<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T17:11:38.844680+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:22963</id>
    <title>ALSA-2026:22963 — Critical: samba security update</title>
    <updated>2026-10-03T17:11:39.163057+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:10: ldb-tools, AlmaLinux:10: libldb, AlmaLinux:10: libldb-devel, AlmaLinux:10: libnetapi, AlmaLinux:10: libnetapi-devel, AlmaLinux:10: libsmbclient, AlmaLinux:10: libsmbclient-devel, AlmaLinux:10: libwbclient, AlmaLinux:10: libwbclient-devel, AlmaLinux:10: python3-ldb and 27 more</p>
<p>Samba is an open-source implementation of the Server Message Block (SMB) protocol and the related Common Internet File System (CIFS) protocol, which allow PC-compatible machines to share files, printers, and various information.</p>
<p>Security Fix(es):</p>
<p>* samba: Missing access check on reparse point operations (CVE-2026-1933)
  * samba: vfs_worm does not block directory modification (CVE-2026-2340)
  * samba: group policy certificate enrollment uses &lt;http://&gt; without validation (CVE-2026-3012)
  * samba: Samba: Remote Code Execution in printing subsystem via unescaped job description (CVE-2026-4480)
  * ngtcp2: ngtcp2: Denial of service via stack buffer overflow during QUIC handshake (CVE-2026-40170)
  * samba: Remote Code Execution in SAMR (CVE-2026-4408)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:22963"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-337279</id>
    <title>EUVD-2026-337279</title>
    <updated>2026-10-03T17:11:39.163277+00:00</updated>
    <content>EUVD-2026-337279</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-337279"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-40170</id>
    <title>fkie_cve-2026-40170</title>
    <updated>2026-10-03T17:11:39.163297+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ngtcp2 is a C implementation of the IETF QUIC protocol. In versions prior to 1.22.1, ngtcp2_qlog_parameters_set_transport_params() serializes peer transport parameters into a fixed 1024-byte stack buffer without bounds checking. When qlog is enabled, a remote peer can send sufficiently large transport parameters during the QUIC handshake to cause writes beyond the buffer boundary, resulting in a stack buffer overflow. This affects deployments that enable the qlog callback and process untrusted peer transport parameters. This issue has been fixed in version 1.22.1. If developers are unable to immediately upgrade, they can disable the qlog on client.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-40170"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-40170</id>
    <title>msrc_CVE-2026-40170 — ngtcp2 has a qlog transport parameter serialization stack buffer overflow</title>
    <updated>2026-10-03T17:11:39.163326+00:00</updated>
    <content>msrc_CVE-2026-40170</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-40170"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10621-1</id>
    <title>openSUSE-SU-2026:10621-1 — libngtcp2-16-1.22.1-1.1 on GA media</title>
    <updated>2026-10-03T17:11:39.163345+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libngtcp2-16-1.22.1-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10621-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:9113</id>
    <title>RHSA-2026:9113 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
    <updated>2026-10-03T17:11:39.163362+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ngtcp2: ngtcp2: Denial of service via stack buffer overflow during QUIC handshake</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:9113"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:22963</id>
    <title>RLSA-2026:22963 — Critical: samba security update</title>
    <updated>2026-10-03T17:11:39.163380+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:10: samba</p>
<p>Samba is an open-source implementation of the Server Message Block (SMB) protocol and the related Common Internet File System (CIFS) protocol, which allow PC-compatible machines to share files, printers, and various information.</p>
<p>Security Fix(es):</p>
<p>* samba: Missing access check on reparse point operations (CVE-2026-1933)</p>
<p>* samba: vfs_worm does not block directory modification (CVE-2026-2340)</p>
<p>* samba: group policy certificate enrollment uses http:// without validation (CVE-2026-3012)</p>
<p>* samba: Samba: Remote Code Execution in printing subsystem via unescaped job description (CVE-2026-4480)</p>
<p>* ngtcp2: ngtcp2: Denial of service via stack buffer overflow during QUIC handshake (CVE-2026-40170)</p>
<p>* samba: Remote Code Execution in SAMR (CVE-2026-4408)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:22963"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:22368-1</id>
    <title>SUSE-SU-2026:22368-1 — Security update for nodejs22</title>
    <updated>2026-10-03T17:11:39.163409+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for nodejs22</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:22368-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-40170</id>
    <title>UBUNTU-CVE-2026-40170</title>
    <updated>2026-10-03T17:11:39.163438+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:22.04:LTS: ngtcp2, Ubuntu:24.04:LTS: ngtcp2, Ubuntu:25.10: ngtcp2, Ubuntu:26.04:LTS: ngtcp2</p>
<p>ngtcp2 is a C implementation of the IETF QUIC protocol. In versions prior to 1.22.1, ngtcp2_qlog_parameters_set_transport_params() serializes peer transport parameters into a fixed 1024-byte stack buffer without bounds checking. When qlog is enabled, a remote peer can send sufficiently large transport parameters during the QUIC handshake to cause writes beyond the buffer boundary, resulting in a stack buffer overflow. This affects deployments that enable the qlog callback and process untrusted peer transport parameters. This issue has been fixed in version 1.22.1. If developers are unable to immediately upgrade, they can disable the qlog on client.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-40170"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1508</id>
    <title>WID-SEC-W-2026-1508 — Samba: Schwachstelle ermöglicht Denial of Service</title>
    <updated>2026-10-03T17:11:39.163467+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Samba ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1508"/>
  </entry>
</feed>
