Local attacker can inject malicious .desktop launcher due to insecure directory permissions. (CVE-2026-6842) Format string vulnerability leads to denial of service. (CVE-2026-6843)
{ "section": "core" }
"https://advisories.mageia.org/MGASA-2026-0121.json"