<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T06:33:41.786193+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-198795</id>
    <title>EUVD-2026-198795</title>
    <updated>2026-10-04T06:33:41.796539+00:00</updated>
    <content>EUVD-2026-198795</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-198795"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-50354</id>
    <title>fkie_cve-2024-50354</title>
    <updated>2026-10-04T06:33:41.796580+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>gnark is a fast zk-SNARK library that offers a high-level API to design circuits. In gnark 0.11.0 and earlier, deserialization of Groth16 verification keys allocate excessive memory, consuming a lot of resources and triggering a crash with the error fatal error: runtime: out of memory.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-50354"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-cph5-3pgr-c82g</id>
    <title>GHSA-cph5-3pgr-c82g — Gnark out-of-memory during deserialization with crafted inputs</title>
    <updated>2026-10-04T06:33:41.796614+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/consensys/gnark</p>
<p>Thanks @pventuzelo for reporting.</p>
<p>From the correspondence:</p>
<p>&gt; Hi,
&gt; 
&gt; We (Fuzzinglabs &amp; Lambdaclass) found that during deserialization of certain files representing a `VerifyingKey`, an excessive memory allocation is happening consuming a lot of resources and even triggering a crash with the error `fatal error: runtime: out of memory`.
&gt; 
&gt; Please find the details below:
&gt; 
&gt; ## Vulnerability Details
&gt; 
&gt; - **Severity:** Critical -&gt; DoS
&gt; - **Affected Component:** Deserialization
&gt; 
&gt; ## Environment
&gt; 
&gt; - **Compiler Version:** go version go1.22.2 linux/amd64
&gt; - **Distro Version:** Ubuntu 24.04.1 LTS
&gt; 
&gt; - **Additional Environment Details:**
&gt;   - `[github.com/consensys/gnark](http://github.com/consensys/gnark) v0.11.0`
&gt;   - `[github.com/consensys/gnark-crypto](http://github.com/consensys/gnark-crypto) v0.14.1-0.20240909142611-e6b99e74cec1`
&gt; 
&gt; ## Steps to Reproduce
&gt; 
&gt; You can download the needed files here: https://drive.google.com/drive/folders/1KQ5I3vv4bUllvqbatGappwbAkIcR2NI_?usp=sharing
&gt; 
&gt; You have to run
&gt; 
&gt; ```shell
&gt; go run gnark_poc.go
&gt; ```
&gt; 
&gt; in a terminal.
&gt; 
&gt; Running the provided code will result in a memory crash or an extremely large memory allocation, which can be observed using the following command:
&gt; 
&gt; ```shell
&gt; go tool pprof -web mem.pprof
&gt; ```
&gt; 
&gt; ## Root Cause Analysis
&gt; 
&gt; The provided code loads a `VerifyingKey` from `old.vk` by calling the `ReadFrom` function. This function is implemented in [backend/groth16/bn254/marshal.go](https:…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-cph5-3pgr-c82g"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:0350-1</id>
    <title>openSUSE-SU-2024:0350-1 — Security update for govulncheck-vulndb</title>
    <updated>2026-10-04T06:33:41.796697+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for govulncheck-vulndb</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:0350-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2024:3950-1</id>
    <title>SUSE-SU-2024:3950-1 — Security update for govulncheck-vulndb</title>
    <updated>2026-10-04T06:33:41.796753+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for govulncheck-vulndb</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2024:3950-1"/>
  </entry>
</feed>
