<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T09:32:08.605529+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:30851</id>
    <title>ALSA-2026:30851 — Important: perl:5.32 security update</title>
    <updated>2026-10-03T09:32:09.140829+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: perl, AlmaLinux:8: perl-Algorithm-Diff, AlmaLinux:8: perl-Archive-Tar, AlmaLinux:8: perl-Archive-Zip, AlmaLinux:8: perl-Attribute-Handlers, AlmaLinux:8: perl-AutoLoader, AlmaLinux:8: perl-AutoSplit, AlmaLinux:8: perl-B, AlmaLinux:8: perl-Benchmark, AlmaLinux:8: perl-CPAN and 212 more</p>
<p>Perl is a high-level programming language that is commonly used for system administration utilities and web programming.</p>
<p>Security Fix(es):</p>
<p>* perl-archive-tar: perl-archive-tar: Path traversal via crafted symlinks allows arbitrary file access (CVE-2026-42496)
  * perl-IO-Compress: perl-IO-Compress: Arbitrary code execution via attacker-controlled output glob (CVE-2026-48962)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:30851"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-48962</id>
    <title>BELL-CVE-2026-48962</title>
    <updated>2026-10-03T09:32:09.141125+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: perl, Alpaquita:25: perl, Alpaquita:stream: perl, BellSoft Hardened Containers:23: perl, BellSoft Hardened Containers:25: perl, BellSoft Hardened Containers:stream: perl</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-48962"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0731</id>
    <title>certfr-2026-avi-0731 — De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Certaines d'entre elles permettent à un at…</title>
    <updated>2026-10-03T09:32:09.141159+00:00</updated>
    <content>certfr-2026-avi-0731</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0731"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-347579</id>
    <title>EUVD-2026-347579</title>
    <updated>2026-10-03T09:32:09.141177+00:00</updated>
    <content>EUVD-2026-347579</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-347579"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-48962</id>
    <title>fkie_cve-2026-48962</title>
    <updated>2026-10-03T09:32:09.141189+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob.</p>
<p>_parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl.</p>
<p>Arbitrary Perl in the output glob executes at the calling process's privilege.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-48962"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-q6wx-vhvq-x7h6</id>
    <title>GHSA-q6wx-vhvq-x7h6</title>
    <updated>2026-10-03T09:32:09.141217+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob.</p>
<p>_parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl.</p>
<p>Arbitrary Perl in the output glob executes at the calling process's privilege.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-q6wx-vhvq-x7h6"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-48962</id>
    <title>msrc_CVE-2026-48962 — IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled o…</title>
    <updated>2026-10-03T09:32:09.141235+00:00</updated>
    <content>msrc_CVE-2026-48962</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-48962"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ncsc-2026-0321</id>
    <title>NCSC-2026-0321 — Meerdere kwetsbaarheden verholpen in IBM AIX en IBM PowerVM VIOS</title>
    <updated>2026-10-03T09:32:09.141253+00:00</updated>
    <content>NCSC-2026-0321</content>
    <link href="https://cve.radiocsirt.org/vuln/ncsc-2026-0321"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-2610</id>
    <title>OESA-2026-2610 — perl-IO-Compress security update</title>
    <updated>2026-10-03T09:32:09.141445+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP3: perl-IO-Compress</p>
<p>This distribution provides a Perl interface to allow reading and writing of compressed data created with the zlib and bzip2 libraries.

Security Fix(es):</p>
<p>IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob.</p>
<p>_parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl.</p>
<p>Arbitrary Perl in the output glob executes at the calling process&amp;apos;s privilege.(CVE-2026-48962)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-2610"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10939-1</id>
    <title>openSUSE-SU-2026:10939-1 — perl-IO-Compress-2.220.0-1.1 on GA media</title>
    <updated>2026-10-03T09:32:09.141480+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>perl-IO-Compress-2.220.0-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10939-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:29182</id>
    <title>RHSA-2026:29182 — Red Hat Security Advisory: perl-IO-Compress security update</title>
    <updated>2026-10-03T09:32:09.141508+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>perl-IO-Compress: perl-IO-Compress: Arbitrary code execution via attacker-controlled output glob</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:29182"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:30851</id>
    <title>RLSA-2026:30851 — Important: perl:5.32 security update</title>
    <updated>2026-10-03T09:32:09.141526+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:8: perl, Rocky Linux:8: perl-Algorithm-Diff, Rocky Linux:8: perl-Archive-Zip, Rocky Linux:8: perl-autodie, Rocky Linux:8: perl-bignum, Rocky Linux:8: perl-Carp, Rocky Linux:8: perl-Compress-Bzip2, Rocky Linux:8: perl-Compress-Raw-Bzip2, Rocky Linux:8: perl-Compress-Raw-Lzma, Rocky Linux:8: perl-Compress-Raw-Zlib and 101 more</p>
<p>Perl is a high-level programming language that is commonly used for system administration utilities and web programming.</p>
<p>Security Fix(es):</p>
<p>* perl-archive-tar: perl-archive-tar: Path traversal via crafted symlinks allows arbitrary file access (CVE-2026-42496)</p>
<p>* perl-IO-Compress: perl-IO-Compress: Arbitrary code execution via attacker-controlled output glob (CVE-2026-48962)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:30851"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-48962</id>
    <title>UBUNTU-CVE-2026-48962</title>
    <updated>2026-10-03T09:32:09.141780+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: perl, Ubuntu:Pro:16.04:LTS: perl, Ubuntu:16.04:LTS: libio-compress-perl, Ubuntu:Pro:18.04:LTS: perl, Ubuntu:18.04:LTS: libio-compress-perl, Ubuntu:Pro:20.04:LTS: perl, Ubuntu:20.04:LTS: libio-compress-perl, Ubuntu:22.04:LTS: libio-compress-perl, Ubuntu:22.04:LTS: perl, Ubuntu:24.04:LTS: libio-compress-perl and 5 more</p>
<p>IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob. _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl. Arbitrary Perl in the output glob executes at the calling process's privilege.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-48962"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2063</id>
    <title>WID-SEC-W-2026-2063 — Red Hat Enterprise Linux (perl-IO-Compress): Schwachstelle ermöglicht Ausführen von beliebigem Programmcode mit den Rec…</title>
    <updated>2026-10-03T09:32:09.141823+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um beliebigen Programmcode mit den Rechten des Dienstes auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2063"/>
  </entry>
</feed>
