<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 05:21:21 +0000</lastBuildDate>
    <item>
      <title>ALSA-2024:0965 — Important: unbound security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2024:0965</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: python3-unbound, AlmaLinux:8: unbound, AlmaLinux:8: unbound-devel, AlmaLinux:8: unbound-libs&lt;/p&gt;
&lt;p&gt;The unbound packages provide a validating, recursive, and caching DNS or DNSSEC resolver.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* bind9: KeyTrap - Extreme CPU consumption in DNSSEC validator (CVE-2023-50387)
* bind9: Preparing an NSEC3 closest encloser proof can exhaust CPU resources (CVE-2023-50868)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: python3-unbound, AlmaLinux:8: unbound, AlmaLinux:8: unbound-devel, AlmaLinux:8: unbound-libs&lt;/p&gt;
&lt;p&gt;The unbound packages provide a validating, recursive, and caching DNS or DNSSEC resolver.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* bind9: KeyTrap - Extreme CPU consumption in DNSSEC validator (CVE-2023-50387)
* bind9: Preparing an NSEC3 closest encloser proof can exhaust CPU resources (CVE-2023-50868)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2024:0965</guid>
    </item>
    <item>
      <title>bdu:2024-01462</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-01462</link>
      <description>bdu:2024-01462</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-01462</guid>
    </item>
    <item>
      <title>BELL-CVE-2023-50868</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2023-50868</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: bind, Alpaquita:23: dnsmasq, Alpaquita:stream: bind, Alpaquita:stream: dnsmasq&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: bind, Alpaquita:23: dnsmasq, Alpaquita:stream: bind, Alpaquita:stream: dnsmasq&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2023-50868</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0122 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;Bind&lt;/span&gt;. Elles permettent à un attaquant…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0122</link>
      <description>certfr-2024-avi-0122</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0122</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-KY78316 — dnsmasqs extract_name() function can be abused to cause a heap buffer overflow, allowing an attacker to inject false DN…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ky78316</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: dnsmasq&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the dnsmasq package. dnsmasqs extract_name() function can be abused to cause a heap buffer overflow, allowing an attacker to inject false DNS cache entries, which could result in DNS lookups to redirect to an attacker-controlled IP address, or to cause a DoS. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: dnsmasq&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the dnsmasq package. dnsmasqs extract_name() function can be abused to cause a heap buffer overflow, allowing an attacker to inject false DNS cache entries, which could result in DNS lookups to redirect to an attacker-controlled IP address, or to cause a DoS. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ky78316</guid>
    </item>
    <item>
      <title>EUVD-2026-259298</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-259298</link>
      <description>EUVD-2026-259298</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-259298</guid>
    </item>
    <item>
      <title>fkie_cve-2023-50868</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-50868</link>
      <description>&lt;p&gt;The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-1 computations) via DNSSEC responses in a random subdomain attack, aka the &amp;#34;NSEC3&amp;#34; issue. The RFC 5155 specification implies that an algorithm must perform thousands of iterations of a hash function in certain situations.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-1 computations) via DNSSEC responses in a random subdomain attack, aka the &amp;#34;NSEC3&amp;#34; issue. The RFC 5155 specification implies that an algorithm must perform thousands of iterations of a hash function in certain situations.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-50868</guid>
    </item>
    <item>
      <title>GHSA-pv4h-p8jr-6cv2</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-pv4h-p8jr-6cv2</link>
      <description>&lt;p&gt;The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-1 computations) via DNSSEC responses in a random subdomain attack, aka the &amp;#34;NSEC3&amp;#34; issue. The RFC 5155 specification implies that an algorithm must perform thousands of iterations of a hash function in certain situations.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-1 computations) via DNSSEC responses in a random subdomain attack, aka the &amp;#34;NSEC3&amp;#34; issue. The RFC 5155 specification implies that an algorithm must perform thousands of iterations of a hash function in certain situations.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-pv4h-p8jr-6cv2</guid>
    </item>
    <item>
      <title>gsd-2023-50868</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-50868</link>
      <description>gsd-2023-50868</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-50868</guid>
    </item>
    <item>
      <title>ICSA-24-319-08 — Siemens SINEC INS</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-24-319-08</link>
      <description>&lt;p&gt;Issue summary: The AES-SIV cipher implementation contains a bug that causes it to ignore empty associated data entries which are unauthenticated as a consequence. Impact summary: Applications that use the AES-SIV algorithm and want to authenticate empty data entries as associated data can be mislead by removing adding or reordering such empty entries as these are ignored by the OpenSSL implementation. We are currently unaware of any such applications. The AES-SIV algorithm allows for authentication of multiple associated data entries along with the encryption. To authenticate empty data the application has to call EVP_EncryptUpdate() (or EVP_CipherUpdate()) with NULL pointer as the output buffer and 0 as the input buffer length. The AES-SIV implementation in OpenSSL just returns success for such a call instead of performing the associated data authentication operation. The empty data thus will not be authenticated. As this issue does not affect non-empty associated data authentication and we expect it to be rare for an application to use empty associated data entries this is qualified as Low severity issue. The code that processes control channel messages sent to `named` calls certain functions recursively during packet parsing. Recursion depth is only limited by the maximum accepted packet size; depending on the environment, this may cause the packet-parsing code to run out of available stack memory, causing `named` to terminate unexpectedly. Since each incoming control cha…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Issue summary: The AES-SIV cipher implementation contains a bug that causes it to ignore empty associated data entries which are unauthenticated as a consequence. Impact summary: Applications that use the AES-SIV algorithm and want to authenticate empty data entries as associated data can be mislead by removing adding or reordering such empty entries as these are ignored by the OpenSSL implementation. We are currently unaware of any such applications. The AES-SIV algorithm allows for authentication of multiple associated data entries along with the encryption. To authenticate empty data the application has to call EVP_EncryptUpdate() (or EVP_CipherUpdate()) with NULL pointer as the output buffer and 0 as the input buffer length. The AES-SIV implementation in OpenSSL just returns success for such a call instead of performing the associated data authentication operation. The empty data thus will not be authenticated. As this issue does not affect non-empty associated data authentication and we expect it to be rare for an application to use empty associated data entries this is qualified as Low severity issue. The code that processes control channel messages sent to `named` calls certain functions recursively during packet parsing. Recursion depth is only limited by the maximum accepted packet size; depending on the environment, this may cause the packet-parsing code to run out of available stack memory, causing `named` to terminate unexpectedly. Since each incoming control cha…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-24-319-08</guid>
    </item>
    <item>
      <title>OESA-2024-1210 — unbound security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-1210</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: unbound, openEuler:20.03-LTS-SP4: unbound, openEuler:22.03-LTS: unbound, openEuler:22.03-LTS-SP1: unbound, openEuler:22.03-LTS-SP2: unbound, openEuler:22.03-LTS-SP3: unbound&lt;/p&gt;
&lt;p&gt;Unbound is a validating, recursive, caching DNS resolver. It is designed to be fast and lean and incorporates modern features based on open standards. To help increase online privacy, Unbound supports DNS-over-TLS which allows clients to encrypt their communication. Unbound is available for most platforms such as FreeBSD, OpenBSD, NetBSD, MacOS, Linux and Microsoft Windows. Unbound is a totally free, open source software under the BSD license. It doesn&amp;amp;apos;t make custom builds or provide specific features to paying customers only.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the &amp;amp;quot;KeyTrap&amp;amp;quot; issue. One of the concerns is that, when there is a zone with many DNSKEY and RRSIG records, the protocol specification implies that an algorithm must evaluate all combinations of DNSKEY and RRSIG records.(CVE-2023-50387)&#13;
&#13;
The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-1 computations) via DNSSEC responses in a random subdomain attack, aka the &amp;amp;quot;NSEC3&amp;amp;quot; issue. The RFC 5155 specification implies that an algorithm must perform thousands of iterations of a hash function in certain situations.(CVE-2023-50868)&#13;
&#13;
A vulnerability was found in Unbound due to incorrect de…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: unbound, openEuler:20.03-LTS-SP4: unbound, openEuler:22.03-LTS: unbound, openEuler:22.03-LTS-SP1: unbound, openEuler:22.03-LTS-SP2: unbound, openEuler:22.03-LTS-SP3: unbound&lt;/p&gt;
&lt;p&gt;Unbound is a validating, recursive, caching DNS resolver. It is designed to be fast and lean and incorporates modern features based on open standards. To help increase online privacy, Unbound supports DNS-over-TLS which allows clients to encrypt their communication. Unbound is available for most platforms such as FreeBSD, OpenBSD, NetBSD, MacOS, Linux and Microsoft Windows. Unbound is a totally free, open source software under the BSD license. It doesn&amp;amp;apos;t make custom builds or provide specific features to paying customers only.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the &amp;amp;quot;KeyTrap&amp;amp;quot; issue. One of the concerns is that, when there is a zone with many DNSKEY and RRSIG records, the protocol specification implies that an algorithm must evaluate all combinations of DNSKEY and RRSIG records.(CVE-2023-50387)&#13;
&#13;
The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-1 computations) via DNSSEC responses in a random subdomain attack, aka the &amp;amp;quot;NSEC3&amp;amp;quot; issue. The RFC 5155 specification implies that an algorithm must perform thousands of iterations of a hash function in certain situations.(CVE-2023-50868)&#13;
&#13;
A vulnerability was found in Unbound due to incorrect de…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-1210</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:0048-1 — Security update for pdns-recursor</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:0048-1</link>
      <description>&lt;p&gt;Security update for pdns-recursor&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for pdns-recursor&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:0048-1</guid>
    </item>
    <item>
      <title>RHSA-2024:0981 — Red Hat Security Advisory: unbound security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:0981</link>
      <description>&lt;p&gt;bind9: KeyTrap - Extreme CPU consumption in DNSSEC validator bind9: Preparing an NSEC3 closest encloser proof can exhaust CPU resources&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;bind9: KeyTrap - Extreme CPU consumption in DNSSEC validator bind9: Preparing an NSEC3 closest encloser proof can exhaust CPU resources&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:0981</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:0574-1 — Security update for bind</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:0574-1</link>
      <description>&lt;p&gt;Security update for bind&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for bind&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:0574-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2023-50868</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-50868</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: bind9, Ubuntu:Pro:14.04:LTS: dnsmasq, Ubuntu:Pro:14.04:LTS: unbound, Ubuntu:Pro:16.04:LTS: bind9, Ubuntu:Pro:16.04:LTS: dnsmasq, Ubuntu:Pro:16.04:LTS: unbound, Ubuntu:Pro:16.04:LTS: knot-resolver, Ubuntu:Pro:16.04:LTS: pdns-recursor, Ubuntu:Pro:18.04:LTS: bind9, Ubuntu:Pro:18.04:LTS: dnsmasq and 19 more&lt;/p&gt;
&lt;p&gt;The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-1 computations) via DNSSEC responses in a random subdomain attack, aka the &amp;#34;NSEC3&amp;#34; issue. The RFC 5155 specification implies that an algorithm must perform thousands of iterations of a hash function in certain situations.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: bind9, Ubuntu:Pro:14.04:LTS: dnsmasq, Ubuntu:Pro:14.04:LTS: unbound, Ubuntu:Pro:16.04:LTS: bind9, Ubuntu:Pro:16.04:LTS: dnsmasq, Ubuntu:Pro:16.04:LTS: unbound, Ubuntu:Pro:16.04:LTS: knot-resolver, Ubuntu:Pro:16.04:LTS: pdns-recursor, Ubuntu:Pro:18.04:LTS: bind9, Ubuntu:Pro:18.04:LTS: dnsmasq and 19 more&lt;/p&gt;
&lt;p&gt;The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-1 computations) via DNSSEC responses in a random subdomain attack, aka the &amp;#34;NSEC3&amp;#34; issue. The RFC 5155 specification implies that an algorithm must perform thousands of iterations of a hash function in certain situations.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-50868</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-0386 — Internet Systems Consortium BIND: Mehrere Schwachstellen ermöglichen Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0386</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Internet Systems Consortium BIND ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Internet Systems Consortium BIND ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0386</guid>
    </item>
  </channel>
</rss>
