<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T15:26:10.897024+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-09701</id>
    <title>bdu:2026-09701</title>
    <updated>2026-10-02T15:26:10.903268+00:00</updated>
    <content>bdu:2026-09701</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-09701"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0456</id>
    <title>certfr-2026-avi-0456 — De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Elles permettent à un attaquant de provoqu…</title>
    <updated>2026-10-02T15:26:10.903316+00:00</updated>
    <content>certfr-2026-avi-0456</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0456"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-281103</id>
    <title>EUVD-2026-281103</title>
    <updated>2026-10-02T15:26:10.903342+00:00</updated>
    <content>EUVD-2026-281103</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-281103"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-35201</id>
    <title>fkie_cve-2026-35201</title>
    <updated>2026-10-02T15:26:10.903360+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Discount is an implementation of John Gruber's Markdown markup language in C. From 1.3.1.1 to before 2.2.7.4, a signed length truncation bug causes an out-of-bounds read in the default Markdown parse path. Inputs larger than INT_MAX are truncated to a signed int before entering the native parser, allowing the parser to read past the end of the supplied buffer and crash the process. This vulnerability is fixed in 2.2.7.4.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-35201"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-6r34-94wq-jhrc</id>
    <title>GHSA-6r34-94wq-jhrc — rdiscount has an Out-of-bounds Read</title>
    <updated>2026-10-02T15:26:10.903400+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> RubyGems: rdiscount</p>
<p>### Summary</p>
<p>A signed length truncation bug causes an out-of-bounds read in the default Markdown parse path. Inputs larger than `INT_MAX` are truncated to a signed `int` before entering the native parser, allowing the parser to read past the end of the supplied buffer and crash the process</p>
<p>### Details</p>
<p>In both public entry points:</p>
<p>- `ext/rdiscount.c:97`
- `ext/rdiscount.c:136`</p>
<p>`RSTRING_LEN(text)` is passed directly into `mkd_string()`:</p>
<p>```c
MMIOT *doc = mkd_string(RSTRING_PTR(text), RSTRING_LEN(text), flags);
```</p>
<p>`mkd_string()` accepts `int len`:</p>
<p>- `ext/mkdio.c:174`</p>
<p>```c
Document * mkd_string(const char *buf, int len, mkd_flag_t flags)
{
    struct string_stream about;</p>
<p>about.data = buf;
    about.size = len;</p>
<p>return populate((getc_func)__mkd_io_strget, &amp;about, flags &amp; INPUT_MASK);
}
```</p>
<p>The parser stores the remaining input length in a signed `int`:</p>
<p>- `ext/markdown.h:205`</p>
<p>```c
struct string_stream {
    const char *data;
    int   size;
};
```</p>
<p>The read loop stops only when `size == 0`:</p>
<p>- `ext/mkdio.c:161`</p>
<p>```c
int __mkd_io_strget(struct string_stream *in)
{
    if ( !in-&gt;size ) return EOF;</p>
<p>--(in-&gt;size);</p>
<p>return *(in-&gt;data)++;
}
```</p>
<p>If the Ruby string length exceeds `INT_MAX`, the value can truncate to a negative `int`. In that state, the parser continues incrementing `data` and reading past the end of the original Ruby string, causing an out-of-bounds read and native crash.</p>
<p>Affected APIs:</p>
<p>- `RDiscount.new(input).to_html`
- `RDiscount.new(inp…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-6r34-94wq-jhrc"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-35201</id>
    <title>msrc_CVE-2026-35201 — Discount has an Out-of-bounds Read in rdiscount</title>
    <updated>2026-10-02T15:26:10.903486+00:00</updated>
    <content>msrc_CVE-2026-35201</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-35201"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-35201</id>
    <title>UBUNTU-CVE-2026-35201</title>
    <updated>2026-10-02T15:26:10.903511+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: discount, Ubuntu:18.04:LTS: discount, Ubuntu:20.04:LTS: discount, Ubuntu:22.04:LTS: discount, Ubuntu:24.04:LTS: discount, Ubuntu:25.10: discount, Ubuntu:26.04:LTS: discount</p>
<p>Discount is an implementation of John Gruber's Markdown markup language in C. From 1.3.1.1 to before 2.2.7.4, a signed length truncation bug causes an out-of-bounds read in the default Markdown parse path. Inputs larger than INT_MAX are truncated to a signed int before entering the native parser, allowing the parser to read past the end of the supplied buffer and crash the process. This vulnerability is fixed in 2.2.7.4.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-35201"/>
  </entry>
</feed>
