Advisories ยป MGASA-2026-0298

Updated graphite2 packages fix a security vulnerability

Publication date: 25 Jul 2026
Modification date: 25 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-50593

Description

The updated packages fix a security vulnerability:
Graphite before 1.3.15 has an integer underflow and resultant
out-of-bounds write via Graphite actions, because slotat does not ensure
that an offset is within the allowed slot-map range. (CVE-2026-50593)
                

References

SRPMS

10/core

9/core