Actualizaciones de Seguridad

MGASA-2026-0388 - Updated thunderbird packages fix security vulnerabilities

Mageia Security - 9 Septiembre, 2026 - 19:01
Publication date: 09 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-84637 , CVE-2026-84639 , CVE-2026-84640 , CVE-2026-84641 , CVE-2026-84642 , CVE-2026-75874 , CVE-2026-16365 , CVE-2026-84118 , CVE-2026-84119 , CVE-2026-84120 , CVE-2026-84121 , CVE-2026-84122 , CVE-2026-84123 , CVE-2026-84124 , CVE-2026-84125 , CVE-2026-74952 , CVE-2026-84129 , CVE-2026-16371 , CVE-2026-84130 , CVE-2026-84131 , CVE-2026-84132 , CVE-2026-84133 , CVE-2026-84134 , CVE-2026-84136 , CVE-2026-84137 , CVE-2026-84139 , CVE-2026-84140 , CVE-2026-84141 , CVE-2026-84143 , CVE-2026-84144 , CVE-2026-84145 Description
Uninitialized memory in MIME parsing. (CVE-2026-84639) One byte overflow read in mail parser. (CVE-2026-84640) Information disclosure due to malicious IMAP server response. (CVE-2026-84641) Calendar invitation attachments could launch local executables. (CVE-2026-84637) Allowed UNC hostnames for attachments interpreted as a regular expression. (CVE-2026-84642) Sandbox escape in the Remote Settings Client component. (CVE-2026-75874) Privilege escalation in the DOM: Workers component. (CVE-2026-16365) Use-after-free in the JavaScript: GC component. (CVE-2026-84118) Sandbox escape due to use-after-free in the DOM: Navigation component. (CVE-2026-84119) Use-after-free in the Audio/Video component. (CVE-2026-84120) Sandbox escape due to use-after-free in the DOM: Security component. (CVE-2026-84121) Use-after-free in the Audio/Video component. (CVE-2026-84122) Privilege escalation due to use-after-free in the Graphics: WebGPU component. (CVE-2026-84123) Use-after-free in the DOM: Core & HTML component. (CVE-2026-84124) Use-after-free in the DOM: Core & HTML component. (CVE-2026-84125) Privilege escalation in the DOM: Navigation component. (CVE-2026-16371) Privilege escalation in the Application Update component. (CVE-2026-74952) Site isolation issue in the DOM: Navigation component. (CVE-2026-84129) Information disclosure in the Graphics: WebGPU component. (CVE-2026-84130) Privilege escalation due to invalid pointer in the Graphics component. (CVE-2026-84131) Information disclosure in the Networking: HTTP component. (CVE-2026-84132) Site isolation issue in the DOM: Push Subscriptions component. (CVE-2026-84133) Other issue in the Profile Backup component. (CVE-2026-84134) Other issue in the DOM: Navigation component. (CVE-2026-84136) Spoofing issue in the DOM: Core & HTML component. (CVE-2026-84137) Clickjacking issue in the DOM: Events component. (CVE-2026-84139) Site isolation issue in the DOM: Navigation component. (CVE-2026-84140) Integer overflow in the Graphics: ImageLib component. (CVE-2026-84141) Internally found bugs fixed in Thunderbird 155, Thunderbird ESR 153.2 and Thunderbird ESR 140.15. (CVE-2026-84143) Internally found bugs fixed in Thunderbird 155 and Thunderbird ESR 153.2. (CVE-2026-84144) Internally found bugs fixed in Thunderbird 155, Thunderbird ESR 153.2 and Thunderbird ESR 140.15. (CVE-2026-84145) References
SRPMS 10/core
  • thunderbird-153.2.0-1.mga10
  • thunderbird-l10n-153.2.0-1.mga10
9/core
  • thunderbird-140.15.0-1.mga9
  • thunderbird-l10n-140.15.0-1.mga9

MGASA-2026-0387 - Updated firefox & nss packages fix security vulnerabilities

Mageia Security - 9 Septiembre, 2026 - 19:01
Publication date: 09 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-75874 , CVE-2026-16365 , CVE-2026-84118 , CVE-2026-84119 , CVE-2026-84120 , CVE-2026-84121 , CVE-2026-84122 , CVE-2026-84123 , CVE-2026-84124 , CVE-2026-84125 , CVE-2026-74952 , CVE-2026-84129 , CVE-2026-16371 , CVE-2026-84130 , CVE-2026-84131 , CVE-2026-84132 , CVE-2026-84133 , CVE-2026-84134 , CVE-2026-84136 , CVE-2026-84137 , CVE-2026-84139 , CVE-2026-84140 , CVE-2026-84141 , CVE-2026-84143 , CVE-2026-84144 , CVE-2026-84145 Description
Sandbox escape in the Remote Settings Client component. (CVE-2026-75874) Privilege escalation in the DOM: Workers component. (CVE-2026-16365) Use-after-free in the JavaScript: GC component. (CVE-2026-84118) Sandbox escape due to use-after-free in the DOM: Navigation component. (CVE-2026-84119) Use-after-free in the Audio/Video component. (CVE-2026-84120) Sandbox escape due to use-after-free in the DOM: Security component. (CVE-2026-84121) Use-after-free in the Audio/Video component. (CVE-2026-84122) Privilege escalation due to use-after-free in the Graphics: WebGPU component. (CVE-2026-84123) Use-after-free in the DOM: Core & HTML component. (CVE-2026-84124) Use-after-free in the DOM: Core & HTML component. (CVE-2026-84125) Privilege escalation in the DOM: Navigation component. (CVE-2026-16371) Privilege escalation in the Application Update component. (CVE-2026-74952) Site isolation issue in the DOM: Navigation component. (CVE-2026-84129) Information disclosure in the Graphics: WebGPU component. (CVE-2026-84130) Privilege escalation due to invalid pointer in the Graphics component. (CVE-2026-84131) Information disclosure in the Networking: HTTP component. (CVE-2026-84132) Site isolation issue in the DOM: Push Subscriptions component. (CVE-2026-84133) Other issue in the Profile Backup component. (CVE-2026-84134) Other issue in the DOM: Navigation component. (CVE-2026-84136) Spoofing issue in the DOM: Core & HTML component. (CVE-2026-84137) Clickjacking issue in the DOM: Events component. (CVE-2026-84139) Site isolation issue in the DOM: Navigation component. (CVE-2026-84140) Integer overflow in the Graphics: ImageLib component. (CVE-2026-84141) Internally found bugs fixed in Firefox 155, Firefox ESR 153.2 and Firefox ESR 140.15. (CVE-2026-84143) Internally found bugs fixed in Firefox 155 and Firefox ESR 153.2. (CVE-2026-84144) Internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox ESR 140.15 and Firefox ESR 115.40. (CVE-2026-84145) References
SRPMS 10/core
  • firefox-l10n-153.2.0-1.mga10
  • firefox-153.2.0-1.mga10
  • nss-3.128.0-1.mga10
9/core
  • firefox-l10n-140.15.0-1.mga9
  • firefox-140.15.0-1.mga9
  • nss-3.128.0-1.mga9

MGASA-2026-0386 - Updated wget packages fix a security vulnerability

Mageia Security - 9 Septiembre, 2026 - 19:01
Publication date: 09 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-16599 Description
Denial of Service in GNU wget. (CVE-2026-16599) References
SRPMS 10/core
  • wget-1.25.0-2.3.mga10
9/core
  • wget-1.21.4-1.5.mga9

MGASA-2026-0385 - Updated dovecot package fixes security vulnerabilities

Mageia Security - 9 Septiembre, 2026 - 05:15
Publication date: 09 Sep 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-33263 , CVE-2026-33607 , CVE-2026-27852 , CVE-2026-33606 , CVE-2026-33604 , CVE-2026-40014 , CVE-2026-40013 , CVE-2026-33605 , CVE-2026-40018 , CVE-2026-40019 , CVE-2026-40015 , CVE-2026-40017 , CVE-2026-40203 , CVE-2026-42007 , CVE-2026-40204 , CVE-2026-40205 , CVE-2026-42008 , CVE-2026-42395 , CVE-2026-42393 , CVE-2026-52681 , CVE-2026-42392 , CVE-2026-73208 , CVE-2026-73209 , CVE-2026-42391 , CVE-2026-52687 Description
submission-login: Panic when mail_max_userip_connections is reached: Panic: epoll_ctl(del, 8) failed: Bad file descriptor. (CVE-2026-33263) Dovecot IMAP LIST match_sub() Exponential Backtracking — CPU Denial of Service. (CVE-2026-33607) DoS by sending mail with bad header. (CVE-2026-27852) dsync: Mail content can cause dsync protocol injection. (CVE-2026-33606) SMTP Smuggling via Missing Dot-Stuffing After Bare Carriage Return. (CVE-2026-33604) IMAP THREAD REFERENCES O(N²) CPU DoS via Crafted References Header
(index-thread-links.c). (CVE-2026-40014) pigeonhole: Stack Buffer Underflow in Pigeonhole ManageSieve CHECKSCRIPT/PUTSCRIPT. (CVE-2026-40013) managesieve-login: Pre-auth crash. (CVE-2026-33605) MySQL multi-byte escaping wrong. (CVE-2026-40018) v2.4.3 regression: managesieve-login pre-auth infinite loop. (CVE-2026-40019) imap-hibernate can be crashed. (CVE-2026-40015) IMAP THREAD O(M³) CPU DoS via CRC32 Hash Collision in strmap (mail-index-strmap.c / hash2.c). (CVE-2026-40017) IMAP Compression Can Reveal Whether a Small Synced Email Body Matches Sender-Chosen Text. (CVE-2026-40203) Sieve editheader RCE. (CVE-2026-42007) acl: lda_mailbox_autocreate can bypass acl restrictions. (CVE-2026-40204) OAuth2 passdb scope enforcement bypass via OR semantics in remote validation path. (CVE-2026-40205) XCLIENT FORWARD= bare token not namespaced, allows nopassword injection via trusted proxy. (CVE-2026-42008) Single NUL-Byte XCLIENT FORWARD Payload Crashes. (CVE-2026-42395) doveadm_password or api key length can still be leaked with timing comparisons. (CVE-2026-42393) Sieve resource usage tracking lost when active script changes. (CVE-2026-52681) imap-urlauth leaks memory into user-visible error messages. (CVE-2026-42392) auth: db-oauth2: aud claim used as fallback for missing scope claim. (CVE-2026-73208) imap-login crash: Self-recursion on zero-output decompress chunks. (CVE-2026-73209) imap: Pre-login memory/CPU growth with ID command. (CVE-2026-42391) IMAP: COMPRESS ZSTD can cause excessive memory usage. (CVE-2026-52687) References
SRPMS 10/core
  • dovecot-2.4.5-2.mga10

MGASA-2026-0384 - Updated spice-vdagent packages fix security vulnerabilities

Mageia Security - 9 Septiembre, 2026 - 05:15
Publication date: 09 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-57965 , CVE-2026-57966 Description
Integer overflow in udscs_write() leading to heap buffer overflow. (CVE-2026-57965) Path traversal in file transfer via unsanitized filename. (CVE-2026-57966) References
SRPMS 10/core
  • spice-vdagent-0.23.0-1.1.mga10
9/core
  • spice-vdagent-0.22.1-2.1.mga9

MGAA-2026-0122 - Updated python-intervaltree package fixes bug

Mageia Security - 9 Septiembre, 2026 - 05:15
Publication date: 09 Sep 2026
Type: bugfix
Affected Mageia releases : 10
Description
python3-intervaltree have a missing requirement on python3-sortedcontainers, this produce that the python IDE Spyder crash at start. This update fixes the reported issue. References
SRPMS 10/core
  • python-intervaltree-3.2.0-1.1.mga10

MGASA-2026-0383 - Updated freerdp packages fix security vulnerabilities

Mageia Security - 8 Septiembre, 2026 - 03:47
Publication date: 08 Sep 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-22851 , CVE-2026-22853 , CVE-2026-22858 , CVE-2026-25941 , CVE-2026-25942 , CVE-2026-25952 , CVE-2026-25953 , CVE-2026-25954 , CVE-2026-25955 , CVE-2026-25959 , CVE-2026-25997 , CVE-2026-26952 , CVE-2026-33977 , CVE-2026-33982 , CVE-2026-33983 , CVE-2026-33984 , CVE-2026-33985 , CVE-2026-33986 , CVE-2026-33987 , CVE-2026-33995 , CVE-2026-27015 , CVE-2026-27951 , CVE-2026-40033 , CVE-2026-44420 , CVE-2026-44421 , CVE-2026-44422 , CVE-2026-45700 , CVE-2026-55191 , CVE-2026-55192 , CVE-2026-55193 , CVE-2026-55194 , CVE-2026-55648 Description
Updated packages bring lot of security fixes. Please see the links for additional information. References
SRPMS 10/core
  • freerdp-3.31.0-1.mga10

MGASA-2026-0382 - Updated tor packages fix security vulnerabilities

Mageia Security - 8 Septiembre, 2026 - 03:47
Publication date: 08 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-77584 , CVE-2026-77587 , CVE-2026-77638 , CVE-2026-77639 , CVE-2026-77640 , CVE-2026-77641 , CVE-2026-77642 Description
An out-of-bounds write when parsing a consensus or detached signature with unexpected signature digest type (CVE-2026-77642). A NULL write after free when sending a CONFLUX_SWITCH cell fails, resulting in a crash (CVE-2026-77641). An infinite loop when decompressing a truncated zlib/gzip stream with done=1 (CVE-2026-77640). A compression bomb bypass where an attacker could concatenate many gzip or zlib sub-streams (CVE-2026-77639). A race condition where in just the right circumstances a rendezvous point could man-in-the-middle (impersonate) the onion service that the client was trying to reach (CVE-2026-77638). A use-after-free that a malicious exit node could use to crash a client (CVE-2026-77587). Tor before 0.4.9.10 did not reject a CONFLUX_LINK cell that arrives on a circuit which already has attached streams (CVE-2026-77584). References
SRPMS 10/core
  • tor-0.4.9.11-1.mga10
9/core
  • tor-0.4.9.11-1.mga9

MGASA-2026-0381 - Updated apache-mod_auth_openidc packages fix a security vulnerability

Mageia Security - 7 Septiembre, 2026 - 19:46
Publication date: 07 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-54789 Description
Out-of-bounds read and write in state cookie parsing. (CVE-2026-54789) References
SRPMS 10/core
  • apache-mod_auth_openidc-2.4.20.2-1.mga10
9/core
  • apache-mod_auth_openidc-2.4.20.2-1.mga9

MGASA-2026-0380 - Updated python-pyasn1 packages fix security vulnerabilities

Mageia Security - 7 Septiembre, 2026 - 19:46
Publication date: 07 Sep 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-59884 , CVE-2026-59885 , CVE-2026-59886 Description
The BER decoder (shared by the CER and DER codecs) parses long-form tags by accumulating continuation octets in a loop with no upper bound on the size of the tag ID. A crafted input can force the decoder to build an arbitrarily large integer, with CPU cost growing quadratically in input size — a ~1 MB input consumes over a minute of CPU. On Python 3.11+, the oversized tag ID can also trigger an unhandled ValueError (integer string conversion limit) while the decoder formats error messages, violating the documented PyAsn1Error contract and potentially bypassing caller error handling. References
SRPMS 10/core
  • python-pyasn1-0.6.4-1.mga10

MGAA-2026-0121 - Updated radiotray-ng package fixes bug

Mageia Security - 7 Septiembre, 2026 - 19:46
Publication date: 07 Sep 2026
Type: bugfix
Affected Mageia releases : 10
Description
Update the stream links for "KDFC", "CINEMIX", "Radio Paradise", and remove the offline "WNAR-AM Radio" station. References
SRPMS 10/core
  • radiotray-ng-0.2.10-1.mga10

MGAA-2026-0120 - Updated tilibs & tilp2 packages fix bug

Mageia Security - 7 Septiembre, 2026 - 19:46
Publication date: 07 Sep 2026
Type: bugfix
Affected Mageia releases : 10
Description
tilp2 crashes immediately at startup. This update fixes the reported issue. References
SRPMS 10/core
  • tilibs-1.19-1.mga10
  • tilp2-1.19-1.mga10

MGASA-2026-0378 - Updated mingw-expat & expat packages fix security vulnerabilities

Mageia Security - 5 Septiembre, 2026 - 05:35
Publication date: 05 Sep 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-66046 , CVE-2026-76641 , CVE-2026-76956 , CVE-2026-76957 Description
Expat Denial of Service via storeAtts() Quadratic Complexity. (CVE-2026-66046) Expat Out-of-Bounds Read via dtdCopy. (CVE-2026-76641) In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted XML content. (CVE-2026-76956) libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. (CVE-2026-76957) References
SRPMS 10/core
  • mingw-expat-2.8.4-1.mga10
  • expat-2.8.4-1.mga10

MGASA-2026-0377 - Updated python-linkify-it-py package fixes security vulnerabilities

Mageia Security - 5 Septiembre, 2026 - 05:35
Publication date: 05 Sep 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-48801 , CVE-2026-59887 Description
LinkifyIt.match() was quadratic on untrusted input when linkify is enabled (GHSA-8m2q-wq3r-6hq8). Fix quadratic complexity in LinkifyIt.match(), port of linkify-it 5.0.1 and 5.0.2 (upstream CVE-2026-48801, CVE-2026-59887) (#82) Match validators at a position instead of slicing the tail, needed because Python 3.10 does not optimize the ^ anchor (#82) Allow ; in the email name, matching linkify-it. Behavior change: a;b@example.com is now linkified (#82) References
SRPMS 10/core
  • python-linkify-it-py-2.1.1-1.mga10

MGASA-2026-0376 - Updated tomcat packages fix security vulnerabilities

Mageia Security - 4 Septiembre, 2026 - 18:53
Publication date: 04 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-59083 , CVE-2026-59084 , CVE-2026-66299 , CVE-2026-65182 , CVE-2026-65183 , CVE-2026-65637 , CVE-2026-65905 , CVE-2026-65927 , CVE-2026-66422 , CVE-2026-68525 , CVE-2026-68569 , CVE-2026-68763 , CVE-2026-73180 Description
Incorrect URL decoding in RewriteValve may allow security control bypass. (CVE-2026-59083) EncryptInterceptor requirements not clearly documented. (CVE-2026-59084) DoS via WebSocket chat example. (CVE-2026-66299) Bypass longest prefix security constraint. (CVE-2026-65182) TOCTOU when setting specific permissions for Unix Domain Sockets. (CVE-2026-65183) HTTP/2 no-authority bypass of strict SNI validation - CVE-2026-32990 fix incomplete. (CVE-2026-65637) Limited replay attack possible with DIGEST authentication. (CVE-2026-65905) RewriteValve [N] restarts at the second rule and may bypass access control. (CVE-2026-65927) Servlet role references can bypass declarative role constraints. (CVE-2026-66422) Redirect after FORM auth may bypass method specific constraints. (CVE-2026-68525) Principal lookup can fail open in some cases. (CVE-2026-68569) DoS via allocation leak in HTTP/2 backlog tracking when a stream is reset. (CVE-2026-68763) Authenticated WebSocket session survives end of HTTP session. (CVE-2026-73180) References
SRPMS 10/core
  • tomcat-9.0.121-1.mga10
9/core
  • tomcat-9.0.121-1.mga9

MGASA-2026-0375 - Updated mbedtls packages fix security vulnerabilities

Mageia Security - 4 Septiembre, 2026 - 18:53
Publication date: 04 Sep 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-25832 , CVE-2026-35336 , CVE-2026-49300 , CVE-2026-50579 , CVE-2026-50580 , CVE-2026-50581 , CVE-2026-50583 , CVE-2026-50584 , CVE-2026-50585 , CVE-2026-50586 , CVE-2026-50587 , CVE-2026-50588 , CVE-2026-50640 , CVE-2026-50713 , CVE-2026-54435 , CVE-2026-54441 , CVE-2026-73064 Description
TLS 1.3 client accepts HelloRetryRequest selecting an unadvertised group. (CVE-2026-25832) Possible buffer overflow in mbedtls_ecdh_calc_secret(). (CVE-2026-35336) X.509 CA bit forgery via invalid basicConstraints extension. (CVE-2026-49300) Use-after-free in mbedtls_pkcs7_free() when reusing a PKCS7 context. (CVE-2026-50579) Remote buffer overflow in TLS 1.2 ECDHE-PSK client handshake. (CVE-2026-50580) Extended master secret calculation failure ignored. (CVE-2026-50581) A 1-byte buffer overread when parsing a malformed ECC public key in the PK module. (CVE-2026-50583) ChaCha20 counter overflow can reuse keystream. (CVE-2026-50584) Incomplete context reset in mbedtls_ssl_session_reset(). (CVE-2026-50585) A potential information disclosure in TLS 1.2 servers using session tickets. If the session ticket write callback failed without setting the lifetime output parameter, Mbed TLS could send 4 bytes of uninitialized stack memory to the peer in the NewSessionTicket message. (CVE-2026-50586) Timing side-channel in RSA PKCS#1 v1.5 decryption. (CVE-2026-50587) Out-of-bounds read in TLS 1.2 EC J-PAKE ServerKeyExchange parsing. (CVE-2026-50588) Ignored TLS 1.3 resumption secret derivation error. (CVE-2026-50640) Heap corruption with early renegotiation after corrupted record in DTLS. (CVE-2026-50713) Side channel leak in ECC optimized modp. (CVE-2026-54435) Signature algorithm restrictions not enforced on certificate chain. (CVE-2026-54441) A random generator fault can compromise TLS data integrity. (CVE-2026-73064) References
SRPMS 10/core
  • mbedtls-3.6.7-1.mga10

MGASA-2026-0374 - Updated microcode packages fix security vulnerabilities

Mageia Security - 4 Septiembre, 2026 - 18:53
Publication date: 04 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2025-31936 , CVE-2025-31938 , CVE-2026-20917 , CVE-2025-35973 , CVE-2026-20716 , CVE-2026-20760 , CVE-2026-20713 , CVE-2026-20707 Description
A potential security vulnerability for some Intel® Xeon® 6 processor with Intel® Trust Domain Extensions (Intel® TDX) may allow escalation of privilege. (CVE-2025-31936) A potential security vulnerability in some Intel® Xeon® 6 processor with Intel® Trust Domain Extensions (Intel® TDX) may allow information disclosure. (CVE-2025-31938) A potential security vulnerability in some Intel® Processors may allow information disclosure. (CVE-2026-20917) A potential security vulnerability in some Intel® Processors may allow escalation of privilege. (CVE-2025-35973) A potential security vulnerability in some Intel® Processors may allow escalation of privilege. (CVE-2026-20716) A potential security vulnerability in some Intel® Processors may allow denial of service. (CVE-2026-20760) Potential security vulnerabilities in some Intel® Xeon® Processors may allow escalation of privilege. (CVE-2026-20713) A potential security vulnerability in some 3rd Gen Intel® Xeon® Scalable Processors may allow denial of service. (CVE-2026-20707) References
SRPMS 10/nonfree
  • microcode-0.20260812-1.mga10.nonfree
9/nonfree
  • microcode-0.20260812-1.mga9.nonfree

MGASA-2026-0372 - Updated python-gitpython packages fix security vulnerabilities

Mageia Security - 3 Septiembre, 2026 - 19:06
Publication date: 03 Sep 2026
Type: security
Affected Mageia releases : 9
CVE: CVE-2023-40267 , CVE-2023-41040 , CVE-2026-42215 Description
CVE-2023-40267 GitPython before 3.1.32 does not block insecure non-multi options in clone and clone_from. NOTE: this issue exists because of an incomplete fix for CVE-2022-24439. CVE-2023-41040 In order to resolve some git references, GitPython reads files from the `.git` directory, in some places the name of the file being read is provided by the user, GitPython doesn't check if this file is located outside the `.git` directory. This allows an attacker to make GitPython read any file from the system. CVE-2026-42215 From version 3.1.30 to before version 3.1.47, GitPython blocks dangerous Git options such as --upload-pack and --receive-pack by default, but the equivalent Python kwargs upload_pack and receive_pack bypass that check. If an application passes attacker-controlled kwargs into Repo.clone_from(), Remote.fetch(), Remote.pull(), or Remote.push(), this leads to arbitrary command execution even when allow_unsafe_options is left at its default value of False. This issue has been patched in version 3.1.47. References
SRPMS 9/core
  • python-gitpython-3.1.50-1.mga9
Feed