References: https://www.openwall.com/lists/oss-security/2026/04/11/1 https://www.openwall.com/lists/oss-security/2026/04/11/2
CVE: (none) => CVE-2026-40198, CVE-2026-40199Source RPM: (none) => perl-Net-CIDR-Lite-0.220.0-3.mga10.src.rpm, perl-Net-CIDR-Lite-0.220.0-2.mga9.src.rpmFlags: (none) => affects_mga9+Status comment: (none) => Fixed upstream in 0.23 (aka 0.230.0)Whiteboard: (none) => MGA9TOO
A straight version update.
Assignee: bugsquad => perl
Fedora has issued an advisory on April 22: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SKKSURTDDZIA5TCZ3QL5KFVFSKVVMRSQ/
For Cauldron, I asked for a freeze move. Suggested advisory: ======================== The updated package fixes security vulnerabilities: Net::CIDR::Lite versions before 0.23 for Perl does not validate IPv6 group count, which may allow IP ACL bypass. (CVE-2026-40198) Net::CIDR::Lite versions before 0.23 for Perl mishandles IPv4 mapped IPv6 addresses, which may allow IP ACL bypass. (CVE-2026-40199) References: https://www.openwall.com/lists/oss-security/2026/04/11/1 https://www.openwall.com/lists/oss-security/2026/04/11/2 https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SKKSURTDDZIA5TCZ3QL5KFVFSKVVMRSQ/ ======================== Updated package in core/updates_testing: ======================== perl-Net-CIDR-Lite-0.230.0-1.mga9 from SRPM: perl-Net-CIDR-Lite-0.230.0-1.mga9.src.rpm
Status comment: Fixed upstream in 0.23 (aka 0.230.0) => (none)Flags: affects_mga9+ => (none)Source RPM: perl-Net-CIDR-Lite-0.220.0-3.mga10.src.rpm, perl-Net-CIDR-Lite-0.220.0-2.mga9.src.rpm => perl-Net-CIDR-Lite-0.220.0-2.mga9.src.rpmStatus: NEW => ASSIGNEDVersion: Cauldron => 9Whiteboard: MGA9TOO => (none)Assignee: perl => qa-bugs
Keywords: (none) => advisory
MGA9-64 server Plasma Wayland on Compaq H000SB. No installation issues. Ref bug 29205 Checked that MCC - Networkcenter is not disturbed by it. OK for me.
CC: (none) => herman.viaene
Whiteboard: (none) => MGA9-64-OKFlags: (none) => test_passed_mga9_64+
Validating.
Keywords: (none) => validated_updateCC: (none) => andrewsfarm, sysadmin-bugs
An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2026-0115.html
Resolution: (none) => FIXEDStatus: ASSIGNED => RESOLVED