<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T19:00:33.900141+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-12887</id>
    <title>bdu:2025-12887</title>
    <updated>2026-10-02T19:00:33.957619+00:00</updated>
    <content>bdu:2025-12887</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-12887"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-9232</id>
    <title>BELL-CVE-2025-9232</title>
    <updated>2026-10-02T19:00:33.957666+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:25: openssl, Alpaquita:stream: openssl, BellSoft Hardened Containers:25: openssl, BellSoft Hardened Containers:stream: openssl</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-9232"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0835</id>
    <title>certfr-2025-avi-0835 — De multiples vulnérabilités ont été découvertes dans OpenSSL. Elles permettent à un attaquant de provoquer une exécutio…</title>
    <updated>2026-10-02T19:00:33.957700+00:00</updated>
    <content>certfr-2025-avi-0835</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0835"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-336302</id>
    <title>EUVD-2026-336302</title>
    <updated>2026-10-02T19:00:33.957718+00:00</updated>
    <content>EUVD-2026-336302</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-336302"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-9232</id>
    <title>fkie_cve-2025-9232</title>
    <updated>2026-10-02T19:00:33.957730+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Issue summary: An application using the OpenSSL HTTP client API functions may
trigger an out-of-bounds read if the 'no_proxy' environment variable is set and
the host portion of the authority component of the HTTP URL is an IPv6 address.</p>
<p>Impact summary: An out-of-bounds read can trigger a crash which leads to
Denial of Service for an application.</p>
<p>The OpenSSL HTTP client API functions can be used directly by applications
but they are also used by the OCSP client functions and CMP (Certificate
Management Protocol) client implementation in OpenSSL. However the URLs used
by these implementations are unlikely to be controlled by an attacker.</p>
<p>In this vulnerable code the out of bounds read can only trigger a crash.
Furthermore the vulnerability requires an attacker-controlled URL to be
passed from an application to the OpenSSL function and the user has to have
a 'no_proxy' environment variable set. For the aforementioned reasons the
issue was assessed as Low severity.</p>
<p>The vulnerable code was introduced in the following patch releases:
3.0.16, 3.1.8, 3.2.4, 3.3.3, 3.4.0 and 3.5.0.</p>
<p>The FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this
issue, as the HTTP client implementation is outside the OpenSSL FIPS module
boundary.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-9232"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-76r2-c3cg-f5r9</id>
    <title>GHSA-76r2-c3cg-f5r9</title>
    <updated>2026-10-02T19:00:33.957766+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Issue summary: An application using the OpenSSL HTTP client API functions may
trigger an out-of-bounds read if the 'no_proxy' environment variable is set and
the host portion of the authority component of the HTTP URL is an IPv6 address.</p>
<p>Impact summary: An out-of-bounds read can trigger a crash which leads to
Denial of Service for an application.</p>
<p>The OpenSSL HTTP client API functions can be used directly by applications
but they are also used by the OCSP client functions and CMP (Certificate
Management Protocol) client implementation in OpenSSL. However the URLs used
by these implementations are unlikely to be controlled by an attacker.</p>
<p>In this vulnerable code the out of bounds read can only trigger a crash.
Furthermore the vulnerability requires an attacker-controlled URL to be
passed from an application to the OpenSSL function and the user has to have
a 'no_proxy' environment variable set. For the aforementioned reasons the
issue was assessed as Low severity.</p>
<p>The vulnerable code was introduced in the following patch releases:
3.0.16, 3.1.8, 3.2.4, 3.3.3, 3.4.0 and 3.5.0.</p>
<p>The FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this
issue, as the HTTP client implementation is outside the OpenSSL FIPS module
boundary.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-76r2-c3cg-f5r9"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-25-162-05</id>
    <title>ICSA-25-162-05 — Siemens SIMATIC S7-1500 CPU family</title>
    <updated>2026-10-02T19:00:33.957791+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplemental groups are not initialized as expected. Helper programs for AuthorizedKeysCommand and AuthorizedPrincipalsCommand may run with privileges associated with group memberships of the sshd process, if the configuration specifies running the command as a different user. A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is configured with no-aaaa mode via /etc/resolv.conf, a DNS response via TCP larger than 2048 bytes can potentially disclose stack contents through the function returned address data, and may cause a crash. A flaw was found in glibc. In an extremely rare situation, the getaddrinfo function may access memory that has been freed, resulting in an application crash. This issue is only exploitable when a NSS module implements only the _nss_*_gethostbyname2_r and _nss_*_getcanonname_r hooks without implementing the _nss_*_gethostbyname3_r hook. The resolved name should return a large number of IPv6 and IPv4, and the call to the getaddrinfo function should have the AF_INET6 address family with AI_CANONNAME, AI_ALL and AI_V4MAPPED as flags. A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment var…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-25-162-05"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-9232</id>
    <title>msrc_CVE-2025-9232 — Out-of-bounds read in HTTP client no_proxy handling</title>
    <updated>2026-10-02T19:00:33.958329+00:00</updated>
    <content>msrc_CVE-2025-9232</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-9232"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ncsc-2026-0079</id>
    <title>NCSC-2026-0079 — Kwetsbaarheden verholpen in Siemens producten</title>
    <updated>2026-10-02T19:00:33.958346+00:00</updated>
    <content>NCSC-2026-0079</content>
    <link href="https://cve.radiocsirt.org/vuln/ncsc-2026-0079"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15723-1</id>
    <title>openSUSE-SU-2025:15723-1 — regclient-0.10.0-1.1 on GA media</title>
    <updated>2026-10-02T19:00:33.958397+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>regclient-0.10.0-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15723-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:7261</id>
    <title>RHSA-2026:7261 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
    <updated>2026-10-02T19:00:33.958417+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>openssl: Out-of-bounds read &amp; write in RFC 3211 KEK Unwrap openssl: Timing side-channel in SM2 algorithm on 64 bit ARM openssl: Out-of-bounds read in HTTP client no_proxy handling openssl: OpenSSL: Arbitrary code execution or denial of service through crafted PKCS#12 file openssl: OpenSSL: Remote code execution or Denial of Service via oversized Initialization Vector in CMS parsing openssl: OpenSSL: Denial of Service via NULL pointer dereference in QUIC protocol handling openssl: OpenSSL: Data integrity bypass in `openssl dgst` command due to silent truncation openssl: OpenSSL: Denial of Service due to excessive memory allocation in TLS 1.3 certificate compression openssl: OpenSSL: Denial of Service due to out-of-bounds write in BIO filter openssl: OpenSSL: Information disclosure and data tampering via specific low-level OCB encryption/decryption calls openssl: OpenSSL: Arbitrary code execution due to out-of-bounds write in PKCS#12 processing openssl: OpenSSL: Denial of Service via malformed TimeStamp Response openssl: OpenSSL: Denial of Service via malformed PKCS#12 file processing openssl: OpenSSL TLS 1.3 server may choose unexpected key agreement group openssl: OpenSSL: Denial of Service due to type confusion in PKCS#12 file processing openssl: OpenSSL: Denial of Service via type confusion in PKCS#7 signature verification openssl: openssl: Denial of Service due to out-of-bounds read in AES-CFB128 openssl: OpenSSL: Arbitrary code execution due to use-after-free in DANE TLS…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:7261"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ssa-032379</id>
    <title>SSA-032379 — SSA-032379: Multiple Vulnerabilities in SIMATIC CN 4100 Before V5.0</title>
    <updated>2026-10-02T19:00:33.958468+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:

drm/amd/display: Check link_res-&gt;hpo_dp_link_enc before using it

[WHAT &amp; HOW]
Functions dp_enable_link_phy and dp_disable_link_phy can pass link_res
without initializing hpo_dp_link_enc and it is necessary to check for
null before dereferencing.

This fixes 2 FORWARD_NULL issues reported by Coverity. In the Linux kernel, the following vulnerability has been resolved:</p>
<p>fs: relax assertions on failure to encode file handles</p>
<p>Encoding file handles is usually performed by a filesystem &gt;encode_fh()
method that may fail for various reasons.</p>
<p>The legacy users of exportfs_encode_fh(), namely, nfsd and
name_to_handle_at(2) syscall are ready to cope with the possibility
of failure to encode a file handle.</p>
<p>There are a few other users of exportfs_encode_{fh,fid}() that
currently have a WARN_ON() assertion when -&gt;encode_fh() fails.
Relax those assertions because they are wrong.</p>
<p>The second linked bug report states commit 16aac5ad1fa9 ("ovl: support
encoding non-decodable file handles") in v6.6 as the regressing commit,
but this is not accurate.</p>
<p>The aforementioned commit only increases the chances of the assertion
and allows triggering the assertion with the reproducer using overlayfs,
inotify and drop_caches.</p>
<p>Triggering this assertion was always possible with other filesystems and
other reasons of -&gt;encode_fh() failures and more particularly, it was
also possible with the exact same reproducer using overlay…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ssa-032379"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:21213-1</id>
    <title>SUSE-SU-2025:21213-1 — Security update for openssl-3</title>
    <updated>2026-10-02T19:00:33.959500+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for openssl-3</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:21213-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-9232</id>
    <title>UBUNTU-CVE-2025-9232</title>
    <updated>2026-10-02T19:00:33.959519+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: nodejs, Ubuntu:Pro:18.04:LTS: nodejs, Ubuntu:Pro:22.04:LTS: nodejs, Ubuntu:25.10: edk2, Ubuntu:25.10: openssl, Ubuntu:26.04:LTS: edk2, Ubuntu:26.04:LTS: openssl</p>
<p>Issue summary: An application using the OpenSSL HTTP client API functions may trigger an out-of-bounds read if the 'no_proxy' environment variable is set and the host portion of the authority component of the HTTP URL is an IPv6 address. Impact summary: An out-of-bounds read can trigger a crash which leads to Denial of Service for an application. The OpenSSL HTTP client API functions can be used directly by applications but they are also used by the OCSP client functions and CMP (Certificate Management Protocol) client implementation in OpenSSL. However the URLs used by these implementations are unlikely to be controlled by an attacker. In this vulnerable code the out of bounds read can only trigger a crash. Furthermore the vulnerability requires an attacker-controlled URL to be passed from an application to the OpenSSL function and the user has to have a 'no_proxy' environment variable set. For the aforementioned reasons the issue was assessed as Low severity. The vulnerable code was introduced in the following patch releases: 3.0.16, 3.1.8, 3.2.4, 3.3.3, 3.4.0 and 3.5.0. The FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this issue, as the HTTP client implementation is outside the OpenSSL FIPS module boundary.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-9232"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2166</id>
    <title>WID-SEC-W-2025-2166 — OpenSSL und LibreSSL: Mehrere Schwachstellen</title>
    <updated>2026-10-02T19:00:33.959557+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in OpenSSL und LibreSSL ausnutzen, um potentiell beliebigen Code auszuführen, einen Denial of Service-Zustand zu verursachen und vertrauliche Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2166"/>
  </entry>
</feed>
