<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T15:38:04.462374+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:49520</id>
    <title>ALSA-2026:49520 — Important: ldns security update</title>
    <updated>2026-10-03T15:38:04.800381+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: ldns, AlmaLinux:8: ldns-devel, AlmaLinux:8: ldns-doc, AlmaLinux:8: ldns-utils, AlmaLinux:8: perl-ldns, AlmaLinux:8: python3-ldns</p>
<p>The ldns packages contain a library with the aim to simplify DNS programming in C. All low-level DNS/DNSSEC operations are supported. We also define a higher level API which allows a programmer to (for instance) create or sign packets.</p>
<p>Security Fix(es):</p>
<p>* ldns: ldns: Off-path poisoning attacks due to insufficient query-response matching (CVE-2026-10846)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:49520"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-12817</id>
    <title>bdu:2026-12817</title>
    <updated>2026-10-03T15:38:04.800458+00:00</updated>
    <content>bdu:2026-12817</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-12817"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0753</id>
    <title>certfr-2026-avi-0753 — De multiples vulnérabilités ont été découvertes dans Microsoft Azure. Elles permettent à un attaquant de provoquer un p…</title>
    <updated>2026-10-03T15:38:04.800476+00:00</updated>
    <content>certfr-2026-avi-0753</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0753"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-326398</id>
    <title>EUVD-2026-326398</title>
    <updated>2026-10-03T15:38:04.800492+00:00</updated>
    <content>EUVD-2026-326398</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-326398"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-10846</id>
    <title>fkie_cve-2026-10846</title>
    <updated>2026-10-03T15:38:04.800503+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>NLnet Labs ldns 1.2.0 up to and including versions 1.9.0, when used in applications as (stub) resolver over UDP, lacks matching the query destination address and port with the response source address and port. Furthermore not the query ID, neither the question of the query is matched with that of the response. This makes applications, that use ldns for (stub) resolver functionality over UDP, vulnerable for off-path poisoning attacks. The drill tool, which is shipped with ldns, suffers from this vulnerability.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-10846"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-x77r-8q36-8529</id>
    <title>GHSA-x77r-8q36-8529</title>
    <updated>2026-10-03T15:38:04.800527+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>NLnet Labs ldns 1.2.0 up to and including versions 1.9.0, when used in applications as (stub) resolver over UDP, lacks matching the query destination address and port with the response source address and port. Furthermore not the query ID, neither the question of the query is matched with that of the response. This makes applications, that use ldns for (stub) resolver functionality over UDP, vulnerable for off-path poisoning attacks. The drill tool, which is shipped with ldns, suffers from this vulnerability.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-x77r-8q36-8529"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-10846</id>
    <title>msrc_CVE-2026-10846 — Insufficient verification that responses belong to a query</title>
    <updated>2026-10-03T15:38:04.800543+00:00</updated>
    <content>msrc_CVE-2026-10846</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-10846"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-2788</id>
    <title>OESA-2026-2788 — ldns security update</title>
    <updated>2026-10-03T15:38:04.800559+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP4: ldns, openEuler:22.03-LTS-SP4: ldns, openEuler:24.03-LTS-SP1: ldns, openEuler:24.03-LTS-SP3: ldns</p>
<p>The goal of ldns is to simplify DNS programming, it supports recent RFCs  like the DNSSEC documents, and allows developers to easily create software  conforming to current RFCs, and experimental software for current Internet  Drafts. A secondary benefit of using ldns is speed; ldns is written in C  it should be a lot faster than Perl.

Security Fix(es):</p>
<p>NLnet Labs ldns 1.2.0 up to and including versions 1.9.0, when used in applications as (stub) resolver over UDP, lacks matching the query destination address and port with the response source address and port. Furthermore not the query ID, neither the question of the query is matched with that of the response. This makes applications, that use ldns for (stub) resolver functionality over UDP, vulnerable for off-path poisoning attacks. The drill tool, which is shipped with ldns, suffers from this vulnerability.(CVE-2026-10846)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-2788"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10998-1</id>
    <title>openSUSE-SU-2026:10998-1 — ldns-1.9.2-1.1 on GA media</title>
    <updated>2026-10-03T15:38:04.800589+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ldns-1.9.2-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10998-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:53402</id>
    <title>RHSA-2026:53402 — Red Hat Security Advisory: ldns security update</title>
    <updated>2026-10-03T15:38:04.800605+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ldns: ldns: Off-path poisoning attacks due to insufficient query-response matching</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:53402"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:49520</id>
    <title>RLSA-2026:49520 — Important: ldns security update</title>
    <updated>2026-10-03T15:38:04.800621+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:8: ldns</p>
<p>The ldns packages contain a library with the aim to simplify DNS programming in C. All low-level DNS/DNSSEC operations are supported. We also define a higher level API which allows a programmer to (for instance) create or sign packets.</p>
<p>Security Fix(es):</p>
<p>* ldns: ldns: Off-path poisoning attacks due to insufficient query-response matching (CVE-2026-10846)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:49520"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:22167-1</id>
    <title>SUSE-SU-2026:22167-1 — Security update for ldns</title>
    <updated>2026-10-03T15:38:04.800643+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for ldns</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:22167-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-10846</id>
    <title>UBUNTU-CVE-2026-10846</title>
    <updated>2026-10-03T15:38:04.800657+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: ldns, Ubuntu:Pro:18.04:LTS: ldns, Ubuntu:Pro:20.04:LTS: ldns, Ubuntu:Pro:22.04:LTS: ldns, Ubuntu:Pro:24.04:LTS: ldns, Ubuntu:25.10: ldns, Ubuntu:Pro:26.04:LTS: ldns</p>
<p>NLnet Labs ldns 1.2.0 up to and including versions 1.9.0, when used in applications as (stub) resolver over UDP, lacks matching the query destination address and port with the response source address and port. Furthermore not the query ID, neither the question of the query is matched with that of the response. This makes applications, that use ldns for (stub) resolver functionality over UDP, vulnerable for off-path poisoning attacks. The drill tool, which is shipped with ldns, suffers from this vulnerability.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-10846"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1871</id>
    <title>WID-SEC-W-2026-1871 — FreeBSD Project FreeBSD OS: Mehrere Schwachstellen</title>
    <updated>2026-10-03T15:38:04.800683+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann mehrere Schwachstellen in FreeBSD Project FreeBSD OS ausnutzen, um erweiterte Rechte zu erlangen – möglicherweise sogar Administratorrechte –, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, Daten zu manipulieren oder andere, nicht näher definierte Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1871"/>
  </entry>
</feed>
