<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T03:43:02.520206+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-27143</id>
    <title>CVE-2026-27143 — Missing bound checks can lead to memory corruption in safe Go in cmd/compile</title>
    <updated>2026-10-05T03:43:02.587784+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go toolchain cmd/compile</p>
<p>Arithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the compiler would allow for invalid indexing to occur at runtime, potentially leading to memory corruption.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-27143"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-hfvc-g4fc-pqhx</id>
    <title>GHSA-hfvc-g4fc-pqhx — opentelemetry-go: BSD kenv command not using absolute path enables PATH hijacking</title>
    <updated>2026-10-05T03:43:02.587846+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: go.opentelemetry.io/otel/sdk</p>
<p>## Summary</p>
<p>The fix for GHSA-9h8m-3fm2-qjrq (CVE-2026-24051) changed the Darwin `ioreg` command to use an absolute path but left the BSD `kenv` command using a bare name, allowing the same PATH hijacking attack on BSD and Solaris platforms.</p>
<p>## Root Cause</p>
<p>`sdk/resource/host_id.go` line 42:</p>
<p>if result, err := r.execCommand("kenv", "-q", "smbios.system.uuid"); err == nil {</p>
<p>Compare with the fixed Darwin path at line 58:</p>
<p>result, err := r.execCommand("/usr/sbin/ioreg", "-rd1", "-c", "IOPlatformExpertDevice")</p>
<p>The `execCommand` helper at `sdk/resource/host_id_exec.go` uses `exec.Command(name, arg...)` which searches `$PATH` when the command name contains no path separator.</p>
<p>Affected platforms (per build tag in `host_id_bsd.go:4`): DragonFly BSD, FreeBSD, NetBSD, OpenBSD, Solaris.</p>
<p>The `kenv` path is reached when `/etc/hostid` does not exist (line 38-40), which is common on FreeBSD systems.</p>
<p>## Attack</p>
<p>1. Attacker has local access to a system running a Go application that imports `go.opentelemetry.io/otel/sdk`
2. Attacker places a malicious `kenv` binary earlier in `$PATH`
3. Application initializes OpenTelemetry resource detection at startup
4. `hostIDReaderBSD.read()` calls `exec.Command("kenv", ...)` which resolves to the malicious binary
5. Arbitrary code executes in the context of the application</p>
<p>Same attack vector and impact as CVE-2026-24051.</p>
<p>## Suggested Fix</p>
<p>Use the absolute path:</p>
<p>if result, err := r.execCommand("/bin/kenv", "-q", "smbios.system.uuid"); e…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-hfvc-g4fc-pqhx"/>
  </entry>
</feed>
