{"id":"MGASA-2025-0181","summary":"Updated cockpit packages fix security vulnerability & bug","details":"Mageia's internal bug: In the current version you can't login in the web\ninterface with firefox or chromium-browser packaged by Mageia. This\nupdate fixes the issue, but it is reported that could need to reboot and\nclear cookies from your browser.\nA flaw was found in the cockpit package. This flaw allows an\nauthenticated user to kill any process when enabling the pam_env's\nuser_readenv option, which leads to a denial of service (DoS) attack -\nCVE-2024-6126.\nPlease note that you need to edit /etc/nsswitch.conf as recommended in\nhttps://bugs.mageia.org/show_bug.cgi?id=33368#c18.\n","modified":"2026-04-16T04:43:39.924861317Z","published":"2025-06-09T18:14:56Z","upstream":["CVE-2024-6126"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2025-0181.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=33368"}],"affected":[{"package":{"name":"cockpit","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/cockpit?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"338-1.6.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2025-0181.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}