<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 09:03:38 +0000</lastBuildDate>
    <item>
      <title>ALSA-2024:4212 — Moderate: golang security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2024:4212</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: go-toolset, AlmaLinux:9: golang, AlmaLinux:9: golang-bin, AlmaLinux:9: golang-docs, AlmaLinux:9: golang-misc, AlmaLinux:9: golang-src, AlmaLinux:9: golang-tests&lt;/p&gt;
&lt;p&gt;The golang packages provide the Go programming language compiler.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* golang: archive/zip: Incorrect handling of certain ZIP files (CVE-2024-24789)
* golang: net/netip: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses (CVE-2024-24790)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: go-toolset, AlmaLinux:9: golang, AlmaLinux:9: golang-bin, AlmaLinux:9: golang-docs, AlmaLinux:9: golang-misc, AlmaLinux:9: golang-src, AlmaLinux:9: golang-tests&lt;/p&gt;
&lt;p&gt;The golang packages provide the Go programming language compiler.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* golang: archive/zip: Incorrect handling of certain ZIP files (CVE-2024-24789)
* golang: net/netip: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses (CVE-2024-24790)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2024:4212</guid>
    </item>
    <item>
      <title>bdu:2024-04485</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-04485</link>
      <description>bdu:2024-04485</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-04485</guid>
    </item>
    <item>
      <title>BELL-CVE-2024-24789</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2024-24789</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: go, Alpaquita:stream: go, BellSoft Hardened Containers:23: go, BellSoft Hardened Containers:stream: go&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: go, Alpaquita:stream: go, BellSoft Hardened Containers:23: go, BellSoft Hardened Containers:stream: go&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2024-24789</guid>
    </item>
    <item>
      <title>BIT-golang-2024-24789 — Mishandling of corrupt central directory record in archive/zip</title>
      <link>https://cve.radiocsirt.org/vuln/bit-golang-2024-24789</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: golang&lt;/p&gt;
&lt;p&gt;The archive/zip package&amp;#39;s handling of certain types of invalid zip files differs from the behavior of most zip implementations. This misalignment could be exploited to create an zip file with contents that vary depending on the implementation reading the file. The archive/zip package now rejects files containing these errors.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: golang&lt;/p&gt;
&lt;p&gt;The archive/zip package&amp;#39;s handling of certain types of invalid zip files differs from the behavior of most zip implementations. This misalignment could be exploited to create an zip file with contents that vary depending on the implementation reading the file. The archive/zip package now rejects files containing these errors.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-golang-2024-24789</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0873 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0873</link>
      <description>certfr-2024-avi-0873</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0873</guid>
    </item>
    <item>
      <title>EUVD-2026-217245</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-217245</link>
      <description>EUVD-2026-217245</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-217245</guid>
    </item>
    <item>
      <title>fkie_cve-2024-24789</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-24789</link>
      <description>&lt;p&gt;The archive/zip package&amp;#39;s handling of certain types of invalid zip files differs from the behavior of most zip implementations. This misalignment could be exploited to create an zip file with contents that vary depending on the implementation reading the file. The archive/zip package now rejects files containing these errors.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The archive/zip package&amp;#39;s handling of certain types of invalid zip files differs from the behavior of most zip implementations. This misalignment could be exploited to create an zip file with contents that vary depending on the implementation reading the file. The archive/zip package now rejects files containing these errors.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-24789</guid>
    </item>
    <item>
      <title>GHSA-236w-p7wf-5ph8</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-236w-p7wf-5ph8</link>
      <description>&lt;p&gt;The archive/zip package&amp;#39;s handling of certain types of invalid zip files differs from the behavior of most zip implementations. This misalignment could be exploited to create an zip file with contents that vary depending on the implementation reading the file. The archive/zip package now rejects files containing these errors.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The archive/zip package&amp;#39;s handling of certain types of invalid zip files differs from the behavior of most zip implementations. This misalignment could be exploited to create an zip file with contents that vary depending on the implementation reading the file. The archive/zip package now rejects files containing these errors.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-236w-p7wf-5ph8</guid>
    </item>
    <item>
      <title>gsd-2024-24789</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-24789</link>
      <description>gsd-2024-24789</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-24789</guid>
    </item>
    <item>
      <title>msrc_CVE-2024-24789 — Mishandling of corrupt central directory record in archive/zip</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2024-24789</link>
      <description>msrc_CVE-2024-24789</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2024-24789</guid>
    </item>
    <item>
      <title>OESA-2024-1769 — golang security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-1769</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: golang&lt;/p&gt;
&lt;p&gt;The Go Programming Language.&#13;
&#13;
Security Fix(es):&#13;
&#13;
The archive/zip package&amp;amp;apos;s handling of certain types of invalid zip files differs from the behavior of most zip implementations. This misalignment could be exploited to create an zip file with contents that vary depending on the implementation reading the file. The archive/zip package now rejects files containing these errors.(CVE-2024-24789)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: golang&lt;/p&gt;
&lt;p&gt;The Go Programming Language.&#13;
&#13;
Security Fix(es):&#13;
&#13;
The archive/zip package&amp;amp;apos;s handling of certain types of invalid zip files differs from the behavior of most zip implementations. This misalignment could be exploited to create an zip file with contents that vary depending on the implementation reading the file. The archive/zip package now rejects files containing these errors.(CVE-2024-24789)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-1769</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:14020-1 — go1.22-1.22.4-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:14020-1</link>
      <description>&lt;p&gt;go1.22-1.22.4-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;go1.22-1.22.4-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:14020-1</guid>
    </item>
    <item>
      <title>RHEA-2025:0507 — Red Hat Enhancement Advisory: Advisory for publishing Helm 3.15.4 GA release</title>
      <link>https://cve.radiocsirt.org/vuln/rhea-2025:0507</link>
      <description>&lt;p&gt;golang: net: malformed DNS message can cause infinite loop golang: archive/zip: Incorrect handling of certain ZIP files golang: net/netip: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;golang: net: malformed DNS message can cause infinite loop golang: archive/zip: Incorrect handling of certain ZIP files golang: net/netip: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhea-2025:0507</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:1935-1 — Security update for go1.22</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:1935-1</link>
      <description>&lt;p&gt;Security update for go1.22&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for go1.22&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:1935-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-24789</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-24789</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: golang-1.10, Ubuntu:Pro:16.04:LTS: golang-1.18, Ubuntu:16.04:LTS: golang-1.10, Ubuntu:Pro:16.04:LTS: golang-1.13, Ubuntu:18.04:LTS: golang-1.10, Ubuntu:Pro:18.04:LTS: golang-1.13, Ubuntu:Pro:18.04:LTS: golang-1.16, Ubuntu:Pro:18.04:LTS: golang-1.18, Ubuntu:20.04:LTS: golang-1.18, Ubuntu:20.04:LTS: golang-1.21 and 13 more&lt;/p&gt;
&lt;p&gt;The archive/zip package&amp;#39;s handling of certain types of invalid zip files differs from the behavior of most zip implementations. This misalignment could be exploited to create an zip file with contents that vary depending on the implementation reading the file. The archive/zip package now rejects files containing these errors.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: golang-1.10, Ubuntu:Pro:16.04:LTS: golang-1.18, Ubuntu:16.04:LTS: golang-1.10, Ubuntu:Pro:16.04:LTS: golang-1.13, Ubuntu:18.04:LTS: golang-1.10, Ubuntu:Pro:18.04:LTS: golang-1.13, Ubuntu:Pro:18.04:LTS: golang-1.16, Ubuntu:Pro:18.04:LTS: golang-1.18, Ubuntu:20.04:LTS: golang-1.18, Ubuntu:20.04:LTS: golang-1.21 and 13 more&lt;/p&gt;
&lt;p&gt;The archive/zip package&amp;#39;s handling of certain types of invalid zip files differs from the behavior of most zip implementations. This misalignment could be exploited to create an zip file with contents that vary depending on the implementation reading the file. The archive/zip package now rejects files containing these errors.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-24789</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-1287 — Golang Go: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1287</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Golang Go ausnutzen, um Sicherheitsvorkehrungen zu umgehen und um Dateien zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Golang Go ausnutzen, um Sicherheitsvorkehrungen zu umgehen und um Dateien zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1287</guid>
    </item>
  </channel>
</rss>
