<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T22:55:35.426428+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-233377</id>
    <title>EUVD-2026-233377</title>
    <updated>2026-10-05T22:55:35.434069+00:00</updated>
    <content>EUVD-2026-233377</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-233377"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-46149</id>
    <title>fkie_cve-2022-46149</title>
    <updated>2026-10-05T22:55:35.434107+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Cap'n Proto is a data interchange format and remote procedure call (RPC) system. Cap'n Proro prior to versions 0.7.1, 0.8.1, 0.9.2, and 0.10.3, as well as versions of Cap'n Proto's Rust implementation prior to 0.13.7, 0.14.11, and 0.15.2 are vulnerable to out-of-bounds read due to logic error handling list-of-list. This issue may lead someone to remotely segfault a peer by sending it a malicious message, if the victim performs certain actions on a list-of-pointer type. Exfiltration of memory is possible if the victim performs additional certain actions on a list-of-pointer type. To be vulnerable, an application must perform a specific sequence of actions, described in the GitHub Security Advisory. The bug is present in inlined code, therefore the fix will require rebuilding dependent applications. Cap'n Proto has C++ fixes available in versions 0.7.1, 0.8.1, 0.9.2, and 0.10.3. The `capnp` Rust crate has fixes available in versions 0.13.7, 0.14.11, and 0.15.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-46149"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-qqff-4vw4-f6hx</id>
    <title>GHSA-qqff-4vw4-f6hx — Cap'n Proto and its Rust implementation vulnerable to out-of-bounds read due to logic error handling list-of-list</title>
    <updated>2026-10-05T22:55:35.434146+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: capnp</p>
<p>The Cap'n Proto library and capnp Rust package are vulnerable to out-of-bounds read due to logic error handling list-of-list. If a message consumer expects data of type "list of pointers", and if the consumer performs certain specific actions on such data, then a message producer can cause the consumer to read out-of-bounds memory. This could trigger a process crash in the consumer, or in some cases could allow exfiltration of private in-memory data.</p>
<p>Impact
======</p>
<p>- Remotely segfault a peer by sending it a malicious message, if the victim performs certain actions on a list-of-pointer type.
- Possible exfiltration of memory, if the victim performs additional certain actions on a list-of-pointer type.
- To be vulnerable, an application must perform a specific sequence of actions, described below. At present, **we are not aware of any vulnerable application**, but we advise updating regardless.</p>
<p>Fixed in
========</p>
<p>Unfortunately, the bug is present in inlined code, therefore the fix will require rebuilding dependent applications.</p>
<p>C++ fix:</p>
<p>- git commit [25d34c67863fd960af34fc4f82a7ca3362ee74b9][0]
- release 0.11 (future)
- release 0.10.3:
  - Unix: https://capnproto.org/capnproto-c++-0.10.3.tar.gz
  - Windows: https://capnproto.org/capnproto-c++-win32-0.10.3.zip
- release 0.9.2:
  - Unix: https://capnproto.org/capnproto-c++-0.9.2.tar.gz
  - Windows: https://capnproto.org/capnproto-c++-win32-0.9.2.zip
- release 0.8.1:
  - Unix: https://capnproto.org/capnproto-c++-0.8.1.tar.gz…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-qqff-4vw4-f6hx"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-46149</id>
    <title>gsd-2022-46149</title>
    <updated>2026-10-05T22:55:35.434204+00:00</updated>
    <content>gsd-2022-46149</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-46149"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12543-1</id>
    <title>openSUSE-SU-2024:12543-1 — capnproto-0.10.3-1.1 on GA media</title>
    <updated>2026-10-05T22:55:35.434217+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>capnproto-0.10.3-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:12543-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2023:1408</id>
    <title>RHSA-2023:1408 — Red Hat Security Advisory: OpenShift Container Platform 4.12.9 packages and security update</title>
    <updated>2026-10-05T22:55:35.434235+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>capnproto: out of bounds read when handling a list of lists.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2023:1408"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rustsec-2022-0068</id>
    <title>RUSTSEC-2022-0068 — out-of-bounds read possible when setting list-of-pointers</title>
    <updated>2026-10-05T22:55:35.434251+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: capnp</p>
<p>If a message consumer expects data
of type "list of pointers",
and if the consumer performs certain specific actions on such data,
then a message producer can cause the consumer to read out-of-bounds memory.
This could trigger a process crash in the consumer,
or in some cases could allow exfiltration of private in-memory data.</p>
<p>The C++ Cap'n Proto library is also affected by this bug.
See the [advisory](https://github.com/capnproto/capnproto/tree/master/security-advisories/2022-11-30-0-pointer-list-bounds.md)
on the main Cap'n Proto repo for a succinct description of
the exact circumstances in which the problem can arise.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rustsec-2022-0068"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-46149</id>
    <title>UBUNTU-CVE-2022-46149</title>
    <updated>2026-10-05T22:55:35.434274+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: capnproto, Ubuntu:16.04:LTS: capnproto, Ubuntu:16.04:LTS: interchange, Ubuntu:Pro:18.04:LTS: capnproto, Ubuntu:Pro:20.04:LTS: capnproto, Ubuntu:22.04:LTS: capnproto</p>
<p>Cap'n Proto is a data interchange format and remote procedure call (RPC) system. Cap'n Proro prior to versions 0.7.1, 0.8.1, 0.9.2, and 0.10.3, as well as versions of Cap'n Proto's Rust implementation prior to 0.13.7, 0.14.11, and 0.15.2 are vulnerable to out-of-bounds read due to logic error handling list-of-list. This issue may lead someone to remotely segfault a peer by sending it a malicious message, if the victim performs certain actions on a list-of-pointer type. Exfiltration of memory is possible if the victim performs additional certain actions on a list-of-pointer type. To be vulnerable, an application must perform a specific sequence of actions, described in the GitHub Security Advisory. The bug is present in inlined code, therefore the fix will require rebuilding dependent applications. Cap'n Proto has C++ fixes available in versions 0.7.1, 0.8.1, 0.9.2, and 0.10.3. The `capnp` Rust crate has fixes available in versions 0.13.7, 0.14.11, and 0.15.2.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-46149"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0775</id>
    <title>WID-SEC-W-2023-0775 — Red Hat OpenShift: Schwachstelle ermöglicht Denial of Service</title>
    <updated>2026-10-05T22:55:35.434322+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat OpenShift ausnutzen, um einen Denial of Service Angriff durchzuführen oder Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0775"/>
  </entry>
</feed>
