Mageia Security
MGASA-2026-0271 - Updated clamav packages fix security vulnerabilities
Publication date: 19 Jul 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-20213 , CVE-2026-20214 , CVE-2026-20215 , CVE-2026-20216 , CVE-2026-20217 , CVE-2026-20243 , CVE-2026-20244 Description The updated packages fix security vulnerabilities: PE File Format Processing Out-of-Bounds Memory Corruption Vulnerability. (CVE-2026-20213) FSG File Format Processing Out-of-Bounds Memory Corruption Vulnerability. (CVE-2026-20214) 7Zip File Format Processing Out-of-Bounds Memory Corruption Vulnerability. (CVE-2026-20215) InstallShield File Format Processing Resource Exhaustion Vulnerability. (CVE-2026-20216) PESpin File Format Processing Out-of-Bounds Memory Corruption Vulnerability. (CVE-2026-20217) ALZ Archive Processing Denial of Service Vulnerability. (CVE-2026-20243) DMG File Processing Denial of Service Vulnerability. (CVE-2026-20244) References
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-20213 , CVE-2026-20214 , CVE-2026-20215 , CVE-2026-20216 , CVE-2026-20217 , CVE-2026-20243 , CVE-2026-20244 Description The updated packages fix security vulnerabilities: PE File Format Processing Out-of-Bounds Memory Corruption Vulnerability. (CVE-2026-20213) FSG File Format Processing Out-of-Bounds Memory Corruption Vulnerability. (CVE-2026-20214) 7Zip File Format Processing Out-of-Bounds Memory Corruption Vulnerability. (CVE-2026-20215) InstallShield File Format Processing Resource Exhaustion Vulnerability. (CVE-2026-20216) PESpin File Format Processing Out-of-Bounds Memory Corruption Vulnerability. (CVE-2026-20217) ALZ Archive Processing Denial of Service Vulnerability. (CVE-2026-20243) DMG File Processing Denial of Service Vulnerability. (CVE-2026-20244) References
- https://bugs.mageia.org/show_bug.cgi?id=35841
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/N4HZVOZRQX4MIQVALYKDCGBZUHHVH4QN/
- https://github.com/Cisco-Talos/clamav/releases/tag/clamav-1.4.5
- https://www.cve.org/CVERecord?id=CVE-2026-20213
- https://www.cve.org/CVERecord?id=CVE-2026-20214
- https://www.cve.org/CVERecord?id=CVE-2026-20215
- https://www.cve.org/CVERecord?id=CVE-2026-20216
- https://www.cve.org/CVERecord?id=CVE-2026-20217
- https://www.cve.org/CVERecord?id=CVE-2026-20243
- https://www.cve.org/CVERecord?id=CVE-2026-20244
- clamav-1.4.5-1.mga10
Categorías: Actualizaciones de Seguridad
MGASA-2026-0270 - Updated erlang packages fix a security vulnerability
Publication date: 19 Jul 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-48855 Description The updated packages fix a security vulnerability: SFTP READLINK response leaks absolute backend filesystem path when root is configured. (CVE-2026-48855) References
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-48855 Description The updated packages fix a security vulnerability: SFTP READLINK response leaks absolute backend filesystem path when root is configured. (CVE-2026-48855) References
- https://bugs.mageia.org/show_bug.cgi?id=35839
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/O2CL6CSAYWT3KK6GLRNIWD7YDNMWHJ4N/
- https://github.com/erlang/otp/security/advisories/GHSA-pv7g-pjrq-x2fh
- https://cna.erlef.org/cves/CVE-2026-48855.html
- https://osv.dev/vulnerability/EEF-CVE-2026-48855
- https://www.cve.org/CVERecord?id=CVE-2026-48855
- erlang-27.3.4.13-1.mga10
Categorías: Actualizaciones de Seguridad
MGASA-2026-0269 - Updated perl-Mojolicious package fixes a security vulnerability
Publication date: 19 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-14803 Description The updated package fixes a security vulnerability: Mojo::JSON versions before 9.47 for Perl allow memory exhaustion via unbounded recursion in the pure-Perl decoder. (CVE-2026-14803) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-14803 Description The updated package fixes a security vulnerability: Mojo::JSON versions before 9.47 for Perl allow memory exhaustion via unbounded recursion in the pure-Perl decoder. (CVE-2026-14803) References
- https://bugs.mageia.org/show_bug.cgi?id=35835
- https://www.openwall.com/lists/oss-security/2026/07/06/2
- https://metacpan.org/release/SRI/Mojolicious-9.47/changes
- https://www.cve.org/CVERecord?id=CVE-2026-14803
- perl-Mojolicious-9.420.0-1.1.mga10
- perl-Mojolicious-9.310.0-1.1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0268 - Updated nmap packages fix a security vulnerability
Publication date: 19 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-58058 Description The updated packages fix a security vulnerability: Integer Underflow in IPv6 Extension Header Parsing. (CVE-2026-58058) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-58058 Description The updated packages fix a security vulnerability: Integer Underflow in IPv6 Extension Header Parsing. (CVE-2026-58058) References
- https://bugs.mageia.org/show_bug.cgi?id=35812
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MIIROUN7QWWO22LUS5B4KPZ4DNYFQYJZ/
- https://github.com/bikini/exploitarium/tree/main/nmap-ipv6-extlen-wrap-poc
- https://www.cve.org/CVERecord?id=CVE-2026-58058
- nmap-7.98-1.1.mga10
- nmap-7.95-1.1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0267 - Updated perl-CSS-Minifier-XS package fixes a security vulnerability
Publication date: 19 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-13593 Description The updated package fixes a security vulnerability: CSS::Minifier::XS versions before 0.14 for Perl have a memory leak when the entire document is minified away. (CVE-2026-13593) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-13593 Description The updated package fixes a security vulnerability: CSS::Minifier::XS versions before 0.14 for Perl have a memory leak when the entire document is minified away. (CVE-2026-13593) References
- https://bugs.mageia.org/show_bug.cgi?id=35781
- https://www.openwall.com/lists/oss-security/2026/06/29/18
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/3PEXBYM5REIQMMQ2BZA2J2AXW7M4U673/
- https://www.cve.org/CVERecord?id=CVE-2026-13593
- perl-CSS-Minifier-XS-0.150.0-1.mga10
- perl-CSS-Minifier-XS-0.150.0-1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0266 - Updated perl-Bytes-Random-Secure package fixes a security vulnerability
Publication date: 19 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-11625 Description The updated package fixes a security vulnerability: Bytes::Random::Secure versions through 0.29 for Perl share internal state across forked processes. (CVE-2026-11625) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-11625 Description The updated package fixes a security vulnerability: Bytes::Random::Secure versions through 0.29 for Perl share internal state across forked processes. (CVE-2026-11625) References
- https://bugs.mageia.org/show_bug.cgi?id=35767
- https://www.openwall.com/lists/oss-security/2026/06/26/5
- https://github.com/daoswald/Bytes-Random-Secure/issues/3
- https://www.cve.org/CVERecord?id=CVE-2026-11625
- perl-Bytes-Random-Secure-0.290.0-7.1.mga10
- perl-Bytes-Random-Secure-0.290.0-6.1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0265 - Updated rsync package fixes security vulnerabilities
Publication date: 18 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-29518 , CVE-2026-43617 , CVE-2026-43618 , CVE-2026-43619 , CVE-2026-43620 , CVE-2026-45232 Description The updated package fixes security vulnerabilities: Rsync < 3.4.3 TOCTOU Race Condition Allows Symlink-Based Arbitrary File Write. (CVE-2026-29518) Rsync < 3.4.3 Authorization Bypass via Hostname Resolution. (CVE-2026-43617) Rsync < 3.4.3 Integer Overflow Information Disclosure. (CVE-2026-43618) Rsync < 3.4.3 Symlink Race Condition via Path-Based Syscalls. (CVE-2026-43619) Rsync < 3.4.3 Out-of-Bounds Array Read via recv_files(). (CVE-2026-43620) Rsync < 3.4.3 Off-by-One Stack Write via HTTP Proxy. (CVE-2026-45232) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-29518 , CVE-2026-43617 , CVE-2026-43618 , CVE-2026-43619 , CVE-2026-43620 , CVE-2026-45232 Description The updated package fixes security vulnerabilities: Rsync < 3.4.3 TOCTOU Race Condition Allows Symlink-Based Arbitrary File Write. (CVE-2026-29518) Rsync < 3.4.3 Authorization Bypass via Hostname Resolution. (CVE-2026-43617) Rsync < 3.4.3 Integer Overflow Information Disclosure. (CVE-2026-43618) Rsync < 3.4.3 Symlink Race Condition via Path-Based Syscalls. (CVE-2026-43619) Rsync < 3.4.3 Out-of-Bounds Array Read via recv_files(). (CVE-2026-43620) Rsync < 3.4.3 Off-by-One Stack Write via HTTP Proxy. (CVE-2026-45232) References
- https://bugs.mageia.org/show_bug.cgi?id=35562
- https://www.openwall.com/lists/oss-security/2026/05/20/6
- https://lists.debian.org/debian-security-announce/2026/msg00193.html
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/FBOANNVT2JXHE24DJ2WIYE2BNCWRGT24/
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/4RPOIF6TVE233FKZN5TAC6XTNQ5WVFYL/
- https://www.openwall.com/lists/oss-security/2026/06/08/1
- https://ubuntu.com/security/notices/USN-8349-1
- https://ubuntu.com/security/notices/USN-8349-2
- https://www.cve.org/CVERecord?id=CVE-2026-29518
- https://www.cve.org/CVERecord?id=CVE-2026-43617
- https://www.cve.org/CVERecord?id=CVE-2026-43618
- https://www.cve.org/CVERecord?id=CVE-2026-43619
- https://www.cve.org/CVERecord?id=CVE-2026-43620
- https://www.cve.org/CVERecord?id=CVE-2026-45232
- rsync-3.4.1-4.1.mga10
- rsync-3.2.7-1.5.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0264 - Updated perl-HTML-Parser packages fix security vulnerability
Publication date: 18 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-8829 Description HTML::Entities versions before 3.84 for Perl read freed heap memory in _decode_entities. (CVE-2026-8829) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-8829 Description HTML::Entities versions before 3.84 for Perl read freed heap memory in _decode_entities. (CVE-2026-8829) References
- https://bugs.mageia.org/show_bug.cgi?id=35632
- https://www.openwall.com/lists/oss-security/2026/06/04/2
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/CNUNI2FWJG22SMHLLF6L6BGYNBH6YI52/
- https://www.cve.org/CVERecord?id=CVE-2026-8829
- perl-HTML-Parser-3.830.0-3.1.mga10
- perl-HTML-Parser-3.810.0-1.1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0263 - Updated perl-Config-IniFiles package fixes a security vulnerability
Publication date: 18 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-11527 Description The updated package fixes a security vulnerability: Config::IniFiles versions before 3.001000 for Perl allow OS command injection and file overwrite via a 2-arg open() of the -file argument in _make_filehandle. (CVE-2026-11527) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-11527 Description The updated package fixes a security vulnerability: Config::IniFiles versions before 3.001000 for Perl allow OS command injection and file overwrite via a 2-arg open() of the -file argument in _make_filehandle. (CVE-2026-11527) References
- https://bugs.mageia.org/show_bug.cgi?id=35701
- https://www.openwall.com/lists/oss-security/2026/06/14/5
- https://metacpan.org/release/SHLOMIF/Config-IniFiles-3.001000/changes
- https://ubuntu.com/security/notices/USN-8445-1
- https://lists.debian.org/debian-security-announce/2026/msg00265.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KNV5NUG6UF4JCFTI7P253PPUETZTA4HE/
- https://www.cve.org/CVERecord?id=CVE-2026-11527
- perl-Config-IniFiles-3.0.3-3.1.mga10
- perl-Config-IniFiles-3.0.3-2.1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0262 - Updated libidn packages fix security vulnerability
Publication date: 18 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-57053 Description GNU libidn before 1.44 is prone to out-of-bounds reads of uninitialized memory in the ToUnicode APIs because of mishandling in idna_to_unicode_internal. The affected code is not present in libidn2. (CVE-2026-57053) References
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-57053 Description GNU libidn before 1.44 is prone to out-of-bounds reads of uninitialized memory in the ToUnicode APIs because of mishandling in idna_to_unicode_internal. The affected code is not present in libidn2. (CVE-2026-57053) References
- https://bugs.mageia.org/show_bug.cgi?id=35726
- http://www.slackware.com/security/viewer.php?l=slackware-security&y=2026&m=slackware-security.355846
- https://lists.gnu.org/archive/html/help-libidn/2026-05/msg00000.html
- https://lists.gnu.org/archive/html/help-libidn/2025-06/msg00000.html
- https://ubuntu.com/security/notices/USN-8521-1
- https://www.cve.org/CVERecord?id=CVE-2026-57053
- libidn-1.43-2.1.mga10
- libidn-1.41-2.1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0261 - Updated upower packages fix security vulnerabilities
Publication date: 18 Jul 2026
Type: security
Affected Mageia releases : 10
Description The updated packages fix some security issues. References
Type: security
Affected Mageia releases : 10
Description The updated packages fix some security issues. References
- https://bugs.mageia.org/show_bug.cgi?id=35877
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/K6XPX2GC7IY5TLTPTXM7QSD2T4LQ6IMN/
- upower-1.91.3-1.mga10
Categorías: Actualizaciones de Seguridad
MGASA-2026-0260 - Updated python-pydantic-settings packages fix a security vulnerability
Publication date: 18 Jul 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-58203 Description The updated packages fix a security vulnerability: NestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file read and bypassing secrets_dir_max_size. (CVE-2026-58203) References
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-58203 Description The updated packages fix a security vulnerability: NestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file read and bypassing secrets_dir_max_size. (CVE-2026-58203) References
- https://bugs.mageia.org/show_bug.cgi?id=35774
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RIQBQN77WGZ57LE5TTARNBPREPF3JLEX/
- https://github.com/pydantic/pydantic-settings/security/advisories/GHSA-4xgf-cpjx-pc3j
- https://www.cve.org/CVERecord?id=CVE-2026-58203
- python-pydantic-settings-2.14.2-1.mga10
Categorías: Actualizaciones de Seguridad
MGASA-2026-0191 - Updated libxmp packages fix security vulnerabilities
Publication date: 10 Jun 2026
Type: security
Affected Mageia releases : 9
CVE: CVE-2023-45676 , CVE-2023-45677 , CVE-2023-45679 , CVE-2023-45680 , CVE-2023-45681 , CVE-2023-45682 , CVE-2025-47256 Description CVE-2023-45679: Attempt to free an uninitialized memory pointer in vorbis_deinit() CVE-2023-45680: Null pointer dereference in vorbis_deinit() CVE-2023-45681: Out of bounds heap buffer write CVE-2023-45676: Multi-byte write heap buffer overflow in start_decoder() CVE-2023-45677: Heap buffer out of bounds write in start_decoder() CVE-2023-45682: Wild address read in vorbis_decode_packet_rest() CVE-2025-47256 stack-based buffer overflow in depack_pha in loaders/prowizard/pha.c via a malformed Pha format tracker module in a .mod file. References
Type: security
Affected Mageia releases : 9
CVE: CVE-2023-45676 , CVE-2023-45677 , CVE-2023-45679 , CVE-2023-45680 , CVE-2023-45681 , CVE-2023-45682 , CVE-2025-47256 Description CVE-2023-45679: Attempt to free an uninitialized memory pointer in vorbis_deinit() CVE-2023-45680: Null pointer dereference in vorbis_deinit() CVE-2023-45681: Out of bounds heap buffer write CVE-2023-45676: Multi-byte write heap buffer overflow in start_decoder() CVE-2023-45677: Heap buffer out of bounds write in start_decoder() CVE-2023-45682: Wild address read in vorbis_decode_packet_rest() CVE-2025-47256 stack-based buffer overflow in depack_pha in loaders/prowizard/pha.c via a malformed Pha format tracker module in a .mod file. References
- https://bugs.mageia.org/show_bug.cgi?id=33915
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CVZWMTH36ES7RCJEMRANBDTL76QBE75Z/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FKMOFYKVMD2LPU7O33SEH2RGSY2ZE73K/
- https://www.cve.org/CVERecord?id=CVE-2023-45676
- https://www.cve.org/CVERecord?id=CVE-2023-45677
- https://www.cve.org/CVERecord?id=CVE-2023-45679
- https://www.cve.org/CVERecord?id=CVE-2023-45680
- https://www.cve.org/CVERecord?id=CVE-2023-45681
- https://www.cve.org/CVERecord?id=CVE-2023-45682
- https://www.cve.org/CVERecord?id=CVE-2025-47256
- libxmp-4.5.0-2.1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0190 - Updated golang-x-net packages fix security vulnerability
Publication date: 10 Jun 2026
Type: security
Affected Mageia releases : 9
CVE: CVE-2024-45338 Description CVE-2024-45338 An attacker can craft an input to the Parse functions that would be processed non-linearly with respect to its length, resulting in extremely slow parsing. This could cause a denial of service. References
Type: security
Affected Mageia releases : 9
CVE: CVE-2024-45338 Description CVE-2024-45338 An attacker can craft an input to the Parse functions that would be processed non-linearly with respect to its length, resulting in extremely slow parsing. This could cause a denial of service. References
- https://bugs.mageia.org/show_bug.cgi?id=34019
- https://github.com/advisories/GHSA-w32m-9786-jp63
- https://www.cve.org/CVERecord?id=CVE-2024-45338
- golang-x-net-0.7.0-2.1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0189 - Updated libssh packages fix security vulnerabilities
Publication date: 10 Jun 2026
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-4877 , CVE-2025-4878 , CVE-2025-5318 , CVE-2025-5351 , CVE-2025-5372 , CVE-2025-5449 , CVE-2025-5987 Description CVE-2025-4877 Write beyond bounds in binary to base64 conversion functions CVE-2025-4878 Use of uninitialized variable in privatekey_from_file() CVE-2025-5318 Likely read beyond bounds in sftp server handle management CVE-2025-5351 Double free in functions exporting keys CVE-2025-5372 ssh_kdf() returns a success code on certain failures CVE-2025-5449 Likely read beyond bounds in sftp server message decoding CVE-2025-5987 Invalid return code for chacha20 poly1305 with OpenSSL backend References
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-4877 , CVE-2025-4878 , CVE-2025-5318 , CVE-2025-5351 , CVE-2025-5372 , CVE-2025-5449 , CVE-2025-5987 Description CVE-2025-4877 Write beyond bounds in binary to base64 conversion functions CVE-2025-4878 Use of uninitialized variable in privatekey_from_file() CVE-2025-5318 Likely read beyond bounds in sftp server handle management CVE-2025-5351 Double free in functions exporting keys CVE-2025-5372 ssh_kdf() returns a success code on certain failures CVE-2025-5449 Likely read beyond bounds in sftp server message decoding CVE-2025-5987 Invalid return code for chacha20 poly1305 with OpenSSL backend References
- https://bugs.mageia.org/show_bug.cgi?id=34405
- https://www.openwall.com/lists/oss-security/2025/06/27/2
- https://www.cve.org/CVERecord?id=CVE-2025-4877
- https://www.cve.org/CVERecord?id=CVE-2025-4878
- https://www.cve.org/CVERecord?id=CVE-2025-5318
- https://www.cve.org/CVERecord?id=CVE-2025-5351
- https://www.cve.org/CVERecord?id=CVE-2025-5372
- https://www.cve.org/CVERecord?id=CVE-2025-5449
- https://www.cve.org/CVERecord?id=CVE-2025-5987
- libssh-0.10.6-1.1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0188 - Updated jq packages fix security vulnerabilities
Publication date: 10 Jun 2026
Type: security
Affected Mageia releases : 9
CVE: CVE-2024-23337 , CVE-2025-48060 , CVE-2026-32316 , CVE-2026-39979 , CVE-2026-33948 , CVE-2026-33947 , CVE-2026-39956 , CVE-2026-40164 Description An integer overflow arises when assigning value using an index of 2147483647, the signed integer limit. This causes a denial of service. (CVE-2024-23337) It was discovered that jq did not correctly handle certain string concatenations. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-32316) It was discovered that jq did not correctly handle recursion in certain circumstances. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-33947) It was discovered that jq did not correctly handle improperly terminated strings. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-33948) It was discovered that jq did not correctly handle checking certain variable types. An attacker could possibly use this issue to cause a denial of service or leak sensitive information. (CVE-2026-39956) It was discovered that jq did not correctly handle certain string formatting. An attacker could possibly use this issue to leak sensitive information or cause a denial of service. (CVE-2026-39979) It was discovered that jq used a fixed seed for hash table operations. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-40164) A heap-buffer-overflow is present in function `jv_string_vfmt` in the jq_fuzz_execute harness from oss-fuzz. This crash happens on file jv.c, line 1456 `void* p = malloc(sz); (CVE-2025-48060) Top-level jq programs loaded from a file with -f are truncated at the first embedded NUL byte on current upstream HEAD. A crafted filter file such as . followed by x00 and arbitrary suffix compiles and executes as only the prefix before the NUL. This leaves jq with a post-CVE-2026-33948 prefix/full-buffer mismatch on the compilation path even though the JSON parser path has already been fixed. (CVE-2026-41256) The ordinary module loader recurses without cycle detection when two otherwise valid modules include each other (CVE-2026-44777) References
Type: security
Affected Mageia releases : 9
CVE: CVE-2024-23337 , CVE-2025-48060 , CVE-2026-32316 , CVE-2026-39979 , CVE-2026-33948 , CVE-2026-33947 , CVE-2026-39956 , CVE-2026-40164 Description An integer overflow arises when assigning value using an index of 2147483647, the signed integer limit. This causes a denial of service. (CVE-2024-23337) It was discovered that jq did not correctly handle certain string concatenations. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-32316) It was discovered that jq did not correctly handle recursion in certain circumstances. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-33947) It was discovered that jq did not correctly handle improperly terminated strings. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-33948) It was discovered that jq did not correctly handle checking certain variable types. An attacker could possibly use this issue to cause a denial of service or leak sensitive information. (CVE-2026-39956) It was discovered that jq did not correctly handle certain string formatting. An attacker could possibly use this issue to leak sensitive information or cause a denial of service. (CVE-2026-39979) It was discovered that jq used a fixed seed for hash table operations. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-40164) A heap-buffer-overflow is present in function `jv_string_vfmt` in the jq_fuzz_execute harness from oss-fuzz. This crash happens on file jv.c, line 1456 `void* p = malloc(sz); (CVE-2025-48060) Top-level jq programs loaded from a file with -f are truncated at the first embedded NUL byte on current upstream HEAD. A crafted filter file such as . followed by x00 and arbitrary suffix compiles and executes as only the prefix before the NUL. This leaves jq with a post-CVE-2026-33948 prefix/full-buffer mismatch on the compilation path even though the JSON parser path has already been fixed. (CVE-2026-41256) The ordinary module loader recurses without cycle detection when two otherwise valid modules include each other (CVE-2026-44777) References
- https://bugs.mageia.org/show_bug.cgi?id=34443
- https://www.openwall.com/lists/oss-security/2026/04/15/8
- https://github.com/jqlang/jq/security/advisories/GHSA-q3h9-m34w-h76f
- https://github.com/jqlang/jq/security/advisories/GHSA-2hhh-px8h-355p
- https://github.com/jqlang/jq/security/advisories/GHSA-32cx-cvvh-2wj9
- https://github.com/jqlang/jq/security/advisories/GHSA-xwrw-4f8h-rjvg
- https://github.com/jqlang/jq/security/advisories/GHSA-6gc3-3g9p-xx28
- https://github.com/jqlang/jq/security/advisories/GHSA-wwj8-gxm6-jc29
- https://github.com/jqlang/jq/security/advisories/GHSA-gf4g-95wj-4q4r
- https://www.cve.org/CVERecord?id=CVE-2024-23337
- https://www.cve.org/CVERecord?id=CVE-2025-48060
- https://www.cve.org/CVERecord?id=CVE-2026-32316
- https://www.cve.org/CVERecord?id=CVE-2026-39979
- https://www.cve.org/CVERecord?id=CVE-2026-33948
- https://www.cve.org/CVERecord?id=CVE-2026-33947
- https://www.cve.org/CVERecord?id=CVE-2026-39956
- https://www.cve.org/CVERecord?id=CVE-2026-40164
- jq-1.6-3.1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0187 - Updated tor packages fix security issues
Publication date: 10 Jun 2026
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-4444 , CVE-2026-44597 , CVE-2026-44599 , CVE-2026-44600 , CVE-2026-44601 , CVE-2026-44602 , CVE-2026-44603 Description This update provides lots of security issues fixed by upstream since our current version. Please see the links for details. References
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-4444 , CVE-2026-44597 , CVE-2026-44599 , CVE-2026-44600 , CVE-2026-44601 , CVE-2026-44602 , CVE-2026-44603 Description This update provides lots of security issues fixed by upstream since our current version. Please see the links for details. References
- https://bugs.mageia.org/show_bug.cgi?id=35486
- https://gitlab.torproject.org/tpo/core/tor/-/blob/tor-0.4.8.25/ReleaseNotes?ref_type=tags#L5
- https://gitlab.torproject.org/tpo/core/tor/-/blob/tor-0.4.9.8/ReleaseNotes?ref_type=tags#L5
- https://www.cve.org/CVERecord?id=CVE-2025-4444
- https://www.cve.org/CVERecord?id=CVE-2026-44597
- https://www.cve.org/CVERecord?id=CVE-2026-44599
- https://www.cve.org/CVERecord?id=CVE-2026-44600
- https://www.cve.org/CVERecord?id=CVE-2026-44601
- https://www.cve.org/CVERecord?id=CVE-2026-44602
- https://www.cve.org/CVERecord?id=CVE-2026-44603
- tor-0.4.9.8-1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0186 - Updated libxpm packages fix security vulnerability
Publication date: 10 Jun 2026
Type: security
Affected Mageia releases : 9
CVE: CVE-2026-4367 Description libXpm Out-of-bounds read in xpmNextWord(). (CVE-2026-4367) References
Type: security
Affected Mageia releases : 9
CVE: CVE-2026-4367 Description libXpm Out-of-bounds read in xpmNextWord(). (CVE-2026-4367) References
- https://bugs.mageia.org/show_bug.cgi?id=35415
- https://www.openwall.com/lists/oss-security/2026/04/21/3
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/RVKVREGNUTRNFASWOP3IK7BSE3RXDHLZ/
- https://www.cve.org/CVERecord?id=CVE-2026-4367
- libxpm-3.5.15-1.2.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0185 - Updated minetest packages fix security vulnerabilities
Publication date: 10 Jun 2026
Type: security
Affected Mageia releases : 9
CVE: CVE-2026-40959 , CVE-2026-40960 Description Mod security sandbox escape. (CVE-2026-40959) HTTP API and insecure environment access control bypass. (CVE-2026-40960) References
Type: security
Affected Mageia releases : 9
CVE: CVE-2026-40959 , CVE-2026-40960 Description Mod security sandbox escape. (CVE-2026-40959) HTTP API and insecure environment access control bypass. (CVE-2026-40960) References
- https://bugs.mageia.org/show_bug.cgi?id=35422
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2K6QTVDXSL7E72EYONNHDCY7I7LTD27B/
- https://lists.debian.org/debian-security-announce/2026/msg00127.html
- https://github.com/luanti-org/luanti/security/advisories/GHSA-g596-mf82-w8c3
- https://github.com/luanti-org/luanti/security/advisories/GHSA-22c4-238c-m5j4
- https://www.cve.org/CVERecord?id=CVE-2026-40959
- https://www.cve.org/CVERecord?id=CVE-2026-40960
- minetest-5.7.0-1.1.mga9
Categorías: Actualizaciones de Seguridad
MGASA-2026-0184 - Updated wireshark packages fix security vulnerabilities
Publication date: 10 Jun 2026
Type: security
Affected Mageia releases : 9
CVE: CVE-2024-11596 , CVE-2024-9781 , CVE-2025-11626 , CVE-2025-13499 , CVE-2025-13945 , CVE-2025-13946 , CVE-2025-1492 , CVE-2025-5601 , CVE-2025-9817 , CVE-2026-0960 , CVE-2026-5405 , CVE-2026-5653 , CVE-2026-6529 , CVE-2026-6530 , CVE-2026-6867 , CVE-2026-6868 , CVE-2026-6869 , CVE-2026-6870 , CVE-2026-7376 , CVE-2026-7378 , CVE-2026-7379 Description Multiple vulnerabilities have been discovered in Wireshark, a network protocol analyzer, which could result in denial of service or the execution of arbitrary code. This update fixes the reported issue. References
Type: security
Affected Mageia releases : 9
CVE: CVE-2024-11596 , CVE-2024-9781 , CVE-2025-11626 , CVE-2025-13499 , CVE-2025-13945 , CVE-2025-13946 , CVE-2025-1492 , CVE-2025-5601 , CVE-2025-9817 , CVE-2026-0960 , CVE-2026-5405 , CVE-2026-5653 , CVE-2026-6529 , CVE-2026-6530 , CVE-2026-6867 , CVE-2026-6868 , CVE-2026-6869 , CVE-2026-6870 , CVE-2026-7376 , CVE-2026-7378 , CVE-2026-7379 Description Multiple vulnerabilities have been discovered in Wireshark, a network protocol analyzer, which could result in denial of service or the execution of arbitrary code. This update fixes the reported issue. References
- https://bugs.mageia.org/show_bug.cgi?id=33641
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/TDSVQBWNGPIXNB6DJ7GN3MKZXQIAMQNM/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7XDTIEL5AXYD7FSCLZTDTSH5DDELHHLL/
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/QKS4A6WNLC3Y3QRK3OCQ4MEHDXODKUI6/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/D55JJLGZUIFAWMHEC7HM4552HI7FDQJE/
- https://lists.debian.org/debian-security-announce/2026/msg00160.html
- https://www.cve.org/CVERecord?id=CVE-2024-11596
- https://www.cve.org/CVERecord?id=CVE-2024-9781
- https://www.cve.org/CVERecord?id=CVE-2025-11626
- https://www.cve.org/CVERecord?id=CVE-2025-13499
- https://www.cve.org/CVERecord?id=CVE-2025-13945
- https://www.cve.org/CVERecord?id=CVE-2025-13946
- https://www.cve.org/CVERecord?id=CVE-2025-1492
- https://www.cve.org/CVERecord?id=CVE-2025-5601
- https://www.cve.org/CVERecord?id=CVE-2025-9817
- https://www.cve.org/CVERecord?id=CVE-2026-0960
- https://www.cve.org/CVERecord?id=CVE-2026-5405
- https://www.cve.org/CVERecord?id=CVE-2026-5653
- https://www.cve.org/CVERecord?id=CVE-2026-6529
- https://www.cve.org/CVERecord?id=CVE-2026-6530
- https://www.cve.org/CVERecord?id=CVE-2026-6867
- https://www.cve.org/CVERecord?id=CVE-2026-6868
- https://www.cve.org/CVERecord?id=CVE-2026-6869
- https://www.cve.org/CVERecord?id=CVE-2026-6870
- https://www.cve.org/CVERecord?id=CVE-2026-7376
- https://www.cve.org/CVERecord?id=CVE-2026-7378
- https://www.cve.org/CVERecord?id=CVE-2026-7379
- wireshark-4.0.17-1.2.mga9
Categorías: Actualizaciones de Seguridad




