<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 03:32:51 +0000</lastBuildDate>
    <item>
      <title>2NGA002579 — ABB Arctic communication solution ARM600 Vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/2nga002579</link>
      <description>&lt;p&gt;ABB is aware of public reports of a vulnerabilities in product versions listed as affected in this advisory. An attacker who successfully exploited these vulnerabilities could cause the product to stop, make the product inacces-sible, take remote control of the product or insert and run arbitrary code.
As part of ABB product lifecycle policy, once a product transitions to end-of-life, we discontinue maintenance, security patches, and technical support to focus on current and future technologies. While the product will continue to function, we strongly recommend implementing mitigations defined in this document, such as using a private APN cellular network between Arctic wireless gateways and ARM600 for establishing VPN tunnels, to mitigate security risks and avoid potential vulnerabilities.
As part of ABB product lifecycle policy, once a product transitions to Limited state, we discontinue maintenance, security patches, and technical support to focus on current and future technologies. While the product will continue to function, we strongly recommend implementing mitigations defined in this document to mitigate security risks.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ABB is aware of public reports of a vulnerabilities in product versions listed as affected in this advisory. An attacker who successfully exploited these vulnerabilities could cause the product to stop, make the product inacces-sible, take remote control of the product or insert and run arbitrary code.
As part of ABB product lifecycle policy, once a product transitions to end-of-life, we discontinue maintenance, security patches, and technical support to focus on current and future technologies. While the product will continue to function, we strongly recommend implementing mitigations defined in this document, such as using a private APN cellular network between Arctic wireless gateways and ARM600 for establishing VPN tunnels, to mitigate security risks and avoid potential vulnerabilities.
As part of ABB product lifecycle policy, once a product transitions to Limited state, we discontinue maintenance, security patches, and technical support to focus on current and future technologies. While the product will continue to function, we strongly recommend implementing mitigations defined in this document to mitigate security risks.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/2nga002579</guid>
    </item>
    <item>
      <title>ALSA-2022:6763 — Important: bind security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2022:6763</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: bind, AlmaLinux:9: bind-chroot, AlmaLinux:9: bind-devel, AlmaLinux:9: bind-dnssec-doc, AlmaLinux:9: bind-dnssec-utils, AlmaLinux:9: bind-libs, AlmaLinux:9: bind-license, AlmaLinux:9: bind-utils, AlmaLinux:9: python3-bind&lt;/p&gt;
&lt;p&gt;The Berkeley Internet Name Domain (BIND) is an implementation of the Domain Name System (DNS) protocols. BIND includes a DNS server (named); a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating correctly.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* bind: BIND 9 resolvers configured to answer from cache with zero stale-answer-timeout may terminate unexpectedly (CVE-2022-3080)
* bind: memory leak in ECDSA DNSSEC verification code (CVE-2022-38177)
* bind: memory leaks in EdDSA DNSSEC verification code (CVE-2022-38178)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: bind, AlmaLinux:9: bind-chroot, AlmaLinux:9: bind-devel, AlmaLinux:9: bind-dnssec-doc, AlmaLinux:9: bind-dnssec-utils, AlmaLinux:9: bind-libs, AlmaLinux:9: bind-license, AlmaLinux:9: bind-utils, AlmaLinux:9: python3-bind&lt;/p&gt;
&lt;p&gt;The Berkeley Internet Name Domain (BIND) is an implementation of the Domain Name System (DNS) protocols. BIND includes a DNS server (named); a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating correctly.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* bind: BIND 9 resolvers configured to answer from cache with zero stale-answer-timeout may terminate unexpectedly (CVE-2022-3080)
* bind: memory leak in ECDSA DNSSEC verification code (CVE-2022-38177)
* bind: memory leaks in EdDSA DNSSEC verification code (CVE-2022-38178)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2022:6763</guid>
    </item>
    <item>
      <title>bdu:2022-06121</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-06121</link>
      <description>bdu:2022-06121</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-06121</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2022-38178 — CVE-2022-38178 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2022-38178</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2022-38178</guid>
    </item>
    <item>
      <title>certfr-2022-avi-1059 — De multiples vulnérabilités ont été découvertes dans les produits IBM.
Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-1059</link>
      <description>certfr-2022-avi-1059</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-1059</guid>
    </item>
    <item>
      <title>EUVD-2026-241559</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-241559</link>
      <description>EUVD-2026-241559</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-241559</guid>
    </item>
    <item>
      <title>fkie_cve-2022-38178</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-38178</link>
      <description>&lt;p&gt;By spoofing the target resolver with responses that have a malformed EdDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;By spoofing the target resolver with responses that have a malformed EdDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-38178</guid>
    </item>
    <item>
      <title>GHSA-349w-cgp3-287r</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-349w-cgp3-287r</link>
      <description>&lt;p&gt;By spoofing the target resolver with responses that have a malformed EdDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;By spoofing the target resolver with responses that have a malformed EdDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-349w-cgp3-287r</guid>
    </item>
    <item>
      <title>gsd-2022-38178</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-38178</link>
      <description>gsd-2022-38178</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-38178</guid>
    </item>
    <item>
      <title>ICSA-25-105-08 — ABB M2M Gateway</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-25-105-08</link>
      <description>&lt;p&gt;ABB is aware of public reports of a vulnerabilities in product versions listed as affected in this advisory. An attacker who successfully exploited these vulnerabilities could cause the product to stop, make the product inacces-sible, take remote control of the product or insert and run arbitrary code.
As part of ABB product lifecycle policy, once a product transitions to end-of-life, we discontinue maintenance, security patches, and technical support to focus on current and future technologies. While the product will continue to function, we strongly recommend implementing mitigations defined in this document, such as using a private APN cellular network between Arctic wireless gateways and ARM600 for establishing VPN tunnels, to mitigate security risks and avoid potential vulnerabilities.
As part of ABB product lifecycle policy, once a product transitions to Limited state, we discontinue maintenance, security patches, and technical support to focus on current and future technologies. While the product will continue to function, we strongly recommend implementing mitigations defined in this document to mitigate security risks.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ABB is aware of public reports of a vulnerabilities in product versions listed as affected in this advisory. An attacker who successfully exploited these vulnerabilities could cause the product to stop, make the product inacces-sible, take remote control of the product or insert and run arbitrary code.
As part of ABB product lifecycle policy, once a product transitions to end-of-life, we discontinue maintenance, security patches, and technical support to focus on current and future technologies. While the product will continue to function, we strongly recommend implementing mitigations defined in this document, such as using a private APN cellular network between Arctic wireless gateways and ARM600 for establishing VPN tunnels, to mitigate security risks and avoid potential vulnerabilities.
As part of ABB product lifecycle policy, once a product transitions to Limited state, we discontinue maintenance, security patches, and technical support to focus on current and future technologies. While the product will continue to function, we strongly recommend implementing mitigations defined in this document to mitigate security risks.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-25-105-08</guid>
    </item>
    <item>
      <title>msrc_CVE-2022-38178 — Memory leaks in EdDSA DNSSEC verification code</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2022-38178</link>
      <description>msrc_CVE-2022-38178</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2022-38178</guid>
    </item>
    <item>
      <title>OESA-2022-1981 — bind security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2022-1981</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: bind&lt;/p&gt;
&lt;p&gt;BIND (Berkeley Internet Name Domain) is an implementation of the DNS (Domain Name System) protocols. BIND includes a DNS server (named), which resolves host names to IP addresses; a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating properly.&#13;
&#13;
&#13;
&#13;
Security Fix(es):&#13;
&#13;
By spoofing the target resolver with responses that have a malformed ECDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.(CVE-2022-38177)&#13;
&#13;
By spoofing the target resolver with responses that have a malformed EdDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.(CVE-2022-38178)&#13;
&#13;
By flooding the target resolver with queries exploiting this flaw an attacker can significantly impair the resolver&amp;amp;apos;s performance, effectively denying legitimate clients access to the DNS resolution service.(CVE-2022-2795)&#13;
&#13;
The underlying bug might cause read past end of the buffer and either read memory it should not read, or crash the process.(CVE-2022-2881)&#13;
&#13;
An attacker can leverage this flaw to gradually erode available memory to the point where named crashes for lack of resources. Upon restart the attacker would have to begin again, but nevertheless there is the potential to deny service.(CVE-2022-2906)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: bind&lt;/p&gt;
&lt;p&gt;BIND (Berkeley Internet Name Domain) is an implementation of the DNS (Domain Name System) protocols. BIND includes a DNS server (named), which resolves host names to IP addresses; a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating properly.&#13;
&#13;
&#13;
&#13;
Security Fix(es):&#13;
&#13;
By spoofing the target resolver with responses that have a malformed ECDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.(CVE-2022-38177)&#13;
&#13;
By spoofing the target resolver with responses that have a malformed EdDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.(CVE-2022-38178)&#13;
&#13;
By flooding the target resolver with queries exploiting this flaw an attacker can significantly impair the resolver&amp;amp;apos;s performance, effectively denying legitimate clients access to the DNS resolution service.(CVE-2022-2795)&#13;
&#13;
The underlying bug might cause read past end of the buffer and either read memory it should not read, or crash the process.(CVE-2022-2881)&#13;
&#13;
An attacker can leverage this flaw to gradually erode available memory to the point where named crashes for lack of resources. Upon restart the attacker would have to begin again, but nevertheless there is the potential to deny service.(CVE-2022-2906)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2022-1981</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:12356-1 — bind-9.18.7-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12356-1</link>
      <description>&lt;p&gt;bind-9.18.7-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;bind-9.18.7-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:12356-1</guid>
    </item>
    <item>
      <title>RHSA-2022:6764 — Red Hat Security Advisory: bind security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2022:6764</link>
      <description>&lt;p&gt;bind: memory leak in ECDSA DNSSEC verification code bind: memory leaks in EdDSA DNSSEC verification code&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;bind: memory leak in ECDSA DNSSEC verification code bind: memory leaks in EdDSA DNSSEC verification code&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2022:6764</guid>
    </item>
    <item>
      <title>SUSE-SU-2022:3499-1 — Security update for bind</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2022:3499-1</link>
      <description>&lt;p&gt;Security update for bind&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for bind&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2022:3499-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-38178</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-38178</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: bind9, Ubuntu:20.04:LTS: bind9, Ubuntu:22.04:LTS: bind9&lt;/p&gt;
&lt;p&gt;By spoofing the target resolver with responses that have a malformed EdDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: bind9, Ubuntu:20.04:LTS: bind9, Ubuntu:22.04:LTS: bind9&lt;/p&gt;
&lt;p&gt;By spoofing the target resolver with responses that have a malformed EdDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-38178</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-1492 — Internet Systems Consortium BIND: Mehrere Schwachstellen ermöglichen Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1492</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Internet Systems Consortium BIND ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Internet Systems Consortium BIND ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1492</guid>
    </item>
  </channel>
</rss>
