<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T22:10:47.894890+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2024:0965</id>
    <title>ALSA-2024:0965 — Important: unbound security update</title>
    <updated>2026-10-02T22:10:48.847556+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: python3-unbound, AlmaLinux:8: unbound, AlmaLinux:8: unbound-devel, AlmaLinux:8: unbound-libs</p>
<p>The unbound packages provide a validating, recursive, and caching DNS or DNSSEC resolver.</p>
<p>Security Fix(es):</p>
<p>* bind9: KeyTrap - Extreme CPU consumption in DNSSEC validator (CVE-2023-50387)
* bind9: Preparing an NSEC3 closest encloser proof can exhaust CPU resources (CVE-2023-50868)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2024:0965"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-01462</id>
    <title>bdu:2024-01462</title>
    <updated>2026-10-02T22:10:48.847644+00:00</updated>
    <content>bdu:2024-01462</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-01462"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2023-50868</id>
    <title>BELL-CVE-2023-50868</title>
    <updated>2026-10-02T22:10:48.847662+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: bind, Alpaquita:23: dnsmasq, Alpaquita:stream: bind, Alpaquita:stream: dnsmasq</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2023-50868"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0122</id>
    <title>certfr-2024-avi-0122 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;Bind&lt;/span&gt;. Elles permettent à un attaquant…</title>
    <updated>2026-10-02T22:10:48.847685+00:00</updated>
    <content>certfr-2024-avi-0122</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0122"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ky78316</id>
    <title>Withdrawn: CLEANSTART-2026-KY78316 — dnsmasqs extract_name() function can be abused to cause a heap buffer overflow, allowing an attacker to inject false DN…</title>
    <updated>2026-10-02T22:10:48.847701+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: dnsmasq</p>
<p>Multiple security vulnerabilities affect the dnsmasq package. dnsmasqs extract_name() function can be abused to cause a heap buffer overflow, allowing an attacker to inject false DNS cache entries, which could result in DNS lookups to redirect to an attacker-controlled IP address, or to cause a DoS. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ky78316"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-259298</id>
    <title>EUVD-2026-259298</title>
    <updated>2026-10-02T22:10:48.847725+00:00</updated>
    <content>EUVD-2026-259298</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-259298"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-50868</id>
    <title>fkie_cve-2023-50868</title>
    <updated>2026-10-02T22:10:48.847737+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-1 computations) via DNSSEC responses in a random subdomain attack, aka the "NSEC3" issue. The RFC 5155 specification implies that an algorithm must perform thousands of iterations of a hash function in certain situations.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-50868"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-pv4h-p8jr-6cv2</id>
    <title>GHSA-pv4h-p8jr-6cv2</title>
    <updated>2026-10-02T22:10:48.847759+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-1 computations) via DNSSEC responses in a random subdomain attack, aka the "NSEC3" issue. The RFC 5155 specification implies that an algorithm must perform thousands of iterations of a hash function in certain situations.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-pv4h-p8jr-6cv2"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-50868</id>
    <title>gsd-2023-50868</title>
    <updated>2026-10-02T22:10:48.847775+00:00</updated>
    <content>gsd-2023-50868</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-50868"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-24-319-08</id>
    <title>ICSA-24-319-08 — Siemens SINEC INS</title>
    <updated>2026-10-02T22:10:48.847785+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Issue summary: The AES-SIV cipher implementation contains a bug that causes it to ignore empty associated data entries which are unauthenticated as a consequence. Impact summary: Applications that use the AES-SIV algorithm and want to authenticate empty data entries as associated data can be mislead by removing adding or reordering such empty entries as these are ignored by the OpenSSL implementation. We are currently unaware of any such applications. The AES-SIV algorithm allows for authentication of multiple associated data entries along with the encryption. To authenticate empty data the application has to call EVP_EncryptUpdate() (or EVP_CipherUpdate()) with NULL pointer as the output buffer and 0 as the input buffer length. The AES-SIV implementation in OpenSSL just returns success for such a call instead of performing the associated data authentication operation. The empty data thus will not be authenticated. As this issue does not affect non-empty associated data authentication and we expect it to be rare for an application to use empty associated data entries this is qualified as Low severity issue. The code that processes control channel messages sent to `named` calls certain functions recursively during packet parsing. Recursion depth is only limited by the maximum accepted packet size; depending on the environment, this may cause the packet-parsing code to run out of available stack memory, causing `named` to terminate unexpectedly. Since each incoming control cha…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-24-319-08"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2024-1210</id>
    <title>OESA-2024-1210 — unbound security update</title>
    <updated>2026-10-02T22:10:48.847978+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: unbound, openEuler:20.03-LTS-SP4: unbound, openEuler:22.03-LTS: unbound, openEuler:22.03-LTS-SP1: unbound, openEuler:22.03-LTS-SP2: unbound, openEuler:22.03-LTS-SP3: unbound</p>
<p>Unbound is a validating, recursive, caching DNS resolver. It is designed to be fast and lean and incorporates modern features based on open standards. To help increase online privacy, Unbound supports DNS-over-TLS which allows clients to encrypt their communication. Unbound is available for most platforms such as FreeBSD, OpenBSD, NetBSD, MacOS, Linux and Microsoft Windows. Unbound is a totally free, open source software under the BSD license. It doesn&amp;apos;t make custom builds or provide specific features to paying customers only.

Security Fix(es):

Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the &amp;quot;KeyTrap&amp;quot; issue. One of the concerns is that, when there is a zone with many DNSKEY and RRSIG records, the protocol specification implies that an algorithm must evaluate all combinations of DNSKEY and RRSIG records.(CVE-2023-50387)

The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-1 computations) via DNSSEC responses in a random subdomain attack, aka the &amp;quot;NSEC3&amp;quot; issue. The RFC 5155 specification implies that an algorithm must perform thousands of iterations of a hash function in certain situations.(CVE-2023-50868)

A vulnerability was found in Unbound due to incorrect de…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2024-1210"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:0048-1</id>
    <title>openSUSE-SU-2024:0048-1 — Security update for pdns-recursor</title>
    <updated>2026-10-02T22:10:48.848021+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for pdns-recursor</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:0048-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:0981</id>
    <title>RHSA-2024:0981 — Red Hat Security Advisory: unbound security update</title>
    <updated>2026-10-02T22:10:48.848040+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>bind9: KeyTrap - Extreme CPU consumption in DNSSEC validator bind9: Preparing an NSEC3 closest encloser proof can exhaust CPU resources</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:0981"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2024:0574-1</id>
    <title>SUSE-SU-2024:0574-1 — Security update for bind</title>
    <updated>2026-10-02T22:10:48.848057+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for bind</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2024:0574-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-50868</id>
    <title>UBUNTU-CVE-2023-50868</title>
    <updated>2026-10-02T22:10:48.848073+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: bind9, Ubuntu:Pro:14.04:LTS: dnsmasq, Ubuntu:Pro:14.04:LTS: unbound, Ubuntu:Pro:16.04:LTS: bind9, Ubuntu:Pro:16.04:LTS: dnsmasq, Ubuntu:Pro:16.04:LTS: unbound, Ubuntu:Pro:16.04:LTS: knot-resolver, Ubuntu:Pro:16.04:LTS: pdns-recursor, Ubuntu:Pro:18.04:LTS: bind9, Ubuntu:Pro:18.04:LTS: dnsmasq and 19 more</p>
<p>The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-1 computations) via DNSSEC responses in a random subdomain attack, aka the "NSEC3" issue. The RFC 5155 specification implies that an algorithm must perform thousands of iterations of a hash function in certain situations.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-50868"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0386</id>
    <title>WID-SEC-W-2024-0386 — Internet Systems Consortium BIND: Mehrere Schwachstellen ermöglichen Denial of Service</title>
    <updated>2026-10-02T22:10:48.848129+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Internet Systems Consortium BIND ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0386"/>
  </entry>
</feed>
