RAOP module accepts unbounded Content-Length values and does not check the pw_array_add() return. (CVE-2026-14324) Multiple unbounded alloca() calls in the PulseAudio protocol server. (CVE-2026-14330)
{ "section": "core" }
"https://advisories.mageia.org/MGASA-2026-0443.json"