Mageia Security

Feed
Mageia Advisories
Updated: hace 2 dias 11 horas

MGAA-2026-0096 - Updated kazam package makes it work again

17 Agosto, 2026 - 16:41
Publication date: 17 Aug 2026
Type: bugfix
Affected Mageia releases : 10
Description
Kazam crashed when importing imp. This update brings the latest commit after version 2.0.0, fixing the reported issue. It is reported that screenrecord in a Wayland session still doesn't work; try using obs-studio, spectacle (not sound), vokoscreenNG or simplescreenrecorder instead. References
SRPMS 10/core
  • kazam-2.0.0-1.20260728.2.mga10

MGAA-2026-0095 - Updated mingw-gcc packages fix upgrade conflicts

17 Agosto, 2026 - 16:41
Publication date: 17 Aug 2026
Type: bugfix
Affected Mageia releases : 10
Description
This update fixes conflicting files to allow a smooth upgrade from mga9 to mga10! References
SRPMS 10/core
  • mingw-gcc-15.2.1-1.1.mga10

MGAA-2026-0094 - Updated sar2 packages fix bug

15 Agosto, 2026 - 18:54
Publication date: 15 Aug 2026
Type: bugfix
Affected Mageia releases : 10
Description
sar2 not find the data in the path in which we locate it, causing the game to fail to start. This update fixes the reported issue. References
SRPMS 10/core
  • sar2-2.6.0-2.1.mga10

MGAA-2026-0093 - Updated soundkonverter packages fix bug

14 Agosto, 2026 - 19:04
Publication date: 14 Aug 2026
Type: bugfix
Affected Mageia releases : 10
Description
soundkonverter can't convert audio files. This update switches to another qt6 fork of soundkonverter to fix the reported issue. Please note that command line operations are still not working. References
SRPMS 10/core
  • soundkonverter-3.0.1.32-1.20260728.1.mga10

MGAA-2026-0092 - Updated php8.5-imap & php8.4-imap packages fix bug

14 Agosto, 2026 - 19:04
Publication date: 14 Aug 2026
Type: bugfix
Affected Mageia releases : 10
Description
Due to an import error, the php[8.4,8.5]-imap package was compiled without SSL support. This update fixes this issue. Please be aware that this package was deprecated by php. Please use an alternative package instead; see the links. References
SRPMS 10/core
  • php8.5-imap-1.0.3-1.1.mga10
  • php8.4-imap-1.0.3-3.1.mga10

MGAA-2026-0091 - Updated perl-App-Asciio & perl-IO-Prompter packages fix bug

14 Agosto, 2026 - 19:04
Publication date: 14 Aug 2026
Type: bugfix
Affected Mageia releases : 10
Description
The current App::Asciio perl module in Mageia 10, version 1.51.3 (released in 2015), depends on Gtk2. This update brings a new version 1.9.02 (released in 2023) which upgraded its dependencies to Gtk3. References
SRPMS 10/core
  • perl-App-Asciio-1.9.2-1.3.mga10
  • perl-IO-Prompter-0.5.4-1.mga10

MGASA-2026-0335 - Updated dhcpcd packages fix security vulnerabilities

13 Agosto, 2026 - 22:59
Publication date: 13 Aug 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-56114 , CVE-2026-56116 Description
Attackers can send a crafted DHCPv6 ADVERTISE message containing an IA_PD IAPREFIX /0 with a valid OPTION_PD_EXCLUDE using an exclude prefix length of /121 through /128 to trigger the out-of-bounds write and potentially corrupt adjacent stack memory (CVE: CVE-2026-56114). Attackers can repeatedly send Router Advertisements containing Route Information options with a lifetime of zero, triggering unfreed allocations in routeinfo_findalloc() that cause linear memory exhaustion and eventual daemon crash (CVE: CVE-2026-56116). References
SRPMS 10/core
  • dhcpcd-10.5.0-1.1.mga10

MGASA-2026-0334 - Updated qemu packages fix many security vulnerabilities

13 Agosto, 2026 - 17:40

MGASA-2026-0333 - Updated roundcubemail packages fix security vulnerabilities

13 Agosto, 2026 - 17:40
Publication date: 13 Aug 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-54432 , CVE-2026-54433 , CVE-2026-62641 , CVE-2026-62642 , CVE-2026-62643 , CVE-2026-62644 Description
Add basic validation for content proxied by the css proxy Fix SSRF bypass via specific local address URLs using 100.64.0.0/10 and fe80::/10 nets, Fix SSRF filter bypass via various forms of nip.io/sslip.io hostnames evading is_local_url() check Fix remote content blocking bypass via unclosed url() in a FuncIRI attribute Fix LDAP filter injection via unescaped %u/%fu/%d substitution into the search_filter Fix arbitrary Sieve script injection via a filter rule name bypassing managesieve_disabled_actions Fix RCE via cmd_learn driver of markasjunk plugin Fix IMAP command injection via mail search and LITERAL+ byte-count desynchronization Fix password's modoboa driver leak of an authentication token to a user-controlled host Fix stored XSS in "Add to address book" action Fix HTML/CSS sanitization bypass via SVG animate by attribute References
SRPMS 10/core
  • roundcubemail-1.7.3-2.mga10

MGASA-2026-0332 - Updated roundcubemail package fixes security vulnerabilities

13 Agosto, 2026 - 17:40

MGAA-2026-0090 - Updated gdm packages fix bug

13 Agosto, 2026 - 17:40
Publication date: 13 Aug 2026
Type: bugfix
Affected Mageia releases : 10
Description
When upgrading from Mageia 9 to Mageia 10 in a graphical session controlled by gdm, gdm restarts in the middle of the distro upgrade process and causes an incomplete/broken upgrade. This update fixes the reported issue. References
SRPMS 10/core
  • gdm-49.2-2.1.mga10

MGAA-2026-0089 - Updated lightdm packages fix bug

13 Agosto, 2026 - 17:40
Publication date: 13 Aug 2026
Type: bugfix
Affected Mageia releases : 10
Description
When upgrading from Mageia 9 to Mageia 10 in a graphical session controlled by lightdm, lightdm restarts in the middle of the distro upgrade process and causes an incomplete/broken upgrade. This update fixes the reported issue. References
SRPMS 10/core
  • lightdm-1.32.0-4.1.mga10

MGAA-2026-0088 - Updated (kmod-)virtualbox(-kvm) packages fix a bug

13 Agosto, 2026 - 17:40
Publication date: 13 Aug 2026
Type: bugfix
Affected Mageia releases : 10
Description
The updated packages fix an issue with sharing the clipboard and Plasma Wayland guests. References
SRPMS 10/core
  • virtualbox-7.2.14-1.mga10
  • virtualbox-kvm-7.2.14-1.mga10
  • kmod-virtualbox-7.2.14-29.mga10

MGAA-2026-0086 - Updated (kmod-)nvidia-current(-wopengpu) packages fix bugs

13 Agosto, 2026 - 17:40
Publication date: 13 Aug 2026
Type: bugfix
Affected Mageia releases : 10
Description
This is a bug fix release for the new 580 series. See the upstream reference for details. References
SRPMS 10/nonfree
  • nvidia-current-580.173.02-1.mga10.nonfree
  • nvidia-current-wopengpu-580.173.02-1.mga10.nonfree
  • kmod-nvidia-current-wopengpu-580.173.02-38.mga10.nonfree

MGASA-2026-0331 - Updated bind packages fix security vulnerabilities

10 Agosto, 2026 - 20:29
Publication date: 10 Aug 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-10723 , CVE-2026-10822 , CVE-2026-11331 , CVE-2026-11605 , CVE-2026-11721 , CVE-2026-12617 , CVE-2026-13204 , CVE-2026-13321 Description
Updated bind packages fix security vulnerabilities: Incorrect acceptance of NSEC3 records. (CVE-2026-10723) Key Record using PRIVATEDNS algorithm may lead to unexpected exit. (CVE-2026-10822) Potential wildcard CNAME RPZ policy bypass. (CVE-2026-11331) Unnecessary validation of DNSSEC signed records. (CVE-2026-11605) Cache poisoning possible with label count discrepancy, RRSIG, and wildcards. (CVE-2026-11721) Record ordering based unexpected exit with CNAME or DNAME. (CVE-2026-12617) Unexpected exit in certain situations with NSEC and NSEC3 both present. (CVE-2026-13204) DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field. (CVE-2026-13321) References
SRPMS 10/core
  • bind-9.20.26-1.mga10

MGASA-2026-0330 - Updated php8.5 packages fix security vulnerabilities

10 Agosto, 2026 - 20:29
Publication date: 10 Aug 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-17544 , CVE-2026-9672 , CVE-2026-17543 , CVE-2026-7260 Description
Updated php 8.5 packages fix some security vulnerabilities. For details see the references. References
SRPMS 10/core
  • php8.5-8.5.9-1.mga10

MGASA-2026-0329 - Updated php8.4 packages fix security vulnerabilities

10 Agosto, 2026 - 20:29
Publication date: 10 Aug 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-17544 , CVE-2026-9672 , CVE-2026-17543 , CVE-2026-7260 Description
The updated php 8.4 packages fix some security vulnerabilities. See the references for more information. References
SRPMS 10/core
  • php8.4-8.4.24-1.1.mga10

MGASA-2026-0328 - Updated openslide packages fix a security vulnerability

10 Agosto, 2026 - 20:29
Publication date: 10 Aug 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-48977 Description
Arbitrary memory write with crafted Ventana BIF file. (CVE-2026-48977) References
SRPMS 10/core
  • openslide-4.0.0-1.1.mga10

MGAA-2026-0085 - Updated rawtherapee package fixes bugs

10 Agosto, 2026 - 20:29
Publication date: 10 Aug 2026
Type: bugfix
Affected Mageia releases : 10
Description
This is rawtherapee version 5.13, the latest from upstream. It is a bugfix and features release. References
SRPMS 10/core
  • rawtherapee-5.13-1.mga10