<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 13:39:52 +0000</lastBuildDate>
    <item>
      <title>ALSA-2023:3722 — Moderate: openssl security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2023:3722</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: openssl, AlmaLinux:9: openssl-devel, AlmaLinux:9: openssl-libs, AlmaLinux:9: openssl-perl&lt;/p&gt;
&lt;p&gt;OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, as well as a full-strength general-purpose cryptography library.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* openssl: Possible DoS translating ASN.1 object identifiers (CVE-2023-2650)
* openssl: Denial of service by excessive resource usage in verifying X509 policy constraints (CVE-2023-0464)
* openssl: Invalid certificate policies in leaf certificates are silently ignored (CVE-2023-0465)
* openssl: Certificate policy check not enabled (CVE-2023-0466)
* openssl: Input buffer over-read in AES-XTS implementation on 64 bit ARM (CVE-2023-1255)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Bug Fix(es):&lt;/p&gt;
&lt;p&gt;* In FIPS mode, openssl KDFs should only allow selected hash algorithms (BZ#2175860)
* In FIPS mode, openssl should reject short KDF input or output keys or provide an indicator (BZ#2175864)
* In FIPS mode, openssl should provide an indicator for AES-GCM to query whether the IV was generated internally or provided externally (BZ#2175868)
* openssl FIPS mode self-test should zeroize `out` in `verify_integrity` in providers/fips/self_test.c (BZ#2175873)
* In FIPS mode, openssl should not support RSA encryption or decryption without padding (outside of RSASVE) or provide an indicator (BZ#2178029)
* In FIPS mode, openssl should reject EVP_PKEY_fromdata…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: openssl, AlmaLinux:9: openssl-devel, AlmaLinux:9: openssl-libs, AlmaLinux:9: openssl-perl&lt;/p&gt;
&lt;p&gt;OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, as well as a full-strength general-purpose cryptography library.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* openssl: Possible DoS translating ASN.1 object identifiers (CVE-2023-2650)
* openssl: Denial of service by excessive resource usage in verifying X509 policy constraints (CVE-2023-0464)
* openssl: Invalid certificate policies in leaf certificates are silently ignored (CVE-2023-0465)
* openssl: Certificate policy check not enabled (CVE-2023-0466)
* openssl: Input buffer over-read in AES-XTS implementation on 64 bit ARM (CVE-2023-1255)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Bug Fix(es):&lt;/p&gt;
&lt;p&gt;* In FIPS mode, openssl KDFs should only allow selected hash algorithms (BZ#2175860)
* In FIPS mode, openssl should reject short KDF input or output keys or provide an indicator (BZ#2175864)
* In FIPS mode, openssl should provide an indicator for AES-GCM to query whether the IV was generated internally or provided externally (BZ#2175868)
* openssl FIPS mode self-test should zeroize `out` in `verify_integrity` in providers/fips/self_test.c (BZ#2175873)
* In FIPS mode, openssl should not support RSA encryption or decryption without padding (outside of RSASVE) or provide an indicator (BZ#2178029)
* In FIPS mode, openssl should reject EVP_PKEY_fromdata…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2023:3722</guid>
    </item>
    <item>
      <title>bdu:2023-02108</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-02108</link>
      <description>bdu:2023-02108</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-02108</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2023-0464 — CVE-2023-0464 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2023-0464</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2023-0464</guid>
    </item>
    <item>
      <title>certfr-2023-avi-0255 — Une vulnérabilité a été découverte dans OpenSSL. Elle permet à un
attaquant de provoquer un déni de service à distance.</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0255</link>
      <description>certfr-2023-avi-0255</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0255</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-GK72927 — Issue summary: PBMAC1 parameters in PKCS#12 files are missing validation
which can trigger a stack-based buffer overflo…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-gk72927</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: openssl&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the openssl package. Issue summary: PBMAC1 parameters in PKCS#12 files are missing validation which can trigger a stack-based buffer overflow, invalid pointer or NULL pointer dereference during MAC verification. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: openssl&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the openssl package. Issue summary: PBMAC1 parameters in PKCS#12 files are missing validation which can trigger a stack-based buffer overflow, invalid pointer or NULL pointer dereference during MAC verification. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-gk72927</guid>
    </item>
    <item>
      <title>EUVD-2026-237293</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-237293</link>
      <description>EUVD-2026-237293</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-237293</guid>
    </item>
    <item>
      <title>fkie_cve-2023-0464</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-0464</link>
      <description>&lt;p&gt;A security vulnerability has been identified in all supported versions&lt;/p&gt;
&lt;p&gt;of OpenSSL related to the verification of X.509 certificate chains
that include policy constraints.  Attackers may be able to exploit this
vulnerability by creating a malicious certificate chain that triggers
exponential use of computational resources, leading to a denial-of-service
(DoS) attack on affected systems.&lt;/p&gt;
&lt;p&gt;Policy processing is disabled by default but can be enabled by passing
the `-policy&amp;#39; argument to the command line utilities or by calling the
`X509_VERIFY_PARAM_set1_policies()&amp;#39; function.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A security vulnerability has been identified in all supported versions&lt;/p&gt;
&lt;p&gt;of OpenSSL related to the verification of X.509 certificate chains
that include policy constraints.  Attackers may be able to exploit this
vulnerability by creating a malicious certificate chain that triggers
exponential use of computational resources, leading to a denial-of-service
(DoS) attack on affected systems.&lt;/p&gt;
&lt;p&gt;Policy processing is disabled by default but can be enabled by passing
the `-policy&amp;#39; argument to the command line utilities or by calling the
`X509_VERIFY_PARAM_set1_policies()&amp;#39; function.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-0464</guid>
    </item>
    <item>
      <title>GHSA-w2w6-xp88-5cvw</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-w2w6-xp88-5cvw</link>
      <description>&lt;p&gt;A security vulnerability has been identified in all supported versions of OpenSSL related to the verification of X.509 certificate chains that include policy constraints. Attackers may be able to exploit this vulnerability by creating a malicious certificate chain that triggers exponential use of computational resources, leading to a denial-of-service (DoS) attack on affected systems. Policy processing is disabled by default but can be enabled by passing the `-policy&amp;#39; argument to the command line utilities or by calling the `X509_VERIFY_PARAM_set1_policies()&amp;#39; function.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A security vulnerability has been identified in all supported versions of OpenSSL related to the verification of X.509 certificate chains that include policy constraints. Attackers may be able to exploit this vulnerability by creating a malicious certificate chain that triggers exponential use of computational resources, leading to a denial-of-service (DoS) attack on affected systems. Policy processing is disabled by default but can be enabled by passing the `-policy&amp;#39; argument to the command line utilities or by calling the `X509_VERIFY_PARAM_set1_policies()&amp;#39; function.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-w2w6-xp88-5cvw</guid>
    </item>
    <item>
      <title>gsd-2023-0464</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-0464</link>
      <description>gsd-2023-0464</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-0464</guid>
    </item>
    <item>
      <title>ICSA-23-166-11 — Siemens SIMATIC S7-1500 TM MFP Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-23-166-11</link>
      <description>&lt;p&gt;json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend. A memory overflow vulnerability was found in the Linux kernel’s ipc functionality of the memcg subsystem, in the way a user calls the semget function multiple times, creating semaphores. This flaw allows a local user to starve the resources, causing a denial of service. The highest threat from this vulnerability is to system availability. A vulnerability was found in the fs/inode.c:inode_init_owner() function logic of the LInux kernel that allows local users to create files for the XFS file-system with an unintended group ownership and with group execution and SGID permission bits set, in a scenario where a directory is SGID and belongs to a certain group and is writable by a user who is not a member of this group. This can lead to excessive permissions granted in case when they should not. This vulnerability is similar to the previous CVE-2018-13405 and adds the missed fix for the XFS. When sending malicous data to kernel by ioctl cmd FBIOPUT_VSCREENINFO,kernel will write memory out of bounds. In gc_data_segment in fs/f2fs/gc.c in the Linux kernel before 5.16.3, special files are not considered, leading to a move_data_page NULL pointer dereference. A flaw was found in the Linux kernel. The existing KVM SEV API has a vulnerability that allows a non-root (host) user-level application to crash the host kernel by creating a confidential guest VM inst…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend. A memory overflow vulnerability was found in the Linux kernel’s ipc functionality of the memcg subsystem, in the way a user calls the semget function multiple times, creating semaphores. This flaw allows a local user to starve the resources, causing a denial of service. The highest threat from this vulnerability is to system availability. A vulnerability was found in the fs/inode.c:inode_init_owner() function logic of the LInux kernel that allows local users to create files for the XFS file-system with an unintended group ownership and with group execution and SGID permission bits set, in a scenario where a directory is SGID and belongs to a certain group and is writable by a user who is not a member of this group. This can lead to excessive permissions granted in case when they should not. This vulnerability is similar to the previous CVE-2018-13405 and adds the missed fix for the XFS. When sending malicous data to kernel by ioctl cmd FBIOPUT_VSCREENINFO,kernel will write memory out of bounds. In gc_data_segment in fs/f2fs/gc.c in the Linux kernel before 5.16.3, special files are not considered, leading to a move_data_page NULL pointer dereference. A flaw was found in the Linux kernel. The existing KVM SEV API has a vulnerability that allows a non-root (host) user-level application to crash the host kernel by creating a confidential guest VM inst…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-23-166-11</guid>
    </item>
    <item>
      <title>OESA-2023-1207 — openssl security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2023-1207</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: openssl, openEuler:20.03-LTS-SP3: openssl, openEuler:22.03-LTS: openssl, openEuler:22.03-LTS-SP1: openssl&lt;/p&gt;
&lt;p&gt;OpenSSL is a robust, commercial-grade, and full-featured toolkit for the Transport Layer Security (TLS) and Secure Sockets Layer (SSL) protocols.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A security vulnerability has been identified in all supported versions of OpenSSL related to the verification of X.509 certificate chains that include policy constraints. Attackers may be able to exploit this vulnerability by creating a malicious certificate chain that triggers exponential use of computational resources, leading to a denial-of-service (DoS) attack on affected systems. Policy processing is disabled by default but can be enabled by passing the `-policy&amp;amp;apos; argument to the command line utilities or by calling the `X509_VERIFY_PARAM_set1_policies()&amp;amp;apos; function.(CVE-2023-0464)&#13;
&#13;
Applications that use a non-default option when verifying certificates may be vulnerable to an attack from a malicious CA to circumvent certain checks. Invalid certificate policies in leaf certificates are silently ignored by OpenSSL and other certificate policy checks are skipped for that certificate. A malicious CA could use this to deliberately assert invalid certificate policies in order to circumvent policy checking on the certificate altogether. Policy processing is disabled by default but can be enabled by passing the `-policy&amp;amp;apos; argument to the command line utilities or by calling the `X509_VERIFY_PARAM_set1_policies()&amp;amp;apos; function.(CVE-2023-0465)&#13;
&#13;
The function X509_VERIFY_PARAM_add0_policy() is docum…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: openssl, openEuler:20.03-LTS-SP3: openssl, openEuler:22.03-LTS: openssl, openEuler:22.03-LTS-SP1: openssl&lt;/p&gt;
&lt;p&gt;OpenSSL is a robust, commercial-grade, and full-featured toolkit for the Transport Layer Security (TLS) and Secure Sockets Layer (SSL) protocols.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A security vulnerability has been identified in all supported versions of OpenSSL related to the verification of X.509 certificate chains that include policy constraints. Attackers may be able to exploit this vulnerability by creating a malicious certificate chain that triggers exponential use of computational resources, leading to a denial-of-service (DoS) attack on affected systems. Policy processing is disabled by default but can be enabled by passing the `-policy&amp;amp;apos; argument to the command line utilities or by calling the `X509_VERIFY_PARAM_set1_policies()&amp;amp;apos; function.(CVE-2023-0464)&#13;
&#13;
Applications that use a non-default option when verifying certificates may be vulnerable to an attack from a malicious CA to circumvent certain checks. Invalid certificate policies in leaf certificates are silently ignored by OpenSSL and other certificate policy checks are skipped for that certificate. A malicious CA could use this to deliberately assert invalid certificate policies in order to circumvent policy checking on the certificate altogether. Policy processing is disabled by default but can be enabled by passing the `-policy&amp;amp;apos; argument to the command line utilities or by calling the `X509_VERIFY_PARAM_set1_policies()&amp;amp;apos; function.(CVE-2023-0465)&#13;
&#13;
The function X509_VERIFY_PARAM_add0_policy() is docum…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2023-1207</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:12824-1 — libopenssl-1_0_0-devel-1.0.2u-14.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12824-1</link>
      <description>&lt;p&gt;libopenssl-1_0_0-devel-1.0.2u-14.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libopenssl-1_0_0-devel-1.0.2u-14.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:12824-1</guid>
    </item>
    <item>
      <title>RHSA-2023:7622 — Red Hat Security Advisory: Red Hat JBoss Web Server 5.7.7 release and security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2023:7622</link>
      <description>&lt;p&gt;openssl: Denial of service by excessive resource usage in verifying X509 policy constraints openssl: Invalid certificate policies in leaf certificates are silently ignored openssl: Certificate policy check not enabled openssl: Possible DoS translating ASN.1 object identifiers openssl: Excessive time spent checking DH keys and parameters OpenSSL: Excessive time spent checking DH q parameter value tomcat: Open Redirect vulnerability in FORM authentication&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;openssl: Denial of service by excessive resource usage in verifying X509 policy constraints openssl: Invalid certificate policies in leaf certificates are silently ignored openssl: Certificate policy check not enabled openssl: Possible DoS translating ASN.1 object identifiers openssl: Excessive time spent checking DH keys and parameters OpenSSL: Excessive time spent checking DH q parameter value tomcat: Open Redirect vulnerability in FORM authentication&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2023:7622</guid>
    </item>
    <item>
      <title>SUSE-SU-2023:1704-1 — Security update for openssl-1_0_0</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2023:1704-1</link>
      <description>&lt;p&gt;Security update for openssl-1_0_0&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for openssl-1_0_0&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2023:1704-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2023-0464</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-0464</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: openssl, Ubuntu:Pro:16.04:LTS: openssl, Ubuntu:Pro:16.04:LTS: edk2, Ubuntu:Pro:FIPS:16.04:LTS: openssl, Ubuntu:18.04:LTS: openssl, Ubuntu:18.04:LTS: openssl1.0, Ubuntu:Pro:18.04:LTS: edk2, Ubuntu:Pro:FIPS-updates:18.04:LTS: openssl, Ubuntu:Pro:FIPS:18.04:LTS: openssl, Ubuntu:20.04:LTS: openssl and 6 more&lt;/p&gt;
&lt;p&gt;A security vulnerability has been identified in all supported versions of OpenSSL related to the verification of X.509 certificate chains that include policy constraints.  Attackers may be able to exploit this vulnerability by creating a malicious certificate chain that triggers exponential use of computational resources, leading to a denial-of-service (DoS) attack on affected systems. Policy processing is disabled by default but can be enabled by passing the `-policy&amp;#39; argument to the command line utilities or by calling the `X509_VERIFY_PARAM_set1_policies()&amp;#39; function.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: openssl, Ubuntu:Pro:16.04:LTS: openssl, Ubuntu:Pro:16.04:LTS: edk2, Ubuntu:Pro:FIPS:16.04:LTS: openssl, Ubuntu:18.04:LTS: openssl, Ubuntu:18.04:LTS: openssl1.0, Ubuntu:Pro:18.04:LTS: edk2, Ubuntu:Pro:FIPS-updates:18.04:LTS: openssl, Ubuntu:Pro:FIPS:18.04:LTS: openssl, Ubuntu:20.04:LTS: openssl and 6 more&lt;/p&gt;
&lt;p&gt;A security vulnerability has been identified in all supported versions of OpenSSL related to the verification of X.509 certificate chains that include policy constraints.  Attackers may be able to exploit this vulnerability by creating a malicious certificate chain that triggers exponential use of computational resources, leading to a denial-of-service (DoS) attack on affected systems. Policy processing is disabled by default but can be enabled by passing the `-policy&amp;#39; argument to the command line utilities or by calling the `X509_VERIFY_PARAM_set1_policies()&amp;#39; function.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-0464</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-0732 — OpenSSL: Schwachstelle ermöglicht Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0732</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in OpenSSL ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in OpenSSL ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0732</guid>
    </item>
  </channel>
</rss>
