Updated chirp packages fix a security vulnerability
Publication date: 09 Oct 2026Modification date: 09 Oct 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-78136
Description
CHIRP — Arbitrary Code Execution via eval() in Kenwood ITM Driver
References
- https://bugs.mageia.org/show_bug.cgi?id=36278
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZJ6SIERICON7N75T5BO4GAWZ2WSJTQK4/
- https://github.com/cduram/CHIRP-CodeExecution_via_Malicious_ImageFile
- https://github.com/kk7ds/chirp/commit/39178dbfc4fece083ab9ed20286d6ae3a91a718e
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/ON7ELO5JWTMNPI6AGJ5VGCQ54D2YEMA5/
- https://www.cve.org/CVERecord?id=CVE-2026-78136
SRPMS
10/core
- chirp-20260925-1.mga10