<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T21:34:13.736790+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-326590</id>
    <title>EUVD-2026-326590</title>
    <updated>2026-10-05T21:34:13.740074+00:00</updated>
    <content>EUVD-2026-326590</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-326590"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-47213</id>
    <title>fkie_cve-2026-47213</title>
    <updated>2026-10-05T21:34:13.740113+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted code. In versions 0.8.2 and prior, Boxlite allows users to configure a timeout for services running inside the virtual machine. When the timeout is triggered, Boxlite sends a signal to kill the process. However, instead of using the uncatchable SIGKILL signal, Boxlite uses the catchable SIGALRM signal. Malicious code running inside the sandbox can exploit this vulnerability to continue running after the timeout is triggered, leading to resource exhaustion within the virtual machine and affecting the availability of the Boxlite service. This issue has been patched via commit 28159fc.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-47213"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xjhv-pp2r-6f82</id>
    <title>GHSA-xjhv-pp2r-6f82 — BoxLite has a Timeout Bypass Vulnerability</title>
    <updated>2026-10-05T21:34:13.740148+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: boxlite</p>
<p>#### Summary</p>
<p>BoxLite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and run OCI containers within them. BoxLite allows users to configure a timeout for services running inside the virtual machine. When the timeout is triggered, BoxLite sends a signal to kill the process. However, instead of using the uncatchable SIGKILL signal, BoxLite uses the catchable SIGALRM signal. Malicious code running inside the sandbox can exploit this vulnerability to continue running after the timeout is triggered, leading to resource exhaustion within the virtual machine and affecting the availability of the BoxLite service.</p>
<p>#### Details</p>
<p>1. ExecRequest with timeout_ms arrives at Execution service</p>
<p>**File:** `guest/src/service/exec/mod.rs` **Function:** `spawn_execution()` (line 315) **Code:**</p>
<p>```rust
// Step 3: Start timeout watcher (if requested)
if req.timeout_ms &gt; 0 {
    timeout::start_timeout_watcher(
        state,
        execution_id.clone(),
        std::time::Duration::from_millis(req.timeout_ms),
    );
}
```</p>
<p>**Issue:** Any nonzero `timeout_ms` triggers the timeout watcher. The host expects this to kill the process after the specified duration.</p>
<p>2. Timeout watcher sends SIGALRM instead of SIGKILL</p>
<p>**File:** `guest/src/service/exec/timeout.rs` **Function:** `start_timeout_watcher()` (line 13) **Code:**</p>
<p>```rust
pub(super) fn start_timeout_watcher(
    exec_state: ExecutionState,
    exec_id: String,
    timeout: Duration,
) {
    tokio::spawn(…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xjhv-pp2r-6f82"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-2400</id>
    <title>PYSEC-2026-2400 — BoxLite has a Timeout Bypass Vulnerability</title>
    <updated>2026-10-05T21:34:13.740253+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: boxlite</p>
<p>#### Summary</p>
<p>BoxLite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and run OCI containers within them. BoxLite allows users to configure a timeout for services running inside the virtual machine. When the timeout is triggered, BoxLite sends a signal to kill the process. However, instead of using the uncatchable SIGKILL signal, BoxLite uses the catchable SIGALRM signal. Malicious code running inside the sandbox can exploit this vulnerability to continue running after the timeout is triggered, leading to resource exhaustion within the virtual machine and affecting the availability of the BoxLite service.</p>
<p>#### Details</p>
<p>1. ExecRequest with timeout_ms arrives at Execution service</p>
<p>**File:** `guest/src/service/exec/mod.rs` **Function:** `spawn_execution()` (line 315) **Code:**</p>
<p>```rust
// Step 3: Start timeout watcher (if requested)
if req.timeout_ms &gt; 0 {
    timeout::start_timeout_watcher(
        state,
        execution_id.clone(),
        std::time::Duration::from_millis(req.timeout_ms),
    );
}
```</p>
<p>**Issue:** Any nonzero `timeout_ms` triggers the timeout watcher. The host expects this to kill the process after the specified duration.</p>
<p>2. Timeout watcher sends SIGALRM instead of SIGKILL</p>
<p>**File:** `guest/src/service/exec/timeout.rs` **Function:** `start_timeout_watcher()` (line 13) **Code:**</p>
<p>```rust
pub(super) fn start_timeout_watcher(
    exec_state: ExecutionState,
    exec_id: String,
    timeout: Duration,
) {
    tokio::spawn(…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-2400"/>
  </entry>
</feed>
