<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T08:25:03.198396+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:50728</id>
    <title>ALSA-2026:50728 — Important: ruby:3.3 security, bug fix, and enhancement update</title>
    <updated>2026-10-03T08:25:03.721484+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: ruby, AlmaLinux:8: ruby-bundled-gems, AlmaLinux:8: ruby-default-gems, AlmaLinux:8: ruby-devel, AlmaLinux:8: ruby-doc, AlmaLinux:8: ruby-libs, AlmaLinux:8: rubygem-abrt, AlmaLinux:8: rubygem-abrt-doc, AlmaLinux:8: rubygem-bigdecimal, AlmaLinux:8: rubygem-bundler and 20 more</p>
<p>Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks.</p>
<p>Security Fix(es):</p>
<p>* zlib: zlib: Memory corruption via buffer overflow in Zlib::GzipReader (CVE-2026-27820)
  * net-imap: Net::IMAP: Arbitrary IMAP command injection via CRLF sequences in unvalidated input (CVE-2026-42257)
  * ruby/net-imap: ruby: Net::IMAP: Denial of Service via large iteration count in SCRAM authentication (CVE-2026-42256)
  * net-imap: Net::IMAP: Command injection via non-synchronizing literals (CVE-2026-47240)
  * net-imap: Net::IMAP: Arbitrary IMAP command injection due to improper input validation (CVE-2026-47242)
  * net-imap: rubygem-net-imap: Net::IMAP: Denial of Service via malformed command input (CVE-2026-47241)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* ruby:3.3/ruby: Rebase to the latest Ruby 3.3 release [almalinux-8] (JIRA:AlmaLinux-170929)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:50728"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-42256</id>
    <title>BELL-CVE-2026-42256</title>
    <updated>2026-10-03T08:25:03.721700+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:25: ruby-net-imap, Alpaquita:stream: ruby-net-imap</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-42256"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-imap-backup-cve-2026-42256</id>
    <title>BREW-imap-backup-CVE-2026-42256 — net-imap vulnerable to denial of service via high iteration count for `SCRAM-*` authentication</title>
    <updated>2026-10-03T08:25:03.721744+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: imap-backup</p>
<p>### Summary</p>
<p>When authenticating a connection with `SCRAM-SHA1` or `SCRAM-SHA256`, a hostile server can perform a computational denial-of-service attack on the client process by sending a big iteration count value.</p>
<p>### Details</p>
<p>A hostile IMAP server can send an arbitrarily large PBKDF2 iteration count in the SCRAM server-first-message, causing the client to perform an expensive `OpenSSL::KDF.pbkdf2_hmac` call.   Because the PBKDF2 function is a blocking C extension and holds onto Ruby’s Global VM Lock, it can freeze the entire Ruby VM for the duration of the computation.</p>
<p>OpenSSL enforces an effective maximum by using a 32-bit signed integer for the iteration count,  Depending on hardware capabilities and OpenSSL version, this iteration count may be sufficient for to block all Ruby threads in the process for over seven minutes.</p>
<p>This is listed as one of the "Security Considerations", in [RFC 7804](https://www.rfc-editor.org/rfc/rfc7804.html#page-15):
&gt;   A hostile server can perform a computational denial-of-service attack on clients by sending a big iteration count value.  In order to defend against that, a client implementation can pick a maximum iteration count that it is willing to use and reject any values that exceed that threshold (in such cases, the client, of course, has to fail the authentication).</p>
<p>### Impact</p>
<p>During SCRAM authentication to a hostile server, the entire Ruby VM will be locked for the duration of the computation.  Depending on hardware capabilities…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-imap-backup-cve-2026-42256"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0958</id>
    <title>certfr-2026-avi-0958 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-03T08:25:03.721821+00:00</updated>
    <content>certfr-2026-avi-0958</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0958"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-mh39201</id>
    <title>CLEANSTART-2026-MH39201 — Security fix for CVE-2026-42256 applied in: ruby-fluentd-1.19 1.19.2-r2</title>
    <updated>2026-10-03T08:25:03.721841+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: ruby-fluentd-1.19</p>
<p>Security vulnerability affects the ruby-fluentd-1.19 package. This issue is resolved in later releases. See references for vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-mh39201"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-309972</id>
    <title>EUVD-2026-309972</title>
    <updated>2026-10-03T08:25:03.721863+00:00</updated>
    <content>EUVD-2026-309972</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-309972"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-42256</id>
    <title>fkie_cve-2026-42256</title>
    <updated>2026-10-03T08:25:03.721875+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. From versions 0.4.0 to before 0.4.24, 0.5.0 to before 0.5.14, and 0.6.0 to before 0.6.4, when authenticating a connection with SCRAM-SHA1 or SCRAM-SHA256, a hostile server can perform a computational denial-of-service attack on the client process by sending a big iteration count value. This issue has been patched in versions 0.4.24, 0.5.14, and 0.6.4.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-42256"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-87pf-fpwv-p7m7</id>
    <title>GHSA-87pf-fpwv-p7m7 — net-imap vulnerable to denial of service via high iteration count for `SCRAM-*` authentication</title>
    <updated>2026-10-03T08:25:03.721899+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> RubyGems: net-imap</p>
<p>### Summary</p>
<p>When authenticating a connection with `SCRAM-SHA1` or `SCRAM-SHA256`, a hostile server can perform a computational denial-of-service attack on the client process by sending a big iteration count value.</p>
<p>### Details</p>
<p>A hostile IMAP server can send an arbitrarily large PBKDF2 iteration count in the SCRAM server-first-message, causing the client to perform an expensive `OpenSSL::KDF.pbkdf2_hmac` call.   Because the PBKDF2 function is a blocking C extension and holds onto Ruby’s Global VM Lock, it can freeze the entire Ruby VM for the duration of the computation.</p>
<p>OpenSSL enforces an effective maximum by using a 32-bit signed integer for the iteration count,  Depending on hardware capabilities and OpenSSL version, this iteration count may be sufficient for to block all Ruby threads in the process for over seven minutes.</p>
<p>This is listed as one of the "Security Considerations", in [RFC 7804](https://www.rfc-editor.org/rfc/rfc7804.html#page-15):
&gt;   A hostile server can perform a computational denial-of-service attack on clients by sending a big iteration count value.  In order to defend against that, a client implementation can pick a maximum iteration count that it is willing to use and reject any values that exceed that threshold (in such cases, the client, of course, has to fail the authentication).</p>
<p>### Impact</p>
<p>During SCRAM authentication to a hostile server, the entire Ruby VM will be locked for the duration of the computation.  Depending on hardware capabilities…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-87pf-fpwv-p7m7"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-42256</id>
    <title>msrc_CVE-2026-42256 — net-imap: Denial of service via high iteration count for `SCRAM-*` authentication</title>
    <updated>2026-10-03T08:25:03.721945+00:00</updated>
    <content>msrc_CVE-2026-42256</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-42256"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21225-1</id>
    <title>openSUSE-SU-2026:21225-1 — Security update for rmt-server</title>
    <updated>2026-10-03T08:25:03.721974+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for rmt-server</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:21225-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:33551</id>
    <title>RHSA-2026:33551 — Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update</title>
    <updated>2026-10-03T08:25:03.721993+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ruby: net-imap: Net::IMAP: Denial of Service via crafted IMAP responses net-imap: ruby: Net::IMAP: Information disclosure via man-in-the-middle attack bypassing TLS ruby/net-imap: ruby: Net::IMAP: Denial of Service via large iteration count in SCRAM authentication net-imap: Net::IMAP: Command injection via non-synchronizing literals net-imap: rubygem-net-imap: Net::IMAP: Denial of Service via malformed command input net-imap: Net::IMAP: Arbitrary IMAP command injection due to improper input validation</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:33551"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:50728</id>
    <title>RLSA-2026:50728 — Important: ruby:3.3 security, bug fix, and enhancement update</title>
    <updated>2026-10-03T08:25:03.722019+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:8: ruby, Rocky Linux:8: rubygem-abrt, Rocky Linux:8: rubygem-mysql2, Rocky Linux:8: rubygem-pg</p>
<p>Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks.</p>
<p>Security Fix(es):</p>
<p>* zlib: zlib: Memory corruption via buffer overflow in Zlib::GzipReader (CVE-2026-27820)</p>
<p>* net-imap: Net::IMAP: Arbitrary IMAP command injection via CRLF sequences in unvalidated input (CVE-2026-42257)</p>
<p>* ruby/net-imap: ruby: Net::IMAP: Denial of Service via large iteration count in SCRAM authentication (CVE-2026-42256)</p>
<p>* net-imap: Net::IMAP: Command injection via non-synchronizing literals (CVE-2026-47240)</p>
<p>* net-imap: Net::IMAP: Arbitrary IMAP command injection due to improper input validation (CVE-2026-47242)</p>
<p>* net-imap: rubygem-net-imap: Net::IMAP: Denial of Service via malformed command input (CVE-2026-47241)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* ruby:3.3/ruby: Rebase to the latest Ruby 3.3 release [rhel-8] (JIRA:Rocky Linux-170929)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:50728"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-42256</id>
    <title>UBUNTU-CVE-2026-42256</title>
    <updated>2026-10-03T08:25:03.722063+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:25.10: jruby, Ubuntu:25.10: ruby3.3, Ubuntu:26.04:LTS: ruby3.3</p>
<p>Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. From versions 0.4.0 to before 0.4.24, 0.5.0 to before 0.5.14, and 0.6.0 to before 0.6.4, when authenticating a connection with SCRAM-SHA1 or SCRAM-SHA256, a hostile server can perform a computational denial-of-service attack on the client process by sending a big iteration count value. This issue has been patched in versions 0.4.24, 0.5.14, and 0.6.4.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-42256"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2117</id>
    <title>WID-SEC-W-2026-2117 — HCL BigFix Compliance (Ruby): Mehrere Schwachstellen</title>
    <updated>2026-10-03T08:25:03.722100+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in HCL BigFix Compliance ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand herbeizuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2117"/>
  </entry>
</feed>
