Actualizaciones de Seguridad
MGASA-2026-0413 - Updated python-starlette package fixes security vulnerabilities
Publication date: 17 Sep 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-48817 , CVE-2026-54282 , CVE-2026-54283 Description
Arbitrary HTTP method dispatched to `HTTPEndpoint` attributes via `getattr`. (CVE-2026-48817) Unvalidated request path concatenated into authority poisons request.url.hostname. (CVE-2026-54282) References
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-48817 , CVE-2026-54282 , CVE-2026-54283 Description
Arbitrary HTTP method dispatched to `HTTPEndpoint` attributes via `getattr`. (CVE-2026-48817) Unvalidated request path concatenated into authority poisons request.url.hostname. (CVE-2026-54282) References
- https://bugs.mageia.org/show_bug.cgi?id=36224
- https://lists.debian.org/debian-security-announce/2026/msg00389.html
- https://www.cve.org/CVERecord?id=CVE-2026-48817
- https://www.cve.org/CVERecord?id=CVE-2026-54282
- https://www.cve.org/CVERecord?id=CVE-2026-54283
- python-starlette-0.46.0-3.2.mga10
Categorías: Actualizaciones de Seguridad
MGASA-2026-0412 - Updated libgd packages fix a security vulnerability
Publication date: 16 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-9672 Description
A vulnerability was discovered in libgd2, a library for programmatic graphics creation and manipulation, which may result in denial of service or potentially the execution of arbitrary code if a malformed GIF file is processed. References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-9672 Description
A vulnerability was discovered in libgd2, a library for programmatic graphics creation and manipulation, which may result in denial of service or potentially the execution of arbitrary code if a malformed GIF file is processed. References
- https://bugs.mageia.org/show_bug.cgi?id=36162
- https://lists.debian.org/debian-security-announce/2026/msg00320.html?pow_referer=https%3A%2F%2Fbugs.mageia.org%2F
- https://www.cve.org/CVERecord?id=CVE-2026-9672
- libgd-2.3.3-11.1.mga10
- libgd-2.3.3-6.1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0411 - Updated packagekit packages fix a security vulnerability
Publication date: 16 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-10294 Description
PackageKit API pk-transaction.c g_file_test improper authorization. (CVE-2026-10294) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-10294 Description
PackageKit API pk-transaction.c g_file_test improper authorization. (CVE-2026-10294) References
- https://bugs.mageia.org/show_bug.cgi?id=36166
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/M6KYMZZSTVVP7SBKMB54MNOK7HGHQQN4/
- https://github.com/PackageKit/PackageKit/issues/969
- https://www.cve.org/CVERecord?id=CVE-2026-10294
- packagekit-1.3.5-1.1.mga10
- packagekit-1.2.6-2.2.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0410 - Updated aom packages fix security vulnerabilities
Publication date: 16 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-56208 , CVE-2026-56209 , CVE-2026-56210 , CVE-2026-56211 Description
Heap buffer overflow in av1 encoder first-pass stats buffer via lap mode. (CVE-2026-56208) Arbitrary address write via svc layer context oob and cyclic refresh map pointer hijack. (CVE-2026-56209) Heap-buffer-overflow read via missing bounds check in ctrl_set_layer_id. (CVE-2026-56210) Remote code execution via svc layer context handling with attacker-controlled frames. (CVE-2026-56211) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-56208 , CVE-2026-56209 , CVE-2026-56210 , CVE-2026-56211 Description
Heap buffer overflow in av1 encoder first-pass stats buffer via lap mode. (CVE-2026-56208) Arbitrary address write via svc layer context oob and cyclic refresh map pointer hijack. (CVE-2026-56209) Heap-buffer-overflow read via missing bounds check in ctrl_set_layer_id. (CVE-2026-56210) Remote code execution via svc layer context handling with attacker-controlled frames. (CVE-2026-56211) References
- https://bugs.mageia.org/show_bug.cgi?id=36170
- https://lists.debian.org/debian-security-announce/2026/msg00322.html
- https://www.cve.org/CVERecord?id=CVE-2026-56208
- https://www.cve.org/CVERecord?id=CVE-2026-56209
- https://www.cve.org/CVERecord?id=CVE-2026-56210
- https://www.cve.org/CVERecord?id=CVE-2026-56211
- aom-3.13.1-1.1.mga10
- aom-3.6.0-1.2.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0409 - Updated python-h2 packages fix a security vulnerability
Publication date: 16 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-71554 Description
Duplicate Host header facilitate request smuggling. (CVE-2026-71554) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-71554 Description
Duplicate Host header facilitate request smuggling. (CVE-2026-71554) References
- https://bugs.mageia.org/show_bug.cgi?id=36188
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/IDTJHCXCD2JELR2ZHWETBBYC3OYTW7QH/
- https://github.com/python-hyper/h2/security/advisories/GHSA-6hr6-w5qg-qmwg
- https://www.cve.org/CVERecord?id=CVE-2026-71554
- python-h2-4.3.0-1.1.mga10
- python-h2-4.1.0-2.1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0408 - Updated cockpit packages fix a security vulnerability
Publication date: 16 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-76235 Description
Cockpit-ws: unauthenticated remote memory leak via cockpitlang cookie in send_login_html. (CVE-2026-76235) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-76235 Description
Cockpit-ws: unauthenticated remote memory leak via cockpitlang cookie in send_login_html. (CVE-2026-76235) References
- https://bugs.mageia.org/show_bug.cgi?id=36207
- https://lists.debian.org/debian-security-announce/2026/msg00385.html
- https://bugzilla.redhat.com/show_bug.cgi?id=2519497
- https://github.com/cockpit-project/cockpit/pull/23633
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KV2ED2IAJAGOAIPNS3HQS7G4KHJANP3C/
- https://www.cve.org/CVERecord?id=CVE-2026-76235
- cockpit-356.2-1.1.mga10
- cockpit-356.2-1.1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0407 - Updated libcupsfilters & cups-filters packages fix security vulnerabilities
Publication date: 14 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-64611 , CVE-2026-64612 Description
cpu exhaustion via infinite loop in cfieee1284normalizemakemodel(). (CVE-2026-64611) cups image filter process abort via malformed png. (CVE-2026-64612) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-64611 , CVE-2026-64612 Description
cpu exhaustion via infinite loop in cfieee1284normalizemakemodel(). (CVE-2026-64611) cups image filter process abort via malformed png. (CVE-2026-64612) References
- https://bugs.mageia.org/show_bug.cgi?id=36182
- https://www.cve.org/CVERecord?id=CVE-2026-64611
- https://www.cve.org/CVERecord?id=CVE-2026-64612
- libcupsfilters-2.1.1-5.1.mga10
- cups-filters-1.28.16-6.4.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0406 - Updated zip packages fix a security vulnerability
Publication date: 14 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2018-13410 Description
zip test option (-T) command injection. Info-ZIP Zip 3.0, when the -T and -TT command-line options are used, allows attackers to cause a denial of service (invalid free and application crash) or possibly have unspecified other impact because of an off-by-one error. (CVE-2018-13410) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2018-13410 Description
zip test option (-T) command injection. Info-ZIP Zip 3.0, when the -T and -TT command-line options are used, allows attackers to cause a denial of service (invalid free and application crash) or possibly have unspecified other impact because of an off-by-one error. (CVE-2018-13410) References
- https://bugs.mageia.org/show_bug.cgi?id=36143
- https://www.openwall.com/lists/oss-security/2026/08/14/1
- https://sintonen.fi/advisories/infozip-test-option-command-injection.txt
- https://lists.debian.org/debian-security-announce/2026/msg00350.html
- https://www.cve.org/CVERecord?id=CVE-2018-13410
- zip-3.0-17.1.mga10
- zip-3.0-14.1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0405 - Updated unzip packages fix security vulnerabilities
Publication date: 14 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
Description
Vulnerabilities were discovered in the Info-ZIP unzip program, which could result in the execution of arbitrary code if a specially crafted file is processed. References
Type: security
Affected Mageia releases : 10 , 9
Description
Vulnerabilities were discovered in the Info-ZIP unzip program, which could result in the execution of arbitrary code if a specially crafted file is processed. References
- https://bugs.mageia.org/show_bug.cgi?id=36184
- https://lists.debian.org/debian-security-announce/2026/msg00351.html
- unzip-6.0-8.1.mga10
- unzip-6.0-4.1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0404 - Updated perl-HTML-FormFu packages fix a security vulnerability
Publication date: 14 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-19873 Description
HTML::FormFu versions through 2.08 for Perl allow resource exhaustion via an unbounded repeat count from the query string in Repeatable elements. (CVE-2026-19873) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-19873 Description
HTML::FormFu versions through 2.08 for Perl allow resource exhaustion via an unbounded repeat count from the query string in Repeatable elements. (CVE-2026-19873) References
- https://bugs.mageia.org/show_bug.cgi?id=36232
- https://www.openwall.com/lists/oss-security/2026/08/31/7
- https://github.com/FormFu/HTML-FormFu/issues/71
- https://www.cve.org/CVERecord?id=CVE-2026-19873
- perl-HTML-FormFu-2.60.0-5.1.mga10
- perl-HTML-FormFu-2.60.0-4.1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0403 - Updated bzip2 packages fix a security vulnerability
Publication date: 14 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-42250 Description
Off-by-One Leading to Out-of-Bounds Write in bzip2. (CVE-2026-42250 References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-42250 Description
Off-by-One Leading to Out-of-Bounds Write in bzip2. (CVE-2026-42250 References
- https://bugs.mageia.org/show_bug.cgi?id=36240
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/5BZUFTRN4TGNACBM45SR6YO5FURLM3CM/
- https://inbox.sourceware.org/bzip2-devel/20260528145407.293768-1-mark@klomp.org/
- https://www.cve.org/CVERecord?id=CVE-2026-42250
- bzip2-1.0.8-7.1.mga10
- bzip2-1.0.8-5.1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0402 - Updated libssh2 packages fix security vulnerabilities
Publication date: 14 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-66032 , CVE-2026-66033 , CVE-2026-66035 Description
Double-Free Heap Corruption via sftp_open(). (CVE-2026-66032) Integer Underflow DoS via AES-GCM Cipher Negotiation. (CVE-2026-66033) Heap Buffer Overflow via ETM Cipher Negotiation. (CVE-2026-66035) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-66032 , CVE-2026-66033 , CVE-2026-66035 Description
Double-Free Heap Corruption via sftp_open(). (CVE-2026-66032) Integer Underflow DoS via AES-GCM Cipher Negotiation. (CVE-2026-66033) Heap Buffer Overflow via ETM Cipher Negotiation. (CVE-2026-66035) References
- https://bugs.mageia.org/show_bug.cgi?id=36256
- https://ubuntu.com/security/notices/USN-8722-1
- https://www.cve.org/CVERecord?id=CVE-2026-66032
- https://www.cve.org/CVERecord?id=CVE-2026-66033
- https://www.cve.org/CVERecord?id=CVE-2026-66035
- libssh2-1.11.1-2.2.mga10
- libssh2-1.11.0-1.2.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0401 - Updated tar packages fix security vulnerabilities
Publication date: 14 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2025-45582 , CVE-2026-18508 , CVE-2026-18477 Description
GNU Tar through 1.35 allows file overwrite via directory traversal in crafted TAR archives, with a certain two-step process. (CVE-2025-45582) Tar: toctou in incremental dumpdir 'x' rename handling allows restore path escape. (CVE-2026-18477) Tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite. (CVE-2026-18508) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2025-45582 , CVE-2026-18508 , CVE-2026-18477 Description
GNU Tar through 1.35 allows file overwrite via directory traversal in crafted TAR archives, with a certain two-step process. (CVE-2025-45582) Tar: toctou in incremental dumpdir 'x' rename handling allows restore path escape. (CVE-2026-18477) Tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite. (CVE-2026-18508) References
- https://bugs.mageia.org/show_bug.cgi?id=36289
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ASLMG5TUYWS2IEKBCOWN5KZ2K55V366N/
- https://www.cve.org/CVERecord?id=CVE-2025-45582
- https://www.cve.org/CVERecord?id=CVE-2026-18508
- https://www.cve.org/CVERecord?id=CVE-2026-18477
- tar-1.35-4.1.mga10
- tar-1.35-4.1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0400 - Updated perl-Authen-SASL packages fix a security vulnerability
Publication date: 14 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-86219 Description
Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept replayed authentication responses via unverified nonce in server_step. (CVE-2026-86219) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-86219 Description
Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept replayed authentication responses via unverified nonce in server_step. (CVE-2026-86219) References
- https://bugs.mageia.org/show_bug.cgi?id=36264
- https://www.openwall.com/lists/oss-security/2026/09/06/1
- https://metacpan.org/release/EHUELS/Authen-SASL-2.2000/source/lib/Authen/SASL/Perl/DIGEST_MD5.pm#L203-222
- https://metacpan.org/release/EHUELS/Authen-SASL-2.2000/source/lib/Authen/SASL/Perl/DIGEST_MD5.pm#L410-414
- https://datatracker.ietf.org/doc/html/rfc2831#section-2.1.2
- https://metacpan.org/release/EHUELS/Authen-SASL-2.2100/changes
- https://www.cve.org/CVERecord?id=CVE-2026-86219
- perl-Authen-SASL-2.190.0-1.1.mga10
- perl-Authen-SASL-2.160.0-13.2.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0399 - Updated bind package fixes a security vulnerability
Publication date: 13 Sep 2026
Type: security
Affected Mageia releases : 9
CVE: CVE-2026-13204 Description
It was discovered that Bind incorrectly handled DNSSEC validation when a domain was covered by both NSEC and NSEC3 records with only one type having an RRSIG. A remote attacker could possibly use this issue to cause Bind to crash, resulting in a denial of service (CVE-2026-13204). References
Type: security
Affected Mageia releases : 9
CVE: CVE-2026-13204 Description
It was discovered that Bind incorrectly handled DNSSEC validation when a domain was covered by both NSEC and NSEC3 records with only one type having an RRSIG. A remote attacker could possibly use this issue to cause Bind to crash, resulting in a denial of service (CVE-2026-13204). References
- https://bugs.mageia.org/show_bug.cgi?id=36241
- https://ubuntu.com/security/notices/USN-8696-1
- https://kb.isc.org/docs/cve-2026-13204
- https://www.cve.org/CVERecord?id=CVE-2026-13204
- https://www.cve.org/CVERecord?id=CVE-2026-13204
- bind-9.18.50-1.1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0398 - Updated ffmpeg package fixes security vulnerabilities
Publication date: 13 Sep 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-58049 , CVE-2026-64830 , CVE-2026-64832 , CVE-2026-64833 , CVE-2026-64834 , CVE-2026-64835 , CVE-2026-65703 , CVE-2026-65704 , CVE-2026-65705 , CVE-2026-65706 , CVE-2026-66036 , CVE-2026-66037 , CVE-2026-66038 , CVE-2026-66039 , CVE-2026-66041 , CVE-2026-70628 , CVE-2026-70629 , CVE-2026-70630 , CVE-2026-70631 , CVE-2026-70632 , CVE-2026-75141 , CVE-2026-75142 , CVE-2026-75143 , CVE-2026-75144 , CVE-2026-75146 Description
Out-of-Bounds Write in RASC Decoder decode_dlta(). (CVE-2026-58049) Heap Buffer Overflow via VobSub Subtitle Demuxer. (CVE-2026-64830) Double-Free in NVDEC Hardware Decoder via nvdec.c. (CVE-2026-64832) Out-of-Bounds Read via S/PDIF Muxer spdifenc.c. (CVE-2026-64833) Infinite Loop DoS via RTP/ASF Demuxer. (CVE-2026-64834) Out-of-Bounds Memory Access in ADX Audio Decoder. (CVE-2026-64835) Out-of-Bounds Write in TDSC Video Decoder. (CVE-2026-65703) Out-of-Bounds Write via TY Demuxer and Shorten Decoder. (CVE-2026-65704) vf_floodfill Out-of-Bounds Write via filter_frame(). (CVE-2026-65705) vf_swaprect Out-of-Bounds Write via NV12 Frame Processing. (CVE-2026-65706) Heap Out-of-Bounds Write in vf_hqdn3d Filter. (CVE-2026-66036) IAMF Demuxer Uncontrolled Resource Consumption via mix_presentation_obu(). (CVE-2026-66037) LCL/ZLIB Video Decoder Information Disclosure via lcldec.c. (CVE-2026-66038) MACE6 Audio Decoder Heap Out-of-Bounds Write via CAF File. (CVE-2026-66039) Heap Out-of-Bounds Write via vf_quirc Filter. (CVE-2026-66041) DVB Subtitle Parser Heap Buffer Overflow via WTV File. (CVE-2026-70628) Uninitialized Heap Memory Read in RSCC Decoder. (CVE-2026-70629) Uninitialized Heap Memory Read in Screenpresso Decoder. (CVE-2026-70630) Uninitialized Heap Memory Read in TIFF Decoder. (CVE-2026-70631) Heap Out-of-Bounds Write in CFHD Decoder via AVI Demuxing. (CVE-2026-70632) Heap Buffer Overflow in hvcC Box Writer via HEVC Muxing. (CVE-2026-75141) Stack Buffer Overflow in MPEG-PS Muxer via mpegenc.c. (CVE-2026-75142) Heap Buffer Overflow via RIST Protocol Reader. (CVE-2026-75143) Heap Buffer Overflow in VC-2/Dirac RTP Packetizer. (CVE-2026-75144) Out-of-Bounds Read in DASH Demuxer via dashdec.c. (CVE-2026-75146) References
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-58049 , CVE-2026-64830 , CVE-2026-64832 , CVE-2026-64833 , CVE-2026-64834 , CVE-2026-64835 , CVE-2026-65703 , CVE-2026-65704 , CVE-2026-65705 , CVE-2026-65706 , CVE-2026-66036 , CVE-2026-66037 , CVE-2026-66038 , CVE-2026-66039 , CVE-2026-66041 , CVE-2026-70628 , CVE-2026-70629 , CVE-2026-70630 , CVE-2026-70631 , CVE-2026-70632 , CVE-2026-75141 , CVE-2026-75142 , CVE-2026-75143 , CVE-2026-75144 , CVE-2026-75146 Description
Out-of-Bounds Write in RASC Decoder decode_dlta(). (CVE-2026-58049) Heap Buffer Overflow via VobSub Subtitle Demuxer. (CVE-2026-64830) Double-Free in NVDEC Hardware Decoder via nvdec.c. (CVE-2026-64832) Out-of-Bounds Read via S/PDIF Muxer spdifenc.c. (CVE-2026-64833) Infinite Loop DoS via RTP/ASF Demuxer. (CVE-2026-64834) Out-of-Bounds Memory Access in ADX Audio Decoder. (CVE-2026-64835) Out-of-Bounds Write in TDSC Video Decoder. (CVE-2026-65703) Out-of-Bounds Write via TY Demuxer and Shorten Decoder. (CVE-2026-65704) vf_floodfill Out-of-Bounds Write via filter_frame(). (CVE-2026-65705) vf_swaprect Out-of-Bounds Write via NV12 Frame Processing. (CVE-2026-65706) Heap Out-of-Bounds Write in vf_hqdn3d Filter. (CVE-2026-66036) IAMF Demuxer Uncontrolled Resource Consumption via mix_presentation_obu(). (CVE-2026-66037) LCL/ZLIB Video Decoder Information Disclosure via lcldec.c. (CVE-2026-66038) MACE6 Audio Decoder Heap Out-of-Bounds Write via CAF File. (CVE-2026-66039) Heap Out-of-Bounds Write via vf_quirc Filter. (CVE-2026-66041) DVB Subtitle Parser Heap Buffer Overflow via WTV File. (CVE-2026-70628) Uninitialized Heap Memory Read in RSCC Decoder. (CVE-2026-70629) Uninitialized Heap Memory Read in Screenpresso Decoder. (CVE-2026-70630) Uninitialized Heap Memory Read in TIFF Decoder. (CVE-2026-70631) Heap Out-of-Bounds Write in CFHD Decoder via AVI Demuxing. (CVE-2026-70632) Heap Buffer Overflow in hvcC Box Writer via HEVC Muxing. (CVE-2026-75141) Stack Buffer Overflow in MPEG-PS Muxer via mpegenc.c. (CVE-2026-75142) Heap Buffer Overflow via RIST Protocol Reader. (CVE-2026-75143) Heap Buffer Overflow in VC-2/Dirac RTP Packetizer. (CVE-2026-75144) Out-of-Bounds Read in DASH Demuxer via dashdec.c. (CVE-2026-75146) References
- https://bugs.mageia.org/show_bug.cgi?id=36272
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/36MFOOZUWA23VQEN5YTRKBQNH32RPWZB/
- https://www.cve.org/CVERecord?id=CVE-2026-58049
- https://www.cve.org/CVERecord?id=CVE-2026-64830
- https://www.cve.org/CVERecord?id=CVE-2026-64832
- https://www.cve.org/CVERecord?id=CVE-2026-64833
- https://www.cve.org/CVERecord?id=CVE-2026-64834
- https://www.cve.org/CVERecord?id=CVE-2026-64835
- https://www.cve.org/CVERecord?id=CVE-2026-65703
- https://www.cve.org/CVERecord?id=CVE-2026-65704
- https://www.cve.org/CVERecord?id=CVE-2026-65705
- https://www.cve.org/CVERecord?id=CVE-2026-65706
- https://www.cve.org/CVERecord?id=CVE-2026-66036
- https://www.cve.org/CVERecord?id=CVE-2026-66037
- https://www.cve.org/CVERecord?id=CVE-2026-66038
- https://www.cve.org/CVERecord?id=CVE-2026-66039
- https://www.cve.org/CVERecord?id=CVE-2026-66041
- https://www.cve.org/CVERecord?id=CVE-2026-70628
- https://www.cve.org/CVERecord?id=CVE-2026-70629
- https://www.cve.org/CVERecord?id=CVE-2026-70630
- https://www.cve.org/CVERecord?id=CVE-2026-70631
- https://www.cve.org/CVERecord?id=CVE-2026-70632
- https://www.cve.org/CVERecord?id=CVE-2026-75141
- https://www.cve.org/CVERecord?id=CVE-2026-75142
- https://www.cve.org/CVERecord?id=CVE-2026-75143
- https://www.cve.org/CVERecord?id=CVE-2026-75144
- https://www.cve.org/CVERecord?id=CVE-2026-75146
- ffmpeg-7.1.5-1.1.mga10
- ffmpeg-7.1.5-1.1.mga10.tainted
Categorías: Actualizaciones de Seguridad
MGASA-2026-0397 - Updated librabbitmq packages fix security vulnerabilities
Publication date: 12 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-59986 , CVE-2026-61547 Description
amqp_decode_bytes size_t integer overflow bypasses bounds check on 32-bit (OOB read). (CVE-2026-59986) Heap Buffer Overflow in amqp_send_frame() When Serializing Oversized AMQP_FRAME_BODY. (CVE-2026-61547) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-59986 , CVE-2026-61547 Description
amqp_decode_bytes size_t integer overflow bypasses bounds check on 32-bit (OOB read). (CVE-2026-59986) Heap Buffer Overflow in amqp_send_frame() When Serializing Oversized AMQP_FRAME_BODY. (CVE-2026-61547) References
- https://bugs.mageia.org/show_bug.cgi?id=36189
- https://lists.debian.org/debian-security-announce/2026/msg00358.html
- https://github.com/alanxz/rabbitmq-c/security/advisories/GHSA-jgjf-7fwf-f3c7
- https://github.com/alanxz/rabbitmq-c/security/advisories/GHSA-hfjv-vcp3-39wh
- https://ubuntu.com/security/notices/USN-8724-1
- https://www.cve.org/CVERecord?id=CVE-2026-59986
- https://www.cve.org/CVERecord?id=CVE-2026-61547
- librabbitmq-0.15.0-2.2.mga10
- librabbitmq-0.11.0-1.2.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0396 - Updated xz packages fix security vulnerabilities
Publication date: 12 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
Description
XZ Utils: Invalid write if a decoder is reinitialized after allocation failure References
Type: security
Affected Mageia releases : 10 , 9
Description
XZ Utils: Invalid write if a decoder is reinitialized after allocation failure References
- https://bugs.mageia.org/show_bug.cgi?id=36293
- https://www.openwall.com/lists/oss-security/2026/09/09/5
- https://tukaani.org/xz/invalid-write-after-reinit.html
- https://github.com/tukaani-project/xz/security/advisories/GHSA-5qpq-xqfv-j9pg
- xz-5.8.4-1.mga10
- xz-5.4.7-0.git20260909.1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0395 - Updated java-21-openjdk & java-17-openjdk packages fix security vulnerabilities
Publication date: 12 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-46968 , CVE-2026-46917 , CVE-2026-47010 , CVE-2026-47021 , CVE-2026-47027 , CVE-2026-60147 , CVE-2026-47059 , CVE-2026-47063 , CVE-2026-60589 , CVE-2026-61308 , CVE-2026-70907 Description
Enhance TLS certificate handling. (CVE-2026-46968) Improve DTLS handshaking. (CVE-2026-46917) Enhance JPEG handling. (CVE-2026-47010) Enhance XBM image support. (CVE-2026-47021) Enhance Jar file processing. (CVE-2026-47027) Improve certification checking. (CVE-2026-60147) Enhance AWT ImagingLib. (CVE-2026-47059) Enhance Jar handling. (CVE-2026-47063) Improve Resource Resolving. (CVE-2026-60589) Enhance HTTP Connections. (CVE-2026-61308) Enhance TLS server. (CVE-2026-70907) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-46968 , CVE-2026-46917 , CVE-2026-47010 , CVE-2026-47021 , CVE-2026-47027 , CVE-2026-60147 , CVE-2026-47059 , CVE-2026-47063 , CVE-2026-60589 , CVE-2026-61308 , CVE-2026-70907 Description
Enhance TLS certificate handling. (CVE-2026-46968) Improve DTLS handshaking. (CVE-2026-46917) Enhance JPEG handling. (CVE-2026-47010) Enhance XBM image support. (CVE-2026-47021) Enhance Jar file processing. (CVE-2026-47027) Improve certification checking. (CVE-2026-60147) Enhance AWT ImagingLib. (CVE-2026-47059) Enhance Jar handling. (CVE-2026-47063) Improve Resource Resolving. (CVE-2026-60589) Enhance HTTP Connections. (CVE-2026-61308) Enhance TLS server. (CVE-2026-70907) References
- https://bugs.mageia.org/show_bug.cgi?id=36125
- https://access.redhat.com/errata/RHSA-2026:42889
- https://access.redhat.com/errata/RHSA-2026:55782
- https://access.redhat.com/errata/RHSA-2026:42897
- https://access.redhat.com/errata/RHSA-2026:55788
- https://www.oracle.com/security-alerts/cpujul2026.html#AppendixJAVA
- https://www.oracle.com/security-alerts/cspuaug2026.html#AppendixJAVA
- https://www.cve.org/CVERecord?id=CVE-2026-46968
- https://www.cve.org/CVERecord?id=CVE-2026-46917
- https://www.cve.org/CVERecord?id=CVE-2026-47010
- https://www.cve.org/CVERecord?id=CVE-2026-47021
- https://www.cve.org/CVERecord?id=CVE-2026-47027
- https://www.cve.org/CVERecord?id=CVE-2026-60147
- https://www.cve.org/CVERecord?id=CVE-2026-47059
- https://www.cve.org/CVERecord?id=CVE-2026-47063
- https://www.cve.org/CVERecord?id=CVE-2026-60589
- https://www.cve.org/CVERecord?id=CVE-2026-61308
- https://www.cve.org/CVERecord?id=CVE-2026-70907
- java-21-openjdk-21.0.12.1.1-1.mga10
- java-17-openjdk-17.0.20.1.1-1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0394 - Updated perl-Imager packages fix a security vulnerability
Publication date: 12 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-19082 Description
Imager versions from 0.45_02 before 1.034 for Perl may expose adjacent heap bytes via strlen() over-read from zero-count ASCII EXIF entries in copy_string_tags References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-19082 Description
Imager versions from 0.45_02 before 1.034 for Perl may expose adjacent heap bytes via strlen() over-read from zero-count ASCII EXIF entries in copy_string_tags References
- https://bugs.mageia.org/show_bug.cgi?id=36133
- https://www.openwall.com/lists/oss-security/2026/08/07/6
- https://github.com/tonycoz/imager/security/advisories/GHSA-hx46-55wp-hv6m
- https://metacpan.org/release/TONYC/Imager-1.034/changes
- https://www.cve.org/CVERecord?id=CVE-2026-19082
- perl-Imager-1.34.0-1.1.mga10
- perl-Imager-1.34.0-1.1.mga9
Categorías: Actualizaciones de Seguridad




