<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T13:32:27.931404+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-253807</id>
    <title>EUVD-2026-253807</title>
    <updated>2026-10-04T13:32:27.994113+00:00</updated>
    <content>EUVD-2026-253807</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-253807"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-59942</id>
    <title>fkie_cve-2025-59942</title>
    <updated>2026-10-04T13:32:27.994153+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>go-f3 is a Golang implementation of Fast Finality for Filecoin (F3). In versions 0.8.6 and below, go-f3 panics when it validates a "poison" messages causing Filecoin nodes consuming F3 messages to become vulnerable. A "poison" message can can cause integer overflow in the signer index validation, which can cause the whole node to crash. These malicious messages aren't self-propagating since the bug is in the validator. An attacker needs to directly send the message to all targets. This issue is fixed in version 0.8.7.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-59942"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-g99p-47x7-mq88</id>
    <title>GHSA-g99p-47x7-mq88 — go-f3 module vulnerable to integer overflow leading to panic</title>
    <updated>2026-10-04T13:32:27.994190+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/filecoin-project/go-f3</p>
<p>### Impact</p>
<p>Filecoin nodes consuming F3 messages are vulnerable.  go-f3 panics when it validates a "poison" messages.  A "poison" message can can cause integer overflow in the signer index validation.  In Lotus' case, the whole node will crash.</p>
<p>There is no barrier to entry.  An attacker doesn't need any power to pull off this attack.</p>
<p>These malicious messages aren't self-propagating since the bug is in the validator.  An attacker needs to directly send the message to all targets.</p>
<p>### Patches
The fix was merged and released with go-f3 0.8.7.  All node software (Lotus, Forest, Venus) are using a patched version of go-f3 with their updates for the nv27 network upgrade.</p>
<p>go-f3 now does proper overflow checking using `math.MaxInt64` comparison and returns error `"justificationPower overflow"` when overflow would occur.</p>
<p>### Workarounds
The are no immediate workarounds available.  Nodes should upgrade to the patched version, which they will have done if participating in nv27 on Filecoin mainnet.</p>
<p>### Credits
The initial finding(unrelated path) was reported by [0xNirix](https://github.com/0xNirix) via bug bounty program which wasn't high issue. The further digging by developers led to this finding. Thank you for the contributions.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-g99p-47x7-mq88"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15666-1</id>
    <title>openSUSE-SU-2025:15666-1 — govulncheck-vulndb-0.0.20251023T162509-1.1 on GA media</title>
    <updated>2026-10-04T13:32:27.994242+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>govulncheck-vulndb-0.0.20251023T162509-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15666-1"/>
  </entry>
</feed>
