<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T02:06:10.781303+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2025-70290</id>
    <title>CVE-2025-70290</title>
    <updated>2026-10-08T02:06:10.784195+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability in the ZFS filesystem support can be triggered by malformed on-disk metadata. The issue may result in incorrect memory allocation followed by out-of-bounds memory access, potentially leading to a crash or arbitrary code execution during the boot process.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2025-70290"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/usn-8884-1</id>
    <title>USN-8884-1 — u-boot vulnerabilities</title>
    <updated>2026-10-08T02:06:10.784243+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: u-boot, Ubuntu:Pro:18.04:LTS: u-boot, Ubuntu:Pro:20.04:LTS: u-boot, Ubuntu:22.04:LTS: u-boot, Ubuntu:24.04:LTS: u-boot, Ubuntu:26.04:LTS: u-boot</p>
<p>Timo Preißl discovered that U-Boot incorrectly handled certain malformed
ZFS file system metadata. An attacker could possibly use this issue to
trigger an integer overflow and out-of-bounds memory access, resulting in
arbitrary code execution or a denial of service. (CVE-2025-70290)</p>
<p>Timo Preißl discovered that U-Boot incorrectly calculated buffer sizes when
processing certain ext4 file systems. An attacker could possibly use this
issue to trigger an integer overflow and out-of-bounds memory access,
resulting in arbitrary code execution or a denial of service. This issue
only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu
24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2025-70293)</p>
<p>Mateusz Furdyna discovered that U-Boot incorrectly handled certain
fragmented IP traffic when IP defragmentation was enabled. An attacker
could possibly use this issue to corrupt memory by sending crafted IP
fragments, resulting in arbitrary code execution. (CVE-2026-15390)</p>
<p>Shahriyar Jalayeri and Mehrun P. Hunter discovered that U-Boot incorrectly
handled certain fragmented IP traffic during network boot when IP
defragmentation was enabled. An attacker could possibly use this issue to
trigger an out-of-bounds write, resulting in a denial of service.
(CVE-2026-71971)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/usn-8884-1"/>
  </entry>
</feed>
