Updated icu packages fix security vulnerability
Publication date: 27 Oct 2025Modification date: 27 Oct 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-5222
Description
A stack buffer overflow was found in Internationl components for unicode
(ICU ). While running the genrb binary, the 'subtag' struct overflowed
at the SRBRoot::addTag function. This issue may lead to memory
corruption and local arbitrary code execution.
References
SRPMS
9/core
- icu-73.2-1.2.mga9