Mageia Security

Feed
Mageia Advisories
Updated: hace 8 horas 10 minutos

MGASA-2026-0315 - Updated libvncserver packages fix security vulnerabilities

3 Agosto, 2026 - 19:47
Publication date: 03 Aug 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-32853 , CVE-2026-32854 , CVE-2026-44988 , CVE-2026-50538
The updated packages fix security vulnerabilities: Heap Out-of-Bounds Read in HandleUltraZipBPP due to unchecked subrectangle count. (CVE-2026-32853) NULL pointer dereferences in httpd proxy handlers via malformed CONNECT/GET requests. (CVE-2026-32854) LibVNCClient Tight Gradient decoding allows malicious server-triggered heap/stack OOB writes. (CVE-2026-44988) Attacker-controlled heap out-of-bounds write in libvncclient Tight decoder. (CVE-2026-50538) References SRPMS 10/core
  • libvncserver-0.9.15-2.1.mga10
9/core
  • libvncserver-0.9.14-1.1.mga9

MGASA-2026-0314 - Updated librabbitmq packages fix security vulnerabilities

3 Agosto, 2026 - 19:47
Publication date: 03 Aug 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2023-35789 , CVE-2026-44235 , CVE-2026-44236
The updated packages fix security vulnerabilities: An issue was discovered in the C AMQP client library (aka rabbitmq-c) through 0.13.0 for RabbitMQ. Credentials can only be entered on the command line (e.g., for amqp-publish or amqp-consume) and are thus visible to local attackers by listing a process and its arguments. (CVE-2023-35789) size_t underflow in AMQP frame length computation leads to out-of-bounds read in rabbitmq-c. (CVE-2026-44235) Heap buffer overflow in AMQP login handshake via undersized connection.tune.frame_max. (CVE-2026-44236) References SRPMS 10/core
  • librabbitmq-0.15.0-2.1.mga10
9/core
  • librabbitmq-0.11.0-1.1.mga9

MGASA-2026-0313 - Updated corosync and libqb packages fix security vulnerabilities

3 Agosto, 2026 - 19:47
Publication date: 03 Aug 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-35091 , CVE-2026-35092
The updated packages fix security vulnerabilities: Denial of service and information disclosure via crafted udp packet. (CVE-2026-35091) Denial of service via integer overflow in join message validation. (CVE-2026-35092) Additionally, libqb solves a missing runtime dependency on qb-blackbox. References SRPMS 10/core
  • corosync-3.1.10-2.1.mga10
  • libqb-2.0.9-1.1.mga10
9/core
  • corosync-3.1.7-1.3.mga9
  • libqb-2.0.8-1.1.mga9

MGASA-2026-0312 - Updated kernel, kmod, bluez, firmware, wireless-regdb and drakx-installer-images packages fix security vulnerabilities

1 Agosto, 2026 - 16:58
Publication date: 01 Aug 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-52908 , CVE-2026-52909 , CVE-2026-52910 , CVE-2026-52917 , CVE-2026-52924 , CVE-2026-52929 , CVE-2026-52930 , CVE-2026-52935 , CVE-2026-52939 , CVE-2026-52940 , CVE-2026-52942 , CVE-2026-52946 , CVE-2026-52947 , CVE-2026-52948 , CVE-2026-53131 , CVE-2026-53132 , CVE-2026-53133 , CVE-2026-53134 , CVE-2026-53135 , CVE-2026-53136 , CVE-2026-53137 , CVE-2026-53138 , CVE-2026-53139 , CVE-2026-53140 , CVE-2026-53141 , CVE-2026-53142 , CVE-2026-53143 , CVE-2026-53144 , CVE-2026-53145 , CVE-2026-53146 , CVE-2026-53147 , CVE-2026-53148 , CVE-2026-53149 , CVE-2026-53150 , CVE-2026-53151 , CVE-2026-53152 , CVE-2026-53153 , CVE-2026-53154 , CVE-2026-53156 , CVE-2026-53157 , CVE-2026-53158 , CVE-2026-53159 , CVE-2026-53160 , CVE-2026-53161 , CVE-2026-53162 , CVE-2026-53163 , CVE-2026-53164 , CVE-2026-53166 , CVE-2026-53167 , CVE-2026-53168 , CVE-2026-53175 , CVE-2026-53176 , CVE-2026-53177 , CVE-2026-53179 , CVE-2026-53180 , CVE-2026-53181 , CVE-2026-53182 , CVE-2026-53183 , CVE-2026-53184 , CVE-2026-53185 , CVE-2026-53186 , CVE-2026-53187 , CVE-2026-53188 , CVE-2026-53189 , CVE-2026-53190 , CVE-2026-53191 , CVE-2026-53192 , CVE-2026-53193 , CVE-2026-53194 , CVE-2026-53195 , CVE-2026-53196 , CVE-2026-53197 , CVE-2026-53198 , CVE-2026-53199 , CVE-2026-53202 , CVE-2026-53203 , CVE-2026-53205 , CVE-2026-53207 , CVE-2026-53208 , CVE-2026-53209 , CVE-2026-53210 , CVE-2026-53211 , CVE-2026-53212 , CVE-2026-53213 , CVE-2026-53214 , CVE-2026-53215 , CVE-2026-53216 , CVE-2026-53217 , CVE-2026-53218 , CVE-2026-53219 , CVE-2026-53220 , CVE-2026-53221 , CVE-2026-53223 , CVE-2026-53224 , CVE-2026-53225 , CVE-2026-53226 , CVE-2026-53227 , CVE-2026-53228 , CVE-2026-53229 , CVE-2026-53230 , CVE-2026-53233 , CVE-2026-53234 , CVE-2026-53235 , CVE-2026-53236 , CVE-2026-53237 , CVE-2026-53238 , CVE-2026-53239 , CVE-2026-53240 , CVE-2026-53241 , CVE-2026-53242 , CVE-2026-53245 , CVE-2026-53246 , CVE-2026-53247 , CVE-2026-53248 , CVE-2026-53249 , CVE-2026-53250 , CVE-2026-53251 , CVE-2026-53252 , CVE-2026-53253 , CVE-2026-53254 , CVE-2026-53255 , CVE-2026-53256 , CVE-2026-53258 , CVE-2026-53259 , CVE-2026-53261 , CVE-2026-53262 , CVE-2026-53263 , CVE-2026-53264 , CVE-2026-53265 , CVE-2026-53266 , CVE-2026-53267 , CVE-2026-53268 , CVE-2026-53269 , CVE-2026-53270 , CVE-2026-53271 , CVE-2026-53272 , CVE-2026-53273 , CVE-2026-53274 , CVE-2026-53275 , CVE-2026-53277 , CVE-2026-53325 , CVE-2026-53327 , CVE-2026-53328 , CVE-2026-53329 , CVE-2026-53330 , CVE-2026-53331 , CVE-2026-53332 , CVE-2026-53333 , CVE-2026-53334 , CVE-2026-53335 , CVE-2026-53336 , CVE-2026-53337 , CVE-2026-53338 , CVE-2026-53339 , CVE-2026-53340 , CVE-2026-53341 , CVE-2026-53342 , CVE-2026-53343 , CVE-2026-53345 , CVE-2026-53346 , CVE-2026-53347 , CVE-2026-53349 , CVE-2026-53350 , CVE-2026-53352 , CVE-2026-53353 , CVE-2026-53354 , CVE-2026-53355 , CVE-2026-53356 , CVE-2026-53359 , CVE-2026-53361 , CVE-2026-53362 , CVE-2026-53363 , CVE-2026-53366 , CVE-2026-53381 , CVE-2026-53382 , CVE-2026-53383 , CVE-2026-53384 , CVE-2026-53385 , CVE-2026-53386 , CVE-2026-53387 , CVE-2026-53388 , CVE-2026-53389 , CVE-2026-53390 , CVE-2026-53391 , CVE-2026-53392 , CVE-2026-53393 , CVE-2026-53394 , CVE-2026-53397 , CVE-2026-53398 , CVE-2026-53399 , CVE-2026-53400 , CVE-2026-53402 , CVE-2026-53403 , CVE-2026-63794 , CVE-2026-63795 , CVE-2026-63796 , CVE-2026-63797 , CVE-2026-63798 , CVE-2026-63800 , CVE-2026-63801 , CVE-2026-63802 , CVE-2026-63803 , CVE-2026-63804 , CVE-2026-63805 , CVE-2026-63806 , CVE-2026-63807 , CVE-2026-63808 , CVE-2026-63809 , CVE-2026-63810 , CVE-2026-63812 , CVE-2026-63814 , CVE-2026-63815 , CVE-2026-63816 , CVE-2026-63817 , CVE-2026-63818 , CVE-2026-63819 , CVE-2026-63821 , CVE-2026-63822 , CVE-2026-63823 , CVE-2026-63824 , CVE-2026-63825 , CVE-2026-63826 , CVE-2026-63827 , CVE-2026-63828 , CVE-2026-63829 , CVE-2026-63830 , CVE-2026-63831 , CVE-2026-63832 , CVE-2026-63833 , CVE-2026-63834 , CVE-2026-63835 , CVE-2026-63836 , CVE-2026-63867 , CVE-2026-63868 , CVE-2026-63869 , CVE-2026-63870 , CVE-2026-63871 , CVE-2026-63873 , CVE-2026-63874 , CVE-2026-64187 , CVE-2026-64188 , CVE-2026-64189 , CVE-2026-64191 , CVE-2026-64205 , CVE-2026-64206 , CVE-2026-64207
Upstream kernel version 6.18.39 fixes bugs and vulnerabilities. The kmod, bluez, wireless-regdb, firmware and drakx-installer-images packages have been updated to work with this new kernel. References SRPMS 10/core
  • kernel-6.18.39-1.mga10
  • kmod-virtualbox-7.2.8-28.mga10
  • kmod-xtables-addons-3.30-3.mga10
  • bluez-5.87-1.mga10
  • wireless-regdb-20260530-1.mga10
  • kernel-firmware-20260622-1.mga10
  • drakx-installer-images-2.94-54.mga10
10/nonfree
  • kernel-firmware-nonfree-20260622-1.mga10.nonfree
  • radeon-firmware-20260622-1.mga10.nonfree
  • drakx-installer-images-2.94-54.mga10.nonfree
  • kmod-nvidia-current-wopengpu-580.159.04-37.mga10.nonfree

MGASA-2026-0311 - Updated libxfont2 packages fix security vulnerabilities

30 Julio, 2026 - 18:03
Publication date: 30 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-56001 , CVE-2026-56002 , CVE-2026-56003
The updated packages fix security vulnerabilities: BitmapScaleBitmaps Integer Overflow Heap Buffer Overflow. (CVE-2026-56001) PCF Font Parsing Heap Buffer Overflow. (CVE-2026-56002) computeProps Property Buffer Heap Buffer Overflow. (CVE-2026-56003) References SRPMS 10/core
  • libxfont2-2.0.8-1.mga10
9/core
  • libxfont2-2.0.6-2.1.mga9

MGASA-2026-0310 - Updated 389-ds-base packages fix a security vulnerability

30 Julio, 2026 - 18:03
Publication date: 30 Jul 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-9064
The updated packages fix a security vulnerability: Unbounded ldap controls count in get_ldapmessage_controls_ext() causes cpu and heap amplification (remote dos). (CVE-2026-9064) References SRPMS 10/core
  • 389-ds-base-3.1.3-2.1.mga10

MGASA-2026-0309 - Updated nghttp2 packages fix a security vulnerability

30 Julio, 2026 - 18:03
Publication date: 30 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-58055
The updated packages fix a security vulnerability: HTTP Request/Response Smuggling via Upgrade Request with Content-Length. (CVE-2026-58055) References SRPMS 10/core
  • nghttp2-1.68.1-2.1.mga10
9/core
  • nghttp2-1.61.0-1.2.mga9

MGASA-2026-0307 - Updated gstreamer1.0-libav packages fix security vulnerability

28 Julio, 2026 - 18:06
Publication date: 28 Jul 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-52717
Heap corruption in gst-libav AV protocol pipe. (CVE-2026-52717) References SRPMS 10/core
  • gstreamer1.0-libav-1.26.11-1.1.mga10

MGASA-2026-0306 - Updated libslirp packages fix a security vulnerability

28 Julio, 2026 - 18:06
Publication date: 28 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-9539
The updated packages fix a security vulnerability: TCP URG OOB Read Information Leak. (CVE-2026-9539) References SRPMS 10/core
  • libslirp-4.8.0-2.1.mga10
9/core
  • libslirp-4.6.1-1.1.mga9

MGASA-2026-0305 - Updated sqlite3 packages fix security vulnerabilities

28 Julio, 2026 - 08:15
Publication date: 28 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-50812 , CVE-2026-50813
CVE-2026-50812: A NULL pointer dereference in the SQLite Session Extension in SQLite 3.53.1 and SQLite trunk builds before check-in e807d4e3798efd53 allows an attacker who can supply a malformed changeset blob to cause a denial of service. The issue occurs when sqlite3changeset_apply_v3() applies a corrupt changeset and reaches sqlite3_value_type() with a NULL sqlite3_value pointer. CVE-2026-50813: An issue in SQLite before Fossil check-in 869a51ae84df allows a local attacker to obtain sensitive information via the Session Extension changeset concat/changegroup merge path. References SRPMS 10/core
  • sqlite3-3.51.3-1.2.mga10
9/core
  • sqlite3-3.40.1-1.10.mga9

MGASA-2026-0304 - Updated memcached packages fix security and other issues

28 Julio, 2026 - 08:15
Publication date: 28 Jul 2026
Type: security
Affected Mageia releases : 10 , 9

The updated packages fix bugs including security ones. References SRPMS 10/core
  • memcached-1.6.45-1.mga10
9/core
  • memcached-1.6.45-1.mga9

MGAA-2026-0073 - Updated gscan2pdf packages fix bug

28 Julio, 2026 - 08:15
Publication date: 28 Jul 2026
Type: bugfix
Affected Mageia releases : 10

perl-Gtk2-Ex-PodViewer depends on perl-Gtk2-Ex-Simple-List, but upstream gscan2pdf now explicitly depends on Gtk3::SimpleList, so this dependency seems to be indeed obsolete. Yjis update removes the dependency on perl-Gtk2-Ex-PodViewer. References SRPMS 10/core
  • gscan2pdf-2.13.5-2.1.mga10

MGASA-2026-0303 - Updated x11-server x11-server-xwayland tigervnc packages fix security vulnerabilities

27 Julio, 2026 - 23:45
Publication date: 27 Jul 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-55999 , CVE-2026-56000
The updated packages fix security vulnerabilities: glamor Font Atlas Heap Buffer Overflow. (CVE-2026-55999) GLX contextTags Use-After-Free in CommonMakeCurrent(). (CVE-2026-56000) References SRPMS 10/core
  • x11-server-21.1.24-1.mga10
  • x11-server-xwayland-24.1.13-1.mga10
  • tigervnc-1.15.0-7.1.mga10

MGASA-2026-0302 - Updated libyang packages fix a security vulnerability

27 Julio, 2026 - 23:45
Publication date: 27 Jul 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-41401
The updated packages fix a security vulnerability: Heap Use-After-Free Write in XML Metadata Parsing. (CVE-2026-41401) References SRPMS 10/core
  • libyang-3.13.5-1.1.mga10

MGASA-2026-0301 - Updated nginx packages fix security vulnerabilities

27 Julio, 2026 - 23:45
Publication date: 27 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-42533 , CVE-2026-56434 , CVE-2026-60005
CVE-2026-42533: Heap buffer overflow might occur in a worker process when using the map directive with regex matching if the map variable was included in a string expression after a capture affected by this map; a similar issue might happen when using a non-cacheable variable in a string expression. Thanks to Mufeed VH of Winfunc Research and Maxim Dounin. . CVE-2026-60005: Uninitialized memory access might occur when using unnamed regex captures with the "slice" directive or background cache update, which could result in worker process memory disclosure or worker process termination. . CVE-2026-56434: Use-after-free might occur when processing a specially crafted proxied backend response with the ngx_http_ssi_filter_module. Thanks to P4P3R-HAK. References SRPMS 10/core
  • nginx-1.30.4-1.mga10
9/core
  • nginx-1.30.4-1.mga9

MGAA-2026-0072 - Updated tdlib & purple-telegram-tdlib packages fix bugs

27 Julio, 2026 - 23:45
Publication date: 27 Jul 2026
Type: bugfix
Affected Mageia releases : 10 , 9

purple-telegram-tdlib has been migrated to a new active fork and updated to version 1.1.1. purple-telegram-tdlib updated packages fix an issue where administrators of telegram's groups can't open a chat in the group tdlib has been updated to version 1.8.65, required to build the new version of purple-telegram-tdlib References SRPMS 10/core
  • tdlib-1.8.65-1.git20260613.mga10
  • purple-telegram-tdlib-1.1.1-1.mga10
9/core
  • tdlib-1.8.65-1.git20260613.mga9
  • purple-telegram-tdlib-1.1.1-1.mga9

MGAA-2026-0071 - Updated amarok packages fix a bug

27 Julio, 2026 - 23:45
Publication date: 27 Jul 2026
Type: bugfix
Affected Mageia releases : 10

After right clicking on a music file in Dolphin and selecting to open it with Amarok, Amarok failed to load the file. This update fixes the issue. References SRPMS 10/core
  • amarok-3.3.3-1.mga10

MGAA-2026-0070 - Updated neochat package fixes missing dependency

27 Julio, 2026 - 23:45
Publication date: 27 Jul 2026
Type: bugfix
Affected Mageia releases : 10

If purpose wasn't installed, neochat would not start. This update adds the missing dependency on the purpose package. References SRPMS 10/core
  • neochat-25.12.1-1.1.mga10

MGAA-2026-0069 - Updated ocrfeeder package makes it start again

27 Julio, 2026 - 23:45
Publication date: 27 Jul 2026
Type: bugfix
Affected Mageia releases : 10

The OCRFeeder package wouldn't start since python3.13. This update fixes the issue. References SRPMS 10/core
  • ocrfeeder-0.8.5-4.1.mga10