Advisories ยป MGASA-2026-0474

Updated capnproto package fixes security vulnerabilities

Publication date: 09 Oct 2026
Modification date: 09 Oct 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-32239 , CVE-2026-32240

Description

A negative Content-Length value was converted to unsigned, treating it
as an impossibly large length instead (CVE-2026-32239).
When using Transfer-Encoding: chunked, if a chunk's size parsed to a
value of 2^64 or larger, it would be truncated to a 64-bit integer
(CVE-2026-32240).
                

References

SRPMS

10/core