<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T11:01:00.693424+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:1334</id>
    <title>ALSA-2026:1334 — Moderate: glibc security update</title>
    <updated>2026-10-02T11:01:01.071892+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:10: glibc-doc</p>
<p>The glibc packages provide the standard C libraries (libc), POSIX thread libraries (libpthread), standard math libraries (libm), and the name service cache daemon (nscd) used by multiple programs on the system. Without these libraries, the Linux system cannot function correctly.</p>
<p>Security Fix(es):</p>
<p>* glibc: Integer overflow in memalign leads to heap corruption (CVE-2026-0861)
  * glibc: glibc: Information disclosure via zero-valued network query (CVE-2026-0915)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:1334"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-00915</id>
    <title>bdu:2026-00915</title>
    <updated>2026-10-02T11:01:01.071965+00:00</updated>
    <content>bdu:2026-00915</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-00915"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-0861</id>
    <title>BELL-CVE-2026-0861</title>
    <updated>2026-10-02T11:01:01.071984+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: glibc, Alpaquita:25: glibc, Alpaquita:stream: glibc, BellSoft Hardened Containers:23: glibc, BellSoft Hardened Containers:25: glibc, BellSoft Hardened Containers:stream: glibc</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-0861"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-glibc-cve-2026-0861</id>
    <title>BREW-glibc-CVE-2026-0861 — Integer overflow in memalign leads to heap corruption</title>
    <updated>2026-10-02T11:01:01.072011+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: glibc</p>
<p>Passing too large an alignment to the memalign suite of functions (memalign, posix_memalign, aligned_alloc) in the GNU C Library version 2.30 to 2.42 may result in an integer overflow, which could consequently result in a heap corruption.</p>
<p>Note that the attacker must have control over both, the size as well as the alignment arguments of the memalign function to be able to exploit this.  The size parameter must be close enough to PTRDIFF_MAX so as to overflow size_t along with the large alignment argument.  This limits the malicious inputs for the alignment for memalign to the range [1&lt;&lt;62+ 1, 1&lt;&lt;63] and exactly 1&lt;&lt;63 for posix_memalign and aligned_alloc.</p>
<p>Typically the alignment argument passed to such functions is a known constrained quantity (e.g. page size, block size, struct sizes) and is not attacker controlled, because of which this may not be easily exploitable in practice.  An application bug could potentially result in the input alignment being too large, e.g. due to a different buffer overflow or integer overflow in the application or its dependent libraries, but that is again an uncommon usage pattern given typical sources of alignments.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-glibc-cve-2026-0861"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0199</id>
    <title>certfr-2026-avi-0199 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Certaines d'entre elles permettent à un attaq…</title>
    <updated>2026-10-02T11:01:01.072041+00:00</updated>
    <content>certfr-2026-avi-0199</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0199"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-307834</id>
    <title>EUVD-2026-307834</title>
    <updated>2026-10-02T11:01:01.072058+00:00</updated>
    <content>EUVD-2026-307834</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-307834"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-0861</id>
    <title>fkie_cve-2026-0861</title>
    <updated>2026-10-02T11:01:01.072069+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Passing too large an alignment to the memalign suite of functions (memalign, posix_memalign, aligned_alloc) in the GNU C Library version 2.30 to 2.42 may result in an integer overflow, which could consequently result in a heap corruption.</p>
<p>Note that the attacker must have control over both, the size as well as the alignment arguments of the memalign function to be able to exploit this.  The size parameter must be close enough to PTRDIFF_MAX so as to overflow size_t along with the large alignment argument.  This limits the malicious inputs for the alignment for memalign to the range [1&lt;&lt;62+ 1, 1&lt;&lt;63] and exactly 1&lt;&lt;63 for posix_memalign and aligned_alloc.</p>
<p>Typically the alignment argument passed to such functions is a known constrained quantity (e.g. page size, block size, struct sizes) and is not attacker controlled, because of which this may not be easily exploitable in practice.  An application bug could potentially result in the input alignment being too large, e.g. due to a different buffer overflow or integer overflow in the application or its dependent libraries, but that is again an uncommon usage pattern given typical sources of alignments.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-0861"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-5pf6-63v3-88hw</id>
    <title>GHSA-5pf6-63v3-88hw</title>
    <updated>2026-10-02T11:01:01.072097+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Passing too large an alignment to the memalign suite of functions (memalign, posix_memalign, aligned_alloc, valloc, pvalloc) in the GNU C Library version 2.30 to 2.42 may result in an integer overflow, which could consequently result in a heap corruption.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-5pf6-63v3-88hw"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-0861</id>
    <title>msrc_CVE-2026-0861 — Integer overflow in memalign leads to heap corruption</title>
    <updated>2026-10-02T11:01:01.072112+00:00</updated>
    <content>msrc_CVE-2026-0861</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-0861"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-1198</id>
    <title>OESA-2026-1198 — glibc security update</title>
    <updated>2026-10-02T11:01:01.072127+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS: glibc</p>
<p>The GNU C Library project provides the core libraries for the GNU system and GNU/Linux systems, as well as many other systems that use Linux as the kernel. These libraries provide critical APIs including ISO C11, POSIX.1-2008, BSD, OS-specific APIs and more. These APIs include such foundational facilities as open, read, write, malloc, printf, getaddrinfo, dlopen, pthread_create, crypt,  login, exit and more.

Security Fix(es):</p>
<p>Passing too large an alignment to the memalign suite of functions (memalign, posix_memalign, aligned_alloc) in the GNU C Library version 2.30 to 2.42 may result in an integer overflow, which could consequently result in a heap corruption.</p>
<p>Note that the attacker must have control over both, the size as well as the alignment arguments of the memalign function to be able to exploit this.  The size parameter must be close enough to PTRDIFF_MAX so as to overflow size_t along with the large alignment argument.  This limits the malicious inputs for the alignment for memalign to the range [1&amp;lt;&amp;lt;62+ 1, 1&amp;lt;&amp;lt;63] and exactly 1&amp;lt;&amp;lt;63 for posix_memalign and aligned_alloc.</p>
<p>Typically the alignment argument passed to such functions is a known constrained quantity (e.g. page size, block size, struct sizes) and is not attacker controlled, because of which this may not be easily exploitable in practice.  An application bug could potentially result in the input alignment being too large, e.g. due to a different buffer overflow or integer overflow in the a…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-1198"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10662-1</id>
    <title>openSUSE-SU-2026:10662-1 — glibc-2.43-1.1 on GA media</title>
    <updated>2026-10-02T11:01:01.072163+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>glibc-2.43-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10662-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:3228</id>
    <title>RHSA-2026:3228 — Red Hat Security Advisory: Cost Management Metrics Operator Update</title>
    <updated>2026-10-02T11:01:01.072182+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>openssl: OpenSSL: Arbitrary code execution or denial of service through crafted PKCS#12 file glibc: wordexp with WRDE_REUSE and WRDE_APPEND may return uninitialized memory openssl: OpenSSL: Remote code execution or Denial of Service via oversized Initialization Vector in CMS parsing openssl: OpenSSL: Denial of Service via NULL pointer dereference in QUIC protocol handling openssl: OpenSSL: Data integrity bypass in `openssl dgst` command due to silent truncation openssl: OpenSSL: Denial of Service due to excessive memory allocation in TLS 1.3 certificate compression openssl: OpenSSL: Denial of Service due to out-of-bounds write in BIO filter openssl: OpenSSL: Information disclosure and data tampering via specific low-level OCB encryption/decryption calls openssl: OpenSSL: Arbitrary code execution due to out-of-bounds write in PKCS#12 processing openssl: OpenSSL: Denial of Service via malformed TimeStamp Response openssl: OpenSSL: Denial of Service via malformed PKCS#12 file processing glibc: Integer overflow in memalign leads to heap corruption glibc: glibc: Information disclosure via zero-valued network query openssl: OpenSSL: Denial of Service due to type confusion in PKCS#12 file processing openssl: OpenSSL: Denial of Service via type confusion in PKCS#7 signature verification</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:3228"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:0347-1</id>
    <title>SUSE-SU-2026:0347-1 — Security update for glibc-livepatches</title>
    <updated>2026-10-02T11:01:01.072232+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for glibc-livepatches</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:0347-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-0861</id>
    <title>UBUNTU-CVE-2026-0861</title>
    <updated>2026-10-02T11:01:01.072249+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:20.04:LTS: glibc, Ubuntu:22.04:LTS: glibc, Ubuntu:24.04:LTS: glibc, Ubuntu:25.10: glibc</p>
<p>Passing too large an alignment to the memalign suite of functions (memalign, posix_memalign, aligned_alloc) in the GNU C Library version 2.30 to 2.42 may result in an integer overflow, which could consequently result in a heap corruption. Note that the attacker must have control over both, the size as well as the alignment arguments of the memalign function to be able to exploit this. The size parameter must be close enough to PTRDIFF_MAX so as to overflow size_t along with the large alignment argument.  This limits the malicious inputs for the alignment for memalign to the range [1&lt;&lt;62+ 1, 1&lt;&lt;63] and exactly 1&lt;&lt;63 for posix_memalign and aligned_alloc. Typically the alignment argument passed to such functions is a known constrained quantity (e.g. page size, block size, struct sizes) and is not attacker controlled, because of which this may not be easily exploitable in practice.  An application bug could potentially result in the input alignment being too large, e.g. due to a different buffer overflow or integer overflow in the application or its dependent libraries, but that is again an uncommon usage pattern given typical sources of alignments.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-0861"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0118</id>
    <title>WID-SEC-W-2026-0118 — GNU libc: Schwachstelle ermöglicht Codeausführung</title>
    <updated>2026-10-02T11:01:01.072280+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann eine Schwachstelle in GNU libc ausnutzen, um beliebigen Programmcode auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0118"/>
  </entry>
</feed>
