<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T20:35:00.595813+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2022:6224</id>
    <title>ALSA-2022:6224 — Moderate: openssl security and bug fix update</title>
    <updated>2026-10-03T20:35:00.834007+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: openssl, AlmaLinux:9: openssl-devel, AlmaLinux:9: openssl-libs, AlmaLinux:9: openssl-perl</p>
<p>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, as well as a full-strength general-purpose cryptography library.
Security Fix(es):
* openssl: c_rehash script allows command injection (CVE-2022-1292)
* openssl: Signer certificate verification returns inaccurate response when using OCSP_NOCHECKS (CVE-2022-1343)
* openssl: OPENSSL_LH_flush() breaks reuse of memory (CVE-2022-1473)
* openssl: the c_rehash script allows command injection (CVE-2022-2068)
* openssl: AES OCB fails to encrypt some bytes (CVE-2022-2097)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Bug Fix(es):
* openssl occasionally sends internal error to gnutls when using FFDHE (BZ#2080323)
* openssl req defaults to 3DES (BZ#2085499)
* OpenSSL accepts custom elliptic curve parameters when p is large [almalinux-9] (BZ#2085508)
* OpenSSL mustn't work with ECDSA with explicit curve parameters in FIPS mode (BZ#2085521)
* openssl s_server -groups secp256k1 in FIPS fails because X25519/X448 (BZ#2086554)
* Converting FIPS power-on self test to KAT (BZ#2086866)
* Small RSA keys work for some operations in FIPS mode (BZ#2091938)
* FIPS provider doesn't block RSA encryption for key transport (BZ#2091977)
* OpenSSL testsuite certificates expired (BZ#2095696)
* [IBM 9.1 HW OPT] POWER10 performance enhancements for cryptogr…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2022:6224"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2022-03268</id>
    <title>bdu:2022-03268</title>
    <updated>2026-10-03T20:35:00.834129+00:00</updated>
    <content>bdu:2022-03268</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2022-03268"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2022-1473</id>
    <title>Withdrawn: BELL-CVE-2022-1473 — CVE-2022-1473 does not affect BellSoft software</title>
    <updated>2026-10-03T20:35:00.834158+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2022-1473"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2022-avi-411</id>
    <title>certfr-2022-avi-411 — De multiples vulnérabilités ont été découvertes dans OpenSSL. Certaines
d'entre elles permettent à un attaquant de prov…</title>
    <updated>2026-10-03T20:35:00.834183+00:00</updated>
    <content>certfr-2022-avi-411</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2022-avi-411"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-gk72927</id>
    <title>Withdrawn: CLEANSTART-2026-GK72927 — Issue summary: PBMAC1 parameters in PKCS#12 files are missing validation
which can trigger a stack-based buffer overflo…</title>
    <updated>2026-10-03T20:35:00.834208+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: openssl</p>
<p>Multiple security vulnerabilities affect the openssl package. Issue summary: PBMAC1 parameters in PKCS#12 files are missing validation which can trigger a stack-based buffer overflow, invalid pointer or NULL pointer dereference during MAC verification. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-gk72927"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2022-37792</id>
    <title>cnvd-2022-37792</title>
    <updated>2026-10-03T20:35:00.834252+00:00</updated>
    <content>cnvd-2022-37792</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2022-37792"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-237460</id>
    <title>EUVD-2026-237460</title>
    <updated>2026-10-03T20:35:00.834286+00:00</updated>
    <content>EUVD-2026-237460</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-237460"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-1473</id>
    <title>fkie_cve-2022-1473</title>
    <updated>2026-10-03T20:35:00.834309+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The OPENSSL_LH_flush() function, which empties a hash table, contains a bug that breaks reuse of the memory occuppied by the removed hash table entries. This function is used when decoding certificates or keys. If a long lived process periodically decodes certificates or keys its memory usage will expand without bounds and the process might be terminated by the operating system causing a denial of service. Also traversing the empty hash table entries will take increasingly more time. Typically such long lived processes might be TLS clients or TLS servers configured to accept client certificate authentication. The function was added in the OpenSSL 3.0 version thus older releases are not affected by the issue. Fixed in OpenSSL 3.0.3 (Affected 3.0.0,3.0.1,3.0.2).</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-1473"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-g323-fr93-4j3c</id>
    <title>GHSA-g323-fr93-4j3c — Resource leakage when decoding certificates and keys</title>
    <updated>2026-10-03T20:35:00.834361+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: openssl-src</p>
<p>The OPENSSL_LH_flush() function, which empties a hash table, contains a bug that breaks reuse of the memory occuppied by the removed hash table entries. This function is used when decoding certificates or keys. If a long lived process periodically decodes certificates or keys its memory usage will expand without bounds and the process might be terminated by the operating system causing a denial of service. Also traversing the empty hash table entries will take increasingly more time. Typically such long lived processes might be TLS clients or TLS servers configured to accept client certificate authentication. The function was added in the OpenSSL 3.0 version thus older releases are not affected by the issue. Fixed in OpenSSL 3.0.3 (Affected 3.0.0,3.0.1,3.0.2).</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-g323-fr93-4j3c"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-1473</id>
    <title>gsd-2022-1473</title>
    <updated>2026-10-03T20:35:00.834405+00:00</updated>
    <content>gsd-2022-1473</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-1473"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-23-047-03</id>
    <title>ICSA-23-047-03 — Siemens Brownfield Connectivity Client</title>
    <updated>2026-10-03T20:35:00.834425+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. Under certain circumstances, the command line OCSP verify function reports successful verification when the varification in fact failed. In this case the incorrect successful response will also be accompanied by error messages showing the failure and contradicting the apparently successful result. When using the RC4-MD5 ciphersuite, which is disabled by default, an attacker is able to modify data in transit due to an incorrect use of the AAD data as the MAC key in OpenSSL 3.0. An attacker is not able to decrypt any communication. The used OpenSSL version improperly reuses memory when decoding certificates or keys. This can lead to a process termination and Denial of Service for long lived processes.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-23-047-03"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12204-1</id>
    <title>openSUSE-SU-2024:12204-1 — libopenssl-3-devel-3.0.5-1.1 on GA media</title>
    <updated>2026-10-03T20:35:00.834463+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libopenssl-3-devel-3.0.5-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:12204-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rustsec-2022-0025</id>
    <title>RUSTSEC-2022-0025 — Resource leakage when decoding certificates and keys</title>
    <updated>2026-10-03T20:35:00.834492+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: openssl-src</p>
<p>The `OPENSSL_LH_flush()` function, which empties a hash table, contains
a bug that breaks reuse of the memory occupied by the removed hash
table entries.</p>
<p>This function is used when decoding certificates or keys. If a long lived
process periodically decodes certificates or keys its memory usage will
expand without bounds and the process might be terminated by the operating
system causing a denial of service. Also traversing the empty hash table
entries will take increasingly more time.</p>
<p>Typically such long lived processes might be TLS clients or TLS servers
configured to accept client certificate authentication.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rustsec-2022-0025"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-1473</id>
    <title>UBUNTU-CVE-2022-1473</title>
    <updated>2026-10-03T20:35:00.834533+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: openssl, Ubuntu:Pro:16.04:LTS: edk2, Ubuntu:Pro:FIPS:16.04:LTS: openssl, Ubuntu:22.04:LTS: openssl</p>
<p>The OPENSSL_LH_flush() function, which empties a hash table, contains a bug that breaks reuse of the memory occuppied by the removed hash table entries. This function is used when decoding certificates or keys. If a long lived process periodically decodes certificates or keys its memory usage will expand without bounds and the process might be terminated by the operating system causing a denial of service. Also traversing the empty hash table entries will take increasingly more time. Typically such long lived processes might be TLS clients or TLS servers configured to accept client certificate authentication. The function was added in the OpenSSL 3.0 version thus older releases are not affected by the issue. Fixed in OpenSSL 3.0.3 (Affected 3.0.0,3.0.1,3.0.2).</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-1473"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0071</id>
    <title>WID-SEC-W-2022-0071 — OpenSSL: Mehrere Schwachstellen</title>
    <updated>2026-10-03T20:35:00.834591+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in OpenSSL ausnutzen, um beliebigen Programmcode mit den Rechten des Dienstes auszuführen, Sicherheitsvorkehrungen zu umgehen, Dateien zu manipulieren oder einen Denial of Service Zustand herbeizuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0071"/>
  </entry>
</feed>
