<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T14:13:02.857524+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:25237</id>
    <title>ALSA-2026:25237 — Important: openssl security update</title>
    <updated>2026-10-02T14:13:02.906341+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:10: openssl, AlmaLinux:10: openssl-devel, AlmaLinux:10: openssl-libs, AlmaLinux:10: openssl-perl</p>
<p>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, as well as a full-strength general-purpose cryptography library.</p>
<p>Security Fix(es):</p>
<p>* openssl: OpenSSL: Heap buffer overflow due to signed integer overflow in Unicode output sizing (CVE-2026-7383)
  * openssl: OpenSSL: Denial of Service due to heap out-of-bounds read in CMS password-based decryption (CVE-2026-9076)
  * openssl: OpenSSL: Heap buffer over-read in ASN.1 decoding can lead to denial of service or information disclosure. (CVE-2026-34180)
  * openssl: PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC Keys (CVE-2026-34181)
  * openssl: CMS AuthEnvelopedData Processing May Accept Forged Messages (CVE-2026-34182)
  * openssl: Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler (CVE-2026-34183)
  * openssl: NULL pointer dereference in QUIC server initial packet handling (CVE-2026-42764)
  * openssl: Possible NULL Dereference in Password-Based CMS Decryption (CVE-2026-42766)
  * openssl: NULL Pointer Dereference in CRMF EncryptedValue Decryption (CVE-2026-42767)
  * openssl: Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt() (CVE-2026-42768)
  * openssl: Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate (CVE-2026-42769)
  * openssl: FFC-DH Peer Validation Uses Attacker-Supplied q (CVE-2026-42770)
  * openssl: AES-OCB IV Ignored on EVP_Cipher() Path (CVE-2026-45445)
  * openssl: Incorrect Tag…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:25237"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-42764</id>
    <title>BELL-CVE-2026-42764</title>
    <updated>2026-10-02T14:13:02.906428+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:25: openssl, Alpaquita:stream: openssl, BellSoft Hardened Containers:25: openssl, BellSoft Hardened Containers:stream: openssl</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-42764"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0717</id>
    <title>certfr-2026-avi-0717 — De multiples vulnérabilités ont été découvertes dans OpenSSL. Certaines d'entre elles permettent à un attaquant de prov…</title>
    <updated>2026-10-02T14:13:02.906456+00:00</updated>
    <content>certfr-2026-avi-0717</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0717"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-326330</id>
    <title>EUVD-2026-326330</title>
    <updated>2026-10-02T14:13:02.906473+00:00</updated>
    <content>EUVD-2026-326330</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-326330"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-42764</id>
    <title>fkie_cve-2026-42764</title>
    <updated>2026-10-02T14:13:02.906485+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Issue summary: Receiving a QUIC initial packet with an invalid token may
trigger a NULL pointer dereference in the OpenSSL QUIC server with
address validation disabled.</p>
<p>Impact summary: NULL pointer dereference typically causes abnormal termination
of the affected QUIC server process and a Denial of Service.</p>
<p>If the address validation is disabled in the OpenSSL QUIC server
implementation, an attacker can crash the server by sending an initial
packet with an invalid or expired token.</p>
<p>By default, the client address validation is enabled in the OpenSSL QUIC server
implementation, which makes the default configuration not vulnerable
to this issue. However if the SSL_LISTENER_FLAG_NO_VALIDATE is used with
the SSL_new_listener() call, the address validation is disabled making the
vulnerable code reachable.</p>
<p>The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this
issue, as the affected code is outside the OpenSSL FIPS module boundary.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-42764"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-5pg7-f6xv-j6m4</id>
    <title>GHSA-5pg7-f6xv-j6m4</title>
    <updated>2026-10-02T14:13:02.906515+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Issue summary: Receiving a QUIC initial packet with an invalid token may
trigger a NULL pointer dereference in the OpenSSL QUIC server with
address validation disabled.</p>
<p>Impact summary: NULL pointer dereference typically causes abnormal termination
of the affected QUIC server process and a Denial of Service.</p>
<p>If the address validation is disabled in the OpenSSL QUIC server
implementation, an attacker can crash the server by sending an initial
packet with an invalid or expired token.</p>
<p>By default, the client address validation is enabled in the OpenSSL QUIC server
implementation, which makes the default configuration not vulnerable
to this issue. However if the SSL_LISTENER_FLAG_NO_VALIDATE is used with
the SSL_new_listener() call, the address validation is disabled making the
vulnerable code reachable.</p>
<p>The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this
issue, as the affected code is outside the OpenSSL FIPS module boundary.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-5pg7-f6xv-j6m4"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-42764</id>
    <title>msrc_CVE-2026-42764 — NULL Pointer Dereference in QUIC Server Initial Packet Handling</title>
    <updated>2026-10-02T14:13:02.906536+00:00</updated>
    <content>msrc_CVE-2026-42764</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-42764"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ncsc-2026-0307</id>
    <title>NCSC-2026-0307 — Kwetsbaarheden verholpen in Oracle Database Producten</title>
    <updated>2026-10-02T14:13:02.906551+00:00</updated>
    <content>NCSC-2026-0307</content>
    <link href="https://cve.radiocsirt.org/vuln/ncsc-2026-0307"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11023-1</id>
    <title>openSUSE-SU-2026:11023-1 — libopenssl-3-devel-3.5.3-6.1 on GA media</title>
    <updated>2026-10-02T14:13:02.906583+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libopenssl-3-devel-3.5.3-6.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11023-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:26319</id>
    <title>RHSA-2026:26319 — Red Hat Security Advisory: Red Hat Update Infrastructure 5.2 security update</title>
    <updated>2026-10-02T14:13:02.906608+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>gnutls: gnutls: Security bypass allows acceptance of revoked server certificates via crafted OCSP response gnutls: GnuTLS: Policy bypass due to case-sensitive nameConstraints comparison glibc: glibc: Denial of Service via iconv() function with specific character sets glibc: glibc: Incorrect DNS response parsing via crafted DNS server response glibc: glibc: Invalid DNS hostname returned via gethostbyaddr functions gnutls: gnutls: Information disclosure via heap overread in RSA key exchange gnutls: gnutls: Information disclosure via timing side-channel in PKCS#7 padding removal openssl: OpenSSL: Heap buffer overflow due to signed integer overflow in Unicode output sizing openssl: OpenSSL: Denial of Service due to heap out-of-bounds read in CMS password-based decryption openssl: OpenSSL: Denial of Service due to NULL pointer dereference in CMS EnvelopedData processing gnutls: GnuTLS: Denial of Service via DTLS zero-length fragment gnutls: GnuTLS: Denial of Service via heap buffer overflow in DTLS handshake fragment reassembly openssl: OpenSSL: Heap buffer over-read in ASN.1 decoding can lead to denial of service or information disclosure. openssl: PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC Keys openssl: CMS AuthEnvelopedData Processing May Accept Forged Messages openssl: Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler vim: Vim zip.vim plugin: Arbitrary file overwrite via path traversal bypass gnutls: gnutls: Denial of Service via DTLS packet reordering vu…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:26319"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:25237</id>
    <title>RLSA-2026:25237 — Important: openssl security update</title>
    <updated>2026-10-02T14:13:02.906680+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:10: openssl</p>
<p>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, as well as a full-strength general-purpose cryptography library.</p>
<p>Security Fix(es):</p>
<p>* openssl: OpenSSL: Heap buffer overflow due to signed integer overflow in Unicode output sizing (CVE-2026-7383)</p>
<p>* openssl: OpenSSL: Denial of Service due to heap out-of-bounds read in CMS password-based decryption (CVE-2026-9076)</p>
<p>* openssl: OpenSSL: Heap buffer over-read in ASN.1 decoding can lead to denial of service or information disclosure. (CVE-2026-34180)</p>
<p>* openssl: PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC Keys (CVE-2026-34181)</p>
<p>* openssl: CMS AuthEnvelopedData Processing May Accept Forged Messages (CVE-2026-34182)</p>
<p>* openssl: Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler (CVE-2026-34183)</p>
<p>* openssl: NULL pointer dereference in QUIC server initial packet handling (CVE-2026-42764)</p>
<p>* openssl: Possible NULL Dereference in Password-Based CMS Decryption (CVE-2026-42766)</p>
<p>* openssl: NULL Pointer Dereference in CRMF EncryptedValue Decryption (CVE-2026-42767)</p>
<p>* openssl: Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt() (CVE-2026-42768)</p>
<p>* openssl: Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate (CVE-2026-42769)</p>
<p>* openssl: FFC-DH Peer Validation Uses Attacker-Supplied q (CVE-2026-42770)</p>
<p>* openssl: AES-OCB IV Ignored on EVP_Cipher() Path (CVE-2026-45445)</p>
<p>* openssl: Incorrect Tag Processing for Empt…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:25237"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:22251-1</id>
    <title>SUSE-SU-2026:22251-1 — Security update for openssl-3</title>
    <updated>2026-10-02T14:13:02.906721+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for openssl-3</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:22251-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-42764</id>
    <title>UBUNTU-CVE-2026-42764</title>
    <updated>2026-10-02T14:13:02.906741+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:22.04:LTS: nodejs, Ubuntu:25.10: openssl, Ubuntu:26.04:LTS: edk2, Ubuntu:26.04:LTS: edk2-hwe, Ubuntu:26.04:LTS: openssl</p>
<p>Issue summary: Receiving a QUIC initial packet with an invalid token may trigger a NULL pointer dereference in the OpenSSL QUIC server with address validation disabled. Impact summary: NULL pointer dereference typically causes abnormal termination of the affected QUIC server process and a Denial of Service. If the address validation is disabled in the OpenSSL QUIC server implementation, an attacker can crash the server by sending an initial packet with an invalid or expired token. By default, the client address validation is enabled in the OpenSSL QUIC server implementation, which makes the default configuration not vulnerable to this issue. However if the SSL_LISTENER_FLAG_NO_VALIDATE is used with the SSL_new_listener() call, the address validation is disabled making the vulnerable code reachable. The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-42764"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1852</id>
    <title>WID-SEC-W-2026-1852 — OpenSSL: Mehrere Schwachstellen</title>
    <updated>2026-10-02T14:13:02.906768+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in OpenSSL ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, Daten zu manipulieren oder einen Denial-of-Service-Zustand zu verursachen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1852"/>
  </entry>
</feed>
