Advisories ยป MGASA-2026-0022

Updated glibc packages fix security vulnerabilities

Publication date: 27 Jan 2026
Modification date: 27 Jan 2026
Type: security
Affected Mageia releases : 9
CVE: CVE-2026-0861 , CVE-2026-0915 , CVE-2025-15281

Description

Integer overflow in memalign leads to heap corruption. (CVE-2026-0861)
getnetbyaddr and getnetbyaddr_r leak stack contents to DNS resovler.
(CVE-2026-0915)
wordexp with WRDE_REUSE and WRDE_APPEND may return uninitialized memory.
(CVE-2025-15281)
                

References

SRPMS

9/core