<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T11:03:22.028512+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:67154</id>
    <title>ALSA-2026:67154 — Important: openssl security, bug fix, and enhancement update</title>
    <updated>2026-10-02T11:03:22.370714+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:10: openssl, AlmaLinux:10: openssl-devel, AlmaLinux:10: openssl-libs, AlmaLinux:10: openssl-perl</p>
<p>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, as well as a full-strength general-purpose cryptography library.</p>
<p>Security Fix(es):</p>
<p>* openssl: OpenSSL: Denial of Service via unbounded memory growth in QUIC server (CVE-2026-14456)
  * openssl: QUIC server may trigger double free when processing INITIAL packet (CVE-2026-18798)
  * openssl: heap buffer overflow in CMS key unwrapping (CVE-2026-63072)
  * openssl: invalid pointer dereference in CMP server via crafted protectionAlg (CVE-2026-63076)
  * openssl: RPK server signature algorithm selection can dereference a missing certificate (CVE-2026-14457)
  * openssl: excessive memory use buffering DTLS records for a future epoch (CVE-2026-54874)
  * openssl: untrusted sender DN used as format string in CMP response validation (CVE-2026-63073)
  * openssl: CMP indefinite cache growth of ExtraCerts (CVE-2026-63074)
  * openssl: QUIC ACK-only packet retention can cause memory exhaustion (CVE-2026-63075)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* openssl: HollowByte remote memory-exhaustion DoS fix may be missing [AlmaLinux 10.2.z] (JIRA:AlmaLinux-212362)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:67154"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-14716</id>
    <title>bdu:2026-14716</title>
    <updated>2026-10-02T11:03:22.370805+00:00</updated>
    <content>bdu:2026-14716</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-14716"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-63076</id>
    <title>BELL-CVE-2026-63076</title>
    <updated>2026-10-02T11:03:22.370824+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: openssl, Alpaquita:25: openssl, Alpaquita:stream: openssl, BellSoft Hardened Containers:23: openssl, BellSoft Hardened Containers:25: openssl, BellSoft Hardened Containers:stream: openssl</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-63076"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1079</id>
    <title>certfr-2026-avi-1079 — De multiples vulnérabilités ont été découvertes dans OpenSSL. Elles permettent à un attaquant de provoquer un déni de s…</title>
    <updated>2026-10-02T11:03:22.370850+00:00</updated>
    <content>certfr-2026-avi-1079</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1079"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-358672</id>
    <title>EUVD-2026-358672</title>
    <updated>2026-10-02T11:03:22.370866+00:00</updated>
    <content>EUVD-2026-358672</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-358672"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-63076</id>
    <title>fkie_cve-2026-63076</title>
    <updated>2026-10-02T11:03:22.370877+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Issue summary: OpenSSL CMP password based protection verification only
checks whether the protectionAlg parameter was not NULL and not its
ASN.1 type, before treating it as a PBMParameter. A crafted message can
contain a parameter of a different type, which is then dereferenced as an
invalid pointer.</p>
<p>Impact summary: A remote, unauthenticated attacker can crash an application
acting as a CMP server that accepts PBM-protected messages, or a CMP client
talking to a malicious or intercepted CMP server, resulting in a Denial of
Service.</p>
<p>CWE: CWE-476: NULL Pointer Dereference</p>
<p>Description: When verifying the password-based MAC protection of a CMP
message, OpenSSL library reads the protectionAlg algorithm parameter with
X509_ALGOR_get0(), which returns both the parameter type and its value
pointer. The value is then cast to an ASN1_STRING and treated as the
expected PBMParameter after only checking that pointer is not NULL. The
parameter type returned by X509_ALGOR_get0() was never consulted.</p>
<p>This happens during protection verification, before any MAC is computed, so
no knowledge of the PBM shared secret is required; the only precondition is
that PBM verification is reachable. On the server side this is reached from
OSSL_CMP_SRV_process_request() for any application that stands up a CMP
server accepting PBM-protected messages, and on the client side from CMP
response validation against a malicious or on-path (MITM) server. The
reliable consequence is a denial of service; there i…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-63076"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-r3hf-pf7x-wgqg</id>
    <title>GHSA-r3hf-pf7x-wgqg</title>
    <updated>2026-10-02T11:03:22.370915+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Issue summary: OpenSSL CMP password based protection verification only
checks whether the protectionAlg parameter was not NULL and not its
ASN.1 type, before treating it as a PBMParameter. A crafted message can
contain a parameter of a different type, which is then dereferenced as an
invalid pointer.</p>
<p>Impact summary: A remote, unauthenticated attacker can crash an application
acting as a CMP server that accepts PBM-protected messages, or a CMP client
talking to a malicious or intercepted CMP server, resulting in a Denial of
Service.</p>
<p>CWE: CWE-476: NULL Pointer Dereference</p>
<p>Description: When verifying the password-based MAC protection of a CMP
message, OpenSSL library reads the protectionAlg algorithm parameter with
X509_ALGOR_get0(), which returns both the parameter type and its value
pointer. The value is then cast to an ASN1_STRING and treated as the
expected PBMParameter after only checking that pointer is not NULL. The
parameter type returned by X509_ALGOR_get0() was never consulted.</p>
<p>This happens during protection verification, before any MAC is computed, so
no knowledge of the PBM shared secret is required; the only precondition is
that PBM verification is reachable. On the server side this is reached from
OSSL_CMP_SRV_process_request() for any application that stands up a CMP
server accepting PBM-protected messages, and on the client side from CMP
response validation against a malicious or on-path (MITM) server. The
reliable consequence is a denial of service; there i…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-r3hf-pf7x-wgqg"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-63076</id>
    <title>msrc_CVE-2026-63076 — Invalid Pointer Dereference in CMP Server via Crafted protectionAlg</title>
    <updated>2026-10-02T11:03:22.370943+00:00</updated>
    <content>msrc_CVE-2026-63076</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-63076"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-3624</id>
    <title>OESA-2026-3624 — openssl security update</title>
    <updated>2026-10-02T11:03:22.370960+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP1: openssl</p>
<p>OpenSSL is a robust, commercial-grade, and full-featured toolkit for the Transport Layer Security (TLS) and Secure Sockets Layer (SSL) protocols.

Security Fix(es):</p>
<p>Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches
additional certificates (extraCerts) sent in a CMP message, but never expunges
them (for instance if they are invalid).  If a server reuses an OSSL_CMP_CTX
frequently, this cache of extraCerts may grow unboundedly, and a malicious
client may flood a CMP server with requests driving this growth.</p>
<p>Impact summary: Users utilizing a CMP server that reuses a single OSSL_CMP_CTX
for the lifetime of a server process may observe unbounded memory growth in the
event a malicious client repeatedly sends requests containing unique extra
certificates, which may lead to OOM conditions.</p>
<p>CWE: CWE-770: Allocation of Resources Without Limits or Throttling</p>
<p>Description: If a remote user sends CMP messages to a server with a list of
extraCerts and the message is rejected, the extraCerts from the message remains
in the server contexts untrusted certificate stack.  This exposes servers with
long lived ctx objects to Denial of Service attacks in which an attacker sends
messages intending to be rejected with a large list of additional certificates
repeatedly, forcing the server to store them indefinitely.
   
The issue was fixed by removing the added extra certs if the message is
rejected, using the same method as when the context is configured to not do
caching…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-3624"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11623-1</id>
    <title>openSUSE-SU-2026:11623-1 — libopenssl-3-devel-3.5.3-8.1 on GA media</title>
    <updated>2026-10-02T11:03:22.371002+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libopenssl-3-devel-3.5.3-8.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11623-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:59635</id>
    <title>RHSA-2026:59635 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
    <updated>2026-10-02T11:03:22.371025+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>openssl: OpenSSL: Heap buffer overflow due to signed integer overflow in Unicode output sizing openssl: OpenSSL: Denial of Service due to heap out-of-bounds read in CMS password-based decryption openssl: RPK server signature algorithm selection can dereference a missing certificate openssl: QUIC server may trigger double free when processing INITIAL packet openssl: OpenSSL: Heap buffer over-read in ASN.1 decoding can lead to denial of service or information disclosure. openssl: PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC Keys openssl: CMS AuthEnvelopedData Processing May Accept Forged Messages openssl: Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler openssl: Double-free When Checking OCSP Stapled Response openssl: NULL pointer dereference in QUIC server initial packet handling openssl: NULL Dereference in Certificate Verification with OCSP Checking openssl: Possible NULL Dereference in Password-Based CMS Decryption openssl: NULL Pointer Dereference in CRMF EncryptedValue Decryption openssl: Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt() openssl: Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate openssl: FFC-DH Peer Validation Uses Attacker-Supplied q openssl: Possible Out of Bounds Read in X509_VERIFY_PARAM_set1_email() openssl: AES-OCB IV Ignored on EVP_Cipher() Path openssl: Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes openssl: Heap Use-After-Free in OpenSSL PKCS7_veri…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:59635"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:67154</id>
    <title>RLSA-2026:67154 — Important: openssl security, bug fix, and enhancement update</title>
    <updated>2026-10-02T11:03:22.371086+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:10: openssl</p>
<p>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, as well as a full-strength general-purpose cryptography library.</p>
<p>Security Fix(es):</p>
<p>* openssl: OpenSSL: Denial of Service via unbounded memory growth in QUIC server (CVE-2026-14456)</p>
<p>* openssl: QUIC server may trigger double free when processing INITIAL packet (CVE-2026-18798)</p>
<p>* openssl: heap buffer overflow in CMS key unwrapping (CVE-2026-63072)</p>
<p>* openssl: invalid pointer dereference in CMP server via crafted protectionAlg (CVE-2026-63076)</p>
<p>* openssl: RPK server signature algorithm selection can dereference a missing certificate (CVE-2026-14457)</p>
<p>* openssl: excessive memory use buffering DTLS records for a future epoch (CVE-2026-54874)</p>
<p>* openssl: untrusted sender DN used as format string in CMP response validation (CVE-2026-63073)</p>
<p>* openssl: CMP indefinite cache growth of ExtraCerts (CVE-2026-63074)</p>
<p>* openssl: QUIC ACK-only packet retention can cause memory exhaustion (CVE-2026-63075)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* openssl: HollowByte remote memory-exhaustion DoS fix may be missing [Rocky Linux 10.2.z] (JIRA:Rocky Linux-212362)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:67154"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:23463-1</id>
    <title>SUSE-SU-2026:23463-1 — Security update for openssl-3</title>
    <updated>2026-10-02T11:03:22.371121+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for openssl-3</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:23463-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-63076</id>
    <title>UBUNTU-CVE-2026-63076</title>
    <updated>2026-10-02T11:03:22.371141+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: nodejs, Ubuntu:Pro:18.04:LTS: nodejs, Ubuntu:22.04:LTS: openssl, Ubuntu:Pro:FIPS-preview:22.04:LTS: openssl, Ubuntu:Pro:FIPS-preview:22.04:LTS: openssl-fips, Ubuntu:Pro:FIPS-updates:22.04:LTS: openssl, Ubuntu:Pro:FIPS-updates:22.04:LTS: openssl-fips, Ubuntu:24.04:LTS: edk2, Ubuntu:24.04:LTS: openssl, Ubuntu:Pro:FIPS-updates:24.04:LTS: openssl-fips and 3 more</p>
<p>Issue summary: OpenSSL CMP password based protection verification only checks whether the protectionAlg parameter was not NULL and not its ASN.1 type, before treating it as a PBMParameter. A crafted message can contain a parameter of a different type, which is then dereferenced as an invalid pointer. Impact summary: A remote, unauthenticated attacker can crash an application acting as a CMP server that accepts PBM-protected messages, or a CMP client talking to a malicious or intercepted CMP server, resulting in a Denial of Service. CWE: CWE-476: NULL Pointer Dereference Description: When verifying the password-based MAC protection of a CMP message, OpenSSL library reads the protectionAlg algorithm parameter with X509_ALGOR_get0(), which returns both the parameter type and its value pointer. The value is then cast to an ASN1_STRING and treated as the expected PBMParameter after only checking that pointer is not NULL. The parameter type returned by X509_ALGOR_get0() was never consulted. This happens during protection verification, before any MAC is computed, so no knowledge of the PBM shared secret is required; the only precondition is that PBM verification is reachable. On the server side this is reached from OSSL_CMP_SRV_process_request() for any application that stands up a CMP server accepting PBM-protected messages, and on the client side from CMP response validation against a malicious or on-path (MITM) server. The reliable consequence is a denial of service; there is no…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-63076"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3005</id>
    <title>WID-SEC-W-2026-3005 — OpenSSL: Mehrere Schwachstellen</title>
    <updated>2026-10-02T11:03:22.371188+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in OpenSSL ausnutzen, um Sicherheitsvorkehrungen zu umgehen, Daten zu manipulieren oder offenzulegen oder einen Denial-of-Service-Zustand herbeizuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3005"/>
  </entry>
</feed>
