<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T17:50:49.617587+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0623</id>
    <title>certfr-2026-avi-0623 — De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Certaines d'entre elles permettent à un at…</title>
    <updated>2026-10-03T17:50:49.888914+00:00</updated>
    <content>certfr-2026-avi-0623</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0623"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-362247</id>
    <title>EUVD-2026-362247</title>
    <updated>2026-10-03T17:50:49.888966+00:00</updated>
    <content>EUVD-2026-362247</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-362247"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-34956</id>
    <title>fkie_cve-2026-34956</title>
    <updated>2026-10-03T17:50:49.888981+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in Open vSwitch. When Open vSwitch is configured with a conntrack flow using FTP helpers over the userspace datapath, a remote attacker can send a specially crafted FTP stream with an EPASV command exceeding 255 characters. This heap access error can lead to a crash, resulting in a Denial of Service (DoS) for the affected system.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-34956"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-q5f5-xxh8-jx9h</id>
    <title>GHSA-q5f5-xxh8-jx9h</title>
    <updated>2026-10-03T17:50:49.889011+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in Open vSwitch. When Open vSwitch is configured with a conntrack flow using FTP helpers over the userspace datapath, a remote attacker can send a specially crafted FTP stream with an EPASV command exceeding 255 characters. This heap access error can lead to a crash, resulting in a Denial of Service (DoS) for the affected system.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-q5f5-xxh8-jx9h"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-34956</id>
    <title>msrc_CVE-2026-34956 — Openvswitch: open vswitch: denial of service via malformed ftp epasv command</title>
    <updated>2026-10-03T17:50:49.889028+00:00</updated>
    <content>msrc_CVE-2026-34956</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-34956"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-1871</id>
    <title>OESA-2026-1871 — openvswitch security update</title>
    <updated>2026-10-03T17:50:49.889044+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP4: openvswitch</p>
<p>Open vSwitch provides standard network bridging functions and support for the OpenFlow protocol for remote per-flow control of traffic.

Security Fix(es):</p>
<p>[&amp;quot;Description\n===========\n\nMultiple versions of Open vSwitch are vulnerable to crafted FTP payloads\ncausing invalid memory accesses, potential denial of service, and possible\nremote code execution.  This impacts the userspace implementation of\nconntrack.  Triggering the vulnerability requires that Open vSwitch has\nconfigured conntrack flows specifying the FTP alg handler.  Conntrack\nhandlers in userspace are not automatically applied.\n\nThe issue is caused by type narrowing when copying FTP substrings.  It\nhas existed in all versions of the userspace conntrack supporting the\nFTP handler.  This was introduced with Open vSwitch version 2.8.0 and\naffects all versions up to 3.7.0.\n\nThe Common Vulnerabilities and Exposures project (cve.mitre.org) has\nassigned CVE-2026-34956 identifier to this issue.  At the time of writing\nthe flaw is considered with Moderate impact and 5.9 CVSS.\n\n\nMitigation\n==========\n\nFor any affected version of Open vSwitch, avoiding the FTP alg will\nprevent the issue from triggering.  The Open vSwitch team does not\nrecommend attempting to mitigate the vulnerability this way because it\nmay impact packet forwarding.\n\nBy default, alg handlers are not installed, and must be added as part\nof the OpenFlow rules (via &amp;apos;ct(alg=ftp)&amp;apos; for example).\n\nUsers can check if t…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-1871"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10534-1</id>
    <title>openSUSE-SU-2026:10534-1 — libopenvswitch-3_7-0-3.7.1-33.1 on GA media</title>
    <updated>2026-10-03T17:50:49.889093+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libopenvswitch-3_7-0-3.7.1-33.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10534-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:1440-1</id>
    <title>SUSE-SU-2026:1440-1 — Security update for openvswitch3</title>
    <updated>2026-10-03T17:50:49.889111+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for openvswitch3</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:1440-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-34956</id>
    <title>UBUNTU-CVE-2026-34956</title>
    <updated>2026-10-03T17:50:49.889127+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:18.04:LTS: openvswitch, Ubuntu:20.04:LTS: openvswitch, Ubuntu:22.04:LTS: openvswitch, Ubuntu:24.04:LTS: openvswitch, Ubuntu:25.10: openvswitch, Ubuntu:26.04:LTS: openvswitch</p>
<p>A flaw was found in Open vSwitch. When Open vSwitch is configured with a conntrack flow using FTP helpers over the userspace datapath, a remote attacker can send a specially crafted FTP stream with an EPASV command exceeding 255 characters. This heap access error can lead to a crash, resulting in a Denial of Service (DoS) for the affected system.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-34956"/>
  </entry>
</feed>
