<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T00:06:47.810036+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-bh05638</id>
    <title>CLEANSTART-2026-BH05638 — Security fix for CVE-2026-54332 applied in: calico 3.32.1-r2</title>
    <updated>2026-10-04T00:06:47.814314+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: calico</p>
<p>Security vulnerability affects the calico package. This issue is resolved in later releases. See references for vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-bh05638"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-342158</id>
    <title>EUVD-2026-342158</title>
    <updated>2026-10-04T00:06:47.814360+00:00</updated>
    <content>EUVD-2026-342158</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-342158"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-54332</id>
    <title>fkie_cve-2026-54332</title>
    <updated>2026-10-04T00:06:47.814376+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>gopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the sFlow ExtendedGatewayFlow decoder in layers/sflow.go reads an attacker-controlled 32-bit community count and AS path member count and sizes a slice allocation from those counts without bounding them against the bytes remaining in the datagram, so a 104-byte UDP datagram can drive an allocation of up to 16 GiB and cause an unauthenticated remote denial of service. This issue is fixed in version 1.6.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-54332"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-g6v3-7xmc-w563</id>
    <title>GHSA-g6v3-7xmc-w563 — GoPacket's sFlow ExtendedGatewayFlow decoder: unbounded attacker-controlled allocation (104-byte UDP datagram -&gt; up to…</title>
    <updated>2026-10-04T00:06:47.814400+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/gopacket/gopacket</p>
<p>## Summary</p>
<p>The sFlow `ExtendedGatewayFlow` record decoder in `github.com/gopacket/gopacket` allocates a slice with `make([]uint32, n)` where `n` is an attacker-controlled 32-bit wire field that has no upper bound. Because the allocation happens *before* the read loop that would consume the corresponding bytes, a single small UDP datagram can force a multi-gigabyte allocation. A 104-byte sFlow datagram can request up to 16 GiB and OOM-kill any service that parses sFlow with gopacket. This is an unauthenticated remote denial of service (CWE-770).</p>
<p>## Root cause (file:line @ v1.6.0)</p>
<p>Two sinks in `layers/sflow.go`, both in the `ExtendedGatewayFlow` (record type 1003) decode path:</p>
<p>1. `layers/sflow.go:1306` in `decodeExtendedGatewayFlowRecord`:
```go
*data, communitiesLength = (*data)[4:], binary.BigEndian.Uint32((*data)[:4])
eg.Communities = make([]uint32, communitiesLength)   // communitiesLength is a raw wire uint32, no bound
for j := uint32(0); j &lt; communitiesLength; j++ { ... }
```</p>
<p>2. `layers/sflow.go:1276` in `decodePath` (a helper called from the same record decoder):
```go
*data, ad.Count = (*data)[4:], binary.BigEndian.Uint32((*data)[:4])
ad.Members = make([]uint32, ad.Count)                // ad.Count is a raw wire uint32, no bound
for i := uint32(0); i &lt; ad.Count; i++ { ... }
```</p>
<p>In both cases the `make` is executed before the loop that reads the element bytes, so the allocation size is fully determined by the attacker-supplied count field and is never checked agai…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-g6v3-7xmc-w563"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-54332</id>
    <title>msrc_CVE-2026-54332 — GoPacket's sFlow ExtendedGatewayFlow decoder: unbounded attacker-controlled allocation (104-byte UDP datagram -&gt; up to…</title>
    <updated>2026-10-04T00:06:47.814482+00:00</updated>
    <content>msrc_CVE-2026-54332</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-54332"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-54332</id>
    <title>UBUNTU-CVE-2026-54332</title>
    <updated>2026-10-04T00:06:47.814499+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: gopacket, Ubuntu:18.04:LTS: gopacket, Ubuntu:20.04:LTS: gopacket, Ubuntu:22.04:LTS: gopacket, Ubuntu:24.04:LTS: golang-github-gopacket-gopacket, Ubuntu:24.04:LTS: gopacket, Ubuntu:26.04:LTS: golang-github-gopacket-gopacket, Ubuntu:26.04:LTS: gopacket</p>
<p>gopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the sFlow ExtendedGatewayFlow decoder in layers/sflow.go reads an attacker-controlled 32-bit community count and AS path member count and sizes a slice allocation from those counts without bounding them against the bytes remaining in the datagram, so a 104-byte UDP datagram can drive an allocation of up to 16 GiB and cause an unauthenticated remote denial of service. This issue is fixed in version 1.6.1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-54332"/>
  </entry>
</feed>
