<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T13:40:04.801731+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2023:3722</id>
    <title>ALSA-2023:3722 — Moderate: openssl security and bug fix update</title>
    <updated>2026-10-02T13:40:04.891373+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: openssl, AlmaLinux:9: openssl-devel, AlmaLinux:9: openssl-libs, AlmaLinux:9: openssl-perl</p>
<p>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, as well as a full-strength general-purpose cryptography library.</p>
<p>Security Fix(es):</p>
<p>* openssl: Possible DoS translating ASN.1 object identifiers (CVE-2023-2650)
* openssl: Denial of service by excessive resource usage in verifying X509 policy constraints (CVE-2023-0464)
* openssl: Invalid certificate policies in leaf certificates are silently ignored (CVE-2023-0465)
* openssl: Certificate policy check not enabled (CVE-2023-0466)
* openssl: Input buffer over-read in AES-XTS implementation on 64 bit ARM (CVE-2023-1255)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p>
<p>Bug Fix(es):</p>
<p>* In FIPS mode, openssl KDFs should only allow selected hash algorithms (BZ#2175860)
* In FIPS mode, openssl should reject short KDF input or output keys or provide an indicator (BZ#2175864)
* In FIPS mode, openssl should provide an indicator for AES-GCM to query whether the IV was generated internally or provided externally (BZ#2175868)
* openssl FIPS mode self-test should zeroize `out` in `verify_integrity` in providers/fips/self_test.c (BZ#2175873)
* In FIPS mode, openssl should not support RSA encryption or decryption without padding (outside of RSASVE) or provide an indicator (BZ#2178029)
* In FIPS mode, openssl should reject EVP_PKEY_fromdata…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2023:3722"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-02108</id>
    <title>bdu:2023-02108</title>
    <updated>2026-10-02T13:40:04.891480+00:00</updated>
    <content>bdu:2023-02108</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-02108"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2023-0464</id>
    <title>Withdrawn: BELL-CVE-2023-0464 — CVE-2023-0464 does not affect BellSoft software</title>
    <updated>2026-10-02T13:40:04.891499+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2023-0464"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0255</id>
    <title>certfr-2023-avi-0255 — Une vulnérabilité a été découverte dans OpenSSL. Elle permet à un
attaquant de provoquer un déni de service à distance.</title>
    <updated>2026-10-02T13:40:04.891516+00:00</updated>
    <content>certfr-2023-avi-0255</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2023-avi-0255"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-gk72927</id>
    <title>Withdrawn: CLEANSTART-2026-GK72927 — Issue summary: PBMAC1 parameters in PKCS#12 files are missing validation
which can trigger a stack-based buffer overflo…</title>
    <updated>2026-10-02T13:40:04.891529+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: openssl</p>
<p>Multiple security vulnerabilities affect the openssl package. Issue summary: PBMAC1 parameters in PKCS#12 files are missing validation which can trigger a stack-based buffer overflow, invalid pointer or NULL pointer dereference during MAC verification. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-gk72927"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-237293</id>
    <title>EUVD-2026-237293</title>
    <updated>2026-10-02T13:40:04.891554+00:00</updated>
    <content>EUVD-2026-237293</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-237293"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-0464</id>
    <title>fkie_cve-2023-0464</title>
    <updated>2026-10-02T13:40:04.891565+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>A security vulnerability has been identified in all supported versions</p>
<p>of OpenSSL related to the verification of X.509 certificate chains
that include policy constraints.  Attackers may be able to exploit this
vulnerability by creating a malicious certificate chain that triggers
exponential use of computational resources, leading to a denial-of-service
(DoS) attack on affected systems.</p>
<p>Policy processing is disabled by default but can be enabled by passing
the `-policy' argument to the command line utilities or by calling the
`X509_VERIFY_PARAM_set1_policies()' function.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-0464"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-w2w6-xp88-5cvw</id>
    <title>GHSA-w2w6-xp88-5cvw</title>
    <updated>2026-10-02T13:40:04.891592+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A security vulnerability has been identified in all supported versions of OpenSSL related to the verification of X.509 certificate chains that include policy constraints. Attackers may be able to exploit this vulnerability by creating a malicious certificate chain that triggers exponential use of computational resources, leading to a denial-of-service (DoS) attack on affected systems. Policy processing is disabled by default but can be enabled by passing the `-policy' argument to the command line utilities or by calling the `X509_VERIFY_PARAM_set1_policies()' function.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-w2w6-xp88-5cvw"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-0464</id>
    <title>gsd-2023-0464</title>
    <updated>2026-10-02T13:40:04.891610+00:00</updated>
    <content>gsd-2023-0464</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-0464"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-23-166-11</id>
    <title>ICSA-23-166-11 — Siemens SIMATIC S7-1500 TM MFP Linux Kernel</title>
    <updated>2026-10-02T13:40:04.891621+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend. A memory overflow vulnerability was found in the Linux kernel’s ipc functionality of the memcg subsystem, in the way a user calls the semget function multiple times, creating semaphores. This flaw allows a local user to starve the resources, causing a denial of service. The highest threat from this vulnerability is to system availability. A vulnerability was found in the fs/inode.c:inode_init_owner() function logic of the LInux kernel that allows local users to create files for the XFS file-system with an unintended group ownership and with group execution and SGID permission bits set, in a scenario where a directory is SGID and belongs to a certain group and is writable by a user who is not a member of this group. This can lead to excessive permissions granted in case when they should not. This vulnerability is similar to the previous CVE-2018-13405 and adds the missed fix for the XFS. When sending malicous data to kernel by ioctl cmd FBIOPUT_VSCREENINFO,kernel will write memory out of bounds. In gc_data_segment in fs/f2fs/gc.c in the Linux kernel before 5.16.3, special files are not considered, leading to a move_data_page NULL pointer dereference. A flaw was found in the Linux kernel. The existing KVM SEV API has a vulnerability that allows a non-root (host) user-level application to crash the host kernel by creating a confidential guest VM inst…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-23-166-11"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2023-1207</id>
    <title>OESA-2023-1207 — openssl security update</title>
    <updated>2026-10-02T13:40:04.892075+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: openssl, openEuler:20.03-LTS-SP3: openssl, openEuler:22.03-LTS: openssl, openEuler:22.03-LTS-SP1: openssl</p>
<p>OpenSSL is a robust, commercial-grade, and full-featured toolkit for the Transport Layer Security (TLS) and Secure Sockets Layer (SSL) protocols.

Security Fix(es):

A security vulnerability has been identified in all supported versions of OpenSSL related to the verification of X.509 certificate chains that include policy constraints. Attackers may be able to exploit this vulnerability by creating a malicious certificate chain that triggers exponential use of computational resources, leading to a denial-of-service (DoS) attack on affected systems. Policy processing is disabled by default but can be enabled by passing the `-policy&amp;apos; argument to the command line utilities or by calling the `X509_VERIFY_PARAM_set1_policies()&amp;apos; function.(CVE-2023-0464)

Applications that use a non-default option when verifying certificates may be vulnerable to an attack from a malicious CA to circumvent certain checks. Invalid certificate policies in leaf certificates are silently ignored by OpenSSL and other certificate policy checks are skipped for that certificate. A malicious CA could use this to deliberately assert invalid certificate policies in order to circumvent policy checking on the certificate altogether. Policy processing is disabled by default but can be enabled by passing the `-policy&amp;apos; argument to the command line utilities or by calling the `X509_VERIFY_PARAM_set1_policies()&amp;apos; function.(CVE-2023-0465)

The function X509_VERIFY_PARAM_add0_policy() is docum…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2023-1207"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12824-1</id>
    <title>openSUSE-SU-2024:12824-1 — libopenssl-1_0_0-devel-1.0.2u-14.1 on GA media</title>
    <updated>2026-10-02T13:40:04.892135+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libopenssl-1_0_0-devel-1.0.2u-14.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:12824-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2023:7622</id>
    <title>RHSA-2023:7622 — Red Hat Security Advisory: Red Hat JBoss Web Server 5.7.7 release and security update</title>
    <updated>2026-10-02T13:40:04.892155+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>openssl: Denial of service by excessive resource usage in verifying X509 policy constraints openssl: Invalid certificate policies in leaf certificates are silently ignored openssl: Certificate policy check not enabled openssl: Possible DoS translating ASN.1 object identifiers openssl: Excessive time spent checking DH keys and parameters OpenSSL: Excessive time spent checking DH q parameter value tomcat: Open Redirect vulnerability in FORM authentication</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2023:7622"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2023:1704-1</id>
    <title>SUSE-SU-2023:1704-1 — Security update for openssl-1_0_0</title>
    <updated>2026-10-02T13:40:04.892182+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for openssl-1_0_0</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2023:1704-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-0464</id>
    <title>UBUNTU-CVE-2023-0464</title>
    <updated>2026-10-02T13:40:04.892198+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: openssl, Ubuntu:Pro:16.04:LTS: openssl, Ubuntu:Pro:16.04:LTS: edk2, Ubuntu:Pro:FIPS:16.04:LTS: openssl, Ubuntu:18.04:LTS: openssl, Ubuntu:18.04:LTS: openssl1.0, Ubuntu:Pro:18.04:LTS: edk2, Ubuntu:Pro:FIPS-updates:18.04:LTS: openssl, Ubuntu:Pro:FIPS:18.04:LTS: openssl, Ubuntu:20.04:LTS: openssl and 6 more</p>
<p>A security vulnerability has been identified in all supported versions of OpenSSL related to the verification of X.509 certificate chains that include policy constraints.  Attackers may be able to exploit this vulnerability by creating a malicious certificate chain that triggers exponential use of computational resources, leading to a denial-of-service (DoS) attack on affected systems. Policy processing is disabled by default but can be enabled by passing the `-policy' argument to the command line utilities or by calling the `X509_VERIFY_PARAM_set1_policies()' function.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-0464"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0732</id>
    <title>WID-SEC-W-2023-0732 — OpenSSL: Schwachstelle ermöglicht Denial of Service</title>
    <updated>2026-10-02T13:40:04.892243+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in OpenSSL ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0732"/>
  </entry>
</feed>
