<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 10:33:41 +0000</lastBuildDate>
    <item>
      <title>ALSA-2023:7762 — Moderate: skopeo security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2023:7762</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: skopeo, AlmaLinux:9: skopeo-tests&lt;/p&gt;
&lt;p&gt;The skopeo command lets you inspect images from container image registries, get images and image layers, and use signatures to create and verify files.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* golang: crypto/tls: slow verification of certificate chains containing large RSA keys (CVE-2023-29409)
* golang: html/template: improper handling of HTML-like comments within script contexts (CVE-2023-39318)
* golang: html/template: improper handling of special tags within script contexts (CVE-2023-39319)
* golang: crypto/tls: panic when processing post-handshake message on QUIC connections (CVE-2023-39321)
* golang: crypto/tls: lack of a limit on buffered post-handshake (CVE-2023-39322)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: skopeo, AlmaLinux:9: skopeo-tests&lt;/p&gt;
&lt;p&gt;The skopeo command lets you inspect images from container image registries, get images and image layers, and use signatures to create and verify files.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* golang: crypto/tls: slow verification of certificate chains containing large RSA keys (CVE-2023-29409)
* golang: html/template: improper handling of HTML-like comments within script contexts (CVE-2023-39318)
* golang: html/template: improper handling of special tags within script contexts (CVE-2023-39319)
* golang: crypto/tls: panic when processing post-handshake message on QUIC connections (CVE-2023-39321)
* golang: crypto/tls: lack of a limit on buffered post-handshake (CVE-2023-39322)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2023:7762</guid>
    </item>
    <item>
      <title>BELL-CVE-2023-39322</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2023-39322</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: go, BellSoft Hardened Containers:23: go&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: go, BellSoft Hardened Containers:23: go&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2023-39322</guid>
    </item>
    <item>
      <title>BIT-golang-2023-39322 — Memory exhaustion in QUIC connection handling in crypto/tls</title>
      <link>https://cve.radiocsirt.org/vuln/bit-golang-2023-39322</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: golang&lt;/p&gt;
&lt;p&gt;QUIC connections do not set an upper bound on the amount of data buffered when reading post-handshake messages, allowing a malicious QUIC connection to cause unbounded memory growth. With fix, connections now consistently reject messages larger than 65KiB in size.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: golang&lt;/p&gt;
&lt;p&gt;QUIC connections do not set an upper bound on the amount of data buffered when reading post-handshake messages, allowing a malicious QUIC connection to cause unbounded memory growth. With fix, connections now consistently reject messages larger than 65KiB in size.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-golang-2023-39322</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0646 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0646</link>
      <description>certfr-2024-avi-0646</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0646</guid>
    </item>
    <item>
      <title>EUVD-2026-216694</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-216694</link>
      <description>EUVD-2026-216694</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-216694</guid>
    </item>
    <item>
      <title>fkie_cve-2023-39322</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-39322</link>
      <description>&lt;p&gt;QUIC connections do not set an upper bound on the amount of data buffered when reading post-handshake messages, allowing a malicious QUIC connection to cause unbounded memory growth. With fix, connections now consistently reject messages larger than 65KiB in size.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;QUIC connections do not set an upper bound on the amount of data buffered when reading post-handshake messages, allowing a malicious QUIC connection to cause unbounded memory growth. With fix, connections now consistently reject messages larger than 65KiB in size.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-39322</guid>
    </item>
    <item>
      <title>GHSA-892h-r6cr-53g4</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-892h-r6cr-53g4</link>
      <description>&lt;p&gt;QUIC connections do not set an upper bound on the amount of data buffered when reading post-handshake messages, allowing a malicious QUIC connection to cause unbounded memory growth. With fix, connections now consistently reject messages larger than 65KiB in size.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;QUIC connections do not set an upper bound on the amount of data buffered when reading post-handshake messages, allowing a malicious QUIC connection to cause unbounded memory growth. With fix, connections now consistently reject messages larger than 65KiB in size.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-892h-r6cr-53g4</guid>
    </item>
    <item>
      <title>gsd-2023-39322</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-39322</link>
      <description>gsd-2023-39322</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-39322</guid>
    </item>
    <item>
      <title>OESA-2026-4067 — git-lfs security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-4067</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP3: git-lfs&lt;/p&gt;
&lt;p&gt;Git Large File Storage (LFS) replaces large files such as audio samples, videos, datasets, and graphics with text pointers inside Git, while storing the file contents on a remote server.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Processing an incomplete post-handshake message for a QUIC connection can cause a panic.(CVE-2023-39321)&lt;/p&gt;
&lt;p&gt;QUIC connections do not set an upper bound on the amount of data buffered when reading post-handshake messages, allowing a malicious QUIC connection to cause unbounded memory growth. With fix, connections now consistently reject messages larger than 65KiB in size.(CVE-2023-39322)&lt;/p&gt;
&lt;p&gt;Calling Verify with a VerifyOptions.KeyUsages that contains ExtKeyUsageAny unintentionally disabledpolicy validation. This only affected certificate chains which contain policy graphs, which are rather uncommon.(CVE-2025-22874)&lt;/p&gt;
&lt;p&gt;Git LFS is a Git extension for versioning large files. In Git LFS versions 0.5.2 through 3.7.0, when populating a Git repository&amp;amp;apos;s working tree with the contents of Git LFS objects, certain Git LFS commands may write to files visible outside the current Git working tree if symbolic or hard links exist which collide with the paths of files tracked by Git LFS. The git lfs checkout and git lfs pull commands do not check for symbolic links before writing to files in the working tree, allowing an attacker to craft a repository containing symbolic or hard links that cause Git LFS to write to arbitrary file system locations accessible to the user running these comman…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP3: git-lfs&lt;/p&gt;
&lt;p&gt;Git Large File Storage (LFS) replaces large files such as audio samples, videos, datasets, and graphics with text pointers inside Git, while storing the file contents on a remote server.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Processing an incomplete post-handshake message for a QUIC connection can cause a panic.(CVE-2023-39321)&lt;/p&gt;
&lt;p&gt;QUIC connections do not set an upper bound on the amount of data buffered when reading post-handshake messages, allowing a malicious QUIC connection to cause unbounded memory growth. With fix, connections now consistently reject messages larger than 65KiB in size.(CVE-2023-39322)&lt;/p&gt;
&lt;p&gt;Calling Verify with a VerifyOptions.KeyUsages that contains ExtKeyUsageAny unintentionally disabledpolicy validation. This only affected certificate chains which contain policy graphs, which are rather uncommon.(CVE-2025-22874)&lt;/p&gt;
&lt;p&gt;Git LFS is a Git extension for versioning large files. In Git LFS versions 0.5.2 through 3.7.0, when populating a Git repository&amp;amp;apos;s working tree with the contents of Git LFS objects, certain Git LFS commands may write to files visible outside the current Git working tree if symbolic or hard links exist which collide with the paths of files tracked by Git LFS. The git lfs checkout and git lfs pull commands do not check for symbolic links before writing to files in the working tree, allowing an attacker to craft a repository containing symbolic or hard links that cause Git LFS to write to arbitrary file system locations accessible to the user running these comman…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-4067</guid>
    </item>
    <item>
      <title>openSUSE-SU-2023:0360-1 — Security update for go1.21</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2023:0360-1</link>
      <description>&lt;p&gt;Security update for go1.21&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for go1.21&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2023:0360-1</guid>
    </item>
    <item>
      <title>RHBA-2023:6863 — Red Hat Bug Fix Advisory: LVMS 4.14.z Bug Fix and Enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhba-2023:6863</link>
      <description>&lt;p&gt;golang.org/x/net/html: Cross site scripting golang: crypto/tls: slow verification of certificate chains containing large RSA keys golang: html/template: improper handling of HTML-like comments within script contexts golang: html/template: improper handling of special tags within script contexts golang: crypto/tls: panic when processing post-handshake message on QUIC connections golang: crypto/tls: lack of a limit on buffered post-handshake golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;golang.org/x/net/html: Cross site scripting golang: crypto/tls: slow verification of certificate chains containing large RSA keys golang: html/template: improper handling of HTML-like comments within script contexts golang: html/template: improper handling of special tags within script contexts golang: crypto/tls: panic when processing post-handshake message on QUIC connections golang: crypto/tls: lack of a limit on buffered post-handshake golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhba-2023:6863</guid>
    </item>
    <item>
      <title>Withdrawn: UBUNTU-CVE-2023-39322</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-39322</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: golang-1.21, Ubuntu:22.04:LTS: golang-1.21, Ubuntu:24.04:LTS: golang-1.21&lt;/p&gt;
&lt;p&gt;QUIC connections do not set an upper bound on the amount of data buffered when reading post-handshake messages, allowing a malicious QUIC connection to cause unbounded memory growth. With fix, connections now consistently reject messages larger than 65KiB in size.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: golang-1.21, Ubuntu:22.04:LTS: golang-1.21, Ubuntu:24.04:LTS: golang-1.21&lt;/p&gt;
&lt;p&gt;QUIC connections do not set an upper bound on the amount of data buffered when reading post-handshake messages, allowing a malicious QUIC connection to cause unbounded memory growth. With fix, connections now consistently reject messages larger than 65KiB in size.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-39322</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-2280 — Golang Go: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2280</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Golang Go ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen, Code auszuführen oder einen Denial of Service zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Golang Go ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen, Code auszuführen oder einen Denial of Service zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2280</guid>
    </item>
  </channel>
</rss>
