<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T14:49:44.620754+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-08084</id>
    <title>bdu:2025-08084</title>
    <updated>2026-10-02T14:49:44.710002+00:00</updated>
    <content>bdu:2025-08084</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-08084"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-245856</id>
    <title>EUVD-2026-245856</title>
    <updated>2026-10-02T14:49:44.710039+00:00</updated>
    <content>EUVD-2026-245856</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-245856"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-52889</id>
    <title>fkie_cve-2025-52889</title>
    <updated>2026-10-02T14:49:44.710053+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Incus is a system container and virtual machine manager. When using an ACL on a device connected to a bridge, Incus version 6.12 and 6.13 generates nftables rules for local services (DHCP, DNS...) that partially bypass security options `security.mac_filtering`, `security.ipv4_filtering` and `security.ipv6_filtering`. This can lead to DHCP pool exhaustion and opens the door for other attacks. A patch is available at commit 2516fb19ad8428454cb4edfe70c0a5f0dc1da214.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-52889"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-9q7c-qmhm-jv86</id>
    <title>GHSA-9q7c-qmhm-jv86 — Incus Allocation of Resources Without Limits allows firewall rule bypass on managed bridge networks</title>
    <updated>2026-10-02T14:49:44.710084+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/lxc/incus/v6</p>
<p>### Summary</p>
<p>When using an ACL on a device connected to a bridge, Incus generates nftables rules for local services (DHCP, DNS...) that partially bypass security options `security.mac_filtering`, `security.ipv4_filtering` and `security.ipv6_filtering`. This can lead to DHCP pool exhaustion and opens the door for other attacks.</p>
<p>### Details</p>
<p>In commit a7c33301738aede3c035063e973b1d885d9bac7c, the following rules are added at the top of the bridge input chain:</p>
<p>iifname "{{.hostName}}" ether type ip ip saddr 0.0.0.0 ip daddr 255.255.255.255 udp dport 67 accept
	iifname "{{.hostName}}" ether type ip6 ip6 saddr fe80::/10 ip6 daddr ff02::1:2 udp dport 547 accept
	iifname "{{.hostName}}" ether type ip6 ip6 saddr fe80::/10 ip6 daddr ff02::2 icmpv6 type 133 accept</p>
<p>However, these rules accept packets that should be filtered and maybe dropped by later rules in the "MAC filtering" snippet:</p>
<p>iifname "{{.hostName}}" ether type arp arp saddr ether != {{.hwAddr}} drop
	iifname "{{.hostName}}" ether type ip6 icmpv6 type 136 @nh,528,48 != {{.hwAddrHex}} drop</p>
<p>Therefore, the MAC filtering is ineffective on those new rules. This allows an attacker to request as many IP as they want by sending a lot of DHCP requests with different MAC addresses. Doing so, they can exhaust the DHCP pool, resulting in a DoS of the bridge's network.</p>
<p>Additionaly, the commit adds non-restricted access to the local dnsmasq DNS server:</p>
<p>{{ if .dnsIPv4 }}
	{{ range .dnsIPv4 }}
	iifname "{{$.hostName}}" ip daddr "{{…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-9q7c-qmhm-jv86"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15317-1</id>
    <title>openSUSE-SU-2025:15317-1 — incus-6.14-1.1 on GA media</title>
    <updated>2026-10-02T14:49:44.710142+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>incus-6.14-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15317-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-52889</id>
    <title>UBUNTU-CVE-2025-52889</title>
    <updated>2026-10-02T14:49:44.710161+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:24.04:LTS: incus, Ubuntu:25.10: incus, Ubuntu:Pro:26.04:LTS: incus</p>
<p>Incus is a system container and virtual machine manager. When using an ACL on a device connected to a bridge, Incus version 6.12 and 6.13 generates nftables rules for local services (DHCP, DNS...) that partially bypass security options `security.mac_filtering`, `security.ipv4_filtering` and `security.ipv6_filtering`. This can lead to DHCP pool exhaustion and opens the door for other attacks. A patch is available at commit 2516fb19ad8428454cb4edfe70c0a5f0dc1da214.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-52889"/>
  </entry>
</feed>
