Actualizaciones de Seguridad

MGASA-2026-0407 - Updated libcupsfilters & cups-filters packages fix security vulnerabilities

Mageia Security - 14 Septiembre, 2026 - 17:26
Publication date: 14 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-64611 , CVE-2026-64612 Description
cpu exhaustion via infinite loop in cfieee1284normalizemakemodel(). (CVE-2026-64611) cups image filter process abort via malformed png. (CVE-2026-64612) References
SRPMS 10/core
  • libcupsfilters-2.1.1-5.1.mga10
9/core
  • cups-filters-1.28.16-6.4.mga9

MGASA-2026-0406 - Updated zip packages fix a security vulnerability

Mageia Security - 14 Septiembre, 2026 - 17:26
Publication date: 14 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2018-13410 Description
zip test option (-T) command injection. Info-ZIP Zip 3.0, when the -T and -TT command-line options are used, allows attackers to cause a denial of service (invalid free and application crash) or possibly have unspecified other impact because of an off-by-one error. (CVE-2018-13410) References
SRPMS 10/core
  • zip-3.0-17.1.mga10
9/core
  • zip-3.0-14.1.mga9

MGASA-2026-0405 - Updated unzip packages fix security vulnerabilities

Mageia Security - 14 Septiembre, 2026 - 17:26
Publication date: 14 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
Description
Vulnerabilities were discovered in the Info-ZIP unzip program, which could result in the execution of arbitrary code if a specially crafted file is processed. References
SRPMS 10/core
  • unzip-6.0-8.1.mga10
9/core
  • unzip-6.0-4.1.mga9

MGASA-2026-0404 - Updated perl-HTML-FormFu packages fix a security vulnerability

Mageia Security - 14 Septiembre, 2026 - 17:26
Publication date: 14 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-19873 Description
HTML::FormFu versions through 2.08 for Perl allow resource exhaustion via an unbounded repeat count from the query string in Repeatable elements. (CVE-2026-19873) References
SRPMS 10/core
  • perl-HTML-FormFu-2.60.0-5.1.mga10
9/core
  • perl-HTML-FormFu-2.60.0-4.1.mga9

MGASA-2026-0403 - Updated bzip2 packages fix a security vulnerability

Mageia Security - 14 Septiembre, 2026 - 17:26
Publication date: 14 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-42250 Description
Off-by-One Leading to Out-of-Bounds Write in bzip2. (CVE-2026-42250 References
SRPMS 10/core
  • bzip2-1.0.8-7.1.mga10
9/core
  • bzip2-1.0.8-5.1.mga9

MGASA-2026-0402 - Updated libssh2 packages fix security vulnerabilities

Mageia Security - 14 Septiembre, 2026 - 17:26
Publication date: 14 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-66032 , CVE-2026-66033 , CVE-2026-66035 Description
Double-Free Heap Corruption via sftp_open(). (CVE-2026-66032) Integer Underflow DoS via AES-GCM Cipher Negotiation. (CVE-2026-66033) Heap Buffer Overflow via ETM Cipher Negotiation. (CVE-2026-66035) References
SRPMS 10/core
  • libssh2-1.11.1-2.2.mga10
9/core
  • libssh2-1.11.0-1.2.mga9

MGASA-2026-0401 - Updated tar packages fix security vulnerabilities

Mageia Security - 14 Septiembre, 2026 - 17:26
Publication date: 14 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2025-45582 , CVE-2026-18508 , CVE-2026-18477 Description
GNU Tar through 1.35 allows file overwrite via directory traversal in crafted TAR archives, with a certain two-step process. (CVE-2025-45582) Tar: toctou in incremental dumpdir 'x' rename handling allows restore path escape. (CVE-2026-18477) Tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite. (CVE-2026-18508) References
SRPMS 10/core
  • tar-1.35-4.1.mga10
9/core
  • tar-1.35-4.1.mga9

MGASA-2026-0399 - Updated bind package fixes a security vulnerability

Mageia Security - 13 Septiembre, 2026 - 06:39
Publication date: 13 Sep 2026
Type: security
Affected Mageia releases : 9
CVE: CVE-2026-13204 Description
It was discovered that Bind incorrectly handled DNSSEC validation when a domain was covered by both NSEC and NSEC3 records with only one type having an RRSIG. A remote attacker could possibly use this issue to cause Bind to crash, resulting in a denial of service (CVE-2026-13204). References
SRPMS 9/core
  • bind-9.18.50-1.1.mga9

MGASA-2026-0398 - Updated ffmpeg package fixes security vulnerabilities

Mageia Security - 13 Septiembre, 2026 - 06:39
Publication date: 13 Sep 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-58049 , CVE-2026-64830 , CVE-2026-64832 , CVE-2026-64833 , CVE-2026-64834 , CVE-2026-64835 , CVE-2026-65703 , CVE-2026-65704 , CVE-2026-65705 , CVE-2026-65706 , CVE-2026-66036 , CVE-2026-66037 , CVE-2026-66038 , CVE-2026-66039 , CVE-2026-66041 , CVE-2026-70628 , CVE-2026-70629 , CVE-2026-70630 , CVE-2026-70631 , CVE-2026-70632 , CVE-2026-75141 , CVE-2026-75142 , CVE-2026-75143 , CVE-2026-75144 , CVE-2026-75146 Description
Out-of-Bounds Write in RASC Decoder decode_dlta(). (CVE-2026-58049) Heap Buffer Overflow via VobSub Subtitle Demuxer. (CVE-2026-64830) Double-Free in NVDEC Hardware Decoder via nvdec.c. (CVE-2026-64832) Out-of-Bounds Read via S/PDIF Muxer spdifenc.c. (CVE-2026-64833) Infinite Loop DoS via RTP/ASF Demuxer. (CVE-2026-64834) Out-of-Bounds Memory Access in ADX Audio Decoder. (CVE-2026-64835) Out-of-Bounds Write in TDSC Video Decoder. (CVE-2026-65703) Out-of-Bounds Write via TY Demuxer and Shorten Decoder. (CVE-2026-65704) vf_floodfill Out-of-Bounds Write via filter_frame(). (CVE-2026-65705) vf_swaprect Out-of-Bounds Write via NV12 Frame Processing. (CVE-2026-65706) Heap Out-of-Bounds Write in vf_hqdn3d Filter. (CVE-2026-66036) IAMF Demuxer Uncontrolled Resource Consumption via mix_presentation_obu(). (CVE-2026-66037) LCL/ZLIB Video Decoder Information Disclosure via lcldec.c. (CVE-2026-66038) MACE6 Audio Decoder Heap Out-of-Bounds Write via CAF File. (CVE-2026-66039) Heap Out-of-Bounds Write via vf_quirc Filter. (CVE-2026-66041) DVB Subtitle Parser Heap Buffer Overflow via WTV File. (CVE-2026-70628) Uninitialized Heap Memory Read in RSCC Decoder. (CVE-2026-70629) Uninitialized Heap Memory Read in Screenpresso Decoder. (CVE-2026-70630) Uninitialized Heap Memory Read in TIFF Decoder. (CVE-2026-70631) Heap Out-of-Bounds Write in CFHD Decoder via AVI Demuxing. (CVE-2026-70632) Heap Buffer Overflow in hvcC Box Writer via HEVC Muxing. (CVE-2026-75141) Stack Buffer Overflow in MPEG-PS Muxer via mpegenc.c. (CVE-2026-75142) Heap Buffer Overflow via RIST Protocol Reader. (CVE-2026-75143) Heap Buffer Overflow in VC-2/Dirac RTP Packetizer. (CVE-2026-75144) Out-of-Bounds Read in DASH Demuxer via dashdec.c. (CVE-2026-75146) References
SRPMS 10/core
  • ffmpeg-7.1.5-1.1.mga10
10/tainted
  • ffmpeg-7.1.5-1.1.mga10.tainted

MGASA-2026-0397 - Updated librabbitmq packages fix security vulnerabilities

Mageia Security - 12 Septiembre, 2026 - 18:24
Publication date: 12 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-59986 , CVE-2026-61547 Description
amqp_decode_bytes size_t integer overflow bypasses bounds check on 32-bit (OOB read). (CVE-2026-59986) Heap Buffer Overflow in amqp_send_frame() When Serializing Oversized AMQP_FRAME_BODY. (CVE-2026-61547) References
SRPMS 10/core
  • librabbitmq-0.15.0-2.2.mga10
9/core
  • librabbitmq-0.11.0-1.2.mga9

MGASA-2026-0396 - Updated xz packages fix security vulnerabilities

Mageia Security - 12 Septiembre, 2026 - 18:24
Publication date: 12 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
Description
XZ Utils: Invalid write if a decoder is reinitialized after allocation failure References
SRPMS 10/core
  • xz-5.8.4-1.mga10
9/core
  • xz-5.4.7-0.git20260909.1.mga9

MGASA-2026-0395 - Updated java-21-openjdk & java-17-openjdk packages fix security vulnerabilities

Mageia Security - 12 Septiembre, 2026 - 04:59
Publication date: 12 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-46968 , CVE-2026-46917 , CVE-2026-47010 , CVE-2026-47021 , CVE-2026-47027 , CVE-2026-60147 , CVE-2026-47059 , CVE-2026-47063 , CVE-2026-60589 , CVE-2026-61308 , CVE-2026-70907 Description
Enhance TLS certificate handling. (CVE-2026-46968) Improve DTLS handshaking. (CVE-2026-46917) Enhance JPEG handling. (CVE-2026-47010) Enhance XBM image support. (CVE-2026-47021) Enhance Jar file processing. (CVE-2026-47027) Improve certification checking. (CVE-2026-60147) Enhance AWT ImagingLib. (CVE-2026-47059) Enhance Jar handling. (CVE-2026-47063) Improve Resource Resolving. (CVE-2026-60589) Enhance HTTP Connections. (CVE-2026-61308) Enhance TLS server. (CVE-2026-70907) References
SRPMS 10/core
  • java-21-openjdk-21.0.12.1.1-1.mga10
9/core
  • java-17-openjdk-17.0.20.1.1-1.mga9

MGASA-2026-0394 - Updated perl-Imager packages fix a security vulnerability

Mageia Security - 12 Septiembre, 2026 - 04:59
Publication date: 12 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-19082 Description
Imager versions from 0.45_02 before 1.034 for Perl may expose adjacent heap bytes via strlen() over-read from zero-count ASCII EXIF entries in copy_string_tags References
SRPMS 10/core
  • perl-Imager-1.34.0-1.1.mga10
9/core
  • perl-Imager-1.34.0-1.1.mga9

MGASA-2026-0393 - Updated perl-Catalyst-Plugin-Static-Simple packages fix a security vulnerability

Mageia Security - 12 Septiembre, 2026 - 04:59
Publication date: 12 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-15743 Description
Catalyst::Plugin::Static::Simple versions through 0.38 for Perl mark responses as publicly cacheable References
SRPMS 10/core
  • perl-Catalyst-Plugin-Static-Simple-0.370.0-4.mga10
9/core
  • perl-Catalyst-Plugin-Static-Simple-0.370.0-3.mga9

MGASA-2026-0392 - Updated tor packages fix security vulnerabilities

Mageia Security - 11 Septiembre, 2026 - 23:47
Publication date: 11 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-87724 Description
Tor before 0.4.9.12 interprets the CC_RESPONSE extension even when CC_REQUEST was not sent, which allows remote attackers to cause a denial of service (crash) because of corrupted congestion-control state(CVE-2026-87724) Do not purge memory for OOM from within low-level code (TROVE-2026-043). A hostile cache could trick a client into falsely believing that certain relays' microdescriptors or router descriptors were unusable (TROVE-2026-034). Fix a use-after-free error (TROVE-2026-036). Limit the size of consensus diffs, in bytes and in lines, to prevent a class of memory-based denial-of-service attacks (TROVE-2026-042). Negotiate CGO cryptography with every hop that supports it (TROVE-2026-033). Validate DNS names for complience whenever providing or receiving them from evdns, to limit exposure to a class of application and library bugs (TROVE-2026-035). References
SRPMS 10/core
  • tor-0.4.9.12-1.mga10
9/core
  • tor-0.4.9.12-1.mga9

MGASA-2026-0391 - Updated glibc package fixes security vulnerabilities

Mageia Security - 11 Septiembre, 2026 - 18:26
Publication date: 11 Sep 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-5435 , CVE-2026-6238 , CVE-2026-6368 , CVE-2026-6791 , CVE-2026-19499 , CVE-2026-77117 , CVE-2026-80489 Description
Potential buffer overflow in ns_sprintrrf TSIG handling path. (CVE-2026-5435) Buffer overread in ns_printrrf with corrupted RDATA field. (CVE-2026-6238) wordexp with WRDE_APPEND can return or use invalid memory. (CVE-2026-6368) Potential stack-based buffer clash during tilde expansion in wordexp. (CVE-2026-6791) Fix right-justification in strfmon. (CVE-2026-19499) SHIFT_JISX0213 decoding lacks pending character reset. (CVE-2026-77117) EUC_JISX0213 decoding lacks pending character reset. (CVE-2026-80489) References
SRPMS 10/core
  • glibc-2.42-10.mga10

MGAA-2026-0123 - Updated simgear, flightgear, flightgear-data packages fix bug

Mageia Security - 11 Septiembre, 2026 - 18:26
Publication date: 11 Sep 2026
Type: bugfix
Affected Mageia releases : 10
Description
Updated simgear, flightgear and flightgear-data packages to new stable release version 2024.1.7 References
SRPMS 10/core
  • simgear-2024.1.7-1.mga10
  • flightgear-2024.1.7-1.mga10
  • flightgear-data-2024.1.7-1.mga10

MGASA-2026-0390 - Updated perl-DBI packages fix security vulnerabilities

Mageia Security - 10 Septiembre, 2026 - 00:52
Publication date: 09 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-73193 , CVE-2026-73194 Description
DBI versions before 1.652 for Perl allow a heap out-of-bounds write on 32-bit perl via an integer wraparound in the output buffer size computed by preparse. DBI versions before 1.652 for Perl allow a heap out-of-bounds write via an unvalidated numeric placeholder that sets the binder counter in preparse. References
SRPMS 10/core
  • perl-DBI-1.652.0-2.mga10
9/core
  • perl-DBI-1.652.0-1.1.mga9

MGASA-2026-0389 - Updated ceph packages fix security vulnerabilities

Mageia Security - 10 Septiembre, 2026 - 00:52
Publication date: 09 Sep 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2025-30156 , CVE-2026-50152 , CVE-2026-54330 , CVE-2026-39944 Description
Updated ceph packages fix various security issues allowing authentication bypasses to gain admin privileges on the OSD, MDS, and MGR services. Notice that some of the fixes require kernel support for aes256k (introduced in kernel 7). This update will not break installs using the old (and insecure) AES keys; warnings will appear to migrate all keys (check out "ceph health detail" or "ceph status"). References
SRPMS 10/core
  • ceph-20.2.4-1.mga10
Feed