<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 16:57:13 +0000</lastBuildDate>
    <item>
      <title>ALSA-2021:1702 — Moderate: brotli security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2021:1702</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: brotli, AlmaLinux:8: brotli-devel, AlmaLinux:8: python3-brotli&lt;/p&gt;
&lt;p&gt;Brotli is a generic-purpose lossless compression algorithm that compresses data using a combination of a modern variant of the LZ77 algorithm, Huffman coding and 2nd order context modeling, with a compression ratio comparable to the best currently available general-purpose compression methods. It is similar in speed with deflate but offers more dense compression.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* brotli: buffer overflow when input chunk is larger than 2GiB (CVE-2020-8927)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: brotli, AlmaLinux:8: brotli-devel, AlmaLinux:8: python3-brotli&lt;/p&gt;
&lt;p&gt;Brotli is a generic-purpose lossless compression algorithm that compresses data using a combination of a modern variant of the LZ77 algorithm, Huffman coding and 2nd order context modeling, with a compression ratio comparable to the best currently available general-purpose compression methods. It is similar in speed with deflate but offers more dense compression.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* brotli: buffer overflow when input chunk is larger than 2GiB (CVE-2020-8927)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2021:1702</guid>
    </item>
    <item>
      <title>bdu:2021-01775</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2021-01775</link>
      <description>bdu:2021-01775</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2021-01775</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2020-8927 — CVE-2020-8927 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2020-8927</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2020-8927</guid>
    </item>
    <item>
      <title>BIT-brotli-2020-8927 — Buffer overflow in Brotli library</title>
      <link>https://cve.radiocsirt.org/vuln/bit-brotli-2020-8927</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: brotli&lt;/p&gt;
&lt;p&gt;A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a &amp;#34;one-shot&amp;#34; decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your Brotli library to 1.0.8 or later. If one cannot update, we recommend to use the &amp;#34;streaming&amp;#34; API as opposed to the &amp;#34;one-shot&amp;#34; API, and impose chunk size limits.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: brotli&lt;/p&gt;
&lt;p&gt;A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a &amp;#34;one-shot&amp;#34; decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your Brotli library to 1.0.8 or later. If one cannot update, we recommend to use the &amp;#34;streaming&amp;#34; API as opposed to the &amp;#34;one-shot&amp;#34; API, and impose chunk size limits.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-brotli-2020-8927</guid>
    </item>
    <item>
      <title>BREW-exiftool-CVE-2020-36846</title>
      <link>https://cve.radiocsirt.org/vuln/brew-exiftool-cve-2020-36846</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: exiftool&lt;/p&gt;
&lt;p&gt;A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a &amp;#34;one-shot&amp;#34; decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your Brotli library to 1.0.8 or later. If one cannot update, we recommend to use the &amp;#34;streaming&amp;#34; API as opposed to the &amp;#34;one-shot&amp;#34; API, and impose chunk size limits.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: exiftool&lt;/p&gt;
&lt;p&gt;A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a &amp;#34;one-shot&amp;#34; decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your Brotli library to 1.0.8 or later. If one cannot update, we recommend to use the &amp;#34;streaming&amp;#34; API as opposed to the &amp;#34;one-shot&amp;#34; API, and impose chunk size limits.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-exiftool-cve-2020-36846</guid>
    </item>
    <item>
      <title>certfr-2021-avi-791 — De multiples vulnérabilités ont été découvertes dans les produits IBM.
Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2021-avi-791</link>
      <description>certfr-2021-avi-791</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2021-avi-791</guid>
    </item>
    <item>
      <title>CLEANSTART-2024-XN11840 — buffer overflow exists in the Brotli library versions prior to 1</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2024-xn11840</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: brotli&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the brotli package. A buffer overflow exists in the Brotli library versions prior to 1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: brotli&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the brotli package. A buffer overflow exists in the Brotli library versions prior to 1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2024-xn11840</guid>
    </item>
    <item>
      <title>EUVD-2026-323038</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-323038</link>
      <description>EUVD-2026-323038</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-323038</guid>
    </item>
    <item>
      <title>fkie_cve-2020-8927</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-8927</link>
      <description>&lt;p&gt;A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a &amp;#34;one-shot&amp;#34; decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your Brotli library to 1.0.8 or later. If one cannot update, we recommend to use the &amp;#34;streaming&amp;#34; API as opposed to the &amp;#34;one-shot&amp;#34; API, and impose chunk size limits.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a &amp;#34;one-shot&amp;#34; decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your Brotli library to 1.0.8 or later. If one cannot update, we recommend to use the &amp;#34;streaming&amp;#34; API as opposed to the &amp;#34;one-shot&amp;#34; API, and impose chunk size limits.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-8927</guid>
    </item>
    <item>
      <title>GHSA-5v8v-66v8-mwm7 — Integer overflow in the bundled Brotli C library</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-5v8v-66v8-mwm7</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: compu-brotli-sys, NuGet: Microsoft.NETCore.App.Runtime.linux-arm, NuGet: Microsoft.NETCore.App.Runtime.linux-arm64, NuGet: Microsoft.NETCore.App.Runtime.linux-musl-arm64, NuGet: Microsoft.NETCore.App.Runtime.linux-x64, NuGet: Microsoft.NETCore.App.Runtime.osx-x64, NuGet: Microsoft.NETCore.App.Runtime.win-arm, NuGet: Microsoft.NETCore.App.Runtime.win-arm64, NuGet: Microsoft.NETCore.App.Runtime.win-x64, NuGet: Microsoft.NETCore.App.Runtime.win-x86 and 108 more&lt;/p&gt;
&lt;p&gt;A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a &amp;#34;one-shot&amp;#34; decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your Brotli library to 1.0.8 or later. If one cannot update, we recommend to use the &amp;#34;streaming&amp;#34; API as opposed to the &amp;#34;one-shot&amp;#34; API, and impose chunk size limits.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: compu-brotli-sys, NuGet: Microsoft.NETCore.App.Runtime.linux-arm, NuGet: Microsoft.NETCore.App.Runtime.linux-arm64, NuGet: Microsoft.NETCore.App.Runtime.linux-musl-arm64, NuGet: Microsoft.NETCore.App.Runtime.linux-x64, NuGet: Microsoft.NETCore.App.Runtime.osx-x64, NuGet: Microsoft.NETCore.App.Runtime.win-arm, NuGet: Microsoft.NETCore.App.Runtime.win-arm64, NuGet: Microsoft.NETCore.App.Runtime.win-x64, NuGet: Microsoft.NETCore.App.Runtime.win-x86 and 108 more&lt;/p&gt;
&lt;p&gt;A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a &amp;#34;one-shot&amp;#34; decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your Brotli library to 1.0.8 or later. If one cannot update, we recommend to use the &amp;#34;streaming&amp;#34; API as opposed to the &amp;#34;one-shot&amp;#34; API, and impose chunk size limits.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-5v8v-66v8-mwm7</guid>
    </item>
    <item>
      <title>gsd-2020-8927</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-8927</link>
      <description>gsd-2020-8927</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-8927</guid>
    </item>
    <item>
      <title>openSUSE-SU-2020:1578-1 — Security update for brotli</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2020:1578-1</link>
      <description>&lt;p&gt;Security update for brotli&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for brotli&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2020:1578-1</guid>
    </item>
    <item>
      <title>PYSEC-2020-29</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2020-29</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: brotli&lt;/p&gt;
&lt;p&gt;A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a &amp;#34;one-shot&amp;#34; decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your Brotli library to 1.0.8 or later. If one cannot update, we recommend to use the &amp;#34;streaming&amp;#34; API as opposed to the &amp;#34;one-shot&amp;#34; API, and impose chunk size limits.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: brotli&lt;/p&gt;
&lt;p&gt;A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a &amp;#34;one-shot&amp;#34; decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your Brotli library to 1.0.8 or later. If one cannot update, we recommend to use the &amp;#34;streaming&amp;#34; API as opposed to the &amp;#34;one-shot&amp;#34; API, and impose chunk size limits.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2020-29</guid>
    </item>
    <item>
      <title>RHSA-2022:0828 — Red Hat Security Advisory: .NET 5.0 on RHEL 7 security and bugfix update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2022:0828</link>
      <description>&lt;p&gt;brotli: buffer overflow when input chunk is larger than 2GiB dotnet: ASP.NET Denial of Service via FormPipeReader dotnet: double parser stack buffer overrun&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;brotli: buffer overflow when input chunk is larger than 2GiB dotnet: ASP.NET Denial of Service via FormPipeReader dotnet: double parser stack buffer overrun&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2022:0828</guid>
    </item>
    <item>
      <title>RUSTSEC-2021-0131 — Integer overflow in the bundled Brotli C library</title>
      <link>https://cve.radiocsirt.org/vuln/rustsec-2021-0131</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: brotli-sys&lt;/p&gt;
&lt;p&gt;A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a &amp;#34;one-shot&amp;#34; decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB.&lt;/p&gt;
&lt;p&gt;An updated version of `brotli-sys` has not been released. If one cannot update the C library, its authors recommend to use the &amp;#34;streaming&amp;#34; API as opposed to the &amp;#34;one-shot&amp;#34; API, and impose chunk size limits.&lt;/p&gt;
&lt;p&gt;In Rust the issue can be mitigated by migrating to the `brotli` crate, which provides a Rust implementation of Brotli compression and decompression that is not affected by this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: brotli-sys&lt;/p&gt;
&lt;p&gt;A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a &amp;#34;one-shot&amp;#34; decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB.&lt;/p&gt;
&lt;p&gt;An updated version of `brotli-sys` has not been released. If one cannot update the C library, its authors recommend to use the &amp;#34;streaming&amp;#34; API as opposed to the &amp;#34;one-shot&amp;#34; API, and impose chunk size limits.&lt;/p&gt;
&lt;p&gt;In Rust the issue can be mitigated by migrating to the `brotli` crate, which provides a Rust implementation of Brotli compression and decompression that is not affected by this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rustsec-2021-0131</guid>
    </item>
    <item>
      <title>SUSE-SU-2021:3942-1 — Security update for brotli</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2021:3942-1</link>
      <description>&lt;p&gt;Security update for brotli&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for brotli&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2021:3942-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2020-8927</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-8927</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: brotli, Ubuntu:18.04:LTS: brotli, Ubuntu:20.04:LTS: brotli&lt;/p&gt;
&lt;p&gt;A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a &amp;#34;one-shot&amp;#34; decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your Brotli library to 1.0.8 or later. If one cannot update, we recommend to use the &amp;#34;streaming&amp;#34; API as opposed to the &amp;#34;one-shot&amp;#34; API, and impose chunk size limits.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: brotli, Ubuntu:18.04:LTS: brotli, Ubuntu:20.04:LTS: brotli&lt;/p&gt;
&lt;p&gt;A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a &amp;#34;one-shot&amp;#34; decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your Brotli library to 1.0.8 or later. If one cannot update, we recommend to use the &amp;#34;streaming&amp;#34; API as opposed to the &amp;#34;one-shot&amp;#34; API, and impose chunk size limits.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-8927</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-0227 — IBM QRadar SIEM: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0227</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in IBM QRadar SIEM ausnutzen, um seine Privilegien zu erweitern, Administratorrechte zu erlangen, beliebigen Programmcode auszuführen, Informationen offenzulegen, Dateien zu manipulieren oder Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in IBM QRadar SIEM ausnutzen, um seine Privilegien zu erweitern, Administratorrechte zu erlangen, beliebigen Programmcode auszuführen, Informationen offenzulegen, Dateien zu manipulieren oder Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0227</guid>
    </item>
  </channel>
</rss>
