<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T14:15:51.889568+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2021:4198</id>
    <title>ALSA-2021:4198 — Moderate: edk2 security, bug fix, and enhancement update</title>
    <updated>2026-10-02T14:15:51.952190+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: edk2-ovmf</p>
<p>EDK (Embedded Development Kit) is a project to enable UEFI support for Virtual Machines. This package contains a sample 64-bit UEFI firmware for QEMU and KVM.</p>
<p>The following packages have been upgraded to a later upstream version: edk2 (20210527gite1999b264f1f). (BZ#1846481, BZ#1938238)</p>
<p>Security Fix(es):</p>
<p>* openssl: integer overflow in CipherUpdate (CVE-2021-23840)</p>
<p>* openssl: NULL pointer dereference in X509_issuer_and_serial_hash() (CVE-2021-23841)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p>
<p>Additional Changes:</p>
<p>For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2021:4198"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2021-03744</id>
    <title>bdu:2021-03744</title>
    <updated>2026-10-02T14:15:51.952280+00:00</updated>
    <content>bdu:2021-03744</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2021-03744"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2021-23841</id>
    <title>Withdrawn: BELL-CVE-2021-23841 — CVE-2021-23841 does not affect BellSoft software</title>
    <updated>2026-10-02T14:15:51.952329+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2021-23841"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2021-avi-124</id>
    <title>certfr-2021-avi-124 — De multiples vulnérabilités ont été découvertes dans OpenSSL. Elles
permettent à un attaquant de provoquer un déni de s…</title>
    <updated>2026-10-02T14:15:51.952362+00:00</updated>
    <content>certfr-2021-avi-124</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2021-avi-124"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-gk72927</id>
    <title>Withdrawn: CLEANSTART-2026-GK72927 — Issue summary: PBMAC1 parameters in PKCS#12 files are missing validation
which can trigger a stack-based buffer overflo…</title>
    <updated>2026-10-02T14:15:51.952377+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: openssl</p>
<p>Multiple security vulnerabilities affect the openssl package. Issue summary: PBMAC1 parameters in PKCS#12 files are missing validation which can trigger a stack-based buffer overflow, invalid pointer or NULL pointer dereference during MAC verification. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-gk72927"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2021-14754</id>
    <title>cnvd-2021-14754</title>
    <updated>2026-10-02T14:15:51.952401+00:00</updated>
    <content>cnvd-2021-14754</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2021-14754"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-174509</id>
    <title>EUVD-2026-174509</title>
    <updated>2026-10-02T14:15:51.952414+00:00</updated>
    <content>EUVD-2026-174509</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-174509"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-23841</id>
    <title>fkie_cve-2021-23841</title>
    <updated>2026-10-02T14:15:51.952424+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The OpenSSL public API function X509_issuer_and_serial_hash() attempts to create a unique hash value based on the issuer and serial number data contained within an X509 certificate. However it fails to correctly handle any errors that may occur while parsing the issuer field (which might occur if the issuer field is maliciously constructed). This may subsequently result in a NULL pointer deref and a crash leading to a potential denial of service attack. The function X509_issuer_and_serial_hash() is never directly called by OpenSSL itself so applications are only vulnerable if they use this function directly and they use it on certificates that may have been obtained from untrusted sources. OpenSSL versions 1.1.1i and below are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1j. OpenSSL versions 1.0.2x and below are affected by this issue. However OpenSSL 1.0.2 is out of support and no longer receiving public updates. Premium support customers of OpenSSL 1.0.2 should upgrade to 1.0.2y. Other users should upgrade to 1.1.1j. Fixed in OpenSSL 1.1.1j (Affected 1.1.1-1.1.1i). Fixed in OpenSSL 1.0.2y (Affected 1.0.2-1.0.2x).</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-23841"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-84rm-qf37-fgc2</id>
    <title>GHSA-84rm-qf37-fgc2 — Integer Overflow in openssl-src</title>
    <updated>2026-10-02T14:15:51.952454+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: openssl-src</p>
<p>Calls to EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate may overflow the output length argument in some cases where the input length is close to the maximum permissable length for an integer on the platform. In such cases the return value from the function call will be 1 (indicating success), but the output length value will be negative. This could cause applications to behave incorrectly or crash. OpenSSL versions 1.1.1i and below are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1j. OpenSSL versions 1.0.2x and below are affected by this issue. However OpenSSL 1.0.2 is out of support and no longer receiving public updates. Premium support customers of OpenSSL 1.0.2 should upgrade to 1.0.2y. Other users should upgrade to 1.1.1j. Fixed in OpenSSL 1.1.1j (Affected 1.1.1-1.1.1i). Fixed in OpenSSL 1.0.2y (Affected 1.0.2-1.0.2x).</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-84rm-qf37-fgc2"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-23841</id>
    <title>gsd-2021-23841</title>
    <updated>2026-10-02T14:15:51.952494+00:00</updated>
    <content>gsd-2021-23841</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-23841"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-21-336-06</id>
    <title>ICSA-21-336-06 — Hitachi Energy APM Edge</title>
    <updated>2026-10-02T14:15:51.952518+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer dereference will result, leading to a crash and a denial of service attack. A server is only vulnerable if it has TLSv1.2 and renegotiation enabled (which is the default configuration). OpenSSL TLS clients are not impacted by this issue. All OpenSSL 1.1.1 versions are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1k. OpenSSL 1.0.2 is not impacted by this issue. Fixed in OpenSSL 1.1.1k (Affected 1.1.1-1.1.1j). Hitachi Energy is aware of public reports of this vulnerability in the following open-source software components: OpenSSL, LibSSL, libxml2 and GRUB2 bootloader. The vulnerability also affects some APM Edge products. An attacker who successfully exploits this vulnerability could cause the product to become inaccessible. SEE NVD for full Description. In situations where an attacker receives automated notification of the success or failure of a decryption attempt an attacker, after sending a very large number of messages to be decrypted, can recover a CMS/PKCS7 transported encryption key or decrypt any RSA encrypted message that was encrypted with the public RSA key, using a Bleichenbacher padding oracle attack. Applications are not a…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-21-336-06"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2021-23841</id>
    <title>msrc_CVE-2021-23841 — Null pointer deref in X509_issuer_and_serial_hash()</title>
    <updated>2026-10-02T14:15:51.952795+00:00</updated>
    <content>msrc_CVE-2021-23841</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2021-23841"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2021-1121</id>
    <title>OESA-2021-1121 — openssl security update</title>
    <updated>2026-10-02T14:15:51.952813+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS: openssl, openEuler:20.03-LTS-SP1: openssl</p>
<p>OpenSSL is a robust, commercial-grade, and full-featured toolkit for the Transport Layer Security (TLS) and Secure Sockets Layer (SSL) protocols.

Security Fix(es):

The OpenSSL public API function X509_issuer_and_serial_hash() attempts to create a unique hash value based on the issuer and serial number data contained within an X509 certificate. However it fails to correctly handle any errors that may occur while parsing the issuer field (which might occur if the issuer field is maliciously constructed). This may subsequently result in a NULL pointer deref and a crash leading to a potential denial of service attack. The function X509_issuer_and_serial_hash() is never directly called by OpenSSL itself so applications are only vulnerable if they use this function directly and they use it on certificates that may have been obtained from untrusted sources. OpenSSL versions 1.1.1i and below are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1j. OpenSSL versions 1.0.2x and below are affected by this issue. However OpenSSL 1.0.2 is out of support and no longer receiving public updates. Premium support customers of OpenSSL 1.0.2 should upgrade to 1.0.2y. Other users should upgrade to 1.1.1j. Fixed in OpenSSL 1.1.1j (Affected 1.1.1-1.1.1i). Fixed in OpenSSL 1.0.2y (Affected 1.0.2-1.0.2x).(CVE-2021-23841)

Calls to EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate may overflow the output length argument in some cases where the input length…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2021-1121"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2021:0427-1</id>
    <title>openSUSE-SU-2021:0427-1 — Security update for openssl-1_1</title>
    <updated>2026-10-02T14:15:51.952849+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for openssl-1_1</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2021:0427-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2021:1168</id>
    <title>RHSA-2021:1168 — Red Hat Security Advisory: Red Hat Advanced Cluster Management 2.2.2 security and bug fix update</title>
    <updated>2026-10-02T14:15:51.952867+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>golang.org/x/text: possibility to trigger an infinite loop in encoding/unicode could lead to crash nodejs-lodash: ReDoS via the toNumber, trim and trimEnd functions golang.org/x/text: Panic in language.ParseAcceptLanguage while parsing -u- extension golang.org/x/text: Panic in language.ParseAcceptLanguage while processing bcp47 tag go-slug: partial protection against zip slip attacks fastify-reply-from: crafted URL allows prefix scape of the proxied backend service fastify-http-proxy: crafted URL allows prefix scape of the proxied backend service nodejs-lodash: command injection via template openssl: integer overflow in CipherUpdate openssl: NULL pointer dereference in X509_issuer_and_serial_hash()</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2021:1168"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rustsec-2021-0058</id>
    <title>RUSTSEC-2021-0058 — Null pointer deref in `X509_issuer_and_serial_hash()`</title>
    <updated>2026-10-02T14:15:51.952900+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: openssl-src</p>
<p>The OpenSSL public API function `X509_issuer_and_serial_hash()` attempts to
create a unique hash value based on the issuer and serial number data contained
within an X509 certificate. However it fails to correctly handle any errors
that may occur while parsing the issuer field (which might occur if the issuer
field is maliciously constructed). This may subsequently result in a NULL
pointer deref and a crash leading to a potential denial of service attack.</p>
<p>The function `X509_issuer_and_serial_hash()` is never directly called by OpenSSL
itself so applications are only vulnerable if they use this function directly
and they use it on certificates that may have been obtained from untrusted
sources.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rustsec-2021-0058"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2021:0725-1</id>
    <title>SUSE-SU-2021:0725-1 — Security update for openssl-1_0_0</title>
    <updated>2026-10-02T14:15:51.952923+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for openssl-1_0_0</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2021:0725-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-23841</id>
    <title>UBUNTU-CVE-2021-23841</title>
    <updated>2026-10-02T14:15:51.952948+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: openssl, Ubuntu:16.04:LTS: openssl, Ubuntu:18.04:LTS: openssl, Ubuntu:18.04:LTS: openssl1.0, Ubuntu:20.04:LTS: openssl</p>
<p>The OpenSSL public API function X509_issuer_and_serial_hash() attempts to create a unique hash value based on the issuer and serial number data contained within an X509 certificate. However it fails to correctly handle any errors that may occur while parsing the issuer field (which might occur if the issuer field is maliciously constructed). This may subsequently result in a NULL pointer deref and a crash leading to a potential denial of service attack. The function X509_issuer_and_serial_hash() is never directly called by OpenSSL itself so applications are only vulnerable if they use this function directly and they use it on certificates that may have been obtained from untrusted sources. OpenSSL versions 1.1.1i and below are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1j. OpenSSL versions 1.0.2x and below are affected by this issue. However OpenSSL 1.0.2 is out of support and no longer receiving public updates. Premium support customers of OpenSSL 1.0.2 should upgrade to 1.0.2y. Other users should upgrade to 1.1.1j. Fixed in OpenSSL 1.1.1j (Affected 1.1.1-1.1.1i). Fixed in OpenSSL 1.0.2y (Affected 1.0.2-1.0.2x).</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-23841"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0602</id>
    <title>WID-SEC-W-2022-0602 — IBM Security Verify Access: Mehrere Schwachstellen</title>
    <updated>2026-10-02T14:15:51.953005+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter anonymer, authentisierter oder lokaler Angreifer oder ein Angreifer aus dem angrenzenden Netzwerk kann mehrere Schwachstellen in IBM Security Verify Access ausnutzen, um einen Cross-Site-Scripting-Angriff durchzuführen, vertrauliche Informationen offenzulegen, seine Privilegien zu erweitern, Informationen zu manipulieren, einen Denial-of-Service-Zustand zu verursachen und Sicherheitsmaßnahmen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0602"/>
  </entry>
</feed>
