It was found that shadow-utils had a buffer overflow where if a buffer was left NULL for a cycle the next cycle would happily write past the entries buffer (CVE-2017-12424).
{ "section": "core" }
"https://advisories.mageia.org/MGASA-2017-0465.json"