Updated graphite2 packages fix a security vulnerability
Publication date: 25 Jul 2026Modification date: 25 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-50593
Description
The updated packages fix a security vulnerability:
Graphite before 1.3.15 has an integer underflow and resultant
out-of-bounds write via Graphite actions, because slotat does not ensure
that an offset is within the allowed slot-map range. (CVE-2026-50593)
References
SRPMS
10/core
- graphite2-1.3.14-4.1.mga10
9/core
- graphite2-1.3.14-2.1.mga9