Mageia Security

Feed
Mageia Advisories
Updated: hace 4 horas 54 minutos

MGAA-2026-0061 - Updated nut packages fix a bug

23 Julio, 2026 - 18:45
Publication date: 23 Jul 2026
Type: bugfix
Affected Mageia releases : 10

nut-scanner failed to start. This update fixes the issue and also updates the nut packages to the latest maintained release. References SRPMS 10/core
  • nut-2.8.5-1.mga10

MGAA-2026-0060 - Updated warpinator packages fix launch failure.

23 Julio, 2026 - 18:45
Publication date: 23 Jul 2026
Type: bugfix
Affected Mageia releases : 10

warpinator uses the grpcio module, but with a stamp of the used module version. The stamp was not in accordance with the version of the provided module in the distro, preventing launch. This update fixes that. References SRPMS 10/core
  • warpinator-2.0.4-1.mga10

MGASA-2026-0287 - Updated tig package fixes a security vulnerability

21 Julio, 2026 - 16:19
Publication date: 21 Jul 2026
Type: security
Affected Mageia releases : 10

The updated package fixes a security vulnerability: editor command injection vulnerability. References SRPMS 10/core
  • tig-2.6.1-1.mga10

MGAA-2026-0059 - Updated mageia-theme, grub2 & grub2-mageia-theme-dejavu packages fix bugs

21 Julio, 2026 - 16:19
Publication date: 21 Jul 2026
Type: bugfix
Affected Mageia releases : 10

The updates packages fix issues in our signature background. The images have been reworked providing a better look. Building with mock is fixed allowing the produced mageia-theme and mageia-theme-extra packages to be installed together. Fix the plymouth theme which still was the Mageia 9 version after upgrades. Behind the scenes some processes are now done at build time, avoiding recurring issues with interlaced images. References SRPMS 10/core
  • mageia-theme-10.11-1.1.mga10
  • grub2-2.12-15.1.mga10
  • grub2-mageia-theme-dejavu-1.0-17.1.mga10

MGAA-2026-0058 - Updated serd, sord, sratom, suil and lilv to the latest versions

21 Julio, 2026 - 04:53
Publication date: 21 Jul 2026
Type: bugfix
Affected Mageia releases : 10

The last versions of serd, sord, sratom, suil and lilv couldn't be submitted because of Cauldron FREEZE. References SRPMS 10/core
  • serd-0.32.8-1.mga10
  • sord-0.16.22-1.mga10
  • sratom-0.6.22-1.mga10
  • lilv-0.26.4-1.mga10
  • suil-0.10.26-3.mga10

MGASA-2026-0286 - Updated perl-CGI-Session package fixes a security vulnerability

20 Julio, 2026 - 20:06
Publication date: 20 Jul 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-56016
The updated package fixes a security vulnerability: CGI::Session::ID::md5 versions before 4.49 for Perl generate predictable session ids from low-entropy sources. (CVE-2026-56016) References SRPMS 10/core
  • perl-CGI-Session-4.490.0-1.mga10

MGASA-2026-0285 - Updated php8.4 and php8.5 packages fix security vulnerabilities

20 Julio, 2026 - 20:06
Publication date: 20 Jul 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-14355
The updated php8.4 and php8.5 packages fix several security issues, e.g. Memory corruption (zend_mm_heap corrupted) in openssl_encrypt with AES-WRAP-PAD. (CVE-2026-14355) References SRPMS 10/core
  • php8.4-8.4.23-1.mga10
  • php8.5-8.5.8-1.mga10

MGASA-2026-0284 - Updated perl-Imager package fixes security vulnerabilities

20 Julio, 2026 - 20:06
Publication date: 20 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2024-53901 , CVE-2026-13705 , CVE-2026-13708 , CVE-2026-14454
The updated package fixes security vulnerabilities: The Imager package before 1.025 for Perl has a heap-based buffer overflow leading to denial of service, or possibly unspecified other impact, when the trim() method is called on a crafted input image. (CVE-2024-53901) Imager versions before 1.032 for Perl have a heap out-of-bounds read in the bundled Imager::File::SGI reader via a 16-bit RLE literal run in read_rgb_16_rle. (CVE-2026-13705) Imager::File::JPEG versions before 1.003 for Perl leak heap memory when reading a JPEG with repeated APP13 markers in i_readjpeg_wiol. (CVE-2026-13708) Imager versions before 1.033 for Perl treat unsigned EXIF IFD entry counts as signed. (CVE-2026-14454) References SRPMS 10/core
  • perl-Imager-1.33.0-1.mga10
9/core
  • perl-Imager-1.19.0-2.2.mga9

MGASA-2026-0283 - Updated perl-JavaScript-Minifier-XS package fixes security vulnerabilities

20 Julio, 2026 - 20:06
Publication date: 20 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-56017 , CVE-2026-56018
The updated package fixes security vulnerabilities: JavaScript::Minifier::XS versions before 0.16 for Perl crash with a NULL pointer dereference when the first meaningful token of the input is a slash. (CVE-2026-56017) JavaScript::Minifier::XS versions before 0.16 for Perl leak memory on every call to minify(), allowing unbounded memory growth. (CVE-2026-56018) References SRPMS 10/core
  • perl-JavaScript-Minifier-XS-0.160.0-1.mga10
9/core
  • perl-JavaScript-Minifier-XS-0.160.0-1.mga9

MGASA-2026-0282 - Updated graphicsmagick packages fix a security vulnerability

20 Julio, 2026 - 20:06
Publication date: 20 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-46523
The updated packages fix a security vulnerability: Use-After-Free in MSL decoder. (CVE-2026-46523) References SRPMS 10/core
  • graphicsmagick-1.3.46-5.1.mga10
10/tainted
  • graphicsmagick-1.3.46-5.1.mga10.tainted
9/core
  • graphicsmagick-1.3.40-1.7.mga9
9/tainted
  • graphicsmagick-1.3.40-1.7.mga9.tainted

MGASA-2026-0281 - Updated python-nltk packages fix security vulnerability

20 Julio, 2026 - 20:06
Publication date: 20 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-54293
URL-Encoded Path Traversal in nltk.data.load() Allows Arbitrary Local File Read. (CVE-2026-54293) References SRPMS 10/core
  • python-nltk-3.9.4-1.1.mga10
9/core
  • python-nltk-3.9.4-1.1.mga9

MGASA-2026-0280 - Updated nilfs-utils packages fix security vulnerability

20 Julio, 2026 - 20:06
Publication date: 20 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-55392
Undefined Behavior and Out-of-Memory via Unvalidated s_log_block_size. (CVE-2026-55392) References SRPMS 10/core
  • nilfs-utils-2.2.11-3.1.mga10
9/core
  • nilfs-utils-2.2.9-1.1.mga9

MGASA-2026-0278 - Updated sqlite3 packages fix security vulnerabilities

20 Julio, 2026 - 20:06
Publication date: 20 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-11822 , CVE-2026-11824
The updated packages fix security vulnerabilities: SQLite before 3.53.2 Memory Corruption in FTS5 Extension. (CVE-2026-11822) SQLite before 3.53.2 Heap Buffer Overflow via FTS5 fts5ChunkIterate. (CVE-2026-11824) References SRPMS 10/core
  • sqlite3-3.51.3-1.1.mga10
9/core
  • sqlite3-3.40.1-1.9.mga9

MGASA-2026-0277 - Updated xmlstarlet package fixes a security vulnerability

20 Julio, 2026 - 20:06
Publication date: 20 Jul 2026
Type: security
Affected Mageia releases : 10 , 9

The updated package fixes a security vulnerability: XML external entity vulnerability. References: https://lists.fedoraproject.org/archives/list/package-announce@lists.fed oraproject.org/message/KDR5XRMVBCDZ4HWDCGLKDVKGSCWACG33/ References SRPMS 10/core
  • xmlstarlet-1.6.1-12.1.mga10
9/core
  • xmlstarlet-1.6.1-9.1.mga9

MGASA-2026-0276 - Updated golang packages fix security vulnerabilities

20 Julio, 2026 - 20:06
Publication date: 20 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-42504 , CVE-2026-42507 , CVE-2026-27145 , CVE-2026-39822 , CVE-2026-42505
The updated packages fix security vulnerabilities: mime: quadratic complexity in WordDecoder.DecodeHeader. (CVE-2026-42504) net/textproto: arbitrary input are included in errors without any escaping. (CVE-2026-42507) crypto/x509: split candidate hostname only once. (CVE-2026-27145) os: Root escape via symlink plus trailing slash. (CVE-2026-39822) crypto/tls: Encrypted Client Hello privacy leak. (CVE-2026-42505) References SRPMS 10/core
  • golang-1.25.12-1.mga10
9/core
  • golang-1.25.12-1.mga9

MGASA-2026-0275 - Updated haveged package fixes a security vulnerability

20 Julio, 2026 - 20:06
Publication date: 20 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-41054
The updated package fixes a security vulnerability: Privilege escalation via command socket. (CVE-2026-41054) References SRPMS 10/core
  • haveged-1.9.21-2.mga10
9/core
  • haveged-1.9.21-2.mga9

MGASA-2026-0274 - Updated php packages fix a security vulnerability

20 Julio, 2026 - 20:06
Publication date: 20 Jul 2026
Type: security
Affected Mageia releases : 9
CVE: CVE-2026-14355
The updated php packages fix a security issue: Memory corruption (zend_mm_heap corrupted) in openssl_encrypt with AES-WRAP-PAD. (CVE-2026-14355) References SRPMS 9/core
  • php-8.2.32-1.mga9

MGASA-2026-0273 - Updated libssh2 packages fix security vulnerabilities

20 Julio, 2026 - 20:06
Publication date: 20 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2025-15661 , CVE-2026-7598 , CVE-2026-55199 , CVE-2026-55200 , CVE-2026-58050 , CVE-2026-58051
The updated packages fix security vulnerabilities: Heap Buffer Over-read via sftp_symlink() in sftp.c. (CVE-2025-15661) libssh2 userauth.c userauth_password integer overflow. (CVE-2026-7598) Pre-Authentication DoS via SSH_MSG_EXT_INFO Handler. (CVE-2026-55199) Out-of-Bounds Write via Unchecked packet_length in transport.c. (CVE-2026-55200) Integer Overflow in publickey Subsystem Attribute Allocation. (CVE-2026-58050) Free of Uninitialized Pointer in publickey List Cleanup. (CVE-2026-58051) References SRPMS 10/core
  • libssh2-1.11.1-2.1.mga10
9/core
  • libssh2-1.11.0-1.1.mga9

MGASA-2026-0272 - Updated perl-String-Util package fixes a security vulnerability

19 Julio, 2026 - 07:29
Publication date: 19 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-14895
The updated package fixes a security vulnerability: String::Util versions before 1.36 for Perl are susceptible to a regular expression denial of service. (CVE-2026-14895) References SRPMS 10/core
  • perl-String-Util-1.350.0-2.1.mga10
9/core
  • perl-String-Util-1.340.0-1.1.mga9