<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 19:13:34 +0000</lastBuildDate>
    <item>
      <title>bdu:2023-03248</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-03248</link>
      <description>bdu:2023-03248</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-03248</guid>
    </item>
    <item>
      <title>EUVD-2026-214628</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-214628</link>
      <description>EUVD-2026-214628</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-214628</guid>
    </item>
    <item>
      <title>fkie_cve-2023-26964</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-26964</link>
      <description>&lt;p&gt;An issue was discovered in hyper v0.13.7. h2-0.2.4 Stream stacking occurs when the H2 component processes HTTP2 RST_STREAM frames. As a result, the memory and CPU usage are high which can lead to a Denial of Service (DoS).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An issue was discovered in hyper v0.13.7. h2-0.2.4 Stream stacking occurs when the H2 component processes HTTP2 RST_STREAM frames. As a result, the memory and CPU usage are high which can lead to a Denial of Service (DoS).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-26964</guid>
    </item>
    <item>
      <title>GHSA-f8vr-r385-rh5r — h2 vulnerable to denial of service</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-f8vr-r385-rh5r</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: h2&lt;/p&gt;
&lt;p&gt;Hyper is an HTTP library for Rust and h2 is an HTTP 2.0 client &amp;amp; server implementation for Rust. An issue was discovered in h2 v0.2.4 when processing header frames. It incorrectly processes the HTTP2 `RST_STREAM` frames by not always releasing the memory immediately upon receiving the reset frame, leading to stream stacking. As a result, the memory and CPU usage are high which can lead to a Denial of Service (DoS).&lt;/p&gt;
&lt;p&gt;This issue affects users only when dealing with http2 connections.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: h2&lt;/p&gt;
&lt;p&gt;Hyper is an HTTP library for Rust and h2 is an HTTP 2.0 client &amp;amp; server implementation for Rust. An issue was discovered in h2 v0.2.4 when processing header frames. It incorrectly processes the HTTP2 `RST_STREAM` frames by not always releasing the memory immediately upon receiving the reset frame, leading to stream stacking. As a result, the memory and CPU usage are high which can lead to a Denial of Service (DoS).&lt;/p&gt;
&lt;p&gt;This issue affects users only when dealing with http2 connections.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-f8vr-r385-rh5r</guid>
    </item>
    <item>
      <title>gsd-2023-26964</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-26964</link>
      <description>gsd-2023-26964</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-26964</guid>
    </item>
    <item>
      <title>msrc_CVE-2023-26964 — An issue was discovered in hyper v0.13.7. h2-0.2.4 Stream stacking occurs when the H2 component processes HTTP2 RST_STR…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2023-26964</link>
      <description>msrc_CVE-2023-26964</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2023-26964</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:0294-1 — Security update for kanidm</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:0294-1</link>
      <description>&lt;p&gt;Security update for kanidm&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for kanidm&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:0294-1</guid>
    </item>
    <item>
      <title>RUSTSEC-2023-0034 — Resource exhaustion vulnerability in h2 may lead to Denial of Service (DoS)</title>
      <link>https://cve.radiocsirt.org/vuln/rustsec-2023-0034</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: h2&lt;/p&gt;
&lt;p&gt;If an attacker is able to flood the network with pairs of `HEADERS`/`RST_STREAM` frames, such that the `h2` application is not able to accept them faster than the bytes are received, the pending accept queue can grow in memory usage. Being able to do this consistently can result in excessive memory use, and eventually trigger Out Of Memory.&lt;/p&gt;
&lt;p&gt;This flaw is corrected in [hyperium/h2#668](https://github.com/hyperium/h2/pull/668), which restricts remote reset stream count by default.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: h2&lt;/p&gt;
&lt;p&gt;If an attacker is able to flood the network with pairs of `HEADERS`/`RST_STREAM` frames, such that the `h2` application is not able to accept them faster than the bytes are received, the pending accept queue can grow in memory usage. Being able to do this consistently can result in excessive memory use, and eventually trigger Out Of Memory.&lt;/p&gt;
&lt;p&gt;This flaw is corrected in [hyperium/h2#668](https://github.com/hyperium/h2/pull/668), which restricts remote reset stream count by default.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rustsec-2023-0034</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:02809-1 — Security update for rust-keylime</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:02809-1</link>
      <description>&lt;p&gt;Security update for rust-keylime&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for rust-keylime&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:02809-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2023-26964</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-26964</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: rust-hyper, Ubuntu:24.04:LTS: rust-hyper, Ubuntu:25.10: rust-hyper, Ubuntu:26.04:LTS: rust-hyper&lt;/p&gt;
&lt;p&gt;An issue was discovered in hyper v0.13.7. h2-0.2.4 Stream stacking occurs when the H2 component processes HTTP2 RST_STREAM frames. As a result, the memory and CPU usage are high which can lead to a Denial of Service (DoS).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: rust-hyper, Ubuntu:24.04:LTS: rust-hyper, Ubuntu:25.10: rust-hyper, Ubuntu:26.04:LTS: rust-hyper&lt;/p&gt;
&lt;p&gt;An issue was discovered in hyper v0.13.7. h2-0.2.4 Stream stacking occurs when the H2 component processes HTTP2 RST_STREAM frames. As a result, the memory and CPU usage are high which can lead to a Denial of Service (DoS).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-26964</guid>
    </item>
  </channel>
</rss>
