Actualizaciones de Seguridad

MGAA-2026-0119 - Updated drakx-net packages add nl80211 (iw) scan and WPA3 (SAE) support

Mageia Security - 3 Septiembre, 2026 - 19:06
Publication date: 03 Sep 2026
Type: bugfix
Affected Mageia releases : 10 , 9
Description
Our drakx.net packages still depended on deprecated wext (iwlist), causing problems with finding and connecting to networks for several users. This update adds both nl80211 (iw) scan and WPA3 (SAE) support, thus fixing the issues. References
SRPMS 10/core
  • drakx-net-2.65-1.mga10
9/core
  • drakx-net-2.65-1.mga9

MGASA-2026-0371 - Updated bubblewrap package fixes security vulnerabilities

Mageia Security - 2 Septiembre, 2026 - 17:59
Publication date: 02 Sep 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-87766 Description
Sandbox escape: symlink traversal via /oldroot allows writing files outside sandbox during setup References
SRPMS 10/core
  • bubblewrap-0.12.0-1.mga10

MGASA-2026-0370 - Updated perl-Text-CSV_XS packages fix a security vulnerability

Mageia Security - 2 Septiembre, 2026 - 17:59
Publication date: 02 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-7111 Description
Text::CSV_XS versions before 1.62 for Perl have a use-after-free when registered callbacks extend the Perl argument stack, which may enable type confusion or memory corruption. References
SRPMS 10/core
  • perl-Text-CSV_XS-1.640.0-1.mga10
9/core
  • perl-Text-CSV_XS-1.640.0-1.mga9

MGASA-2026-0369 - Updated libalsa2 packages fix security vulnerabilities

Mageia Security - 2 Septiembre, 2026 - 17:59
Publication date: 02 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-25068 , CVE-2026-56109 Description
alsa-lib 1.2.15.2 Topology Decoder Heap-based Buffer Overflow. (CVE-2026-25068) ALSA Library < 1.2.16.1 Double-Free via parse_def() in conf.c. (CVE-2026-56109) References
SRPMS 10/core
  • libalsa2-1.2.15.2-1.1.mga10
9/core
  • libalsa2-1.2.9-1.1.mga9

MGASA-2026-0368 - Updated perl-XML-Bare packages fix security vulnerabilities

Mageia Security - 2 Septiembre, 2026 - 17:59
Publication date: 02 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-57074 , CVE-2026-13401 Description
XML::Bare versions through 0.53 for Perl have an unbounded character lookahead. XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attributes. References
SRPMS 10/core
  • perl-XML-Bare-0.530.0-26.mga10
9/core
  • perl-XML-Bare-0.530.0-22.mga9

MGASA-2026-0367 - Updated perl-YAML-Syck packages fix security vulnerabilities

Mageia Security - 2 Septiembre, 2026 - 17:59
Publication date: 02 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-13713 , CVE-2026-57075 , CVE-2026-57076 , CVE-2026-57077 Description
YAML::Syck versions before 1.47 for Perl allow a use-after-free and double-free via an anchor node freed while still on the parser value stack YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via a signed-char lookup-table index in syck_base64dec YAML::Syck versions before 1.47 for Perl allow a heap use-after-free via an anchor name reused as an anchors-table key in syck_hdlr_add_anchor YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via an unbounded newline scan in newline_len References
SRPMS 10/core
  • perl-YAML-Syck-1.470.0-1.mga10
9/core
  • perl-YAML-Syck-1.470.0-1.mga9

MGASA-2026-0366 - Updated libarchive packages fix security vulnerabilities

Mageia Security - 2 Septiembre, 2026 - 17:59
Publication date: 02 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-14164 , CVE-2026-15028 , CVE-2026-5745 , CVE-2025-5918 , CVE-2025-60753 , CVE-2026-4111 , CVE-2026-4424 , CVE-2026-4426 , CVE-2026-5121 Description
Double-free vulnerability in rar5 decompression logic via dangling filtered_buf pointer in init_unpack(). (CVE-2026-14164) Heap overflow oob read while parsing a tar archive contains a pax extended header. (CVE-2026-15028) A null pointer dereference vulnerability exists in the acl parser of libarchive. (CVE-2026-5745) Reading past eof may be triggered for piped file streams. (CVE-2025-5918) An issue was discovered in libarchive bsdtar before version 3.8.1 in function apply_substitution in file tar/subst.c when processing crafted -s substitution rules. This can cause unbounded memory allocation and lead to denial of service (Out-of-Memory crash). (CVE-2025-60753) Infinite loop denial of service in rar5 decompression via archive_read_data() in libarchive. (CVE-2026-4111) Information disclosure via heap out-of-bounds read in rar archive processing. (CVE-2026-4424) Denial of service via malformed iso file processing. (CVE-2026-4426) Arbitrary code execution via integer overflow in iso9660 image processing. (CVE-2026-5121) References
SRPMS 10/core
  • libarchive-3.8.9-1.mga10
9/core
  • libarchive-3.6.2-5.6.mga9

MGASA-2026-0365 - Updated perl-Net-OAuth packages fix security vulnerabilities

Mageia Security - 2 Septiembre, 2026 - 17:59
Publication date: 02 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-72887 , CVE-2026-72888 , CVE-2026-72889 , CVE-2026-75589 Description
Net::OAuth::Client versions before 0.32 for Perl allow the service provider to silently downgrade OAuth 1.0a to OAuth 1.0 in get_request_token Net::OAuth versions before 0.32 for Perl allow memory exhaustion via unbounded caching of failed module loads in smart_require Net::OAuth versions before 0.33 for Perl allow the sender to choose the signature algorithm in verify Net::OAuth versions before 0.33 for Perl check HMAC-SHA1, HMAC-SHA256 and PLAINTEXT signatures with a non-constant-time comparison in verify References
SRPMS 10/core
  • perl-Net-OAuth-0.330.0-1.mga10
9/core
  • perl-Net-OAuth-0.330.0-1.mga9

MGASA-2026-0364 - Updated apr-util packages fix security vulnerabilities

Mageia Security - 2 Septiembre, 2026 - 17:59
Publication date: 02 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2025-49506 , CVE-2026-32327 , CVE-2026-34191 , CVE-2026-34501 , CVE-2026-34502 Description
Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack. (CVE-2025-49506) Apache Portable Runtime Utility: apr-util XML stack recursion crash. (CVE-2026-32327) Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracle. (CVE-2026-34191) Apache Portable Runtime Utility: Heap buffer overflow in APR redis client. (CVE-2026-34501) Apache Portable Runtime Utility: Heap buffer overflow in APR memcached client. (CVE-2026-34502) References
SRPMS 10/core
  • apr-util-1.6.3-3.1.mga10
9/core
  • apr-util-1.6.3-1.1.mga9

MGAA-2026-0118 - Updated opencpn-climatology-plugin package fixes bug

Mageia Security - 2 Septiembre, 2026 - 17:59
Publication date: 02 Sep 2026
Type: bugfix
Affected Mageia releases : 10
Description
Updated package provides more recent climatology data (data from 2026) than the previous version (data from 2019). References
SRPMS 10/core
  • opencpn-climatology-plugin-1.6.37.0-1.git20260510.mga10

MGASA-2026-0362 - Updated perl-HTTP-Date packages fix a security vulnerability

Mageia Security - 1 Septiembre, 2026 - 08:04
Publication date: 01 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-14741 Description
HTTP::Date versions before 6.08 for Perl allow CPU exhaustion via polynomial regex backtracking in parse_date References
SRPMS 10/core
  • perl-HTTP-Date-6.80.0-1.mga10
9/core
  • perl-HTTP-Date-6.80.0-1.mga9

MGASA-2026-0361 - Updated perl-Date-Manip packages fix security vulnerabilities

Mageia Security - 1 Septiembre, 2026 - 08:04
Publication date: 01 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-60074 , CVE-2026-60075 Description
Date::Manip versions through 6.99 for Perl return corrupted dates via non-ASCII decimal digits that pass the numeric range tests in check Date::Manip versions through 6.99 for Perl allow CPU exhaustion via quadratic backtracking in the unanchored time substitution in _parse_time References
SRPMS 10/core
  • perl-Date-Manip-6.990.0-1.mga10
9/core
  • perl-Date-Manip-6.990.0-1.mga9

MGASA-2026-0360 - Updated perl-HTML-FormHandler packages fix a security vulnerability

Mageia Security - 1 Septiembre, 2026 - 08:04
Publication date: 01 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2022-4993 Description
HTML::FormHandler versions through 0.40068 for Perl allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notation template References
SRPMS 10/core
  • perl-HTML-FormHandler-0.400.680-8.mga10
9/core
  • perl-HTML-FormHandler-0.400.680-6.mga9

MGASA-2026-0359 - Updated nodejs packages fix security vulnerabilities

Mageia Security - 1 Septiembre, 2026 - 04:06
Publication date: 01 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-56846 , CVE-2026-56848 , CVE-2026-58043 , CVE-2026-56850 , CVE-2026-58040 , CVE-2026-58042 , CVE-2026-58045 , CVE-2026-56847 , CVE-2026-58039 , CVE-2026-58044 Description
http2: retain header memory in session accounting. (CVE-2026-56846) http2: defer rst stream while in scope. (CVE-2026-56848) permission: avoid granting radix split nodes. (CVE-2026-58043) https: distinguish PFX object-array agent keys. (CVE-2026-56850) https: bind identity checks to session reuse. (CVE-2026-58040) dns: handle large resolveAny address replies. (CVE-2026-58042) zlib: throw on out-of-bounds write buffers. (CVE-2026-58045) permission: enforce fs write permission for trace events. (CVE-2026-56847) permission: check final report output path. (CVE-2026-58039) http: reject requests exceeding max header count. (CVE-2026-58044) References
SRPMS 10/core
  • nodejs-22.23.2-1.mga10
9/core
  • nodejs-22.23.2-1.mga9

MGASA-2026-0358 - Updated roundcubemail packages fix security vulnerabilities

Mageia Security - 1 Septiembre, 2026 - 04:06
Publication date: 01 Sep 2026
Type: security
Affected Mageia releases : 9
Description
* Add basic validation for content proxied by the css proxy acta2.jpg acta.jpg advisories avatar.jpg avatar.png bdk-key.bkup bdk-mga9.txt bdk-new.key bdkpackagers.key bdkpackagers.sec bdkpass bin blogdrake.net bookmarks.html BRF Descargas Desktop diagrana.pdf discover-missing Documentos Dragon Quest: Dai no Daibouken - Bravest Full OP Sub Español [2MZON1ev9DE].mkv ejemplo añadir_archivo1.spec ejemplo añadir_archivo2.spec google-chrome.spec html i18n.pdf Imágenes index.php kernel-backport kernel-cves.enc kernel-cves.txt lqshell-stylesheet.css mageia-advisories MANOLO MUÑOZ VS ALBERTO VAZQUEZ MANO A MANO 24 EXITAZOS RANCHEROS CON MARIACHI.opus MEGA megasync-10.tar.gz #*message*-20260914-112747# mgaadv-error.txt mgarepo mirrorbdk mock Música origen.rss out.pnm PDF Plantillas Precure News - Star Detective PreCure! OP (Movie Footage Edition) [2099120870992310272].mp4 Proyectos qatest qa-testing qphotorec.desktop qphotorec.log reinstall.sh repodkfix.sh repositorio rpm rss Sailor Moon Cosmos AMV - Makenai (Sailor Star Song).mp4 sshrc style.html Taylor Swift, les coulisses du succès [120464-000-A].mp4 test.jpg tmp update-bdkkey.sh urpm-ng-distupgrade-orphans vdhcoapp-2.0.19 Ventoy Backup Vídeos VirtualBox VMs xen test xen-mga#33082 YAML-LibYAML-Test-dir zekemx Fix SSRF bypass via specific local address URLs using 100.64.0.0/10 and fe80::/10 nets, reported by Dmytro Ivanenko acta2.jpg acta.jpg advisories avatar.jpg avatar.png bdk-key.bkup bdk-mga9.txt bdk-new.key bdkpackagers.key bdkpackagers.sec bdkpass bin blogdrake.net bookmarks.html BRF Descargas Desktop diagrana.pdf discover-missing Documentos Dragon Quest: Dai no Daibouken - Bravest Full OP Sub Español [2MZON1ev9DE].mkv ejemplo añadir_archivo1.spec ejemplo añadir_archivo2.spec google-chrome.spec html i18n.pdf Imágenes index.php kernel-backport kernel-cves.enc kernel-cves.txt lqshell-stylesheet.css mageia-advisories MANOLO MUÑOZ VS ALBERTO VAZQUEZ MANO A MANO 24 EXITAZOS RANCHEROS CON MARIACHI.opus MEGA megasync-10.tar.gz #*message*-20260914-112747# mgaadv-error.txt mgarepo mirrorbdk mock Música origen.rss out.pnm PDF Plantillas Precure News - Star Detective PreCure! OP (Movie Footage Edition) [2099120870992310272].mp4 Proyectos qatest qa-testing qphotorec.desktop qphotorec.log reinstall.sh repodkfix.sh repositorio rpm rss Sailor Moon Cosmos AMV - Makenai (Sailor Star Song).mp4 sshrc style.html Taylor Swift, les coulisses du succès [120464-000-A].mp4 test.jpg tmp update-bdkkey.sh urpm-ng-distupgrade-orphans vdhcoapp-2.0.19 Ventoy Backup Vídeos VirtualBox VMs xen test xen-mga#33082 YAML-LibYAML-Test-dir zekemx Fix SSRF filter bypass via various forms of nip.io/sslip.io hostnames evading is_local_url() check, reported by Milan Hoppe acta2.jpg acta.jpg advisories avatar.jpg avatar.png bdk-key.bkup bdk-mga9.txt bdk-new.key bdkpackagers.key bdkpackagers.sec bdkpass bin blogdrake.net bookmarks.html BRF Descargas Desktop diagrana.pdf discover-missing Documentos Dragon Quest: Dai no Daibouken - Bravest Full OP Sub Español [2MZON1ev9DE].mkv ejemplo añadir_archivo1.spec ejemplo añadir_archivo2.spec google-chrome.spec html i18n.pdf Imágenes index.php kernel-backport kernel-cves.enc kernel-cves.txt lqshell-stylesheet.css mageia-advisories MANOLO MUÑOZ VS ALBERTO VAZQUEZ MANO A MANO 24 EXITAZOS RANCHEROS CON MARIACHI.opus MEGA megasync-10.tar.gz #*message*-20260914-112747# mgaadv-error.txt mgarepo mirrorbdk mock Música origen.rss out.pnm PDF Plantillas Precure News - Star Detective PreCure! OP (Movie Footage Edition) [2099120870992310272].mp4 Proyectos qatest qa-testing qphotorec.desktop qphotorec.log reinstall.sh repodkfix.sh repositorio rpm rss Sailor Moon Cosmos AMV - Makenai (Sailor Star Song).mp4 sshrc style.html Taylor Swift, les coulisses du succès [120464-000-A].mp4 test.jpg tmp update-bdkkey.sh urpm-ng-distupgrade-orphans vdhcoapp-2.0.19 Ventoy Backup Vídeos VirtualBox VMs xen test xen-mga#33082 YAML-LibYAML-Test-dir zekemx Fix remote content blocking bypass via unclosed url() in a FuncIRI attribute, reported by Milan Hoppe acta2.jpg acta.jpg advisories avatar.jpg avatar.png bdk-key.bkup bdk-mga9.txt bdk-new.key bdkpackagers.key bdkpackagers.sec bdkpass bin blogdrake.net bookmarks.html BRF Descargas Desktop diagrana.pdf discover-missing Documentos Dragon Quest: Dai no Daibouken - Bravest Full OP Sub Español [2MZON1ev9DE].mkv ejemplo añadir_archivo1.spec ejemplo añadir_archivo2.spec google-chrome.spec html i18n.pdf Imágenes index.php kernel-backport kernel-cves.enc kernel-cves.txt lqshell-stylesheet.css mageia-advisories MANOLO MUÑOZ VS ALBERTO VAZQUEZ MANO A MANO 24 EXITAZOS RANCHEROS CON MARIACHI.opus MEGA megasync-10.tar.gz #*message*-20260914-112747# mgaadv-error.txt mgarepo mirrorbdk mock Música origen.rss out.pnm PDF Plantillas Precure News - Star Detective PreCure! OP (Movie Footage Edition) [2099120870992310272].mp4 Proyectos qatest qa-testing qphotorec.desktop qphotorec.log reinstall.sh repodkfix.sh repositorio rpm rss Sailor Moon Cosmos AMV - Makenai (Sailor Star Song).mp4 sshrc style.html Taylor Swift, les coulisses du succès [120464-000-A].mp4 test.jpg tmp update-bdkkey.sh urpm-ng-distupgrade-orphans vdhcoapp-2.0.19 Ventoy Backup Vídeos VirtualBox VMs xen test xen-mga#33082 YAML-LibYAML-Test-dir zekemx Fix LDAP filter injection via unescaped %u/%fu/%d substitution into the `search_filter`, reported by Milan Hoppe acta2.jpg acta.jpg advisories avatar.jpg avatar.png bdk-key.bkup bdk-mga9.txt bdk-new.key bdkpackagers.key bdkpackagers.sec bdkpass bin blogdrake.net bookmarks.html BRF Descargas Desktop diagrana.pdf discover-missing Documentos Dragon Quest: Dai no Daibouken - Bravest Full OP Sub Español [2MZON1ev9DE].mkv ejemplo añadir_archivo1.spec ejemplo añadir_archivo2.spec google-chrome.spec html i18n.pdf Imágenes index.php kernel-backport kernel-cves.enc kernel-cves.txt lqshell-stylesheet.css mageia-advisories MANOLO MUÑOZ VS ALBERTO VAZQUEZ MANO A MANO 24 EXITAZOS RANCHEROS CON MARIACHI.opus MEGA megasync-10.tar.gz #*message*-20260914-112747# mgaadv-error.txt mgarepo mirrorbdk mock Música origen.rss out.pnm PDF Plantillas Precure News - Star Detective PreCure! OP (Movie Footage Edition) [2099120870992310272].mp4 Proyectos qatest qa-testing qphotorec.desktop qphotorec.log reinstall.sh repodkfix.sh repositorio rpm rss Sailor Moon Cosmos AMV - Makenai (Sailor Star Song).mp4 sshrc style.html Taylor Swift, les coulisses du succès [120464-000-A].mp4 test.jpg tmp update-bdkkey.sh urpm-ng-distupgrade-orphans vdhcoapp-2.0.19 Ventoy Backup Vídeos VirtualBox VMs xen test xen-mga#33082 YAML-LibYAML-Test-dir zekemx Fix arbitrary Sieve script injection via a filter rule name bypassing `managesieve_disabled_actions`, reported by Milan Hoppe acta2.jpg acta.jpg advisories avatar.jpg avatar.png bdk-key.bkup bdk-mga9.txt bdk-new.key bdkpackagers.key bdkpackagers.sec bdkpass bin blogdrake.net bookmarks.html BRF Descargas Desktop diagrana.pdf discover-missing Documentos Dragon Quest: Dai no Daibouken - Bravest Full OP Sub Español [2MZON1ev9DE].mkv ejemplo añadir_archivo1.spec ejemplo añadir_archivo2.spec google-chrome.spec html i18n.pdf Imágenes index.php kernel-backport kernel-cves.enc kernel-cves.txt lqshell-stylesheet.css mageia-advisories MANOLO MUÑOZ VS ALBERTO VAZQUEZ MANO A MANO 24 EXITAZOS RANCHEROS CON MARIACHI.opus MEGA megasync-10.tar.gz #*message*-20260914-112747# mgaadv-error.txt mgarepo mirrorbdk mock Música origen.rss out.pnm PDF Plantillas Precure News - Star Detective PreCure! OP (Movie Footage Edition) [2099120870992310272].mp4 Proyectos qatest qa-testing qphotorec.desktop qphotorec.log reinstall.sh repodkfix.sh repositorio rpm rss Sailor Moon Cosmos AMV - Makenai (Sailor Star Song).mp4 sshrc style.html Taylor Swift, les coulisses du succès [120464-000-A].mp4 test.jpg tmp update-bdkkey.sh urpm-ng-distupgrade-orphans vdhcoapp-2.0.19 Ventoy Backup Vídeos VirtualBox VMs xen test xen-mga#33082 YAML-LibYAML-Test-dir zekemx Fix RCE via cmd_learn driver of markasjunk plugin, reported by nept1337 acta2.jpg acta.jpg advisories avatar.jpg avatar.png bdk-key.bkup bdk-mga9.txt bdk-new.key bdkpackagers.key bdkpackagers.sec bdkpass bin blogdrake.net bookmarks.html BRF Descargas Desktop diagrana.pdf discover-missing Documentos Dragon Quest: Dai no Daibouken - Bravest Full OP Sub Español [2MZON1ev9DE].mkv ejemplo añadir_archivo1.spec ejemplo añadir_archivo2.spec google-chrome.spec html i18n.pdf Imágenes index.php kernel-backport kernel-cves.enc kernel-cves.txt lqshell-stylesheet.css mageia-advisories MANOLO MUÑOZ VS ALBERTO VAZQUEZ MANO A MANO 24 EXITAZOS RANCHEROS CON MARIACHI.opus MEGA megasync-10.tar.gz #*message*-20260914-112747# mgaadv-error.txt mgarepo mirrorbdk mock Música origen.rss out.pnm PDF Plantillas Precure News - Star Detective PreCure! OP (Movie Footage Edition) [2099120870992310272].mp4 Proyectos qatest qa-testing qphotorec.desktop qphotorec.log reinstall.sh repodkfix.sh repositorio rpm rss Sailor Moon Cosmos AMV - Makenai (Sailor Star Song).mp4 sshrc style.html Taylor Swift, les coulisses du succès [120464-000-A].mp4 test.jpg tmp update-bdkkey.sh urpm-ng-distupgrade-orphans vdhcoapp-2.0.19 Ventoy Backup Vídeos VirtualBox VMs xen test xen-mga#33082 YAML-LibYAML-Test-dir zekemx Fix IMAP command injection via mail search and LITERAL+ byte-count desynchronization, reported by Zach Hanley of Horizon3.ai acta2.jpg acta.jpg advisories avatar.jpg avatar.png bdk-key.bkup bdk-mga9.txt bdk-new.key bdkpackagers.key bdkpackagers.sec bdkpass bin blogdrake.net bookmarks.html BRF Descargas Desktop diagrana.pdf discover-missing Documentos Dragon Quest: Dai no Daibouken - Bravest Full OP Sub Español [2MZON1ev9DE].mkv ejemplo añadir_archivo1.spec ejemplo añadir_archivo2.spec google-chrome.spec html i18n.pdf Imágenes index.php kernel-backport kernel-cves.enc kernel-cves.txt lqshell-stylesheet.css mageia-advisories MANOLO MUÑOZ VS ALBERTO VAZQUEZ MANO A MANO 24 EXITAZOS RANCHEROS CON MARIACHI.opus MEGA megasync-10.tar.gz #*message*-20260914-112747# mgaadv-error.txt mgarepo mirrorbdk mock Música origen.rss out.pnm PDF Plantillas Precure News - Star Detective PreCure! OP (Movie Footage Edition) [2099120870992310272].mp4 Proyectos qatest qa-testing qphotorec.desktop qphotorec.log reinstall.sh repodkfix.sh repositorio rpm rss Sailor Moon Cosmos AMV - Makenai (Sailor Star Song).mp4 sshrc style.html Taylor Swift, les coulisses du succès [120464-000-A].mp4 test.jpg tmp update-bdkkey.sh urpm-ng-distupgrade-orphans vdhcoapp-2.0.19 Ventoy Backup Vídeos VirtualBox VMs xen test xen-mga#33082 YAML-LibYAML-Test-dir zekemx Fix password’s modoboa driver leak of an authentication token to a user-controlled host, reported by [meifukun](https://github.com/meifukun) acta2.jpg acta.jpg advisories avatar.jpg avatar.png bdk-key.bkup bdk-mga9.txt bdk-new.key bdkpackagers.key bdkpackagers.sec bdkpass bin blogdrake.net bookmarks.html BRF Descargas Desktop diagrana.pdf discover-missing Documentos Dragon Quest: Dai no Daibouken - Bravest Full OP Sub Español [2MZON1ev9DE].mkv ejemplo añadir_archivo1.spec ejemplo añadir_archivo2.spec google-chrome.spec html i18n.pdf Imágenes index.php kernel-backport kernel-cves.enc kernel-cves.txt lqshell-stylesheet.css mageia-advisories MANOLO MUÑOZ VS ALBERTO VAZQUEZ MANO A MANO 24 EXITAZOS RANCHEROS CON MARIACHI.opus MEGA megasync-10.tar.gz #*message*-20260914-112747# mgaadv-error.txt mgarepo mirrorbdk mock Música origen.rss out.pnm PDF Plantillas Precure News - Star Detective PreCure! OP (Movie Footage Edition) [2099120870992310272].mp4 Proyectos qatest qa-testing qphotorec.desktop qphotorec.log reinstall.sh repodkfix.sh repositorio rpm rss Sailor Moon Cosmos AMV - Makenai (Sailor Star Song).mp4 sshrc style.html Taylor Swift, les coulisses du succès [120464-000-A].mp4 test.jpg tmp update-bdkkey.sh urpm-ng-distupgrade-orphans vdhcoapp-2.0.19 Ventoy Backup Vídeos VirtualBox VMs xen test xen-mga#33082 YAML-LibYAML-Test-dir zekemx Fix stored XSS in “Add to address book” action, reported by Paulos Yibelo from pwn.ai acta2.jpg acta.jpg advisories avatar.jpg avatar.png bdk-key.bkup bdk-mga9.txt bdk-new.key bdkpackagers.key bdkpackagers.sec bdkpass bin blogdrake.net bookmarks.html BRF Descargas Desktop diagrana.pdf discover-missing Documentos Dragon Quest: Dai no Daibouken - Bravest Full OP Sub Español [2MZON1ev9DE].mkv ejemplo añadir_archivo1.spec ejemplo añadir_archivo2.spec google-chrome.spec html i18n.pdf Imágenes index.php kernel-backport kernel-cves.enc kernel-cves.txt lqshell-stylesheet.css mageia-advisories MANOLO MUÑOZ VS ALBERTO VAZQUEZ MANO A MANO 24 EXITAZOS RANCHEROS CON MARIACHI.opus MEGA megasync-10.tar.gz #*message*-20260914-112747# mgaadv-error.txt mgarepo mirrorbdk mock Música origen.rss out.pnm PDF Plantillas Precure News - Star Detective PreCure! OP (Movie Footage Edition) [2099120870992310272].mp4 Proyectos qatest qa-testing qphotorec.desktop qphotorec.log reinstall.sh repodkfix.sh repositorio rpm rss Sailor Moon Cosmos AMV - Makenai (Sailor Star Song).mp4 sshrc style.html Taylor Swift, les coulisses du succès [120464-000-A].mp4 test.jpg tmp update-bdkkey.sh urpm-ng-distupgrade-orphans vdhcoapp-2.0.19 Ventoy Backup Vídeos VirtualBox VMs xen test xen-mga#33082 YAML-LibYAML-Test-dir zekemx Fix HTML/CSS sanitization bypass via SVG animate `by` attribute, reported by vectrain References
SRPMS 9/core
  • roundcubemail-1.6.18-1.mga9

MGASA-2026-0357 - Updated varnish packages fix security vulnerabilities

Mageia Security - 1 Septiembre, 2026 - 04:06
Publication date: 01 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-34475 , CVE-2026-50052 Description
The updated packages fix security vulnerabilities: Varnish Cache before 8.0.1 and Varnish Enterprise before 6.0.16r12, in certain unchecked req.url scenarios, mishandle URLs with a path of / for HTTP/1.1, potentially leading to cache poisoning or authentication bypass. (CVE-2026-34475) In Vinyl Cache before 9.0.1 and Varnish Cache before 9.0.3, a deficiency in HTTP/2 request parsing can be exploited to launch a backend request desync attack (request smuggling), which in turn can be used for cache poisoning, authentication bypass, or possibly even information disclosure and manipulation. The attack vector only exists if HTTP/2 support is enabled by setting the feature parameter to contain +http2. HTTP/2 support is disabled by default. (CVE-2026-50052) References
SRPMS 10/core
  • varnish-8.0.2-2.mga10
9/core
  • varnish-7.7.3-1.1.mga9

MGASA-2026-0356 - Updated perl-Mojolicious packages fix a security vulnerability

Mageia Security - 1 Septiembre, 2026 - 04:06
Publication date: 01 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-15747 Description
Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session CSRF token to a BREACH compression oracle. References
SRPMS 10/core
  • perl-Mojolicious-9.480.0-1.1.mga10
9/core
  • perl-Mojolicious-9.480.0-1.1.mga9

MGASA-2026-0355 - Updated vim packages fix security vulnerabilities

Mageia Security - 1 Septiembre, 2026 - 04:06
Publication date: 01 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-73077 , CVE-2026-73078 , CVE-2026-73074 , CVE-2026-73070 , CVE-2026-73075 , CVE-2026-73071 , CVE-2026-73073 , CVE-2026-73072 , CVE-2026-73076 Description
Arbitrary Code Execution via Shell Keyword Lookup in Vim < 9.2.0839. (CVE-2026-73077) Arbitrary Code Execution via Netrw Menu Construction in Vim < 9.2.0840. (CVE-2026-73078) Heap Buffer Overflow in Text Property Handling in Vim < 9.2.0841. (CVE-2026-73074) Stack Buffer Overflow in the Vim Socket Server in Vim < 9.2.0842. (CVE-2026-73070) Out-of-bounds Access in Popup Opacity Handling in Vim >= 9.2.0469 && Vim < 9.2.0843. (CVE-2026-73075) Use-after-free in JSON Decoding in Vim >= 9.2.0511 && Vim < 9.2.0844. (CVE-2026-73071) Arbitrary Ex Command Execution in C Omni-Completion in Vim < 9.2.0845. (CVE-2026-73073) Heap Buffer Overflow when Loading a Spell File in Vim < 9.2.0846. (CVE-2026-73072) Arbitrary Command Execution via Malicious `.VimballRecord` Entry Replay in `vimball.vim`. (CVE-2026-73076) References
SRPMS 10/core
  • vim-9.2.1011-2.mga10
9/core
  • vim-9.2.1011-2.mga9

MGASA-2026-0354 - Updated redis packages fix a security vulnerability

Mageia Security - 31 Agosto, 2026 - 20:40
Publication date: 31 Aug 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-62356 Description
The updated package fixes security vulnerabilities, including: Miscalculated buffer size in CMSketch RDB loading may lead to heap OOB write. (CVE-2026-62356) References
SRPMS 10/core
  • redis-8.6.6-1.mga10
9/core
  • redis-7.2.16-1.mga9
Feed