Fedora has issued an advisory on May 3: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZLLMINU5CKQDNMS5OT7OKS5V6YQFIJUC/ Fixes: https://src.fedoraproject.org/rpms/nano/raw/15cad6aa72c9aecfd87d0cfaeca481824cd7bd00/f/nano-CVE-2026-6842.patch https://src.fedoraproject.org/rpms/nano/raw/15cad6aa72c9aecfd87d0cfaeca481824cd7bd00/f/nano-CVE-2026-6843.patch
Whiteboard: (none) => MGA9TOOFlags: (none) => affects_mga9+CVE: (none) => CVE-2026-6842, CVE-2026-6843Source RPM: (none) => nano-8.7-1.mga10.src.rpm, nano-7.2-1.1.mga9.src.rpmStatus comment: (none) => Patches available from Fedora
Different packagers have maintained Nano, so assigning globally.
Status comment: Patches available from Fedora => Patches available from Fedora, refs givenAssignee: bugsquad => pkg-bugs
For Cauldron, I asked for a freeze move. Suggested advisory: ======================== The updated package fixes security vulnerabilities: Local attacker can inject malicious .desktop launcher due to insecure directory permissions. (CVE-2026-6842) Format string vulnerability leads to denial of service. (CVE-2026-6843) References: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZLLMINU5CKQDNMS5OT7OKS5V6YQFIJUC/ ======================== Updated package in core/updates_testing: ======================== nano-7.2-1.2.mga9 from SRPM: nano-7.2-1.2.mga9.src.rpm
Assignee: pkg-bugs => qa-bugsStatus comment: Patches available from Fedora, refs given => (none)Whiteboard: MGA9TOO => (none)Flags: affects_mga9+ => (none)Status: NEW => ASSIGNEDVersion: Cauldron => 9Source RPM: nano-8.7-1.mga10.src.rpm, nano-7.2-1.1.mga9.src.rpm => nano-7.2-1.1.mga9.src.rpm
Installed and tested without issues. Tested opening, editing, saving, executing external command, copy & pasta, search, replace, undo. All seems to be working as expected. No issues found. System: Mageia 9, x86_64, Plasma DE, AMD Ryzen 5 5600G with Radeon Graphics using amdgpu driver. $ uname -a Linux jupiter 6.6.137-desktop-1.mga9 #1 SMP PREEMPT_DYNAMIC Thu Apr 30 22:24:10 UTC 2026 x86_64 GNU/Linux $ rpm -q nano nano-7.2-1.2.mga9
CC: (none) => mageia
MGA9-64 server Plasma Wayland on Compaq H000SB. Did a little editing in a txt file, saved and checked updates with kwrite.Looks OK. In view of tests above, good to go.
Whiteboard: (none) => MGA9-64-OKFlags: (none) => test_passed_mga9_64+CC: (none) => herman.viaene
Validating.
CC: (none) => andrewsfarm, sysadmin-bugsKeywords: (none) => validated_update
Keywords: (none) => advisory
An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2026-0121.html
Status: ASSIGNED => RESOLVEDResolution: (none) => FIXED