Actualizaciones de Seguridad

MGASA-2026-0413 - Updated python-starlette package fixes security vulnerabilities

Mageia Security - 17 Septiembre, 2026 - 15:10
Publication date: 17 Sep 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-48817 , CVE-2026-54282 , CVE-2026-54283 Description
Arbitrary HTTP method dispatched to `HTTPEndpoint` attributes via `getattr`. (CVE-2026-48817) Unvalidated request path concatenated into authority poisons request.url.hostname. (CVE-2026-54282) References
SRPMS 10/core
  • python-starlette-0.46.0-3.2.mga10

MGASA-2026-0412 - Updated libgd packages fix a security vulnerability

Mageia Security - 16 Septiembre, 2026 - 16:40
Publication date: 16 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-9672 Description
A vulnerability was discovered in libgd2, a library for programmatic graphics creation and manipulation, which may result in denial of service or potentially the execution of arbitrary code if a malformed GIF file is processed. References
SRPMS 10/core
  • libgd-2.3.3-11.1.mga10
9/core
  • libgd-2.3.3-6.1.mga9

MGASA-2026-0411 - Updated packagekit packages fix a security vulnerability

Mageia Security - 16 Septiembre, 2026 - 16:40
Publication date: 16 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-10294 Description
PackageKit API pk-transaction.c g_file_test improper authorization. (CVE-2026-10294) References
SRPMS 10/core
  • packagekit-1.3.5-1.1.mga10
9/core
  • packagekit-1.2.6-2.2.mga9

MGASA-2026-0410 - Updated aom packages fix security vulnerabilities

Mageia Security - 16 Septiembre, 2026 - 16:40
Publication date: 16 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-56208 , CVE-2026-56209 , CVE-2026-56210 , CVE-2026-56211 Description
Heap buffer overflow in av1 encoder first-pass stats buffer via lap mode. (CVE-2026-56208) Arbitrary address write via svc layer context oob and cyclic refresh map pointer hijack. (CVE-2026-56209) Heap-buffer-overflow read via missing bounds check in ctrl_set_layer_id. (CVE-2026-56210) Remote code execution via svc layer context handling with attacker-controlled frames. (CVE-2026-56211) References
SRPMS 10/core
  • aom-3.13.1-1.1.mga10
9/core
  • aom-3.6.0-1.2.mga9

MGASA-2026-0409 - Updated python-h2 packages fix a security vulnerability

Mageia Security - 16 Septiembre, 2026 - 16:40
Publication date: 16 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-71554 Description
Duplicate Host header facilitate request smuggling. (CVE-2026-71554) References
SRPMS 10/core
  • python-h2-4.3.0-1.1.mga10
9/core
  • python-h2-4.1.0-2.1.mga9

MGASA-2026-0407 - Updated libcupsfilters & cups-filters packages fix security vulnerabilities

Mageia Security - 14 Septiembre, 2026 - 17:26
Publication date: 14 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-64611 , CVE-2026-64612 Description
cpu exhaustion via infinite loop in cfieee1284normalizemakemodel(). (CVE-2026-64611) cups image filter process abort via malformed png. (CVE-2026-64612) References
SRPMS 10/core
  • libcupsfilters-2.1.1-5.1.mga10
9/core
  • cups-filters-1.28.16-6.4.mga9

MGASA-2026-0406 - Updated zip packages fix a security vulnerability

Mageia Security - 14 Septiembre, 2026 - 17:26
Publication date: 14 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2018-13410 Description
zip test option (-T) command injection. Info-ZIP Zip 3.0, when the -T and -TT command-line options are used, allows attackers to cause a denial of service (invalid free and application crash) or possibly have unspecified other impact because of an off-by-one error. (CVE-2018-13410) References
SRPMS 10/core
  • zip-3.0-17.1.mga10
9/core
  • zip-3.0-14.1.mga9

MGASA-2026-0405 - Updated unzip packages fix security vulnerabilities

Mageia Security - 14 Septiembre, 2026 - 17:26
Publication date: 14 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
Description
Vulnerabilities were discovered in the Info-ZIP unzip program, which could result in the execution of arbitrary code if a specially crafted file is processed. References
SRPMS 10/core
  • unzip-6.0-8.1.mga10
9/core
  • unzip-6.0-4.1.mga9

MGASA-2026-0404 - Updated perl-HTML-FormFu packages fix a security vulnerability

Mageia Security - 14 Septiembre, 2026 - 17:26
Publication date: 14 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-19873 Description
HTML::FormFu versions through 2.08 for Perl allow resource exhaustion via an unbounded repeat count from the query string in Repeatable elements. (CVE-2026-19873) References
SRPMS 10/core
  • perl-HTML-FormFu-2.60.0-5.1.mga10
9/core
  • perl-HTML-FormFu-2.60.0-4.1.mga9

MGASA-2026-0403 - Updated bzip2 packages fix a security vulnerability

Mageia Security - 14 Septiembre, 2026 - 17:26
Publication date: 14 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-42250 Description
Off-by-One Leading to Out-of-Bounds Write in bzip2. (CVE-2026-42250 References
SRPMS 10/core
  • bzip2-1.0.8-7.1.mga10
9/core
  • bzip2-1.0.8-5.1.mga9

MGASA-2026-0402 - Updated libssh2 packages fix security vulnerabilities

Mageia Security - 14 Septiembre, 2026 - 17:26
Publication date: 14 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-66032 , CVE-2026-66033 , CVE-2026-66035 Description
Double-Free Heap Corruption via sftp_open(). (CVE-2026-66032) Integer Underflow DoS via AES-GCM Cipher Negotiation. (CVE-2026-66033) Heap Buffer Overflow via ETM Cipher Negotiation. (CVE-2026-66035) References
SRPMS 10/core
  • libssh2-1.11.1-2.2.mga10
9/core
  • libssh2-1.11.0-1.2.mga9

MGASA-2026-0401 - Updated tar packages fix security vulnerabilities

Mageia Security - 14 Septiembre, 2026 - 17:26
Publication date: 14 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2025-45582 , CVE-2026-18508 , CVE-2026-18477 Description
GNU Tar through 1.35 allows file overwrite via directory traversal in crafted TAR archives, with a certain two-step process. (CVE-2025-45582) Tar: toctou in incremental dumpdir 'x' rename handling allows restore path escape. (CVE-2026-18477) Tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite. (CVE-2026-18508) References
SRPMS 10/core
  • tar-1.35-4.1.mga10
9/core
  • tar-1.35-4.1.mga9

MGASA-2026-0399 - Updated bind package fixes a security vulnerability

Mageia Security - 13 Septiembre, 2026 - 06:39
Publication date: 13 Sep 2026
Type: security
Affected Mageia releases : 9
CVE: CVE-2026-13204 Description
It was discovered that Bind incorrectly handled DNSSEC validation when a domain was covered by both NSEC and NSEC3 records with only one type having an RRSIG. A remote attacker could possibly use this issue to cause Bind to crash, resulting in a denial of service (CVE-2026-13204). References
SRPMS 9/core
  • bind-9.18.50-1.1.mga9

MGASA-2026-0398 - Updated ffmpeg package fixes security vulnerabilities

Mageia Security - 13 Septiembre, 2026 - 06:39
Publication date: 13 Sep 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-58049 , CVE-2026-64830 , CVE-2026-64832 , CVE-2026-64833 , CVE-2026-64834 , CVE-2026-64835 , CVE-2026-65703 , CVE-2026-65704 , CVE-2026-65705 , CVE-2026-65706 , CVE-2026-66036 , CVE-2026-66037 , CVE-2026-66038 , CVE-2026-66039 , CVE-2026-66041 , CVE-2026-70628 , CVE-2026-70629 , CVE-2026-70630 , CVE-2026-70631 , CVE-2026-70632 , CVE-2026-75141 , CVE-2026-75142 , CVE-2026-75143 , CVE-2026-75144 , CVE-2026-75146 Description
Out-of-Bounds Write in RASC Decoder decode_dlta(). (CVE-2026-58049) Heap Buffer Overflow via VobSub Subtitle Demuxer. (CVE-2026-64830) Double-Free in NVDEC Hardware Decoder via nvdec.c. (CVE-2026-64832) Out-of-Bounds Read via S/PDIF Muxer spdifenc.c. (CVE-2026-64833) Infinite Loop DoS via RTP/ASF Demuxer. (CVE-2026-64834) Out-of-Bounds Memory Access in ADX Audio Decoder. (CVE-2026-64835) Out-of-Bounds Write in TDSC Video Decoder. (CVE-2026-65703) Out-of-Bounds Write via TY Demuxer and Shorten Decoder. (CVE-2026-65704) vf_floodfill Out-of-Bounds Write via filter_frame(). (CVE-2026-65705) vf_swaprect Out-of-Bounds Write via NV12 Frame Processing. (CVE-2026-65706) Heap Out-of-Bounds Write in vf_hqdn3d Filter. (CVE-2026-66036) IAMF Demuxer Uncontrolled Resource Consumption via mix_presentation_obu(). (CVE-2026-66037) LCL/ZLIB Video Decoder Information Disclosure via lcldec.c. (CVE-2026-66038) MACE6 Audio Decoder Heap Out-of-Bounds Write via CAF File. (CVE-2026-66039) Heap Out-of-Bounds Write via vf_quirc Filter. (CVE-2026-66041) DVB Subtitle Parser Heap Buffer Overflow via WTV File. (CVE-2026-70628) Uninitialized Heap Memory Read in RSCC Decoder. (CVE-2026-70629) Uninitialized Heap Memory Read in Screenpresso Decoder. (CVE-2026-70630) Uninitialized Heap Memory Read in TIFF Decoder. (CVE-2026-70631) Heap Out-of-Bounds Write in CFHD Decoder via AVI Demuxing. (CVE-2026-70632) Heap Buffer Overflow in hvcC Box Writer via HEVC Muxing. (CVE-2026-75141) Stack Buffer Overflow in MPEG-PS Muxer via mpegenc.c. (CVE-2026-75142) Heap Buffer Overflow via RIST Protocol Reader. (CVE-2026-75143) Heap Buffer Overflow in VC-2/Dirac RTP Packetizer. (CVE-2026-75144) Out-of-Bounds Read in DASH Demuxer via dashdec.c. (CVE-2026-75146) References
SRPMS 10/core
  • ffmpeg-7.1.5-1.1.mga10
10/tainted
  • ffmpeg-7.1.5-1.1.mga10.tainted

MGASA-2026-0397 - Updated librabbitmq packages fix security vulnerabilities

Mageia Security - 12 Septiembre, 2026 - 18:24
Publication date: 12 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-59986 , CVE-2026-61547 Description
amqp_decode_bytes size_t integer overflow bypasses bounds check on 32-bit (OOB read). (CVE-2026-59986) Heap Buffer Overflow in amqp_send_frame() When Serializing Oversized AMQP_FRAME_BODY. (CVE-2026-61547) References
SRPMS 10/core
  • librabbitmq-0.15.0-2.2.mga10
9/core
  • librabbitmq-0.11.0-1.2.mga9

MGASA-2026-0396 - Updated xz packages fix security vulnerabilities

Mageia Security - 12 Septiembre, 2026 - 18:24
Publication date: 12 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
Description
XZ Utils: Invalid write if a decoder is reinitialized after allocation failure References
SRPMS 10/core
  • xz-5.8.4-1.mga10
9/core
  • xz-5.4.7-0.git20260909.1.mga9

MGASA-2026-0395 - Updated java-21-openjdk & java-17-openjdk packages fix security vulnerabilities

Mageia Security - 12 Septiembre, 2026 - 04:59
Publication date: 12 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-46968 , CVE-2026-46917 , CVE-2026-47010 , CVE-2026-47021 , CVE-2026-47027 , CVE-2026-60147 , CVE-2026-47059 , CVE-2026-47063 , CVE-2026-60589 , CVE-2026-61308 , CVE-2026-70907 Description
Enhance TLS certificate handling. (CVE-2026-46968) Improve DTLS handshaking. (CVE-2026-46917) Enhance JPEG handling. (CVE-2026-47010) Enhance XBM image support. (CVE-2026-47021) Enhance Jar file processing. (CVE-2026-47027) Improve certification checking. (CVE-2026-60147) Enhance AWT ImagingLib. (CVE-2026-47059) Enhance Jar handling. (CVE-2026-47063) Improve Resource Resolving. (CVE-2026-60589) Enhance HTTP Connections. (CVE-2026-61308) Enhance TLS server. (CVE-2026-70907) References
SRPMS 10/core
  • java-21-openjdk-21.0.12.1.1-1.mga10
9/core
  • java-17-openjdk-17.0.20.1.1-1.mga9

MGASA-2026-0394 - Updated perl-Imager packages fix a security vulnerability

Mageia Security - 12 Septiembre, 2026 - 04:59
Publication date: 12 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-19082 Description
Imager versions from 0.45_02 before 1.034 for Perl may expose adjacent heap bytes via strlen() over-read from zero-count ASCII EXIF entries in copy_string_tags References
SRPMS 10/core
  • perl-Imager-1.34.0-1.1.mga10
9/core
  • perl-Imager-1.34.0-1.1.mga9
Feed