Mageia Security

Feed
Mageia Advisories
Updated: hace 3 horas 3 minutos

MGASA-2026-0271 - Updated clamav packages fix security vulnerabilities

19 Julio, 2026 - 07:29
Publication date: 19 Jul 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-20213 , CVE-2026-20214 , CVE-2026-20215 , CVE-2026-20216 , CVE-2026-20217 , CVE-2026-20243 , CVE-2026-20244 Description The updated packages fix security vulnerabilities: PE File Format Processing Out-of-Bounds Memory Corruption Vulnerability. (CVE-2026-20213) FSG File Format Processing Out-of-Bounds Memory Corruption Vulnerability. (CVE-2026-20214) 7Zip File Format Processing Out-of-Bounds Memory Corruption Vulnerability. (CVE-2026-20215) InstallShield File Format Processing Resource Exhaustion Vulnerability. (CVE-2026-20216) PESpin File Format Processing Out-of-Bounds Memory Corruption Vulnerability. (CVE-2026-20217) ALZ Archive Processing Denial of Service Vulnerability. (CVE-2026-20243) DMG File Processing Denial of Service Vulnerability. (CVE-2026-20244) References SRPMS 10/core
  • clamav-1.4.5-1.mga10

MGASA-2026-0270 - Updated erlang packages fix a security vulnerability

19 Julio, 2026 - 07:29
Publication date: 19 Jul 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-48855 Description The updated packages fix a security vulnerability: SFTP READLINK response leaks absolute backend filesystem path when root is configured. (CVE-2026-48855) References SRPMS 10/core
  • erlang-27.3.4.13-1.mga10

MGASA-2026-0269 - Updated perl-Mojolicious package fixes a security vulnerability

19 Julio, 2026 - 07:29
Publication date: 19 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-14803 Description The updated package fixes a security vulnerability: Mojo::JSON versions before 9.47 for Perl allow memory exhaustion via unbounded recursion in the pure-Perl decoder. (CVE-2026-14803) References SRPMS 10/core
  • perl-Mojolicious-9.420.0-1.1.mga10
9/core
  • perl-Mojolicious-9.310.0-1.1.mga9

MGASA-2026-0268 - Updated nmap packages fix a security vulnerability

19 Julio, 2026 - 07:29
Publication date: 19 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-58058 Description The updated packages fix a security vulnerability: Integer Underflow in IPv6 Extension Header Parsing. (CVE-2026-58058) References SRPMS 10/core
  • nmap-7.98-1.1.mga10
9/core
  • nmap-7.95-1.1.mga9

MGASA-2026-0267 - Updated perl-CSS-Minifier-XS package fixes a security vulnerability

19 Julio, 2026 - 07:29
Publication date: 19 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-13593 Description The updated package fixes a security vulnerability: CSS::Minifier::XS versions before 0.14 for Perl have a memory leak when the entire document is minified away. (CVE-2026-13593) References SRPMS 10/core
  • perl-CSS-Minifier-XS-0.150.0-1.mga10
9/core
  • perl-CSS-Minifier-XS-0.150.0-1.mga9

MGASA-2026-0266 - Updated perl-Bytes-Random-Secure package fixes a security vulnerability

19 Julio, 2026 - 07:29
Publication date: 19 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-11625 Description The updated package fixes a security vulnerability: Bytes::Random::Secure versions through 0.29 for Perl share internal state across forked processes. (CVE-2026-11625) References SRPMS 10/core
  • perl-Bytes-Random-Secure-0.290.0-7.1.mga10
9/core
  • perl-Bytes-Random-Secure-0.290.0-6.1.mga9

MGASA-2026-0265 - Updated rsync package fixes security vulnerabilities

19 Julio, 2026 - 00:55
Publication date: 18 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-29518 , CVE-2026-43617 , CVE-2026-43618 , CVE-2026-43619 , CVE-2026-43620 , CVE-2026-45232 Description The updated package fixes security vulnerabilities: Rsync < 3.4.3 TOCTOU Race Condition Allows Symlink-Based Arbitrary File Write. (CVE-2026-29518) Rsync < 3.4.3 Authorization Bypass via Hostname Resolution. (CVE-2026-43617) Rsync < 3.4.3 Integer Overflow Information Disclosure. (CVE-2026-43618) Rsync < 3.4.3 Symlink Race Condition via Path-Based Syscalls. (CVE-2026-43619) Rsync < 3.4.3 Out-of-Bounds Array Read via recv_files(). (CVE-2026-43620) Rsync < 3.4.3 Off-by-One Stack Write via HTTP Proxy. (CVE-2026-45232) References SRPMS 10/core
  • rsync-3.4.1-4.1.mga10
9/core
  • rsync-3.2.7-1.5.mga9

MGASA-2026-0264 - Updated perl-HTML-Parser packages fix security vulnerability

18 Julio, 2026 - 23:21
Publication date: 18 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-8829 Description HTML::Entities versions before 3.84 for Perl read freed heap memory in _decode_entities. (CVE-2026-8829) References SRPMS 10/core
  • perl-HTML-Parser-3.830.0-3.1.mga10
9/core
  • perl-HTML-Parser-3.810.0-1.1.mga9

MGASA-2026-0263 - Updated perl-Config-IniFiles package fixes a security vulnerability

18 Julio, 2026 - 23:21
Publication date: 18 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-11527 Description The updated package fixes a security vulnerability: Config::IniFiles versions before 3.001000 for Perl allow OS command injection and file overwrite via a 2-arg open() of the -file argument in _make_filehandle. (CVE-2026-11527) References SRPMS 10/core
  • perl-Config-IniFiles-3.0.3-3.1.mga10
9/core
  • perl-Config-IniFiles-3.0.3-2.1.mga9

MGASA-2026-0262 - Updated libidn packages fix security vulnerability

18 Julio, 2026 - 19:27
Publication date: 18 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-57053 Description GNU libidn before 1.44 is prone to out-of-bounds reads of uninitialized memory in the ToUnicode APIs because of mishandling in idna_to_unicode_internal. The affected code is not present in libidn2. (CVE-2026-57053) References SRPMS 10/core
  • libidn-1.43-2.1.mga10
9/core
  • libidn-1.41-2.1.mga9

MGASA-2026-0261 - Updated upower packages fix security vulnerabilities

18 Julio, 2026 - 06:48
Publication date: 18 Jul 2026
Type: security
Affected Mageia releases : 10
Description The updated packages fix some security issues. References SRPMS 10/core
  • upower-1.91.3-1.mga10

MGASA-2026-0260 - Updated python-pydantic-settings packages fix a security vulnerability

18 Julio, 2026 - 06:48
Publication date: 18 Jul 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-58203 Description The updated packages fix a security vulnerability: NestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file read and bypassing secrets_dir_max_size. (CVE-2026-58203) References SRPMS 10/core
  • python-pydantic-settings-2.14.2-1.mga10

MGASA-2026-0191 - Updated libxmp packages fix security vulnerabilities

10 Junio, 2026 - 06:07
Publication date: 10 Jun 2026
Type: security
Affected Mageia releases : 9
CVE: CVE-2023-45676 , CVE-2023-45677 , CVE-2023-45679 , CVE-2023-45680 , CVE-2023-45681 , CVE-2023-45682 , CVE-2025-47256 Description CVE-2023-45679: Attempt to free an uninitialized memory pointer in vorbis_deinit() CVE-2023-45680: Null pointer dereference in vorbis_deinit() CVE-2023-45681: Out of bounds heap buffer write CVE-2023-45676: Multi-byte write heap buffer overflow in start_decoder() CVE-2023-45677: Heap buffer out of bounds write in start_decoder() CVE-2023-45682: Wild address read in vorbis_decode_packet_rest() CVE-2025-47256 stack-based buffer overflow in depack_pha in loaders/prowizard/pha.c via a malformed Pha format tracker module in a .mod file. References SRPMS 9/core
  • libxmp-4.5.0-2.1.mga9

MGASA-2026-0190 - Updated golang-x-net packages fix security vulnerability

10 Junio, 2026 - 06:07
Publication date: 10 Jun 2026
Type: security
Affected Mageia releases : 9
CVE: CVE-2024-45338 Description CVE-2024-45338 An attacker can craft an input to the Parse functions that would be processed non-linearly with respect to its length, resulting in extremely slow parsing. This could cause a denial of service. References SRPMS 9/core
  • golang-x-net-0.7.0-2.1.mga9

MGASA-2026-0189 - Updated libssh packages fix security vulnerabilities

10 Junio, 2026 - 06:07
Publication date: 10 Jun 2026
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-4877 , CVE-2025-4878 , CVE-2025-5318 , CVE-2025-5351 , CVE-2025-5372 , CVE-2025-5449 , CVE-2025-5987 Description CVE-2025-4877 Write beyond bounds in binary to base64 conversion functions CVE-2025-4878 Use of uninitialized variable in privatekey_from_file() CVE-2025-5318 Likely read beyond bounds in sftp server handle management CVE-2025-5351 Double free in functions exporting keys CVE-2025-5372 ssh_kdf() returns a success code on certain failures CVE-2025-5449 Likely read beyond bounds in sftp server message decoding CVE-2025-5987 Invalid return code for chacha20 poly1305 with OpenSSL backend References SRPMS 9/core
  • libssh-0.10.6-1.1.mga9

MGASA-2026-0188 - Updated jq packages fix security vulnerabilities

10 Junio, 2026 - 06:07
Publication date: 10 Jun 2026
Type: security
Affected Mageia releases : 9
CVE: CVE-2024-23337 , CVE-2025-48060 , CVE-2026-32316 , CVE-2026-39979 , CVE-2026-33948 , CVE-2026-33947 , CVE-2026-39956 , CVE-2026-40164 Description An integer overflow arises when assigning value using an index of 2147483647, the signed integer limit. This causes a denial of service. (CVE-2024-23337) It was discovered that jq did not correctly handle certain string concatenations. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-32316) It was discovered that jq did not correctly handle recursion in certain circumstances. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-33947) It was discovered that jq did not correctly handle improperly terminated strings. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-33948) It was discovered that jq did not correctly handle checking certain variable types. An attacker could possibly use this issue to cause a denial of service or leak sensitive information. (CVE-2026-39956) It was discovered that jq did not correctly handle certain string formatting. An attacker could possibly use this issue to leak sensitive information or cause a denial of service. (CVE-2026-39979) It was discovered that jq used a fixed seed for hash table operations. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-40164) A heap-buffer-overflow is present in function `jv_string_vfmt` in the jq_fuzz_execute harness from oss-fuzz. This crash happens on file jv.c, line 1456 `void* p = malloc(sz); (CVE-2025-48060) Top-level jq programs loaded from a file with -f are truncated at the first embedded NUL byte on current upstream HEAD. A crafted filter file such as . followed by x00 and arbitrary suffix compiles and executes as only the prefix before the NUL. This leaves jq with a post-CVE-2026-33948 prefix/full-buffer mismatch on the compilation path even though the JSON parser path has already been fixed. (CVE-2026-41256) The ordinary module loader recurses without cycle detection when two otherwise valid modules include each other (CVE-2026-44777) References SRPMS 9/core
  • jq-1.6-3.1.mga9

MGASA-2026-0184 - Updated wireshark packages fix security vulnerabilities

10 Junio, 2026 - 01:39
Publication date: 10 Jun 2026
Type: security
Affected Mageia releases : 9
CVE: CVE-2024-11596 , CVE-2024-9781 , CVE-2025-11626 , CVE-2025-13499 , CVE-2025-13945 , CVE-2025-13946 , CVE-2025-1492 , CVE-2025-5601 , CVE-2025-9817 , CVE-2026-0960 , CVE-2026-5405 , CVE-2026-5653 , CVE-2026-6529 , CVE-2026-6530 , CVE-2026-6867 , CVE-2026-6868 , CVE-2026-6869 , CVE-2026-6870 , CVE-2026-7376 , CVE-2026-7378 , CVE-2026-7379 Description Multiple vulnerabilities have been discovered in Wireshark, a network protocol analyzer, which could result in denial of service or the execution of arbitrary code. This update fixes the reported issue. References SRPMS 9/core
  • wireshark-4.0.17-1.2.mga9