<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T21:21:02.297967+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2024:10978</id>
    <title>ALSA-2024:10978 — Important: python3.12 security update</title>
    <updated>2026-10-03T21:21:02.597035+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: python3.12, AlmaLinux:9: python3.12-debug, AlmaLinux:9: python3.12-devel, AlmaLinux:9: python3.12-idle, AlmaLinux:9: python3.12-libs, AlmaLinux:9: python3.12-test, AlmaLinux:9: python3.12-tkinter</p>
<p>Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.</p>
<p>Security Fix(es):</p>
<p>* python: Virtual environment (venv) activation scripts don't quote paths (CVE-2024-9287)
  * python: Unbounded memory buffering in SelectorSocketTransport.writelines() (CVE-2024-12254)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2024:10978"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-00345</id>
    <title>bdu:2025-00345</title>
    <updated>2026-10-03T21:21:02.597110+00:00</updated>
    <content>bdu:2025-00345</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-00345"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2024-12254</id>
    <title>BELL-CVE-2024-12254</title>
    <updated>2026-10-03T21:21:02.597128+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:stream: python3, BellSoft Hardened Containers:stream: python3</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2024-12254"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-libpython-2024-12254</id>
    <title>BIT-libpython-2024-12254 — Unbounded memory buffering in SelectorSocketTransport.writelines()</title>
    <updated>2026-10-03T21:21:02.597147+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: libpython</p>
<p>Starting in Python 3.12.0, the asyncio._SelectorSocketTransport.writelines()
 method would not "pause" writing and signal to the Protocol to drain 
the buffer to the wire once the write buffer reached the "high-water 
mark". Because of this, Protocols would not periodically drain the write
 buffer potentially leading to memory exhaustion.</p>
<p>This
 vulnerability likely impacts a small number of users, you must be using
 Python 3.12.0 or later, on macOS or Linux, using the asyncio module 
with protocols, and using .writelines() method which had new 
zero-copy-on-write behavior in Python 3.12.0 and later. If not all of 
these factors are true then your usage of Python is unaffected.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-libpython-2024-12254"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0641</id>
    <title>certfr-2025-avi-0641 — De multiples vulnérabilités ont été découvertes dans les produits Splunk. Elles permettent à un attaquant de provoquer…</title>
    <updated>2026-10-03T21:21:02.597172+00:00</updated>
    <content>certfr-2025-avi-0641</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0641"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ci66802</id>
    <title>Withdrawn: CLEANSTART-2026-CI66802 — Security fixes for CVE-2015-2104, CVE-2020-8908, CVE-2021-21295, CVE-2021-21409, CVE-2021-37136, CVE-2022-1471, CVE-202…</title>
    <updated>2026-10-03T21:21:02.597187+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: cassandra-fips</p>
<p>Multiple security vulnerabilities affect the cassandra-fips package. These issues are resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ci66802"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-343285</id>
    <title>EUVD-2026-343285</title>
    <updated>2026-10-03T21:21:02.597210+00:00</updated>
    <content>EUVD-2026-343285</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-343285"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-12254</id>
    <title>fkie_cve-2024-12254</title>
    <updated>2026-10-03T21:21:02.597221+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Starting in Python 3.12.0, the asyncio._SelectorSocketTransport.writelines()
 method would not "pause" writing and signal to the Protocol to drain 
the buffer to the wire once the write buffer reached the "high-water 
mark". Because of this, Protocols would not periodically drain the write
 buffer potentially leading to memory exhaustion.</p>
<p>This
 vulnerability likely impacts a small number of users, you must be using
 Python 3.12.0 or later, on macOS or Linux, using the asyncio module 
with protocols, and using .writelines() method which had new 
zero-copy-on-write behavior in Python 3.12.0 and later. If not all of 
these factors are true then your usage of Python is unaffected.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-12254"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-ph84-rcj2-fxxm</id>
    <title>GHSA-ph84-rcj2-fxxm</title>
    <updated>2026-10-03T21:21:02.597246+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Starting in Python 3.12.0, the asyncio._SelectorSocketTransport.writelines()
 method would not "pause" writing and signal to the Protocol to drain 
the buffer to the wire once the write buffer reached the "high-water 
mark". Because of this, Protocols would not periodically drain the write
 buffer potentially leading to memory exhaustion.</p>
<p>This
 vulnerability likely impacts a small number of users, you must be using
 Python 3.12.0 or later, on macOS or Linux, using the asyncio module 
with protocols, and using .writelines() method which had new 
zero-copy-on-write behavior in Python 3.12.0 and later. If not all of 
these factors are true then your usage of Python is unaffected.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-ph84-rcj2-fxxm"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2024-12254</id>
    <title>msrc_CVE-2024-12254 — Unbounded memory buffering in SelectorSocketTransport.writelines()</title>
    <updated>2026-10-03T21:21:02.597264+00:00</updated>
    <content>msrc_CVE-2024-12254</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2024-12254"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:14581-1</id>
    <title>openSUSE-SU-2024:14581-1 — python312-3.12.8-1.1 on GA media</title>
    <updated>2026-10-03T21:21:02.597279+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python312-3.12.8-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:14581-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhba-2025:6294</id>
    <title>RHBA-2025:6294 — Red Hat Bug Fix Advisory: python3.12 bug fix and enhancement update</title>
    <updated>2026-10-03T21:21:02.597294+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python: cpython: tarfile: ReDos via excessive backtracking while parsing header values python: Virtual environment (venv) activation scripts don't quote paths python: Unbounded memory buffering in SelectorSocketTransport.writelines() python: cpython: URL parser allowed square brackets in domain names</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhba-2025:6294"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2024:4291-1</id>
    <title>SUSE-SU-2024:4291-1 — Security update for python312</title>
    <updated>2026-10-03T21:21:02.597314+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for python312</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2024:4291-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-12254</id>
    <title>UBUNTU-CVE-2024-12254</title>
    <updated>2026-10-03T21:21:02.597327+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:24.04:LTS: python3.12</p>
<p>Starting in Python 3.12.0, the asyncio._SelectorSocketTransport.writelines()  method would not "pause" writing and signal to the Protocol to drain the buffer to the wire once the write buffer reached the "high-water mark". Because of this, Protocols would not periodically drain the write  buffer potentially leading to memory exhaustion. This  vulnerability likely impacts a small number of users, you must be using  Python 3.12.0 or later, on macOS or Linux, using the asyncio module with protocols, and using .writelines() method which had new zero-copy-on-write behavior in Python 3.12.0 and later. If not all of these factors are true then your usage of Python is unaffected.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-12254"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3630</id>
    <title>WID-SEC-W-2024-3630 — Python: Schwachstelle ermöglicht Denial of Service</title>
    <updated>2026-10-03T21:21:02.597357+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Python ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3630"/>
  </entry>
</feed>
