<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T07:43:52.813859+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2024:0748</id>
    <title>ALSA-2024:0748 — Important: container-tools:4.0 security update</title>
    <updated>2026-10-03T07:43:53.280280+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: aardvark-dns, AlmaLinux:8: buildah, AlmaLinux:8: buildah-tests, AlmaLinux:8: cockpit-podman, AlmaLinux:8: conmon, AlmaLinux:8: container-selinux, AlmaLinux:8: containernetworking-plugins, AlmaLinux:8: containers-common, AlmaLinux:8: crit, AlmaLinux:8: criu and 24 more</p>
<p>The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.</p>
<p>Security Fix(es):</p>
<p>* runc: file descriptor leak ("Leaky Vessels") (CVE-2024-21626)</p>
<p>A AlmaLinux Security Bulletin which addresses further details about the Leaky Vessels flaw is available in the References section.</p>
<p>* golang: net/http/internal: Denial of Service (DoS) via Resource Consumption via HTTP requests (CVE-2023-39326)
* golang: crypto/tls: Timing Side Channel attack in RSA based TLS key exchanges. (CVE-2023-45287)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2024:0748"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2023-45287</id>
    <title>BELL-CVE-2023-45287</title>
    <updated>2026-10-03T07:43:53.280401+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: go, BellSoft Hardened Containers:23: go</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2023-45287"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-golang-2023-45287</id>
    <title>BIT-golang-2023-45287 — Before Go 1.20, the RSA based key exchange methods in crypto/tls may exhibit a timing side channel</title>
    <updated>2026-10-03T07:43:53.280426+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: golang</p>
<p>Before Go 1.20, the RSA based TLS key exchanges used the math/big library, which is not constant time. RSA blinding was applied to prevent timing attacks, but analysis shows this may not have been fully effective. In particular it appears as if the removal of PKCS#1 padding may leak timing information, which in turn could be used to recover session key bits. In Go 1.20, the crypto/tls library switched to a fully constant time RSA implementation, which we do not believe exhibits any timing side channels.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-golang-2023-45287"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0646</id>
    <title>certfr-2024-avi-0646 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-03T07:43:53.280448+00:00</updated>
    <content>certfr-2024-avi-0646</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0646"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-216886</id>
    <title>EUVD-2026-216886</title>
    <updated>2026-10-03T07:43:53.280465+00:00</updated>
    <content>EUVD-2026-216886</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-216886"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-45287</id>
    <title>fkie_cve-2023-45287</title>
    <updated>2026-10-03T07:43:53.280477+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Before Go 1.20, the RSA based TLS key exchanges used the math/big library, which is not constant time. RSA blinding was applied to prevent timing attacks, but analysis shows this may not have been fully effective. In particular it appears as if the removal of PKCS#1 padding may leak timing information, which in turn could be used to recover session key bits. In Go 1.20, the crypto/tls library switched to a fully constant time RSA implementation, which we do not believe exhibits any timing side channels.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-45287"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-33qr-2xwr-95pw</id>
    <title>GHSA-33qr-2xwr-95pw</title>
    <updated>2026-10-03T07:43:53.280499+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Before Go 1.20, the RSA based TLS key exchanges used the math/big library, which is not constant time. RSA blinding was applied to prevent timing attacks, but analysis shows this may not have been fully effective. In particular it appears as if the removal of PKCS#1 padding may leak timing information, which in turn could be used to recover session key bits. In Go 1.20, the crypto/tls library switched to a fully constant time RSA implementation, which we do not believe exhibits any timing side channels.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-33qr-2xwr-95pw"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-45287</id>
    <title>gsd-2023-45287</title>
    <updated>2026-10-03T07:43:53.280515+00:00</updated>
    <content>gsd-2023-45287</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-45287"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2023-45287</id>
    <title>msrc_CVE-2023-45287 — Before Go 1.20, the RSA based key exchange methods in crypto/tls may exhibit a timing side channel</title>
    <updated>2026-10-03T07:43:53.280525+00:00</updated>
    <content>msrc_CVE-2023-45287</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2023-45287"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhba-2025:1772</id>
    <title>RHBA-2025:1772 — Red Hat Bug Fix Advisory: Updated 7.1 container image is now available in the Red Hat Ecosystem Catalog</title>
    <updated>2026-10-03T07:43:53.280541+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>golang: crypto/tls: Timing Side Channel attack in RSA based TLS key exchanges. golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON jose: resource exhaustion jose-go: improper handling of highly compressed data envoy: HTTP/2 CPU exhaustion due to CONTINUATION frame flood go/parser: golang: Calling any of the Parse functions containing deeply nested literals can cause a panic/stack exhaustion encoding/gob: golang: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion keepalived: Integer overflow vulnerability in vrrp_ipsets_handler</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhba-2025:1772"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:2180</id>
    <title>RHSA-2024:2180 — Red Hat Security Advisory: runc security update</title>
    <updated>2026-10-03T07:43:53.280572+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>golang: io/fs: stack exhaustion in Glob golang: compress/gzip: stack exhaustion in Reader.Read golang: path/filepath: stack exhaustion in Glob golang: crypto/tls: Timing Side Channel attack in RSA based TLS key exchanges.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:2180"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-45287</id>
    <title>UBUNTU-CVE-2023-45287</title>
    <updated>2026-10-03T07:43:53.280617+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:20.04:LTS: golang-1.20, Ubuntu:22.04:LTS: golang-1.20</p>
<p>Before Go 1.20, the RSA based TLS key exchanges used the math/big library, which is not constant time. RSA blinding was applied to prevent timing attacks, but analysis shows this may not have been fully effective. In particular it appears as if the removal of PKCS#1 padding may leak timing information, which in turn could be used to recover session key bits. In Go 1.20, the crypto/tls library switched to a fully constant time RSA implementation, which we do not believe exhibits any timing side channels.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-45287"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-3059</id>
    <title>WID-SEC-W-2023-3059 — Golang Go: Schwachstelle ermöglicht Offenlegung von Informationen</title>
    <updated>2026-10-03T07:43:53.280653+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Golang Go ausnutzen, um Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-3059"/>
  </entry>
</feed>
