<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T01:48:40.831162+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2024:1462</id>
    <title>ALSA-2024:1462 — Important: golang security update</title>
    <updated>2026-10-03T01:48:41.867782+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: go-toolset, AlmaLinux:9: golang, AlmaLinux:9: golang-bin, AlmaLinux:9: golang-docs, AlmaLinux:9: golang-misc, AlmaLinux:9: golang-src, AlmaLinux:9: golang-tests</p>
<p>The golang packages provide the Go programming language compiler.</p>
<p>Security Fix(es):</p>
<p>* golang: golang-fips/openssl: Memory leaks in code encrypting and decrypting RSA payloads (CVE-2024-1394)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2024:1462"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-02371</id>
    <title>bdu:2024-02371</title>
    <updated>2026-10-03T01:48:41.867895+00:00</updated>
    <content>bdu:2024-02371</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-02371"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0646</id>
    <title>certfr-2024-avi-0646 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-03T01:48:41.867916+00:00</updated>
    <content>certfr-2024-avi-0646</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0646"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-357256</id>
    <title>EUVD-2026-357256</title>
    <updated>2026-10-03T01:48:41.867934+00:00</updated>
    <content>EUVD-2026-357256</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-357256"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-1394</id>
    <title>fkie_cve-2024-1394</title>
    <updated>2026-10-03T01:48:41.867945+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A memory leak flaw was found in Golang in the RSA encrypting/decrypting code, which might lead to a resource exhaustion vulnerability using attacker-controlled inputs​. The memory leak happens in github.com/golang-fips/openssl/openssl/rsa.go#L113. The objects leaked are pkey​ and ctx​. That function uses named return parameters to free pkey​ and ctx​ if there is an error initializing the context or setting the different properties. All return statements related to error cases follow the "return nil, nil, fail(...)" pattern, meaning that pkey​ and ctx​ will be nil inside the deferred function that should free them.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-1394"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-78hx-gp6g-7mj6</id>
    <title>GHSA-78hx-gp6g-7mj6 — Memory leaks in code encrypting and verifying RSA payloads</title>
    <updated>2026-10-03T01:48:41.867976+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/golang-fips/go, Go: github.com/golang-fips/openssl/v2, Go: github.com/microsoft/go-crypto-openssl, Go: github.com/microsoft/go-crypto-openssl/openssl</p>
<p>Using crafted public RSA keys which are not compliant with SP 800-56B can cause a small memory leak when encrypting and verifying payloads.</p>
<p>An attacker can leverage this flaw to gradually erode available memory to the point where the host crashes for lack of resources. Upon restart the attacker would have to begin again, but nevertheless there is the potential to deny service.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-78hx-gp6g-7mj6"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2024-1394</id>
    <title>gsd-2024-1394</title>
    <updated>2026-10-03T01:48:41.868006+00:00</updated>
    <content>gsd-2024-1394</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2024-1394"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:1462</id>
    <title>RHSA-2024:1462 — Red Hat Security Advisory: golang security update</title>
    <updated>2026-10-03T01:48:41.868019+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>golang-fips/openssl: Memory leaks in code encrypting and decrypting RSA payloads</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:1462"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:1468</id>
    <title>RHSA-2024:1468 — Red Hat Security Advisory: go-toolset-1.19-golang security update</title>
    <updated>2026-10-03T01:48:41.868039+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>golang-fips/openssl: Memory leaks in code encrypting and decrypting RSA payloads</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:1468"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0681</id>
    <title>WID-SEC-W-2024-0681 — Red Hat Enterprise Linux: Golang-Komponenten-Schwachstelle ermöglicht Denial of Service</title>
    <updated>2026-10-03T01:48:41.868056+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat OpenShift, Red Hat Ansible Automation Platform und Red Hat Enterprise Linux ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0681"/>
  </entry>
</feed>
