MGASA-2025-0241 - Updated quictls packages with two security issues and bug fixes. MGASA-2025-0241 - Updated quictls packages with two security issues and bug fixes Publication date: 20 Oct 2025 URL: https://advisories.mageia.org/MGASA-2025-0241.html Type: security Affected Mageia releases: 9 CVE: CVE-2025-9230, CVE-2025-9232 Description: Two security issues and miscellaneous minor bug fixes. Fix Out-of-bounds read & write in RFC 3211 KEK Unwrap. (CVE-2025-9230) Fix Out-of-bounds read in HTTP client no_proxy handling. (CVE-2025-9232) References: - https://bugs.mageia.org/show_bug.cgi?id=34674 - https://openssl-library.org/news/vulnerabilities/#CVE-2025-9230 - https://openssl-library.org/news/vulnerabilities/#CVE-2025-9232 - https://www.cve.org/CVERecord?id=CVE-2025-9230 - https://www.cve.org/CVERecord?id=CVE-2025-9232 SRPMS: - 9/core/quictls-3.0.18-1.mga9 . Two security issues and bug fixes on Mageia for quictls, addressing out-of-bounds improvements to enhance security.. Mageia, quictls, security updates. . Severity: Important. LinuxSecurity.com Team
Timing side-channel in ECDSA signature computation. (CVE-2024-13176) References: - https://bugs.mageia.org/show_bug.cgi?id=34106 - https://openssl-library.org/news/secadv/20250120.txt . MGASA-2025-0101 - Updated quictls packages fix security vulnerability Publication date: 17 Mar 2025 URL: https://advisories.mageia.org/MGASA-2025-0101.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-13176 Timing side-channel in ECDSA signature computation. (CVE-2024-13176) References: - https://bugs.mageia.org/show_bug.cgi?id=34106 - https://openssl-library.org/news/secadv/20250120.txt - https://www.cve.org/CVERecord?id=CVE-2024-13176 SRPMS: - 9/core/quictls-3.0.15-1.2.mga9 . Security Advisory for Mageia 9 addressing timing side-channel in ECDSA signature computation vulnerability.. timing, side-channel, ecdsa, signature, computation, (cve-2024-13176), https, //bugs. . Severity: Important. LinuxSecurity.com Team
Invalid low-level GF(2^m) parameters can lead to an OOB memory access. (CVE-2024-9143) References: - https://bugs.mageia.org/show_bug.cgi?id=33736 . MGASA-2024-0354 - Updated quictls packages fix security vulnerability Publication date: 09 Nov 2024 URL: https://advisories.mageia.org/MGASA-2024-0354.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-9143 Invalid low-level GF(2^m) parameters can lead to an OOB memory access. (CVE-2024-9143) References: - https://bugs.mageia.org/show_bug.cgi?id=33736 - https://openssl-library.org/news/secadv/20241016.txt - https://www.cve.org/CVERecord?id=CVE-2024-9143 SRPMS: - 9/core/quictls-3.0.15-1.1.mga9 . MGASA-2024-0457 outlines resolutions for buffer overflow vulnerabilities identified in quictls. Essential patches and documentation available for Mageia users.. Mageia security, quictls update, memory access fix, security advisory 2024. . LinuxSecurity.com Team
The updated packages fix security vulnerabilities References: - https://bugs.mageia.org/show_bug.cgi?id=33614 - https://openssl-library.org/news/vulnerabilities-3.0/index.html . MGASA-2024-0330 - Updated quictls packages fix security vulnerabilities Publication date: 11 Oct 2024 URL: https://advisories.mageia.org/MGASA-2024-0330.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-5535 The updated packages fix security vulnerabilities References: - https://bugs.mageia.org/show_bug.cgi?id=33614 - - https://www.cve.org/CVERecord?id=CVE-2024-5535 SRPMS: - 9/core/quictls-3.0.15-1.mga9 . The newly released quictls packages for Mageia address vulnerabilities related to CVE-2024-5535, which was disclosed on October 11, 2024.. security advisory, Mageia updates, quictls patch, software vulnerability fix. . Severity: Critical. LinuxSecurity.com Team
The updated packages fix security vulnerabilities References: - https://bugs.mageia.org/show_bug.cgi?id=33468 - https://openssl-library.org/news/vulnerabilities-3.0/index.html . MGASA-2024-0281 - Updated quictls packages fix security vulnerabilities Publication date: 19 Aug 2024 URL: https://advisories.mageia.org/MGASA-2024-0281.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-5535, CVE-2024-4741, CVE-2024-4603, CVE-2024-2511, CVE-2024-0727, CVE-2023-6237, CVE-2023-6129, CVE-2023-5678 The updated packages fix security vulnerabilities References: - https://bugs.mageia.org/show_bug.cgi?id=33468 - - https://www.cve.org/CVERecord?id=CVE-2024-5535 - https://www.cve.org/CVERecord?id=CVE-2024-4741 - https://www.cve.org/CVERecord?id=CVE-2024-4603 - https://www.cve.org/CVERecord?id=CVE-2024-2511 - https://www.cve.org/CVERecord?id=CVE-2024-0727 - https://www.cve.org/CVERecord?id=CVE-2023-6237 - https://www.cve.org/CVERecord?id=CVE-2023-6129 - https://www.cve.org/CVERecord?id=CVE-2023-5678 SRPMS: - 9/core/quictls-3.0.14-1.1.mga9 . The recent updates to quictls packages in Mageia address multiple serious security vulnerabilities. Advisory MGASA-2024-0282 was released on 19 August 2024.. Mageia Security, quictls Updates, Critical Security Fix, Software Update. . Severity: Critical. LinuxSecurity.com Team
The updated packages fix security vulnerabilities: Excessive time spent in DH check / generation with large Q parameter value. (CVE-2023-5678) POLY1305 MAC implementation corrupts vector registers on PowerPC. (CVE-2023-6129) . MGASA-2024-0036 - Updated quictls packages fix security vulnerabilities Publication date: 14 Feb 2024 URL: https://advisories.mageia.org/MGASA-2024-0036.html Type: security Affected Mageia releases: 9 CVE: CVE-2023-5678, CVE-2023-6129, CVE-2023-6237, CVE-2024-0727 The updated packages fix security vulnerabilities: Excessive time spent in DH check / generation with large Q parameter value. (CVE-2023-5678) POLY1305 MAC implementation corrupts vector registers on PowerPC. (CVE-2023-6129) Excessive time spent checking invalid RSA public keys. (CVE-2023-6237) PKCS12 Decoding crashes. (CVE-2024-0727) References: - https://bugs.mageia.org/show_bug.cgi?id=32794 - https://bugs.mageia.org/show_bug.cgi?id=32498 - https://openssl-library.org/news/secadv/20231106.txt - https://openssl-library.org/news/secadv/20240109.txt - https://openssl-library.org/news/secadv/20240115.txt - https://openssl-library.org/news/secadv/20240125.txt - https://www.cve.org/CVERecord?id=CVE-2023-5678 - https://www.cve.org/CVERecord?id=CVE-2023-6129 - https://www.cve.org/CVERecord?id=CVE-2023-6237 - https://www.cve.org/CVERecord?id=CVE-2024-0727 SRPMS: - 9/core/quictls-3.0.12-1.1.mga9 . Recent updates to quictls packages tackle vulnerabilities that lead to prolonged computation durations and problems with vector registers on PowerPC architectures.. Mageia Security Update, Quictls Fix, PowerPC Advisory. . Severity: Critical. LinuxSecurity.com Team
The updated packages fix a security vulnerability: Incorrect cipher key & IV length processing. (CVE-2023-5363) References: . MGASA-2023-0317 - Updated quictls packages fix a security vulnerability Publication date: 12 Nov 2023 URL: https://advisories.mageia.org/MGASA-2023-0317.html Type: security Affected Mageia releases: 9 CVE: CVE-2023-5363 The updated packages fix a security vulnerability: Incorrect cipher key & IV length processing. (CVE-2023-5363) References: - https://bugs.mageia.org/show_bug.cgi?id=32484 - https://www.cve.org/CVERecord?id=CVE-2023-5363 SRPMS: - 9/core/quictls-3.0.12-1.mga9 . Mageia 2023-0318 patches address a flaw in handling of buffer sizes and authentication mechanisms within openssl libraries.. Mageia Security Update, Quictls Issue, Cipher Key Vulnerability. . Severity: Critical. LinuxSecurity.com Team
The updated packages fix security vulnerabilities: AES-SIV implementation ignores empty associated data entries. (CVE-2023-2975) . MGASA-2023-0273 - Updated quictls packages fix security vulnerabilities Publication date: 30 Sep 2023 URL: https://advisories.mageia.org/MGASA-2023-0273.html Type: security Affected Mageia releases: 9 CVE: CVE-2023-2975, CVE-2023-3446, CVE-2023-3817 The updated packages fix security vulnerabilities: AES-SIV implementation ignores empty associated data entries. (CVE-2023-2975) Excessive time spent checking DH keys and parameters. (CVE-2023-3446) Excessive time spent checking DH q parameter value. (CVE-2023-3817) References: - https://bugs.mageia.org/show_bug.cgi?id=32248 - https://www.cve.org/CVERecord?id=CVE-2023-2975 - https://www.cve.org/CVERecord?id=CVE-2023-3446 - https://www.cve.org/CVERecord?id=CVE-2023-3817 - https://openssl-library.org/news/secadv/20230714.txt - https://openssl-library.org/news/secadv/20230719.txt - https://openssl-library.org/news/secadv/20230731.txt - https://www.cve.org/CVERecord?id=CVE-2023-2975 - https://www.cve.org/CVERecord?id=CVE-2023-3446 - https://www.cve.org/CVERecord?id=CVE-2023-3817 SRPMS: - 9/core/quictls-3.0.10-1.mga9 . Enhanced quictls packages for Mageia tackle weaknesses linked to AES-SIV and reduce the delay in parameter verification.. Mageia Security Advisory, quictls Update, AES-SIV Vulnerability, Security Patches, DH Parameter Checks. . Severity: Low. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.