<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T23:51:26.098259+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:1472</id>
    <title>ALSA-2026:1472 — Important: openssl security update</title>
    <updated>2026-10-02T23:51:26.326282+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:10: openssl, AlmaLinux:10: openssl-devel, AlmaLinux:10: openssl-libs, AlmaLinux:10: openssl-perl</p>
<p>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, as well as a full-strength general-purpose cryptography library.</p>
<p>Security Fix(es):</p>
<p>* openssl: OpenSSL: Arbitrary code execution or denial of service through crafted PKCS#12 file (CVE-2025-11187)
  * openssl: OpenSSL: Remote code execution or Denial of Service via oversized Initialization Vector in CMS parsing (CVE-2025-15467)
  * openssl: OpenSSL: Denial of Service via NULL pointer dereference in QUIC protocol handling (CVE-2025-15468)
  * openssl: OpenSSL: Data integrity bypass in `openssl dgst` command due to silent truncation (CVE-2025-15469)
  * openssl: OpenSSL: Denial of Service due to excessive memory allocation in TLS 1.3 certificate compression (CVE-2025-66199)
  * openssl: OpenSSL: Denial of Service due to out-of-bounds write in BIO filter (CVE-2025-68160)
  * openssl: OpenSSL: Information disclosure and data tampering via specific low-level OCB encryption/decryption calls (CVE-2025-69418)
  * openssl: OpenSSL: Arbitrary code execution due to out-of-bounds write in PKCS#12 processing (CVE-2025-69419)
  * openssl: OpenSSL: Denial of Service via malformed PKCS#12 file processing (CVE-2025-69421)
  * openssl: OpenSSL: Denial of Service via malformed TimeStamp Response (CVE-2025-69420)
  * openssl: OpenSSL: Denial of Service due to type confusion in PKCS#12 file processing (CVE-2026-22795)
  * openssl: OpenSSL: Denial of Service via type confusion i…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:1472"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-02935</id>
    <title>bdu:2026-02935</title>
    <updated>2026-10-02T23:51:26.326370+00:00</updated>
    <content>bdu:2026-02935</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-02935"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-69418</id>
    <title>BELL-CVE-2025-69418</title>
    <updated>2026-10-02T23:51:26.326388+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: openssl, Alpaquita:25: openssl, Alpaquita:stream: openssl, BellSoft Hardened Containers:23: openssl, BellSoft Hardened Containers:25: openssl, BellSoft Hardened Containers:stream: openssl</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-69418"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0096</id>
    <title>certfr-2026-avi-0096 — De multiples vulnérabilités ont été découvertes dans OpenSSL. Certaines d'entre elles permettent à un attaquant de prov…</title>
    <updated>2026-10-02T23:51:26.326415+00:00</updated>
    <content>certfr-2026-avi-0096</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0096"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-317190</id>
    <title>EUVD-2026-317190</title>
    <updated>2026-10-02T23:51:26.326431+00:00</updated>
    <content>EUVD-2026-317190</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-317190"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-69418</id>
    <title>fkie_cve-2025-69418</title>
    <updated>2026-10-02T23:51:26.326443+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Issue summary: When using the low-level OCB API directly with AES-NI or&lt;br&gt;other hardware-accelerated code paths, inputs whose length is not a multiple&lt;br&gt;of 16 bytes can leave the final partial block unencrypted and unauthenticated.&lt;br&gt;&lt;br&gt;Impact summary: The trailing 1-15 bytes of a message may be exposed in&lt;br&gt;cleartext on encryption and are not covered by the authentication tag,&lt;br&gt;allowing an attacker to read or tamper with those bytes without detection.&lt;br&gt;&lt;br&gt;The low-level OCB encrypt and decrypt routines in the hardware-accelerated&lt;br&gt;stream path process full 16-byte blocks but do not advance the input/output&lt;br&gt;pointers. The subsequent tail-handling code then operates on the original&lt;br&gt;base pointers, effectively reprocessing the beginning of the buffer while&lt;br&gt;leaving the actual trailing bytes unprocessed. The authentication checksum&lt;br&gt;also excludes the true tail bytes.&lt;br&gt;&lt;br&gt;However, typical OpenSSL consumers using EVP are not affected because the&lt;br&gt;higher-level EVP and provider OCB implementations split inputs so that full&lt;br&gt;blocks and trailing partial blocks are processed in separate calls, avoiding&lt;br&gt;the problematic code path. Additionally, TLS does not use OCB ciphersuites.&lt;br&gt;The vulnerability only affects applications that call the low-level&lt;br&gt;CRYPTO_ocb128_encrypt() or CRYPTO_ocb128_decrypt() functions directly with&lt;br&gt;non-block-aligned lengths in a single call on hardware-accelerated builds.&lt;br&gt;For these reasons the issue was assessed as Low severit…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-69418"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-78qr-24v5-7q73</id>
    <title>GHSA-78qr-24v5-7q73</title>
    <updated>2026-10-02T23:51:26.326478+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Issue summary: When using the low-level OCB API directly with AES-NI or&lt;br&gt;other hardware-accelerated code paths, inputs whose length is not a multiple&lt;br&gt;of 16 bytes can leave the final partial block unencrypted and unauthenticated.&lt;br&gt;&lt;br&gt;Impact summary: The trailing 1-15 bytes of a message may be exposed in&lt;br&gt;cleartext on encryption and are not covered by the authentication tag,&lt;br&gt;allowing an attacker to read or tamper with those bytes without detection.&lt;br&gt;&lt;br&gt;The low-level OCB encrypt and decrypt routines in the hardware-accelerated&lt;br&gt;stream path process full 16-byte blocks but do not advance the input/output&lt;br&gt;pointers. The subsequent tail-handling code then operates on the original&lt;br&gt;base pointers, effectively reprocessing the beginning of the buffer while&lt;br&gt;leaving the actual trailing bytes unprocessed. The authentication checksum&lt;br&gt;also excludes the true tail bytes.&lt;br&gt;&lt;br&gt;However, typical OpenSSL consumers using EVP are not affected because the&lt;br&gt;higher-level EVP and provider OCB implementations split inputs so that full&lt;br&gt;blocks and trailing partial blocks are processed in separate calls, avoiding&lt;br&gt;the problematic code path. Additionally, TLS does not use OCB ciphersuites.&lt;br&gt;The vulnerability only affects applications that call the low-level&lt;br&gt;CRYPTO_ocb128_encrypt() or CRYPTO_ocb128_decrypt() functions directly with&lt;br&gt;non-block-aligned lengths in a single call on hardware-accelerated builds.&lt;br&gt;For these reasons the issue was assessed as Low severit…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-78qr-24v5-7q73"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-24-102-01</id>
    <title>ICSA-24-102-01 — Siemens SIMATIC S7-1500 TM MFP</title>
    <updated>2026-10-02T23:51:26.326504+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An out-of-bounds (OOB) memory write flaw was found in the NFSD in the Linux kernel. Missing sanity may lead to a write beyond bmval[bmlen-1] in nfsd4_decode_bitmap4 in fs/nfsd/nfs4xdr.c. In this flaw, a local attacker with user privilege may gain access to out-of-bounds memory, leading to a system integrity and confidentiality threat. fs/nfsd/trace.h in the Linux kernel before 5.13.4 might allow remote attackers to cause a denial of service (out-of-bounds read in strlen) by sending NFS traffic when the trace event framework is being used for nfsd. SUNRPC: null pointer dereference in svc_rqst_free(). When alloc_pages_node() returns null in svc_rqst_alloc(), the null rq_scratch_page pointer will be dereferenced when calling put_page() in svc_rqst_free(). NFSD: READDIR buffer overflow. If a client sends a READDIR count argument that is too small (say, zero), then the buffer size calculation in the new init_dirlist helper functions results in an underflow, allowing the XDR stream functions to write beyond the actual buffer. This calculation has always been suspect. NFSD has never sanity- checked the READDIR count argument, but the old entry encoders managed the problem correctly. With the commits below, entry encoding changed, exposing the underflow to the pointer arithmetic in xdr_reserve_space(). Modern NFS clients attempt to retrieve as much data as possible for each READDIR request. nfsd: NULL dereference in nfs3svc_encode_getaclres. A NULL pointer dereference vulnerability…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-24-102-01"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-1411</id>
    <title>OESA-2026-1411 — openssl security update</title>
    <updated>2026-10-02T23:51:26.327911+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP2: openssl</p>
<p>OpenSSL is a robust, commercial-grade, and full-featured toolkit for the Transport Layer Security (TLS) and Secure Sockets Layer (SSL) protocols.

Security Fix(es):</p>
<p>Issue summary: Parsing CMS AuthEnvelopedData message with maliciously
crafted AEAD parameters can trigger a stack buffer overflow.</p>
<p>Impact summary: A stack buffer overflow may lead to a crash, causing Denial
of Service, or potentially remote code execution.</p>
<p>When parsing CMS AuthEnvelopedData structures that use AEAD ciphers such as
AES-GCM, the IV (Initialization Vector) encoded in the ASN.1 parameters is
copied into a fixed-size stack buffer without verifying that its length fits
the destination. An attacker can supply a crafted CMS message with an
oversized IV, causing a stack-based out-of-bounds write before any
authentication or tag verification occurs.</p>
<p>Applications and services that parse untrusted CMS or PKCS#7 content using
AEAD ciphers (e.g., S/MIME AuthEnvelopedData with AES-GCM) are vulnerable.
Because the overflow occurs prior to authentication, no valid key material
is required to trigger it. While exploitability to remote code execution
depends on platform and toolchain mitigations, the stack-based write
primitive represents a severe risk.</p>
<p>The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this
issue, as the CMS implementation is outside the OpenSSL FIPS module
boundary.</p>
<p>OpenSSL 3.6, 3.5, 3.4, 3.3 and 3.0 are vulnerable to this issue.</p>
<p>OpenSSL 1.1.1 and 1.0.2 are not affected b…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-1411"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10237-1</id>
    <title>openSUSE-SU-2026:10237-1 — libopenssl-3-devel-3.5.3-2.1 on GA media</title>
    <updated>2026-10-02T23:51:26.327994+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libopenssl-3-devel-3.5.3-2.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10237-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:1736</id>
    <title>RHSA-2026:1736 — Red Hat Security Advisory: A Subscription Management tool for finding and reporting Red Hat product usage</title>
    <updated>2026-10-02T23:51:26.328021+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>curl: libcurl: Curl out of bounds read for cookie path openssl: OpenSSL: Arbitrary code execution or denial of service through crafted PKCS#12 file cpython: python: cpython: Quadratic algorithm in xml.dom.minidom leads to denial of service postgresql: libpq: libpq undersizes allocations, via integer wraparound glib: Integer overflow in in g_escape_uri_string() cpython: Excessive read buffering DoS in http.client openssl: OpenSSL: Remote code execution or Denial of Service via oversized Initialization Vector in CMS parsing openssl: OpenSSL: Denial of Service via NULL pointer dereference in QUIC protocol handling openssl: OpenSSL: Data integrity bypass in `openssl dgst` command due to silent truncation openssl: OpenSSL: Denial of Service due to excessive memory allocation in TLS 1.3 certificate compression urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion urllib3: urllib3 Streaming API improperly handles highly compressed data openssl: OpenSSL: Denial of Service due to out-of-bounds write in BIO filter GnuPG: GnuPG: Information disclosure and potential arbitrary code execution via out-of-bounds write openssl: OpenSSL: Information disclosure and data tampering via specific low-level OCB encryption/decryption calls openssl: OpenSSL: Arbitrary code execution due to out-of-bounds write in PKCS#12 processing openssl: OpenSSL: Denial of Service via malformed TimeStamp Response openssl: OpenSSL: Denial of Service via malformed PKCS#12 file processing urllib…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:1736"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ssa-265688</id>
    <title>SSA-265688 — SSA-265688: Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 TM MFP V1.1</title>
    <updated>2026-10-02T23:51:26.328072+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An out-of-bounds (OOB) memory write flaw was found in the NFSD in the Linux kernel. Missing sanity may lead to a write beyond bmval[bmlen-1] in nfsd4_decode_bitmap4 in fs/nfsd/nfs4xdr.c. In this flaw, a local attacker with user privilege may gain access to out-of-bounds memory, leading to a system integrity and confidentiality threat. fs/nfsd/trace.h in the Linux kernel before 5.13.4 might allow remote attackers to cause a denial of service (out-of-bounds read in strlen) by sending NFS traffic when the trace event framework is being used for nfsd. SUNRPC: null pointer dereference in svc_rqst_free(). When alloc_pages_node() returns null in svc_rqst_alloc(), the null rq_scratch_page pointer will be dereferenced when calling put_page() in svc_rqst_free(). NFSD: READDIR buffer overflow. If a client sends a READDIR count argument that is too small (say, zero), then the buffer size calculation in the new init_dirlist helper functions results in an underflow, allowing the XDR stream functions to write beyond the actual buffer. This calculation has always been suspect. NFSD has never sanity- checked the READDIR count argument, but the old entry encoders managed the problem correctly. With the commits below, entry encoding changed, exposing the underflow to the pointer arithmetic in xdr_reserve_space(). Modern NFS clients attempt to retrieve as much data as possible for each READDIR request. nfsd: NULL dereference in nfs3svc_encode_getaclres. A NULL pointer dereference vulnerability…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ssa-265688"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:0311-1</id>
    <title>SUSE-SU-2026:0311-1 — Security update for openssl-3</title>
    <updated>2026-10-02T23:51:26.329060+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for openssl-3</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:0311-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-69418</id>
    <title>UBUNTU-CVE-2025-69418</title>
    <updated>2026-10-02T23:51:26.329084+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: edk2, Ubuntu:Pro:16.04:LTS: nodejs, Ubuntu:Pro:18.04:LTS: openssl, Ubuntu:Pro:18.04:LTS: edk2, Ubuntu:Pro:18.04:LTS: nodejs, Ubuntu:Pro:FIPS-updates:18.04:LTS: openssl, Ubuntu:Pro:FIPS:18.04:LTS: openssl, Ubuntu:20.04:LTS: edk2, Ubuntu:Pro:20.04:LTS: openssl, Ubuntu:Pro:FIPS-updates:20.04:LTS: openssl and 16 more</p>
<p>Issue summary: When using the low-level OCB API directly with AES-NI or&lt;br&gt;other hardware-accelerated code paths, inputs whose length is not a multiple&lt;br&gt;of 16 bytes can leave the final partial block unencrypted and unauthenticated.&lt;br&gt;&lt;br&gt;Impact summary: The trailing 1-15 bytes of a message may be exposed in&lt;br&gt;cleartext on encryption and are not covered by the authentication tag,&lt;br&gt;allowing an attacker to read or tamper with those bytes without detection.&lt;br&gt;&lt;br&gt;The low-level OCB encrypt and decrypt routines in the hardware-accelerated&lt;br&gt;stream path process full 16-byte blocks but do not advance the input/output&lt;br&gt;pointers. The subsequent tail-handling code then operates on the original&lt;br&gt;base pointers, effectively reprocessing the beginning of the buffer while&lt;br&gt;leaving the actual trailing bytes unprocessed. The authentication checksum&lt;br&gt;also excludes the true tail bytes.&lt;br&gt;&lt;br&gt;However, typical OpenSSL consumers using EVP are not affected because the&lt;br&gt;higher-level EVP and provider OCB implementations split inputs so that full&lt;br&gt;blocks and trailing partial blocks are processed in separate calls, avoiding&lt;br&gt;the problematic code path. Additionally, TLS does not use OCB ciphersuites.&lt;br&gt;The vulnerability only affects applications that call the low-level&lt;br&gt;CRYPTO_ocb128_encrypt() or CRYPTO_ocb128_decrypt() functions directly with&lt;br&gt;non-block-aligned lengths in a single call on hardware-accelerated builds.&lt;br&gt;For these reasons the issue was assessed as Low severit…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-69418"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2026-076</id>
    <title>VDE-2026-076 — ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products</title>
    <updated>2026-10-02T23:51:26.329173+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2026-076"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2026-081</id>
    <title>VDE-2026-081 — Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities</title>
    <updated>2026-10-02T23:51:26.329201+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2026-081"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0234</id>
    <title>WID-SEC-W-2026-0234 — OpenSSL: Mehrere Schwachstellen</title>
    <updated>2026-10-02T23:51:26.329242+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in OpenSSL ausnutzen, um beliebigen Programmcode auszuführen, einen Denial-of-Service-Zustand zu verursachen oder vertrauliche Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0234"/>
  </entry>
</feed>
