<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 01:21:29 +0000</lastBuildDate>
    <item>
      <title>ALSA-2022:6224 — Moderate: openssl security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2022:6224</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: openssl, AlmaLinux:9: openssl-devel, AlmaLinux:9: openssl-libs, AlmaLinux:9: openssl-perl&lt;/p&gt;
&lt;p&gt;OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, as well as a full-strength general-purpose cryptography library.
Security Fix(es):
* openssl: c_rehash script allows command injection (CVE-2022-1292)
* openssl: Signer certificate verification returns inaccurate response when using OCSP_NOCHECKS (CVE-2022-1343)
* openssl: OPENSSL_LH_flush() breaks reuse of memory (CVE-2022-1473)
* openssl: the c_rehash script allows command injection (CVE-2022-2068)
* openssl: AES OCB fails to encrypt some bytes (CVE-2022-2097)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Bug Fix(es):
* openssl occasionally sends internal error to gnutls when using FFDHE (BZ#2080323)
* openssl req defaults to 3DES (BZ#2085499)
* OpenSSL accepts custom elliptic curve parameters when p is large [almalinux-9] (BZ#2085508)
* OpenSSL mustn&amp;#39;t work with ECDSA with explicit curve parameters in FIPS mode (BZ#2085521)
* openssl s_server -groups secp256k1 in FIPS fails because X25519/X448 (BZ#2086554)
* Converting FIPS power-on self test to KAT (BZ#2086866)
* Small RSA keys work for some operations in FIPS mode (BZ#2091938)
* FIPS provider doesn&amp;#39;t block RSA encryption for key transport (BZ#2091977)
* OpenSSL testsuite certificates expired (BZ#2095696)
* [IBM 9.1 HW OPT] POWER10 performance enhancements for cryptogr…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: openssl, AlmaLinux:9: openssl-devel, AlmaLinux:9: openssl-libs, AlmaLinux:9: openssl-perl&lt;/p&gt;
&lt;p&gt;OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, as well as a full-strength general-purpose cryptography library.
Security Fix(es):
* openssl: c_rehash script allows command injection (CVE-2022-1292)
* openssl: Signer certificate verification returns inaccurate response when using OCSP_NOCHECKS (CVE-2022-1343)
* openssl: OPENSSL_LH_flush() breaks reuse of memory (CVE-2022-1473)
* openssl: the c_rehash script allows command injection (CVE-2022-2068)
* openssl: AES OCB fails to encrypt some bytes (CVE-2022-2097)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Bug Fix(es):
* openssl occasionally sends internal error to gnutls when using FFDHE (BZ#2080323)
* openssl req defaults to 3DES (BZ#2085499)
* OpenSSL accepts custom elliptic curve parameters when p is large [almalinux-9] (BZ#2085508)
* OpenSSL mustn&amp;#39;t work with ECDSA with explicit curve parameters in FIPS mode (BZ#2085521)
* openssl s_server -groups secp256k1 in FIPS fails because X25519/X448 (BZ#2086554)
* Converting FIPS power-on self test to KAT (BZ#2086866)
* Small RSA keys work for some operations in FIPS mode (BZ#2091938)
* FIPS provider doesn&amp;#39;t block RSA encryption for key transport (BZ#2091977)
* OpenSSL testsuite certificates expired (BZ#2095696)
* [IBM 9.1 HW OPT] POWER10 performance enhancements for cryptogr…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2022:6224</guid>
    </item>
    <item>
      <title>bdu:2022-03268</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-03268</link>
      <description>bdu:2022-03268</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-03268</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2022-1473 — CVE-2022-1473 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2022-1473</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2022-1473</guid>
    </item>
    <item>
      <title>certfr-2022-avi-411 — De multiples vulnérabilités ont été découvertes dans OpenSSL. Certaines
d'entre elles permettent à un attaquant de prov…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-411</link>
      <description>certfr-2022-avi-411</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-411</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-GK72927 — Issue summary: PBMAC1 parameters in PKCS#12 files are missing validation
which can trigger a stack-based buffer overflo…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-gk72927</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: openssl&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the openssl package. Issue summary: PBMAC1 parameters in PKCS#12 files are missing validation which can trigger a stack-based buffer overflow, invalid pointer or NULL pointer dereference during MAC verification. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: openssl&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the openssl package. Issue summary: PBMAC1 parameters in PKCS#12 files are missing validation which can trigger a stack-based buffer overflow, invalid pointer or NULL pointer dereference during MAC verification. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-gk72927</guid>
    </item>
    <item>
      <title>cnvd-2022-37792</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2022-37792</link>
      <description>cnvd-2022-37792</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2022-37792</guid>
    </item>
    <item>
      <title>EUVD-2026-237460</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-237460</link>
      <description>EUVD-2026-237460</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-237460</guid>
    </item>
    <item>
      <title>fkie_cve-2022-1473</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-1473</link>
      <description>&lt;p&gt;The OPENSSL_LH_flush() function, which empties a hash table, contains a bug that breaks reuse of the memory occuppied by the removed hash table entries. This function is used when decoding certificates or keys. If a long lived process periodically decodes certificates or keys its memory usage will expand without bounds and the process might be terminated by the operating system causing a denial of service. Also traversing the empty hash table entries will take increasingly more time. Typically such long lived processes might be TLS clients or TLS servers configured to accept client certificate authentication. The function was added in the OpenSSL 3.0 version thus older releases are not affected by the issue. Fixed in OpenSSL 3.0.3 (Affected 3.0.0,3.0.1,3.0.2).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The OPENSSL_LH_flush() function, which empties a hash table, contains a bug that breaks reuse of the memory occuppied by the removed hash table entries. This function is used when decoding certificates or keys. If a long lived process periodically decodes certificates or keys its memory usage will expand without bounds and the process might be terminated by the operating system causing a denial of service. Also traversing the empty hash table entries will take increasingly more time. Typically such long lived processes might be TLS clients or TLS servers configured to accept client certificate authentication. The function was added in the OpenSSL 3.0 version thus older releases are not affected by the issue. Fixed in OpenSSL 3.0.3 (Affected 3.0.0,3.0.1,3.0.2).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-1473</guid>
    </item>
    <item>
      <title>GHSA-g323-fr93-4j3c — Resource leakage when decoding certificates and keys</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-g323-fr93-4j3c</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: openssl-src&lt;/p&gt;
&lt;p&gt;The OPENSSL_LH_flush() function, which empties a hash table, contains a bug that breaks reuse of the memory occuppied by the removed hash table entries. This function is used when decoding certificates or keys. If a long lived process periodically decodes certificates or keys its memory usage will expand without bounds and the process might be terminated by the operating system causing a denial of service. Also traversing the empty hash table entries will take increasingly more time. Typically such long lived processes might be TLS clients or TLS servers configured to accept client certificate authentication. The function was added in the OpenSSL 3.0 version thus older releases are not affected by the issue. Fixed in OpenSSL 3.0.3 (Affected 3.0.0,3.0.1,3.0.2).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: openssl-src&lt;/p&gt;
&lt;p&gt;The OPENSSL_LH_flush() function, which empties a hash table, contains a bug that breaks reuse of the memory occuppied by the removed hash table entries. This function is used when decoding certificates or keys. If a long lived process periodically decodes certificates or keys its memory usage will expand without bounds and the process might be terminated by the operating system causing a denial of service. Also traversing the empty hash table entries will take increasingly more time. Typically such long lived processes might be TLS clients or TLS servers configured to accept client certificate authentication. The function was added in the OpenSSL 3.0 version thus older releases are not affected by the issue. Fixed in OpenSSL 3.0.3 (Affected 3.0.0,3.0.1,3.0.2).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-g323-fr93-4j3c</guid>
    </item>
    <item>
      <title>gsd-2022-1473</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-1473</link>
      <description>gsd-2022-1473</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-1473</guid>
    </item>
    <item>
      <title>ICSA-23-047-03 — Siemens Brownfield Connectivity Client</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-23-047-03</link>
      <description>&lt;p&gt;The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. Under certain circumstances, the command line OCSP verify function reports successful verification when the varification in fact failed. In this case the incorrect successful response will also be accompanied by error messages showing the failure and contradicting the apparently successful result. When using the RC4-MD5 ciphersuite, which is disabled by default, an attacker is able to modify data in transit due to an incorrect use of the AAD data as the MAC key in OpenSSL 3.0. An attacker is not able to decrypt any communication. The used OpenSSL version improperly reuses memory when decoding certificates or keys. This can lead to a process termination and Denial of Service for long lived processes.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. Under certain circumstances, the command line OCSP verify function reports successful verification when the varification in fact failed. In this case the incorrect successful response will also be accompanied by error messages showing the failure and contradicting the apparently successful result. When using the RC4-MD5 ciphersuite, which is disabled by default, an attacker is able to modify data in transit due to an incorrect use of the AAD data as the MAC key in OpenSSL 3.0. An attacker is not able to decrypt any communication. The used OpenSSL version improperly reuses memory when decoding certificates or keys. This can lead to a process termination and Denial of Service for long lived processes.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-23-047-03</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:12204-1 — libopenssl-3-devel-3.0.5-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12204-1</link>
      <description>&lt;p&gt;libopenssl-3-devel-3.0.5-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libopenssl-3-devel-3.0.5-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:12204-1</guid>
    </item>
    <item>
      <title>RUSTSEC-2022-0025 — Resource leakage when decoding certificates and keys</title>
      <link>https://cve.radiocsirt.org/vuln/rustsec-2022-0025</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: openssl-src&lt;/p&gt;
&lt;p&gt;The `OPENSSL_LH_flush()` function, which empties a hash table, contains
a bug that breaks reuse of the memory occupied by the removed hash
table entries.&lt;/p&gt;
&lt;p&gt;This function is used when decoding certificates or keys. If a long lived
process periodically decodes certificates or keys its memory usage will
expand without bounds and the process might be terminated by the operating
system causing a denial of service. Also traversing the empty hash table
entries will take increasingly more time.&lt;/p&gt;
&lt;p&gt;Typically such long lived processes might be TLS clients or TLS servers
configured to accept client certificate authentication.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: openssl-src&lt;/p&gt;
&lt;p&gt;The `OPENSSL_LH_flush()` function, which empties a hash table, contains
a bug that breaks reuse of the memory occupied by the removed hash
table entries.&lt;/p&gt;
&lt;p&gt;This function is used when decoding certificates or keys. If a long lived
process periodically decodes certificates or keys its memory usage will
expand without bounds and the process might be terminated by the operating
system causing a denial of service. Also traversing the empty hash table
entries will take increasingly more time.&lt;/p&gt;
&lt;p&gt;Typically such long lived processes might be TLS clients or TLS servers
configured to accept client certificate authentication.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rustsec-2022-0025</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-1473</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-1473</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: openssl, Ubuntu:Pro:16.04:LTS: edk2, Ubuntu:Pro:FIPS:16.04:LTS: openssl, Ubuntu:22.04:LTS: openssl&lt;/p&gt;
&lt;p&gt;The OPENSSL_LH_flush() function, which empties a hash table, contains a bug that breaks reuse of the memory occuppied by the removed hash table entries. This function is used when decoding certificates or keys. If a long lived process periodically decodes certificates or keys its memory usage will expand without bounds and the process might be terminated by the operating system causing a denial of service. Also traversing the empty hash table entries will take increasingly more time. Typically such long lived processes might be TLS clients or TLS servers configured to accept client certificate authentication. The function was added in the OpenSSL 3.0 version thus older releases are not affected by the issue. Fixed in OpenSSL 3.0.3 (Affected 3.0.0,3.0.1,3.0.2).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: openssl, Ubuntu:Pro:16.04:LTS: edk2, Ubuntu:Pro:FIPS:16.04:LTS: openssl, Ubuntu:22.04:LTS: openssl&lt;/p&gt;
&lt;p&gt;The OPENSSL_LH_flush() function, which empties a hash table, contains a bug that breaks reuse of the memory occuppied by the removed hash table entries. This function is used when decoding certificates or keys. If a long lived process periodically decodes certificates or keys its memory usage will expand without bounds and the process might be terminated by the operating system causing a denial of service. Also traversing the empty hash table entries will take increasingly more time. Typically such long lived processes might be TLS clients or TLS servers configured to accept client certificate authentication. The function was added in the OpenSSL 3.0 version thus older releases are not affected by the issue. Fixed in OpenSSL 3.0.3 (Affected 3.0.0,3.0.1,3.0.2).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-1473</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-0071 — OpenSSL: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0071</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in OpenSSL ausnutzen, um beliebigen Programmcode mit den Rechten des Dienstes auszuführen, Sicherheitsvorkehrungen zu umgehen, Dateien zu manipulieren oder einen Denial of Service Zustand herbeizuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in OpenSSL ausnutzen, um beliebigen Programmcode mit den Rechten des Dienstes auszuführen, Sicherheitsvorkehrungen zu umgehen, Dateien zu manipulieren oder einen Denial of Service Zustand herbeizuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0071</guid>
    </item>
  </channel>
</rss>
