Mageia Security

Feed
Mageia Advisories
Updated: hace 16 horas 14 minutos

MGAA-2026-0013 - Updated sddm-theme-coffee-ng packages fix bug

20 Febrero, 2026 - 18:27
Publication date: 20 Feb 2026
Type: bugfix
Affected Mageia releases : 9
Description Minor fixes to our alternative sddm theme. References SRPMS 9/core
  • sddm-theme-coffee-ng-2.0-1.2.mga9

MGASA-2026-0043 - Updated microcode packages fix security vulnerabilities

18 Febrero, 2026 - 17:17
Publication date: 18 Feb 2026
Type: security
Affected Mageia releases : 9
CVE: CVE-2024-24853 , CVE-2025-31648 Description The updated package updates AMD CPUs microcodes and fixes security vulnerabilities in Intel CPUs microcodes: Incorrect behavior order in transition between executive monitor and SMI transfer monitor (STM) in some Intel(R) Processor may allow a privileged user to potentially enable escalation of privilege via local access. (CVE-2024-24853) Improper handling of values in the microcode flow for some Intel(R) Processor Family may allow an escalation of privilege. Startup code and smm adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (low), integrity (low) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (low), integrity (low) and availability (none) impacts. (CVE-2025-31648) References SRPMS 9/nonfree
  • microcode-0.20260210-1.mga9.nonfree

MGASA-2026-0042 - Updated vim packages fix security vulnerability

18 Febrero, 2026 - 17:17
Publication date: 18 Feb 2026
Type: security
Affected Mageia releases : 9
CVE: CVE-2026-26269 Description Vim has a Netbeans specialKeys Stack Buffer Overflow. (CVE-2026-26269) References SRPMS 9/core
  • vim-9.1.2148-1.mga9

MGASA-2026-0041 - Updated postgresql15 packages fix security vulnerabilities

17 Febrero, 2026 - 18:47
Publication date: 17 Feb 2026
Type: security
Affected Mageia releases : 9
CVE: CVE-2026-2003 , CVE-2026-2004 , CVE-2026-2005 , CVE-2026-2006 , CVE-2026-2007 Description PostgreSQL oidvector discloses a few bytes of memory. (CVE-2026-2003) PostgreSQL intarray missing validation of type of input to selectivity estimator executes arbitrary code. (CVE-2026-2004) PostgreSQL pgcrypto heap buffer overflow executes arbitrary code. (CVE-2026-2005) PostgreSQL missing validation of multibyte character length executes arbitrary code. (CVE-2026-2006) PostgreSQL pg_trgm heap buffer overflow writes pattern onto server memory. (CVE-2026-2007 References SRPMS 9/core
  • postgresql15-15.16-1.mga9

MGASA-2026-0040 - Updated dcmtk packages fix security vulnerabilities

16 Febrero, 2026 - 17:36
Publication date: 16 Feb 2026
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-14607 , CVE-2025-14841 Description OFFIS DCMTK dcmdata dcbytstr.cc makeDicomByteString memory corruption. (CVE-2025-14607) OFFIS DCMTK dcmqrscp dcmqrdbi.cc startMoveRequest null pointer dereference. (CVE-2025-14841) References SRPMS 9/core
  • dcmtk-3.6.7-4.7.mga9

MGASA-2026-0039 - Updated usbmuxd packages fix security vulnerability

16 Febrero, 2026 - 17:36
Publication date: 16 Feb 2026
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-66004 Description Local privilege escalation in usbmuxd from arbitrary local user to usbmux. (CVE-2025-66004) References SRPMS 9/core
  • usbmuxd-1.1.1-3.1.mga9

MGAA-2026-0012 - Updated mariadb packages fix bug

16 Febrero, 2026 - 17:36
Publication date: 16 Feb 2026
Type: bugfix
Affected Mageia releases : 9
Description Regular update of mariadb which brings some bugfixes. References SRPMS 9/core
  • mariadb-11.4.10-1.mga9

MGASA-2026-0038 - Updated libpng packages fix security vulnerability

12 Febrero, 2026 - 06:54
Publication date: 12 Feb 2026
Type: security
Affected Mageia releases : 9
CVE: CVE-2026-25646 Description Heap buffer overflow in png_set_quantize when called with no histogram and a palette larger than twice the requested maximum number of colors. (CVE-2026-25646) References SRPMS 9/core
  • libpng-1.6.38-1.4.mga9

MGASA-2026-0037 - Updated xrdp packages fix security vulnerability

11 Febrero, 2026 - 18:56
Publication date: 11 Feb 2026
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-68670 Description xrdp improperly checks bounds of domain string length, which leads to Stack-based Buffer Overflow. (CVE-2025-68670) References SRPMS 9/core
  • xrdp-0.9.23.1-1.2.mga9

MGASA-2026-0036 - Updated thunderbird packages fix security vulnerability

11 Febrero, 2026 - 18:56
Publication date: 11 Feb 2026
Type: security
Affected Mageia releases : 9
CVE: CVE-2026-0818 Description CSS-based exfiltration of the content from partially encrypted emails when allowing remote content. (CVE-2026-0818) References SRPMS 9/core
  • thunderbird-140.7.1-1.mga9
  • thunderbird-l10n-140.7.1-1.mga9

MGASA-2026-0035 - Updated golang packages fix security vulnerabilities

11 Febrero, 2026 - 18:56
Publication date: 11 Feb 2026
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-61726 , CVE-2025-61728 , CVE-2025-61730 , CVE-2025-61731 , CVE-2025-61732 , CVE-2025-68119 , CVE-2025-68121 Description net/http: memory exhaustion in Request.ParseForm. (CVE-2025-61726) archive/zip: denial of service when parsing arbitrary ZIP archives. (CVE-2025-61728) crypto/tls: handshake messages may be processed at the incorrect encryption level. (CVE-2025-61730) cmd/go: bypass of flag sanitization can lead to arbitrary code execution. (CVE-2025-61731) Potential code smuggling via doc comments in cmd/cgo. (CVE-2025-61732) cmd/go: unexpected code execution when invoking toolchain. (CVE-2025-68119) crypto/tls: Config.Clone copies automatically generated session ticket keys, session resumption does not account for the expiration of full certificate chain. (CVE-2025-68121) References SRPMS 9/core
  • golang-1.24.13-1.mga9