php#8.2.33
- https://www.cve.org/CVERecord?id=CVE-2026-7260
- https://www.cve.org/CVERecord?id=CVE-2026-17543
- php-8.2.33-1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0321 - Updated acl attr packages fix security vulnerabilities
Publication date: 04 Aug 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-54369 , CVE-2026-54370 , CVE-2026-54371
The updated acl and attr packages fix security issues. References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-54369 , CVE-2026-54370 , CVE-2026-54371
The updated acl and attr packages fix security issues. References
- https://bugs.mageia.org/show_bug.cgi?id=35779
- https://www.openwall.com/lists/oss-security/2026/06/29/1
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3TDUECPBS6YQPFZZ6RNXV3T5EFLLHQZS/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CGDSXLCG4AXTWFBAKM6XYUUYO6LZ7YXY/
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/NOOHLEV27XADU2EMOLPK2E6IY2TZKFKQ/
- https://www.cve.org/CVERecord?id=CVE-2026-54369
- https://www.cve.org/CVERecord?id=CVE-2026-54370
- https://www.cve.org/CVERecord?id=CVE-2026-54371
- acl-2.4.0-3.mga10
- attr-2.6.0-1.mga10
- acl-2.4.0-1.mga9
- attr-2.6.0-1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0320 - Updated perl-Unicode-LineBreak package fixes a security vulnerability
Publication date: 03 Aug 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-8594
The updated package fixes a security vulnerability: Text::LineFold versions through 2019.001 for Perl duplicate the output based on the number of special break characters. (CVE-2026-8594) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-8594
The updated package fixes a security vulnerability: Text::LineFold versions through 2019.001 for Perl duplicate the output based on the number of special break characters. (CVE-2026-8594) References
- https://bugs.mageia.org/show_bug.cgi?id=35612
- https://www.openwall.com/lists/oss-security/2026/05/30/6
- https://www.cve.org/CVERecord?id=CVE-2026-8594
- perl-Unicode-LineBreak-2019.1.0-13.1.mga10
- perl-Unicode-LineBreak-2019.1.0-9.1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0319 - Updated squid packages fix security vulnerabilities
Publication date: 03 Aug 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-47729 , CVE-2026-50012
The updated packages fix security vulnerabilities: Due to a Improper Validation of Syntactic Correctness of Inputbug, Squid is vulnerable to a Out-of-bounds Read attack against the FTP gateway. (CVE-2026-47729) Due to an Improper Input Validation bug, Squid is vulnerable to a Heap-based Buffer Overflow attack against cache digests. (CVE-2026-50012) References
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-47729 , CVE-2026-50012
The updated packages fix security vulnerabilities: Due to a Improper Validation of Syntactic Correctness of Inputbug, Squid is vulnerable to a Out-of-bounds Read attack against the FTP gateway. (CVE-2026-47729) Due to an Improper Input Validation bug, Squid is vulnerable to a Heap-based Buffer Overflow attack against cache digests. (CVE-2026-50012) References
- https://bugs.mageia.org/show_bug.cgi?id=35686
- https://www.openwall.com/lists/oss-security/2026/06/12/1
- https://ubuntu.com/security/notices/USN-8435-1
- https://lists.debian.org/debian-security-announce/2026/msg00271.html
- https://www.cve.org/CVERecord?id=CVE-2026-47729
- https://www.cve.org/CVERecord?id=CVE-2026-50012
- squid-6.12-3.1.mga10
Categorías: Actualizaciones de Seguridad
MGASA-2026-0318 - Updated perl-GD package fixes a security vulnerability
Publication date: 03 Aug 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-11526
The updated package fixes a security vulnerability: GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments in _make_filehandle. (CVE-2026-11526) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-11526
The updated package fixes a security vulnerability: GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments in _make_filehandle. (CVE-2026-11526) References
- https://bugs.mageia.org/show_bug.cgi?id=35700
- https://www.openwall.com/lists/oss-security/2026/06/14/4
- https://metacpan.org/release/RURBAN/GD-2.86/changes
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/FVXC7OE25PPTJFDV7ZFH2DDNTN5ZOZKK/
- https://lists.debian.org/debian-security-announce/2026/msg00256.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WWKANNR4XL34RWTURYNNLPBPFQSJWY4H/
- https://ubuntu.com/security/notices/USN-8484-1
- https://www.cve.org/CVERecord?id=CVE-2026-11526
- perl-GD-2.840.0-1.1.mga10
- perl-GD-2.760.0-3.1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0317 - Updated perl packages fix security vulnerabilities
Publication date: 03 Aug 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-13221 , CVE-2026-57432 , CVE-2026-57433
The updated Mageia 10 perl packages contain security fixes for CVE-2026-13221, CVE-2026-57432 and CVE-2026-57433. The Mageia 9 perl packages were not affected by CVE-2026-13221, they are now updated with fixes for CVE-2026-57432 and CVE-2026-57433. References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-13221 , CVE-2026-57432 , CVE-2026-57433
The updated Mageia 10 perl packages contain security fixes for CVE-2026-13221, CVE-2026-57432 and CVE-2026-57433. The Mageia 9 perl packages were not affected by CVE-2026-13221, they are now updated with fixes for CVE-2026-57432 and CVE-2026-57433. References
- https://bugs.mageia.org/show_bug.cgi?id=35925
- https://www.openwall.com/lists/oss-security/2026/07/13/5
- https://www.openwall.com/lists/oss-security/2026/07/13/6
- https://www.openwall.com/lists/oss-security/2026/07/13/7
- https://www.cve.org/CVERecord?id=CVE-2026-13221
- https://www.cve.org/CVERecord?id=CVE-2026-57432
- https://www.cve.org/CVERecord?id=CVE-2026-57433
- perl-5.42.0-3.mga10
- perl-5.36.0-1.4.mga9
Categorías: Actualizaciones de Seguridad




