<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T18:48:29.291503+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-268899</id>
    <title>EUVD-2026-268899</title>
    <updated>2026-10-05T18:48:29.361630+00:00</updated>
    <content>EUVD-2026-268899</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-268899"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-26201</id>
    <title>fkie_cve-2026-26201</title>
    <updated>2026-10-05T18:48:29.361669+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>emp3r0r is a C2 designed by Linux users for Linux environments. Prior to version 3.21.2, multiple shared maps are accessed without consistent synchronization across goroutines. Under concurrent activity, Go runtime can trigger `fatal error: concurrent map read and map write`, causing C2 process crash (availability loss). Version 3.21.2 fixes this issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-26201"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-f5p9-j34q-pwcc</id>
    <title>GHSA-f5p9-j34q-pwcc — emp3r0r Affected by Concurrent Map Access DoS (panic/crash)</title>
    <updated>2026-10-05T18:48:29.361702+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/jm33-m0/emp3r0r/core</p>
<p>## Summary</p>
<p>Multiple shared maps are accessed without consistent synchronization across goroutines. Under concurrent activity, Go runtime can trigger `fatal error: concurrent map read and map write`, causing C2 process crash (availability loss).</p>
<p>## Vulnerable Component(with code examples)</p>
<p>Operator relay map had mixed access patterns (iteration and mutation without a single lock policy):</p>
<p>```go
// vulnerable pattern (operator session map)
for sessionID, op := range OPERATORS { // iteration path
    ...
}</p>
<p>// concurrent mutation path elsewhere
OPERATORS[operatorSession] = &amp;operator_t{...}
delete(OPERATORS, operatorSession)
```</p>
<p>Port-forwarding session map had read/write paths guarded inconsistently:</p>
<p>```go
// vulnerable pattern (port forward map)
if sess, ok := PortFwds[id]; ok { // read path
    ...
}</p>
<p>PortFwds[id] = newSession // write path
delete(PortFwds, id)      // delete path
```</p>
<p>FTP stream map similarly mixed concurrent iteration with mutation:</p>
<p>```go
// vulnerable pattern (FTP stream map)
for token, stream := range FTPStreams { // iteration path
    ...
}</p>
<p>FTPStreams[token] = stream // write path
delete(FTPStreams, token)  // delete path
```</p>
<p>## Attack Vector</p>
<p>1. Attacker (or stress traffic in authenticated flows) triggers high concurrency in normal control paths.
2. Operator sessions connect/disconnect while message forwarding and file-transfer workflows are active.
3. Concurrent read/write hits shared maps.
4. Go runtime panics with concurrent map read/write erro…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-f5p9-j34q-pwcc"/>
  </entry>
</feed>
