Mageia alert MGASA-2026-0353 (openssl)
| From: | Mageia Updates <updates-announce@ml.mageia.org> | |
| To: | updates-announce@ml.mageia.org | |
| Subject: | [updates-announce] MGASA-2026-0353: Updated openssl packages fix security vulnerabilities | |
| Date: | Mon, 31 Aug 2026 21:41:23 +0200 | |
| Message-ID: | <20260831194123.865309FEBA@duvel.mageia.org> | |
| Archive-link: | Article |
MGASA-2026-0353 - Updated openssl packages fix security vulnerabilities Publication date: 31 Aug 2026 URL: https://advisories.mageia.org/MGASA-2026-0353.html Type: security Affected Mageia releases: 10, 9 CVE: CVE-2026-14456, CVE-2026-18798, CVE-2026-63072, CVE-2026-63076, CVE-2026-14457, CVE-2026-54874, CVE-2026-63073, CVE-2026-63074, CVE-2026-63075, CVE-2026-75803 Description: Unbounded Memory Growth in QUIC Server Incoming Channel Queue. (CVE-2026-14456) QUIC Server May Trigger Double Free When Processing INITIAL Packet. (CVE-2026-18798) Heap Buffer Overflow in CMS Key Unwrapping. (CVE-2026-63072) Invalid Pointer Dereference in CMP Server via Crafted protectionAlg. (CVE-2026-63076) RPK Server Signature Algorithm Selection Can Dereference a Missing Certificate. (CVE-2026-14457) Excessive Memory Use Buffering DTLS Records for a Future Epoch. (CVE-2026-54874) Untrusted Sender DN Used as Format String in CMP Response Validation. (CVE-2026-63073) CMP Indefinite Cache Growth of ExtraCerts. (CVE-2026-63074) QUIC ACK-only Packet Retention Can Cause Memory Exhaustion. (CVE-2026-63075) References: - https://bugs.mageia.org/show_bug.cgi?id=36139 - https://www.openwall.com/lists/oss-security/2026/08/13/4 - https://openssl-library.org/news/secadv/20260813.txt - https://www.openwall.com/lists/oss-security/2026/08/25/3 - https://openssl-library.org/news/secadv/20260825.txt - https://lists.debian.org/debian-security-announce/2026/ms... - https://www.cve.org/CVERecord?id=CVE-2026-14456 - https://www.cve.org/CVERecord?id=CVE-2026-18798 - https://www.cve.org/CVERecord?id=CVE-2026-63072 - https://www.cve.org/CVERecord?id=CVE-2026-63076 - https://www.cve.org/CVERecord?id=CVE-2026-14457 - https://www.cve.org/CVERecord?id=CVE-2026-54874 - https://www.cve.org/CVERecord?id=CVE-2026-63073 - https://www.cve.org/CVERecord?id=CVE-2026-63074 - https://www.cve.org/CVERecord?id=CVE-2026-63075 - https://www.cve.org/CVERecord?id=CVE-2026-75803 SRPMS: - 10/core/openssl-3.5.8-1.mga10 - 9/core/openssl-3.0.22-1.mga9
