Updated capnproto package fixes security vulnerabilities
Publication date: 09 Oct 2026Modification date: 09 Oct 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-32239 , CVE-2026-32240
Description
A negative Content-Length value was converted to unsigned, treating it
as an impossibly large length instead (CVE-2026-32239).
When using Transfer-Encoding: chunked, if a chunk's size parsed to a
value of 2^64 or larger, it would be truncated to a 64-bit integer
(CVE-2026-32240).
References
- https://bugs.mageia.org/show_bug.cgi?id=36190
- https://ubuntu.com/security/notices/USN-8650-1
- https://github.com/capnproto/capnproto/security/advisories/GHSA-qjx3-pp3m-9jpm
- https://github.com/capnproto/capnproto/security/advisories/GHSA-vpcq-mx5v-32wm
- https://www.cve.org/CVERecord?id=CVE-2026-32239
- https://www.cve.org/CVERecord?id=CVE-2026-32240
SRPMS
10/core
- capnproto-1.5.0-1.mga10