<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T10:58:12.590457+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1241</id>
    <title>certfr-2026-avi-1241 — De multiples vulnérabilités ont été découvertes dans OpenSSL. Certaines d'entre elles permettent à un attaquant de prov…</title>
    <updated>2026-10-02T10:58:12.659257+00:00</updated>
    <content>certfr-2026-avi-1241</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1241"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-379776</id>
    <title>EUVD-2026-379776</title>
    <updated>2026-10-02T10:58:12.659300+00:00</updated>
    <content>EUVD-2026-379776</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-379776"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-54873</id>
    <title>fkie_cve-2026-54873</title>
    <updated>2026-10-02T10:58:12.659315+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Issue summary: QUIC process may keep memory for QUIC packet
buffer for much longer period than necessary.</p>
<p>Impact summary: Remote peer can exploit this vulnerability
by sending maliciously crafted packets, making the local
QUIC stack to keep the memory for packet buffers allocated.
The time for which the memory remains allocated is entirely
under the control of the potentially malicious remote peer.</p>
<p>CWE: CWE-770: Allocation of Resources Without Limits or Throttling</p>
<p>Description: To save copy operation from the packet buffer to the
stream reassemble buffer the QUIC stack leaves the stream data
on the packet buffer waiting to be copied to a buffer provided
by the local receiving application. The QUIC stack releases
a reference to the packet buffer only after the data are copied
to the application buffer. This design is more efficient for
legitimate data transfers but enables an attacker to allocate a lot
more memory than actually required by the data kept in the receiving
stream buffer.</p>
<p>To mitigate the vulnerability, the QUIC stack now calculates
and monitors memory overhead for every stream. The memory overhead
for a single stream frame is calculated as a difference between the
size of the whole packet that carries the stream frame and the size
of the stream frame itself. The memory overhead for a single stream
frame is added to the total (cumulative) memory overhead QUIC stack
keeps for each stream. Once the cumulative memory overhead exceeds
64kB, the QUIC stack moves the…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-54873"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-8jj8-6qjx-8659</id>
    <title>GHSA-8jj8-6qjx-8659</title>
    <updated>2026-10-02T10:58:12.659361+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Issue summary: QUIC process may keep memory for QUIC packet
buffer for much longer period than necessary.</p>
<p>Impact summary: Remote peer can exploit this vulnerability
by sending maliciously crafted packets, making the local
QUIC stack to keep the memory for packet buffers allocated.
The time for which the memory remains allocated is entirely
under the control of the potentially malicious remote peer.</p>
<p>CWE: CWE-770: Allocation of Resources Without Limits or Throttling</p>
<p>Description: To save copy operation from the packet buffer to the
stream reassemble buffer the QUIC stack leaves the stream data
on the packet buffer waiting to be copied to a buffer provided
by the local receiving application. The QUIC stack releases
a reference to the packet buffer only after the data are copied
to the application buffer. This design is more efficient for
legitimate data transfers but enables an attacker to allocate a lot
more memory than actually required by the data kept in the receiving
stream buffer.</p>
<p>To mitigate the vulnerability, the QUIC stack now calculates
and monitors memory overhead for every stream. The memory overhead
for a single stream frame is calculated as a difference between the
size of the whole packet that carries the stream frame and the size
of the stream frame itself. The memory overhead for a single stream
frame is added to the total (cumulative) memory overhead QUIC stack
keeps for each stream. Once the cumulative memory overhead exceeds
64kB, the QUIC stack moves the…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-8jj8-6qjx-8659"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:74162</id>
    <title>RHSA-2026:74162 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
    <updated>2026-10-02T10:58:12.659392+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>openssl: openssl: Denial of Service via excessive memory allocation in CRL distribution point processing openssl: openssl: Traffic amplification Denial of Service via QUIC packet over-accounting openssl: openssl: Denial of Service via inefficient QUIC stream reassembly openssl: OpenSSL: Private key recovery via timing side-channel in generic elliptic curve operations openssl: openssl: Denial of Service via excessive QUIC packet buffer retention openssl: openssl: information disclosure via non-constant-time SM2 scalar multiplication on ARM64 and RISC-V openssl: openssl: Denial of Service via out-of-bounds write during TLS context switch openssl: OpenSSL: Denial of Service via unenforced QUIC connection flow control openssl: openssl: Denial of Service via crafted CMP certificate revocation response openssl: OpenSSL: Denial of Service via undersized DTLS record openssl: OpenSSL: Private key recovery via SM2 timing side-channel openssl: compat-openssl: openssl: Information disclosure via DTLS handshake retransmission openssl: OpenSSL: Denial of Service via unbounded QUIC connection identifier backlog</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:74162"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-54873</id>
    <title>UBUNTU-CVE-2026-54873</title>
    <updated>2026-10-02T10:58:12.659428+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:22.04:LTS: nodejs, Ubuntu:26.04:LTS: edk2, Ubuntu:26.04:LTS: edk2-hwe, Ubuntu:26.04:LTS: openssl</p>
<p>Issue summary: QUIC process may keep memory for QUIC packet buffer for much longer period than necessary. Impact summary: Remote peer can exploit this vulnerability by sending maliciously crafted packets, making the local QUIC stack to keep the memory for packet buffers allocated. The time for which the memory remains allocated is entirely under the control of the potentially malicious remote peer. CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: To save copy operation from the packet buffer to the stream reassemble buffer the QUIC stack leaves the stream data on the packet buffer waiting to be copied to a buffer provided by the local receiving application. The QUIC stack releases a reference to the packet buffer only after the data are copied to the application buffer. This design is more efficient for legitimate data transfers but enables an attacker to allocate a lot more memory than actually required by the data kept in the receiving stream buffer. To mitigate the vulnerability, the QUIC stack now calculates and monitors memory overhead for every stream. The memory overhead for a single stream frame is calculated as a difference between the size of the whole packet that carries the stream frame and the size of the stream frame itself. The memory overhead for a single stream frame is added to the total (cumulative) memory overhead QUIC stack keeps for each stream. Once the cumulative memory overhead exceeds 64kB, the QUIC stack moves the str…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-54873"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3638</id>
    <title>WID-SEC-W-2026-3638 — OpenSSL: Mehrere Schwachstellen</title>
    <updated>2026-10-02T10:58:12.659465+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in OpenSSL ausnutzen, um Sicherheitsvorkehrungen zu umgehen, vertrauliche Informationen offenzulegen, Daten zu manipulieren und einen Denial-of-Service-Zustand zu verursachen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3638"/>
  </entry>
</feed>
