<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T10:11:39.292766+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-hp09399</id>
    <title>Withdrawn: CLEANSTART-2026-HP09399 — ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label</title>
    <updated>2026-10-04T10:11:39.369573+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: calico</p>
<p>Multiple security vulnerabilities affect the calico package. The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-hp09399"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-342154</id>
    <title>EUVD-2026-342154</title>
    <updated>2026-10-04T10:11:39.369633+00:00</updated>
    <content>EUVD-2026-342154</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-342154"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-54345</id>
    <title>fkie_cve-2026-54345</title>
    <updated>2026-10-04T10:11:39.369649+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>gopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the Diameter AVP decoder computes an AVP data length by subtracting a fixed header size from an attacker-controlled AVP Length field, so a vendor-flagged AVP whose Length is smaller than the 12-byte header underflows the unsigned 32-bit value and drives an unbounded allocation of roughly 4 GiB, and two such messages in succession OOM-kill a collector, causing an unauthenticated remote denial of service. This issue is fixed in version 1.6.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-54345"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-6r28-9ppf-4hj5</id>
    <title>GHSA-6r28-9ppf-4hj5 — GoPacket's Diameter AVP decoder: uint32 underflow on vendor header size leads to unbounded ~4 GiB allocation (unauthent…</title>
    <updated>2026-10-04T10:11:39.369698+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/gopacket/gopacket</p>
<p>## Summary</p>
<p>The Diameter AVP decoder in `github.com/gopacket/gopacket` computes `dataLength := avp.Length - uint32(headerSize)` without first ensuring `avp.Length &gt;= headerSize`. When the Vendor flag is set, `headerSize` is 12, but the only length guard upstream rejects `avp.Length &lt; 8`. An AVP with the Vendor flag set and a 24-bit Length field of 8, 9, 10, or 11 therefore underflows the `uint32` subtraction to ~4,294,967,292, which is passed straight to `make([]byte, dataLength)`. A single 32-byte Diameter message forces a ~4 GiB allocation; a short burst of such messages exhausts memory and OOM-kills memory-constrained collectors. This is an unauthenticated remote denial of service (CWE-191 integer underflow -&gt; CWE-770 unbounded allocation).</p>
<p>## Root cause (file:line @ v1.6.0)</p>
<p>`layers/diameter_avp_decoders.go`, `decodeDiameterAVP`:</p>
<p>```go
avp.Length = uint32(data[5])&lt;&lt;16 | uint32(data[6])&lt;&lt;8 | uint32(data[7]) // 24-bit wire value</p>
<p>if avp.Length &lt; 8 {                       // only rejects &lt; 8
    return DiameterAVP{}, 0, fmt.Errorf("invalid AVP length: %d", avp.Length)
}</p>
<p>headerSize := 8
dataOffset := 8
if avp.Flags.Vendor {                     // Vendor flag = wire bit data[4] &amp; 0x80
    if len(data) &lt; 12 { ... }
    avp.VendorID = binary.BigEndian.Uint32(data[8:12])
    headerSize = 12                       // header is now 12, but only &gt;= 8 was checked
    dataOffset = 12
}</p>
<p>paddedLength := avp.Length                // equals avp.Length; for avp.Length &lt;= 12
if avp.Leng…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-6r28-9ppf-4hj5"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-54345</id>
    <title>UBUNTU-CVE-2026-54345</title>
    <updated>2026-10-04T10:11:39.369811+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: gopacket, Ubuntu:18.04:LTS: gopacket, Ubuntu:20.04:LTS: gopacket, Ubuntu:22.04:LTS: gopacket, Ubuntu:24.04:LTS: golang-github-gopacket-gopacket, Ubuntu:24.04:LTS: gopacket, Ubuntu:26.04:LTS: golang-github-gopacket-gopacket, Ubuntu:26.04:LTS: gopacket</p>
<p>gopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the Diameter AVP decoder computes an AVP data length by subtracting a fixed header size from an attacker-controlled AVP Length field, so a vendor-flagged AVP whose Length is smaller than the 12-byte header underflows the unsigned 32-bit value and drives an unbounded allocation of roughly 4 GiB, and two such messages in succession OOM-kill a collector, causing an unauthenticated remote denial of service. This issue is fixed in version 1.6.1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-54345"/>
  </entry>
</feed>
