Updated pipewire packages fix security vulnerabilities
Publication date: 23 Sep 2026Modification date: 23 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-14324 , CVE-2026-14330
Description
RAOP module accepts unbounded Content-Length values and does not check
the pw_array_add() return. (CVE-2026-14324)
Multiple unbounded alloca() calls in the PulseAudio protocol server.
(CVE-2026-14330)
References
- https://bugs.mageia.org/show_bug.cgi?id=35929
- https://ubuntu.com/security/notices/USN-8535-1
- https://bugzilla.redhat.com/show_bug.cgi?id=2495903
- https://gitlab.freedesktop.org/pipewire/pipewire/-/work_items/5352
- https://bugzilla.redhat.com/show_bug.cgi?id=2495907
- https://www.cve.org/CVERecord?id=CVE-2026-14324
- https://www.cve.org/CVERecord?id=CVE-2026-14330
SRPMS
10/core
- pipewire-1.6.5-1.1.mga10
9/core
- pipewire-0.3.85-6.1.mga9