<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T02:21:55.263184+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-07368</id>
    <title>bdu:2026-07368</title>
    <updated>2026-10-03T02:21:55.267309+00:00</updated>
    <content>bdu:2026-07368</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-07368"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-277741</id>
    <title>EUVD-2026-277741</title>
    <updated>2026-10-03T02:21:55.267351+00:00</updated>
    <content>EUVD-2026-277741</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-277741"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-33743</id>
    <title>fkie_cve-2026-33743</title>
    <updated>2026-10-03T02:21:55.267366+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Incus is a system container and virtual machine manager. Prior to version 6.23.0, a specially crafted storage bucket backup can be used by an user with access to Incus' storage bucket feature to crash the Incus daemon. Repeated use of this attack can be used to keep the server offline causing a denial of service of the control plane API. This does not impact any running workload, existing containers and virtual machines will keep operating. Version 6.23.0 fixes the issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-33743"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-vg76-xmhg-j5x3</id>
    <title>GHSA-vg76-xmhg-j5x3 — Incus vulnerable to denial of source through crafted bucket backup file</title>
    <updated>2026-10-03T02:21:55.267399+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/lxc/incus/v6, Go: github.com/lxc/incus</p>
<p>### Summary
A specially crafted storage bucket backup can be used by an user with access to Incus' storage bucket feature to crash the Incus daemon. Repeated use of this attack can be used to keep the server offline causing a denial of service of the control plane API.</p>
<p>This does not impact any running workload, existing containers and virtual machines will keep operating.</p>
<p>### Details</p>
<p>The S3 transfer manager contains an unchecked string slicing vulnerability that allows an authenticated attacker to crash the daemon during S3 restore operations. While processing tar headers from a supplied backup archive, the code skips only the index entry and strips the expected bucket prefix from all other entries without first validating the header name.</p>
<p>In Go, slicing a string with a starting index beyond the string length triggers a runtime panic. Because no prefix or length validation is performed before this operation, a malicious archive containing a non-index entry with a shorter-than-expected header name can trigger a slice-bounds panic and terminate the daemon. This results in immediate denial of service on the node.</p>
<p>Affected File:
https://github.com/lxc/incus/blob/v6.20.0/internal/server/storage/s3/transfer_manager.go</p>
<p>Affected Code:
```
func (t TransferManager) UploadAllFiles(bucketName string, srcData io.ReadSeeker) error {
    [...]
    for {
        hdr, err := tr.Next()
        if err == io.EOF {
            break // End of archive.
        }</p>
<p>// Skip index.yaml…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-vg76-xmhg-j5x3"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10450-1</id>
    <title>openSUSE-SU-2026:10450-1 — incus-6.23-1.1 on GA media</title>
    <updated>2026-10-03T02:21:55.267461+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>incus-6.23-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10450-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-33743</id>
    <title>UBUNTU-CVE-2026-33743</title>
    <updated>2026-10-03T02:21:55.267482+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:24.04:LTS: incus, Ubuntu:25.10: incus, Ubuntu:Pro:26.04:LTS: incus</p>
<p>Incus is a system container and virtual machine manager. Prior to version 6.23.0, a specially crafted storage bucket backup can be used by an user with access to Incus' storage bucket feature to crash the Incus daemon. Repeated use of this attack can be used to keep the server offline causing a denial of service of the control plane API. This does not impact any running workload, existing containers and virtual machines will keep operating. Version 6.23.0 fixes the issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-33743"/>
  </entry>
</feed>
