<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T16:26:46.428477+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1067</id>
    <title>certfr-2026-avi-1067 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-03T16:26:46.680247+00:00</updated>
    <content>certfr-2026-avi-1067</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1067"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-327702</id>
    <title>EUVD-2026-327702</title>
    <updated>2026-10-03T16:26:46.680301+00:00</updated>
    <content>EUVD-2026-327702</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-327702"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-12087</id>
    <title>fkie_cve-2026-12087</title>
    <updated>2026-10-03T16:26:46.680317+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Socket versions before 2.041 for Perl have an out-of-bounds heap read.</p>
<p>In Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a valid multiaddr lets a source of any length pass the check, and the source is then copied into the 4-byte imr_sourceaddr field with a fixed-size copy. A source shorter than 4 bytes is not rejected, and the copy reads up to 3 bytes past the end of its buffer.</p>
<p>Calling pack_ip_mreq_source() with a source value shorter than 4 bytes copies adjacent heap memory into the returned packed structure.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-12087"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-q5cv-5vf6-95gp</id>
    <title>GHSA-q5cv-5vf6-95gp</title>
    <updated>2026-10-03T16:26:46.680355+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Socket versions before 2.041 for Perl have an out-of-bounds heap read.</p>
<p>In Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a valid multiaddr lets a source of any length pass the check, and the source is then copied into the 4-byte imr_sourceaddr field with a fixed-size copy. A source shorter than 4 bytes is not rejected, and the copy reads up to 3 bytes past the end of its buffer.</p>
<p>Calling pack_ip_mreq_source() with a source value shorter than 4 bytes copies adjacent heap memory into the returned packed structure.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-q5cv-5vf6-95gp"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-12087</id>
    <title>msrc_CVE-2026-12087 — Socket versions before 2.041 for Perl have an out-of-bounds heap read</title>
    <updated>2026-10-03T16:26:46.680377+00:00</updated>
    <content>msrc_CVE-2026-12087</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-12087"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ncsc-2026-0321</id>
    <title>NCSC-2026-0321 — Meerdere kwetsbaarheden verholpen in IBM AIX en IBM PowerVM VIOS</title>
    <updated>2026-10-03T16:26:46.680397+00:00</updated>
    <content>NCSC-2026-0321</content>
    <link href="https://cve.radiocsirt.org/vuln/ncsc-2026-0321"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-2843</id>
    <title>OESA-2026-2843 — perl security update</title>
    <updated>2026-10-03T16:26:46.680635+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP4: perl</p>
<p>Perl 5 is a highly capable, feature-rich programming language with over 30 years of development. Perl 5 runs on over 100 platforms from portables to mainframes and is suitable for both rapid prototyping and large scale development projects.

Security Fix(es):</p>
<p>Socket versions before 2.041 for Perl have an out-of-bounds heap read.</p>
<p>In Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a valid multiaddr lets a source of any length pass the check, and the source is then copied into the 4-byte imr_sourceaddr field with a fixed-size copy. A source shorter than 4 bytes is not rejected, and the copy reads up to 3 bytes past the end of its buffer.</p>
<p>Calling pack_ip_mreq_source() with a source value shorter than 4 bytes copies adjacent heap memory into the returned packed structure.(CVE-2026-12087)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-2843"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21411-1</id>
    <title>openSUSE-SU-2026:21411-1 — Security update for perl</title>
    <updated>2026-10-03T16:26:46.680668+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for perl</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:21411-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:11342</id>
    <title>RHSA-2026:11342 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
    <updated>2026-10-03T16:26:46.680701+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>perl-Socket: perl-Socket: Information Disclosure due to Out-of-Bounds Read</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:11342"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:22847-1</id>
    <title>SUSE-SU-2026:22847-1 — Security update for perl</title>
    <updated>2026-10-03T16:26:46.680718+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for perl</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:22847-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-12087</id>
    <title>UBUNTU-CVE-2026-12087</title>
    <updated>2026-10-03T16:26:46.680735+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: perl, Ubuntu:Pro:16.04:LTS: perl, Ubuntu:16.04:LTS: libsocket-perl, Ubuntu:Pro:18.04:LTS: perl, Ubuntu:18.04:LTS: libsocket-perl, Ubuntu:Pro:20.04:LTS: perl, Ubuntu:20.04:LTS: libsocket-perl, Ubuntu:22.04:LTS: libsocket-perl, Ubuntu:22.04:LTS: perl, Ubuntu:24.04:LTS: libsocket-perl and 5 more</p>
<p>Socket versions before 2.041 for Perl have an out-of-bounds heap read. In Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a valid multiaddr lets a source of any length pass the check, and the source is then copied into the 4-byte imr_sourceaddr field with a fixed-size copy. A source shorter than 4 bytes is not rejected, and the copy reads up to 3 bytes past the end of its buffer. Calling pack_ip_mreq_source() with a source value shorter than 4 bytes copies adjacent heap memory into the returned packed structure.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-12087"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2858</id>
    <title>WID-SEC-W-2026-2858 — IBM AIX und VIOS: Mehrere Schwachstellen</title>
    <updated>2026-10-03T16:26:46.680780+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in IBM AIX und IBM VIOS ausnutzen, um beliebigen Programmcode auszuführen, um seine Privilegien zu erhöhen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, und um Sicherheitsvorkehrungen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2858"/>
  </entry>
</feed>
