<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T22:04:45.588264+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-276715</id>
    <title>EUVD-2026-276715</title>
    <updated>2026-10-05T22:04:45.957539+00:00</updated>
    <content>EUVD-2026-276715</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-276715"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-32953</id>
    <title>fkie_cve-2026-32953</title>
    <updated>2026-10-05T22:04:45.957575+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Tillitis TKey Client package is a Go package for a TKey client. Versions 1.2.0 and below contain a critical bug in the tkeyclient Go module which causes 1 out of every 256 User Supplied Secrets (USS) to be silently ignored, producing the same Compound Device Identifier (CDI)—and thus the same key material—as if no USS is provided. This happens because a buffer index error overwrites the USS-enabled boolean with the first byte of the USS digest, so any USS whose hash starts with 0x00 is effectively discarded. This issue has been fixed in version 1.3.0. Users unable to upgrade immediately should switch to a USS whose hash does not begin with a zero byte.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-32953"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-4w7r-3222-8h6v</id>
    <title>GHSA-4w7r-3222-8h6v — Tillitis TKey Client has an Error in Protocol Implementation</title>
    <updated>2026-10-05T22:04:45.957613+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/tillitis/tkeyclient</p>
<p>## Impact</p>
<p>Some specific (1 out of 256) User Supplied Secrets (USS) were not used,
making the resulting Compound Device Identifier (CDI) the same as if no
USS was provided.</p>
<p>Affected client applications: all client apps using the
[tkeyclient](https://github.com/tillitis/tkeyclient) Go module.</p>
<p>## Patches</p>
<p>Upgrade to v1.3.0.</p>
<p>**NOTE WELL**: For the affected end users upgrading an app containing
`tkeyclient` to v1.3.0 means their key material will change. An end
user can get their old keys by not entering any USS. Please make sure
to communicate this to end users.</p>
<p>## Affected users</p>
<p>The steps required to assess whether your USS is vulnerable may vary
depending on the client application. The example below shows how to
perform the check using `tkey-ssh-agent` and the known vulnerable USS
`adl`.</p>
<p>1. Insert the TKey into the client
2. Run `tkey-ssh-agent -p --uss`
3. When prompted for a User Supplied Secret, enter `adl`
4. Note the public key and call it `pubkey-with-uss`
5. Remove the TKey from the client
6. Insert the TKey into the client again
7. Run `tkey-ssh-agent -p`
8. Note the public key and call it `pubkey-without-uss`</p>
<p>Expected behavior:
`pubkey-with-uss` and `pubkey-without-uss` should not be equal.</p>
<p>Observed behavior:
`pubkey-with-uss` and `pubkey-without-uss` are equal.</p>
<p>## Workaround</p>
<p>We recommend everyone using `tkeyclient` to update to v1.3.0 and
release new versions of the client apps using it.</p>
<p>However, end users that are unable to upgrade to a new version of a…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-4w7r-3222-8h6v"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-32953</id>
    <title>UBUNTU-CVE-2026-32953</title>
    <updated>2026-10-05T22:04:45.957667+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:25.10: golang-github-tillitis-tkeyclient, Ubuntu:26.04:LTS: golang-github-tillitis-tkeyclient</p>
<p>Tillitis TKey Client package is a Go package for a TKey client. Versions 1.2.0 and below contain a critical bug in the tkeyclient Go module which causes 1 out of every 256 User Supplied Secrets (USS) to be silently ignored, producing the same Compound Device Identifier (CDI)—and thus the same key material—as if no USS is provided. This happens because a buffer index error overwrites the USS-enabled boolean with the first byte of the USS digest, so any USS whose hash starts with 0x00 is effectively discarded. This issue has been fixed in version 1.3.0. Users unable to upgrade immediately should switch to a USS whose hash does not begin with a zero byte.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-32953"/>
  </entry>
</feed>
