<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 11:58:26 +0000</lastBuildDate>
    <item>
      <title>ALSA-2023:3083 — Moderate: go-toolset:rhel8 security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2023:3083</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: delve, AlmaLinux:8: go-toolset, AlmaLinux:8: golang, AlmaLinux:8: golang-bin, AlmaLinux:8: golang-docs, AlmaLinux:8: golang-misc, AlmaLinux:8: golang-race, AlmaLinux:8: golang-src, AlmaLinux:8: golang-tests&lt;/p&gt;
&lt;p&gt;Go Toolset provides the Go programming language tools and libraries. Go is alternatively known as golang.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* golang: crypto/tls: large handshake records may cause panics (CVE-2022-41724)
* golang: net/http, mime/multipart: denial of service from excessive resource consumption (CVE-2022-41725)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Bug Fix(es):&lt;/p&gt;
&lt;p&gt;* Backport fix for https://github.com/golang/go/issues/56891 (BZ#2167412)
* Update Go to 1.19.6 (BZ#2174430)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: delve, AlmaLinux:8: go-toolset, AlmaLinux:8: golang, AlmaLinux:8: golang-bin, AlmaLinux:8: golang-docs, AlmaLinux:8: golang-misc, AlmaLinux:8: golang-race, AlmaLinux:8: golang-src, AlmaLinux:8: golang-tests&lt;/p&gt;
&lt;p&gt;Go Toolset provides the Go programming language tools and libraries. Go is alternatively known as golang.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* golang: crypto/tls: large handshake records may cause panics (CVE-2022-41724)
* golang: net/http, mime/multipart: denial of service from excessive resource consumption (CVE-2022-41725)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Bug Fix(es):&lt;/p&gt;
&lt;p&gt;* Backport fix for https://github.com/golang/go/issues/56891 (BZ#2167412)
* Update Go to 1.19.6 (BZ#2174430)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2023:3083</guid>
    </item>
    <item>
      <title>bdu:2024-03152</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-03152</link>
      <description>bdu:2024-03152</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-03152</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2022-41724 — CVE-2022-41724 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2022-41724</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2022-41724</guid>
    </item>
    <item>
      <title>BIT-golang-2022-41724 — Panic on large handshake records in crypto/tls</title>
      <link>https://cve.radiocsirt.org/vuln/bit-golang-2022-41724</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: golang&lt;/p&gt;
&lt;p&gt;Large handshake records may cause panics in crypto/tls. Both clients and servers may send large TLS handshake records which cause servers and clients, respectively, to panic when attempting to construct responses. This affects all TLS 1.3 clients, TLS 1.2 clients which explicitly enable session resumption (by setting Config.ClientSessionCache to a non-nil value), and TLS 1.3 servers which request client certificates (by setting Config.ClientAuth &amp;gt;= RequestClientCert).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: golang&lt;/p&gt;
&lt;p&gt;Large handshake records may cause panics in crypto/tls. Both clients and servers may send large TLS handshake records which cause servers and clients, respectively, to panic when attempting to construct responses. This affects all TLS 1.3 clients, TLS 1.2 clients which explicitly enable session resumption (by setting Config.ClientSessionCache to a non-nil value), and TLS 1.3 servers which request client certificates (by setting Config.ClientAuth &amp;gt;= RequestClientCert).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-golang-2022-41724</guid>
    </item>
    <item>
      <title>certfr-2023-avi-0272 — De multiples vulnérabilités ont été découvertes dans les produits &lt;span
class="textit"&gt;IBM&lt;/span&gt;. Elles permettent à u…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0272</link>
      <description>certfr-2023-avi-0272</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0272</guid>
    </item>
    <item>
      <title>EUVD-2026-221298</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-221298</link>
      <description>EUVD-2026-221298</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-221298</guid>
    </item>
    <item>
      <title>fkie_cve-2022-41724</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-41724</link>
      <description>&lt;p&gt;Large handshake records may cause panics in crypto/tls. Both clients and servers may send large TLS handshake records which cause servers and clients, respectively, to panic when attempting to construct responses. This affects all TLS 1.3 clients, TLS 1.2 clients which explicitly enable session resumption (by setting Config.ClientSessionCache to a non-nil value), and TLS 1.3 servers which request client certificates (by setting Config.ClientAuth &amp;gt;= RequestClientCert).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Large handshake records may cause panics in crypto/tls. Both clients and servers may send large TLS handshake records which cause servers and clients, respectively, to panic when attempting to construct responses. This affects all TLS 1.3 clients, TLS 1.2 clients which explicitly enable session resumption (by setting Config.ClientSessionCache to a non-nil value), and TLS 1.3 servers which request client certificates (by setting Config.ClientAuth &amp;gt;= RequestClientCert).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-41724</guid>
    </item>
    <item>
      <title>GHSA-89mw-w342-mqrr</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-89mw-w342-mqrr</link>
      <description>&lt;p&gt;Large handshake records may cause panics in crypto/tls. Both clients and servers may send large TLS handshake records which cause servers and clients, respectively, to panic when attempting to construct responses. This affects all TLS 1.3 clients, TLS 1.2 clients which explicitly enable session resumption (by setting Config.ClientSessionCache to a non-nil value), and TLS 1.3 servers which request client certificates (by setting Config.ClientAuth &amp;gt;= RequestClientCert).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Large handshake records may cause panics in crypto/tls. Both clients and servers may send large TLS handshake records which cause servers and clients, respectively, to panic when attempting to construct responses. This affects all TLS 1.3 clients, TLS 1.2 clients which explicitly enable session resumption (by setting Config.ClientSessionCache to a non-nil value), and TLS 1.3 servers which request client certificates (by setting Config.ClientAuth &amp;gt;= RequestClientCert).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-89mw-w342-mqrr</guid>
    </item>
    <item>
      <title>gsd-2022-41724</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-41724</link>
      <description>gsd-2022-41724</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-41724</guid>
    </item>
    <item>
      <title>msrc_CVE-2022-41724 — Panic on large handshake records in crypto/tls</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2022-41724</link>
      <description>msrc_CVE-2022-41724</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2022-41724</guid>
    </item>
    <item>
      <title>OESA-2023-1192 — golang security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2023-1192</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: golang, openEuler:20.03-LTS-SP3: golang, openEuler:22.03-LTS: golang, openEuler:22.03-LTS-SP1: golang&lt;/p&gt;
&lt;p&gt;The Go Programming Language.&#13;
&#13;
&#13;
&#13;
Security Fix(es):&#13;
&#13;
A maliciously crafted HTTP/2 stream could cause excessive CPU consumption in the HPACK decoder, sufficient to cause a denial of service from a small number of small requests.(CVE-2022-41723)&#13;
&#13;
Large handshake records may cause panics in crypto/tls. Both clients and servers may send large TLS handshake records which cause servers and clients, respectively, to panic when attempting to construct responses. This affects all TLS 1.3 clients, TLS 1.2 clients which explicitly enable session resumption (by setting Config.ClientSessionCache to a non-nil value), and TLS 1.3 servers which request client certificates (by setting Config.ClientAuth &amp;amp;gt;= RequestClientCert).(CVE-2022-41724)&#13;
&#13;
A denial of service is possible from excessive resource consumption in net/http and mime/multipart. Multipart form parsing with mime/multipart.Reader.ReadForm can consume largely unlimited amounts of memory and disk files. This also affects form parsing in the net/http package with the Request methods FormFile, FormValue, ParseMultipartForm, and PostFormValue. ReadForm takes a maxMemory parameter, and is documented as storing &amp;amp;quot;up to maxMemory bytes +10MB (reserved for non-file parts) in memory&amp;amp;quot;. File parts which cannot be stored in memory are stored on disk in temporary files. The unconfigurable 10MB reserved for non-file parts is excessively large and can potentially open a denial of service vector on its own. However, ReadForm did…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: golang, openEuler:20.03-LTS-SP3: golang, openEuler:22.03-LTS: golang, openEuler:22.03-LTS-SP1: golang&lt;/p&gt;
&lt;p&gt;The Go Programming Language.&#13;
&#13;
&#13;
&#13;
Security Fix(es):&#13;
&#13;
A maliciously crafted HTTP/2 stream could cause excessive CPU consumption in the HPACK decoder, sufficient to cause a denial of service from a small number of small requests.(CVE-2022-41723)&#13;
&#13;
Large handshake records may cause panics in crypto/tls. Both clients and servers may send large TLS handshake records which cause servers and clients, respectively, to panic when attempting to construct responses. This affects all TLS 1.3 clients, TLS 1.2 clients which explicitly enable session resumption (by setting Config.ClientSessionCache to a non-nil value), and TLS 1.3 servers which request client certificates (by setting Config.ClientAuth &amp;amp;gt;= RequestClientCert).(CVE-2022-41724)&#13;
&#13;
A denial of service is possible from excessive resource consumption in net/http and mime/multipart. Multipart form parsing with mime/multipart.Reader.ReadForm can consume largely unlimited amounts of memory and disk files. This also affects form parsing in the net/http package with the Request methods FormFile, FormValue, ParseMultipartForm, and PostFormValue. ReadForm takes a maxMemory parameter, and is documented as storing &amp;amp;quot;up to maxMemory bytes +10MB (reserved for non-file parts) in memory&amp;amp;quot;. File parts which cannot be stored in memory are stored on disk in temporary files. The unconfigurable 10MB reserved for non-file parts is excessively large and can potentially open a denial of service vector on its own. However, ReadForm did…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2023-1192</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:12707-1 — go1.19-1.19.6-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12707-1</link>
      <description>&lt;p&gt;go1.19-1.19.6-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;go1.19-1.19.6-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:12707-1</guid>
    </item>
    <item>
      <title>RHBA-2023:4275 — Red Hat Bug Fix Advisory: Red Hat Quay v3.8.11 bug fix release</title>
      <link>https://cve.radiocsirt.org/vuln/rhba-2023:4275</link>
      <description>&lt;p&gt;golang: net/http: handle server errors after sending GOAWAY golang: golang.org/x/text/language: ParseAcceptLanguage takes a long time to parse complex tags golang: net/url: JoinPath does not strip relative path components in all circumstances golang: net/http: excessive memory growth in a Go server accepting HTTP/2 requests golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding golang: crypto/tls: large handshake records may cause panics golang: net/http, mime/multipart: denial of service from excessive resource consumption golang: net/http, net/textproto: denial of service from excessive memory allocation golang: net/http, net/textproto, mime/multipart: denial of service from excessive resource consumption golang: go/parser: Infinite loop in parsing golang: html/template: backticks not treated as string delimiters golang: html/template: improper sanitization of CSS values golang: html/template: improper handling of JavaScript whitespace golang: html/template: improper handling of empty HTML attributes&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;golang: net/http: handle server errors after sending GOAWAY golang: golang.org/x/text/language: ParseAcceptLanguage takes a long time to parse complex tags golang: net/url: JoinPath does not strip relative path components in all circumstances golang: net/http: excessive memory growth in a Go server accepting HTTP/2 requests golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding golang: crypto/tls: large handshake records may cause panics golang: net/http, mime/multipart: denial of service from excessive resource consumption golang: net/http, net/textproto: denial of service from excessive memory allocation golang: net/http, net/textproto, mime/multipart: denial of service from excessive resource consumption golang: go/parser: Infinite loop in parsing golang: html/template: backticks not treated as string delimiters golang: html/template: improper sanitization of CSS values golang: html/template: improper handling of JavaScript whitespace golang: html/template: improper handling of empty HTML attributes&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhba-2023:4275</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-41724</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-41724</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: golang-1.18, Ubuntu:Pro:16.04:LTS: golang-1.13, Ubuntu:Pro:18.04:LTS: golang-1.13, Ubuntu:Pro:18.04:LTS: golang-1.16, Ubuntu:Pro:18.04:LTS: golang-1.18, Ubuntu:20.04:LTS: golang-1.18, Ubuntu:20.04:LTS: golang-1.13, Ubuntu:20.04:LTS: golang-1.14, Ubuntu:Pro:20.04:LTS: golang-1.16, Ubuntu:22.04:LTS: golang-1.17 and 2 more&lt;/p&gt;
&lt;p&gt;Large handshake records may cause panics in crypto/tls. Both clients and servers may send large TLS handshake records which cause servers and clients, respectively, to panic when attempting to construct responses. This affects all TLS 1.3 clients, TLS 1.2 clients which explicitly enable session resumption (by setting Config.ClientSessionCache to a non-nil value), and TLS 1.3 servers which request client certificates (by setting Config.ClientAuth &amp;gt;= RequestClientCert).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: golang-1.18, Ubuntu:Pro:16.04:LTS: golang-1.13, Ubuntu:Pro:18.04:LTS: golang-1.13, Ubuntu:Pro:18.04:LTS: golang-1.16, Ubuntu:Pro:18.04:LTS: golang-1.18, Ubuntu:20.04:LTS: golang-1.18, Ubuntu:20.04:LTS: golang-1.13, Ubuntu:20.04:LTS: golang-1.14, Ubuntu:Pro:20.04:LTS: golang-1.16, Ubuntu:22.04:LTS: golang-1.17 and 2 more&lt;/p&gt;
&lt;p&gt;Large handshake records may cause panics in crypto/tls. Both clients and servers may send large TLS handshake records which cause servers and clients, respectively, to panic when attempting to construct responses. This affects all TLS 1.3 clients, TLS 1.2 clients which explicitly enable session resumption (by setting Config.ClientSessionCache to a non-nil value), and TLS 1.3 servers which request client certificates (by setting Config.ClientAuth &amp;gt;= RequestClientCert).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-41724</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-0523 — IBM DataPower Gateway: Schwachstelle ermöglicht Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0523</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in IBM DataPower Gateway ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in IBM DataPower Gateway ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0523</guid>
    </item>
  </channel>
</rss>
