<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T20:13:29.156294+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-339044</id>
    <title>EUVD-2026-339044</title>
    <updated>2026-10-02T20:13:29.159115+00:00</updated>
    <content>EUVD-2026-339044</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-339044"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-50185</id>
    <title>fkie_cve-2026-50185</title>
    <updated>2026-10-02T20:13:29.159146+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>RustCrypto CMOV provides conditional move CPU intrinsics which are guaranteed on major platforms to execute in constant-time and not be rewritten as branches by the compiler. From 0.1.1 until 0.5.4, the aarch64 implementations of Cmov and CmovEq in cmov/src/backends/aarch64.rs assume high bits are zero-extended when loading values smaller than a register, so set high bits such as [8..] in a Cmov selector or [16..] of self or other in the u16 and i16 CmovEq implementations can cause left.cmovz(&amp;right, condition) to produce incorrect output. This issue is fixed in version 0.5.4.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-50185"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3rjw-m598-pq24</id>
    <title>GHSA-3rjw-m598-pq24 — Cmov/CmovEq on aarch64 can produce wrong results if high-bits of registers are set</title>
    <updated>2026-10-02T20:13:29.159180+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: cmov</p>
<p>### Summary</p>
<p>The aarch64 implementations of `Cmov` and `CmovEq` seem to assume that the high bits when loading a value of size smaller than a register into a register are zero-extended. However, this is not the case and these bits are unspecified. This can result in a `left.cmovz(&amp;right, condition)` not moving `right` into `left`, even if `condition == 0`.</p>
<p>### Details</p>
<p>The Rust reference for inline assembly states that:
&gt; If a value is of a smaller size than the register it is allocated in then the upper bits of that register will have an undefined value for inputs [..]. [Reference](https://doc.rust-lang.org/reference/inline-assembly.html#r-asm.register-operands.smaller-value)</p>
<p>If the high bits `[8..]` of the selector loaded into a register in the `Cmov` implementation or the high bits `[16..]` of `self` or `other` for CmovEq (specifically the implementation for `u16` and `i16`) are set, the inline asm compares will produce a different result than the Rust code expects based on the narrow types.</p>
<p>In other words, the following assert fails, even though `condition as u8` is zero:
```rust
let condition: u32 = black_box(1 &lt;&lt; 8);
let mut left = 1;
let right = 2;
left.cmovz(&amp;right, condition as u8);
assert_eq!(left, right);
```
Because the ninth bit is set in the original variable, this bit is also set when the truncated condition is loaded into the input register for the `cmp`, causing the `csel` to select the wrong value.</p>
<p>The problematic code is located in `cmov/src/backends/…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3rjw-m598-pq24"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:42923</id>
    <title>RHSA-2026:42923 — Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update</title>
    <updated>2026-10-02T20:13:29.159250+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>cargo: Cargo: Source code overwrite due to symlink mishandling in third-party registries cmov: cmov: Incorrect output due to improper zero-extension in aarch64 conditional move operations</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:42923"/>
  </entry>
</feed>
