Mageia Security

Feed
Mageia Advisories
Updated: hace 2 dias 23 horas

MGASA-2026-0296 - Updated yelp packages fix a security vulnerability

25 Julio, 2026 - 19:04
Publication date: 25 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-13601 Description
The updated packages fix a security vulnerability: Yelp: yelp-xsl: overly permissive content security policy in yelp allows host file disclosure from flatpak applications. (CVE-2026-13601) References SRPMS 10/core
  • yelp-49.0-2.1.mga10
9/core
  • yelp-42.2-1.2.mga9

MGASA-2026-0295 - Updated giflib packages fix a security vulnerability

25 Julio, 2026 - 19:04
Publication date: 25 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-26740 Description
The updated packages fix a security vulnerability: Buffer Overflow vulnerability in giflib v.5.2.2 allows a remote attacker to cause a denial of service via the EGifGCBToExtension overwriting an existing Graphic Control Extension block without validating its allocated size. (CVE-2026-26740) References SRPMS 10/core
  • giflib-5.2.2-4.1.mga10
9/core
  • giflib-5.2.1-7.4.mga9

MGAA-2026-0066 - Updated python-zstandard package fixes a bug

25 Julio, 2026 - 01:31
Publication date: 25 Jul 2026
Type: bugfix
Affected Mageia releases : 9
Description
The previous update was released with the use of the shared library libzstd1, which is now at version 1.5.7 in Mageia 9. However, python-zstandard supported only version 1.5.5. This update patches python-zstandard to use libzstd version 1.5.7. References SRPMS 9/core
  • python-zstandard-0.21.0-1.3.mga9

MGAA-2026-0065 - Updated suricata packages fix the service not starting

25 Julio, 2026 - 01:31
Publication date: 25 Jul 2026
Type: bugfix
Affected Mageia releases : 10 , 9
Description
The suricata server did not start in Mageia 9 and Mageia 10. The updated suricata packages fix the issue. References SRPMS 10/core
  • suricata-7.0.10-3.2.mga10
9/core
  • suricata-7.0.10-1.2.mga9

MGASA-2026-0293 - Updated transmission packages fix a security vulnerability

24 Julio, 2026 - 17:09
Publication date: 24 Jul 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-38978 Description
The updated packages fix a security vulnerability: Transmission through 4.1.1 was found to have a clickjacking weakness in the browser-facing WebUI and RPC response paths. (CVE-2026-38978) References SRPMS 10/core
  • transmission-4.1.3-1.mga10

MGASA-2026-0292 - Updated lrzip package fixes security vulnerabilities

24 Julio, 2026 - 04:58
Publication date: 24 Jul 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2025-15570 , CVE-2025-9396 Description
The updated package fixes security vulnerabilities: ckolivas lrzip stream.c lzma_decompress_buf use after free. (CVE-2025-15570) ckolivas lrzip strtol_l.c __GI_____strtol_l_internal null pointer dereference. (CVE-2025-9396) References SRPMS 10/core
  • lrzip-0.660-1.mga10

MGAA-2026-0064 - Updated rpm-mageia-setup packages fix incompatibility with emacs

24 Julio, 2026 - 04:58
Publication date: 24 Jul 2026
Type: bugfix
Affected Mageia releases : 10
Description
Opening a spec file with emacs on mga10 did no longer provide syntax highlighting. This update fixes the issue. References SRPMS 10/core
  • rpm-mageia-setup-2.84-1.mga10

MGAA-2026-0063 - Updated xonotic packages fix broken online statistics support

24 Julio, 2026 - 04:58
Publication date: 24 Jul 2026
Type: bugfix
Affected Mageia releases : 10
Description
Updated Xonotic packages to fix broken online statistics support. References SRPMS 10/core
  • xonotic-0.8.6-2.1.mga10

MGASA-2026-0291 - Updated cifs-utils packages fix a security vulnerability

23 Julio, 2026 - 18:45
Publication date: 23 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-12505 Description
The updated packages fix a security vulnerability: Local privilege escalation via forged cifs.spnego key description in cifs.upcall. (CVE-2026-12505) References SRPMS 10/core
  • cifs-utils-7.5-1.1.mga10
9/core
  • cifs-utils-7.0-1.2.mga9

MGASA-2026-0290 - Updated socat package fixes a security vulnerability

23 Julio, 2026 - 18:45
Publication date: 23 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-56123 Description
The updated package fixes a security vulnerability: Heap Buffer Overflow via SOCKS5 Reply Parser. (CVE-2026-56123) References SRPMS 10/core
  • socat-1.8.1.0-1.1.mga10
9/core
  • socat-1.8.0.2-1.1.mga9

MGASA-2026-0289 - Updated apache packages fix security vulnerabilities

23 Julio, 2026 - 18:45
Publication date: 23 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-29167 , CVE-2026-29170 , CVE-2026-34355 , CVE-2026-34356 , CVE-2026-42535 , CVE-2026-42536 , CVE-2026-43951 , CVE-2026-44119 , CVE-2026-44185 , CVE-2026-44186 , CVE-2026-44631 , CVE-2026-48913 , CVE-2026-49975 Description
The updated packages fix security vulnerabilities: Apache HTTP Server: mod_ldap per-dir use-after-free. (CVE-2026-29167) Apache HTTP Server: mod_proxy_ftp XSS. (CVE-2026-29170) Apache HTTP Server: mod_proxy_html buffer overflow. (CVE-2026-34355) Apache HTTP Server: ProxyPassReverseCookieMap buffer overflow. (CVE-2026-34356) Apache HTTP Server: mod_dav_fs protected directory access. (CVE-2026-42535) Apache HTTP Server: mod_xml2enc heap overflow. (CVE-2026-42536) Apache HTTP Server: OOB Read in `merge_response_headers` can cause crash. (CVE-2026-43951) Apache HTTP Server: escalation of privilege through expressions in .htaccess in multiple modules. (CVE-2026-44119) Apache HTTP Server: Stack Buffer Over-Read in mod_ssl OCSP `send_request`. (CVE-2026-44185) Apache HTTP Server: Loop in `proxy_ftp_handler` in mod_proxy_ftp. (CVE-2026-44186) Apache HTTP Server: Heap Underflow in `ap_regname` via Signed Char Overflow. (CVE-2026-44631) Apache HTTP Server: mod_http2 memory corruption when file handles exhausted. (CVE-2026-48913) Apache HTTP Server: mod_http2 denial of service. (CVE-2026-49975) References SRPMS 10/core
  • apache-2.4.68-1.mga10
9/core
  • apache-2.4.68-1.mga9

MGASA-2026-0288 - Updated dnsmasq packages fix security vulnerabilities

23 Julio, 2026 - 18:45
Publication date: 23 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-12725 , CVE-2026-12969 Description
The updated dnsmasq packages fix multiple security issues: A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and query logging are both enabled, logging of DS or DNSKEY replies containing unsupported algorithm or digest types can cause dnsmasq to write past the end of an internal logging buffer. A remote attacker able to supply such a DNS response may crash the dnsmasq process, resulting in denial of service. (CVE-2026-12725) An out-of-bounds read vulnerability exists in dnsmasq's find_soa() function in src/rfc1035.c. When parsing NS section records, extract_name() is called with extrabytes=0, failing to validate that 10 additional bytes exist for fixed-length DNS record fields. A remote attacker controlling a DNS zone can exploit this via a crafted NXDOMAIN response to cause a 10-byte heap out-of-bounds read, potentially accessing stale data from prior transactions. (CVE-2026-12969) References SRPMS 10/core
  • dnsmasq-2.93-1.mga10
9/core
  • dnsmasq-2.93-1.mga9

MGAA-2026-0061 - Updated nut packages fix a bug

23 Julio, 2026 - 18:45
Publication date: 23 Jul 2026
Type: bugfix
Affected Mageia releases : 10
Description
nut-scanner failed to start. This update fixes the issue and also updates the nut packages to the latest maintained release. References SRPMS 10/core
  • nut-2.8.5-1.mga10

MGAA-2026-0060 - Updated warpinator packages fix launch failure.

23 Julio, 2026 - 18:45
Publication date: 23 Jul 2026
Type: bugfix
Affected Mageia releases : 10
Description
warpinator uses the grpcio module, but with a stamp of the used module version. The stamp was not in accordance with the version of the provided module in the distro, preventing launch. This update fixes that. References SRPMS 10/core
  • warpinator-2.0.4-1.mga10

MGASA-2026-0287 - Updated tig package fixes a security vulnerability

21 Julio, 2026 - 16:19
Publication date: 21 Jul 2026
Type: security
Affected Mageia releases : 10
Description
The updated package fixes a security vulnerability: editor command injection vulnerability. References SRPMS 10/core
  • tig-2.6.1-1.mga10

MGAA-2026-0059 - Updated mageia-theme, grub2 & grub2-mageia-theme-dejavu packages fix bugs

21 Julio, 2026 - 16:19
Publication date: 21 Jul 2026
Type: bugfix
Affected Mageia releases : 10
Description
The updates packages fix issues in our signature background. The images have been reworked providing a better look. Building with mock is fixed allowing the produced mageia-theme and mageia-theme-extra packages to be installed together. Fix the plymouth theme which still was the Mageia 9 version after upgrades. Behind the scenes some processes are now done at build time, avoiding recurring issues with interlaced images. References SRPMS 10/core
  • mageia-theme-10.11-1.1.mga10
  • grub2-2.12-15.1.mga10
  • grub2-mageia-theme-dejavu-1.0-17.1.mga10

MGAA-2026-0058 - Updated serd, sord, sratom, suil and lilv to the latest versions

21 Julio, 2026 - 04:53
Publication date: 21 Jul 2026
Type: bugfix
Affected Mageia releases : 10
Description
The last versions of serd, sord, sratom, suil and lilv couldn't be submitted because of Cauldron FREEZE. References SRPMS 10/core
  • serd-0.32.8-1.mga10
  • sord-0.16.22-1.mga10
  • sratom-0.6.22-1.mga10
  • lilv-0.26.4-1.mga10
  • suil-0.10.26-3.mga10

MGASA-2026-0286 - Updated perl-CGI-Session package fixes a security vulnerability

20 Julio, 2026 - 20:06
Publication date: 20 Jul 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-56016 Description
The updated package fixes a security vulnerability: CGI::Session::ID::md5 versions before 4.49 for Perl generate predictable session ids from low-entropy sources. (CVE-2026-56016) References SRPMS 10/core
  • perl-CGI-Session-4.490.0-1.mga10