<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 13:38:46 +0000</lastBuildDate>
    <item>
      <title>ALSA-2024:9333 — Low: openssl security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2024:9333</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: openssl, AlmaLinux:9: openssl-devel, AlmaLinux:9: openssl-libs, AlmaLinux:9: openssl-perl&lt;/p&gt;
&lt;p&gt;OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, as well as a full-strength general-purpose cryptography library.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* openssl: Unbounded memory growth with session handling in TLSv1.3 (CVE-2024-2511)
  * openssl: Excessive time spent checking DSA keys and parameters (CVE-2024-4603)
  * openssl: Use After Free with SSL_free_buffers (CVE-2024-4741)
  * openssl: SSL_select_next_proto buffer overread (CVE-2024-5535)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: openssl, AlmaLinux:9: openssl-devel, AlmaLinux:9: openssl-libs, AlmaLinux:9: openssl-perl&lt;/p&gt;
&lt;p&gt;OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, as well as a full-strength general-purpose cryptography library.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* openssl: Unbounded memory growth with session handling in TLSv1.3 (CVE-2024-2511)
  * openssl: Excessive time spent checking DSA keys and parameters (CVE-2024-4603)
  * openssl: Use After Free with SSL_free_buffers (CVE-2024-4741)
  * openssl: SSL_select_next_proto buffer overread (CVE-2024-5535)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2024:9333</guid>
    </item>
    <item>
      <title>bdu:2024-05176</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-05176</link>
      <description>bdu:2024-05176</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-05176</guid>
    </item>
    <item>
      <title>BELL-CVE-2024-4741</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2024-4741</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: openssl, Alpaquita:stream: openssl, BellSoft Hardened Containers:23: openssl, BellSoft Hardened Containers:stream: openssl&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: openssl, Alpaquita:stream: openssl, BellSoft Hardened Containers:23: openssl, BellSoft Hardened Containers:stream: openssl&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2024-4741</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0446 — Une vulnérabilité a été découverte dans OpenSSL. Elle permet à un attaquant de provoquer une exécution de code arbitrai…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0446</link>
      <description>certfr-2024-avi-0446</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0446</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-EV69092 — Security fix for CVE-2024-4741 applied in: openssl 3.3.0-r3</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ev69092</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: openssl&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the openssl package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: openssl&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the openssl package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ev69092</guid>
    </item>
    <item>
      <title>cnvd-2024-45212</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2024-45212</link>
      <description>cnvd-2024-45212</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2024-45212</guid>
    </item>
    <item>
      <title>EUVD-2026-259071</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-259071</link>
      <description>EUVD-2026-259071</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-259071</guid>
    </item>
    <item>
      <title>fkie_cve-2024-4741</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-4741</link>
      <description>&lt;p&gt;Issue summary: Calling the OpenSSL API function SSL_free_buffers may cause
memory to be accessed that was previously freed in some situations&lt;/p&gt;
&lt;p&gt;Impact summary: A use after free can have a range of potential consequences such
as the corruption of valid data, crashes or execution of arbitrary code.
However, only applications that directly call the SSL_free_buffers function are
affected by this issue. Applications that do not call this function are not
vulnerable. Our investigations indicate that this function is rarely used by
applications.&lt;/p&gt;
&lt;p&gt;The SSL_free_buffers function is used to free the internal OpenSSL buffer used
when processing an incoming record from the network. The call is only expected
to succeed if the buffer is not currently in use. However, two scenarios have
been identified where the buffer is freed even when still in use.&lt;/p&gt;
&lt;p&gt;The first scenario occurs where a record header has been received from the
network and processed by OpenSSL, but the full record body has not yet arrived.
In this case calling SSL_free_buffers will succeed even though a record has only
been partially processed and the buffer is still in use.&lt;/p&gt;
&lt;p&gt;The second scenario occurs where a full record containing application data has
been received and processed by OpenSSL but the application has only read part of
this data. Again a call to SSL_free_buffers will succeed even though the buffer
is still in use.&lt;/p&gt;
&lt;p&gt;While these scenarios could occur accidentally during normal operation a
malicious attacker could a…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Issue summary: Calling the OpenSSL API function SSL_free_buffers may cause
memory to be accessed that was previously freed in some situations&lt;/p&gt;
&lt;p&gt;Impact summary: A use after free can have a range of potential consequences such
as the corruption of valid data, crashes or execution of arbitrary code.
However, only applications that directly call the SSL_free_buffers function are
affected by this issue. Applications that do not call this function are not
vulnerable. Our investigations indicate that this function is rarely used by
applications.&lt;/p&gt;
&lt;p&gt;The SSL_free_buffers function is used to free the internal OpenSSL buffer used
when processing an incoming record from the network. The call is only expected
to succeed if the buffer is not currently in use. However, two scenarios have
been identified where the buffer is freed even when still in use.&lt;/p&gt;
&lt;p&gt;The first scenario occurs where a record header has been received from the
network and processed by OpenSSL, but the full record body has not yet arrived.
In this case calling SSL_free_buffers will succeed even though a record has only
been partially processed and the buffer is still in use.&lt;/p&gt;
&lt;p&gt;The second scenario occurs where a full record containing application data has
been received and processed by OpenSSL but the application has only read part of
this data. Again a call to SSL_free_buffers will succeed even though the buffer
is still in use.&lt;/p&gt;
&lt;p&gt;While these scenarios could occur accidentally during normal operation a
malicious attacker could a…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-4741</guid>
    </item>
    <item>
      <title>GHSA-6vgq-8qjq-h578</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6vgq-8qjq-h578</link>
      <description>&lt;p&gt;Issue summary: Calling the OpenSSL API function SSL_free_buffers may cause
memory to be accessed that was previously freed in some situations&lt;/p&gt;
&lt;p&gt;Impact summary: A use after free can have a range of potential consequences such
as the corruption of valid data, crashes or execution of arbitrary code.
However, only applications that directly call the SSL_free_buffers function are
affected by this issue. Applications that do not call this function are not
vulnerable. Our investigations indicate that this function is rarely used by
applications.&lt;/p&gt;
&lt;p&gt;The SSL_free_buffers function is used to free the internal OpenSSL buffer used
when processing an incoming record from the network. The call is only expected
to succeed if the buffer is not currently in use. However, two scenarios have
been identified where the buffer is freed even when still in use.&lt;/p&gt;
&lt;p&gt;The first scenario occurs where a record header has been received from the
network and processed by OpenSSL, but the full record body has not yet arrived.
In this case calling SSL_free_buffers will succeed even though a record has only
been partially processed and the buffer is still in use.&lt;/p&gt;
&lt;p&gt;The second scenario occurs where a full record containing application data has
been received and processed by OpenSSL but the application has only read part of
this data. Again a call to SSL_free_buffers will succeed even though the buffer
is still in use.&lt;/p&gt;
&lt;p&gt;While these scenarios could occur accidentally during normal operation a
malicious attacker could a…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Issue summary: Calling the OpenSSL API function SSL_free_buffers may cause
memory to be accessed that was previously freed in some situations&lt;/p&gt;
&lt;p&gt;Impact summary: A use after free can have a range of potential consequences such
as the corruption of valid data, crashes or execution of arbitrary code.
However, only applications that directly call the SSL_free_buffers function are
affected by this issue. Applications that do not call this function are not
vulnerable. Our investigations indicate that this function is rarely used by
applications.&lt;/p&gt;
&lt;p&gt;The SSL_free_buffers function is used to free the internal OpenSSL buffer used
when processing an incoming record from the network. The call is only expected
to succeed if the buffer is not currently in use. However, two scenarios have
been identified where the buffer is freed even when still in use.&lt;/p&gt;
&lt;p&gt;The first scenario occurs where a record header has been received from the
network and processed by OpenSSL, but the full record body has not yet arrived.
In this case calling SSL_free_buffers will succeed even though a record has only
been partially processed and the buffer is still in use.&lt;/p&gt;
&lt;p&gt;The second scenario occurs where a full record containing application data has
been received and processed by OpenSSL but the application has only read part of
this data. Again a call to SSL_free_buffers will succeed even though the buffer
is still in use.&lt;/p&gt;
&lt;p&gt;While these scenarios could occur accidentally during normal operation a
malicious attacker could a…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6vgq-8qjq-h578</guid>
    </item>
    <item>
      <title>ICSA-24-319-06 — Siemens SCALANCE M-800 Family</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-24-319-06</link>
      <description>&lt;p&gt;An out-of-bounds (OOB) memory access flaw was found in fs/f2fs/node.c in the f2fs module in the Linux kernel in versions before 5.12.0-rc4. A bounds check failure allows a local attacker to gain access to out-of-bounds memory leading to a system crash or a leak of internal kernel information. The highest threat from this vulnerability is to system availability. An issue was discovered in Dnsmasq before 2.90. The default maximum EDNS.0 UDP packet size was set to 4096 but should be 1232 because of DNS Flag Day 2020. dnsmasq 2.9 is vulnerable to Integer Overflow via forward_query. Issue summary: Some non-default TLS server configurations can cause unbounded memory growth when processing TLSv1.3 sessions&#13;
Impact summary: An attacker may exploit certain server configurations to trigger unbounded memory growth that would lead to a Denial of Service This problem can occur in TLSv1.3 if the non-default SSL_OP_NO_TICKET option is being used (but not if early_data support is also configured and the default anti-replay protection is in use). In this case, under certain conditions, the session cache can get into an incorrect state and it will fail to flush properly as it fills. The session cache will continue to grow in an unbounded manner. A malicious client could deliberately create the scenario for this failure to force a Denial of Service. It may also happen by accident in normal operation. This issue only affects TLS servers supporting TLSv1.3. It does not affect TLS clients. The F…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An out-of-bounds (OOB) memory access flaw was found in fs/f2fs/node.c in the f2fs module in the Linux kernel in versions before 5.12.0-rc4. A bounds check failure allows a local attacker to gain access to out-of-bounds memory leading to a system crash or a leak of internal kernel information. The highest threat from this vulnerability is to system availability. An issue was discovered in Dnsmasq before 2.90. The default maximum EDNS.0 UDP packet size was set to 4096 but should be 1232 because of DNS Flag Day 2020. dnsmasq 2.9 is vulnerable to Integer Overflow via forward_query. Issue summary: Some non-default TLS server configurations can cause unbounded memory growth when processing TLSv1.3 sessions&#13;
Impact summary: An attacker may exploit certain server configurations to trigger unbounded memory growth that would lead to a Denial of Service This problem can occur in TLSv1.3 if the non-default SSL_OP_NO_TICKET option is being used (but not if early_data support is also configured and the default anti-replay protection is in use). In this case, under certain conditions, the session cache can get into an incorrect state and it will fail to flush properly as it fills. The session cache will continue to grow in an unbounded manner. A malicious client could deliberately create the scenario for this failure to force a Denial of Service. It may also happen by accident in normal operation. This issue only affects TLS servers supporting TLSv1.3. It does not affect TLS clients. The F…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-24-319-06</guid>
    </item>
    <item>
      <title>msrc_CVE-2024-4741 — Use After Free with SSL_free_buffers</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2024-4741</link>
      <description>msrc_CVE-2024-4741</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2024-4741</guid>
    </item>
    <item>
      <title>OESA-2024-1697 — openssl security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-1697</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: openssl&lt;/p&gt;
&lt;p&gt;The OpenSSL Project is a collaborative effort to develop a robust, commercial-grade, fully featured, and Open Source toolkit implementing the Secure Sockets Layer (SSL v2/v3) and Transport Layer Security (TLS v1) protocols as well as a full-strength general purpose cryptography library. The project is managed by a worldwide community of volunteers that use the Internet to communicate, plan, and develop the OpenSSL tookit and its related documentation.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A use-after-free vulnerability was found in OpenSSL. Calling the OpenSSL API SSL_free_buffers function may cause memory to be accessed that was previously freed in some situations.(CVE-2024-4741)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: openssl&lt;/p&gt;
&lt;p&gt;The OpenSSL Project is a collaborative effort to develop a robust, commercial-grade, fully featured, and Open Source toolkit implementing the Secure Sockets Layer (SSL v2/v3) and Transport Layer Security (TLS v1) protocols as well as a full-strength general purpose cryptography library. The project is managed by a worldwide community of volunteers that use the Internet to communicate, plan, and develop the OpenSSL tookit and its related documentation.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A use-after-free vulnerability was found in OpenSSL. Calling the OpenSSL API SSL_free_buffers function may cause memory to be accessed that was previously freed in some situations.(CVE-2024-4741)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-1697</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:14219-1 — libopenssl-1_1-devel-1.1.1w-11.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:14219-1</link>
      <description>&lt;p&gt;libopenssl-1_1-devel-1.1.1w-11.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libopenssl-1_1-devel-1.1.1w-11.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:14219-1</guid>
    </item>
    <item>
      <title>RLSA-2026:26275 — Important: openssl security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:26275</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: openssl&lt;/p&gt;
&lt;p&gt;OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, as well as a full-strength general-purpose cryptography library.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* openssl: Use After Free with SSL_free_buffers (CVE-2024-4741)&lt;/p&gt;
&lt;p&gt;* openssl: Heap Use-After-Free in OpenSSL PKCS7_verify() (CVE-2026-45447)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: openssl&lt;/p&gt;
&lt;p&gt;OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, as well as a full-strength general-purpose cryptography library.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* openssl: Use After Free with SSL_free_buffers (CVE-2024-4741)&lt;/p&gt;
&lt;p&gt;* openssl: Heap Use-After-Free in OpenSSL PKCS7_verify() (CVE-2026-45447)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:26275</guid>
    </item>
    <item>
      <title>SSA-613116 — SSA-613116: Multiple Vulnerabilities in Third-Party Components in SINEC OS before V3.1</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-613116</link>
      <description>&lt;p&gt;In gc_data_segment in fs/f2fs/gc.c in the Linux kernel before 5.16.3, special files are not considered, leading to a move_data_page NULL pointer dereference. In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;firmware: arm_scmi: Harden accesses to the reset domains&lt;/p&gt;
&lt;p&gt;Accessing reset domains descriptors by the index upon the SCMI drivers
requests through the SCMI reset operations interface can potentially
lead to out-of-bound violations if the SCMI driver misbehave.&lt;/p&gt;
&lt;p&gt;Add an internal consistency check before any such domains descriptors
accesses. In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;media: lgdt3306a: Add a check against null-pointer-def&lt;/p&gt;
&lt;p&gt;The driver should check whether the client provides the platform_data.&lt;/p&gt;
&lt;p&gt;The following log reveals it:&lt;/p&gt;
&lt;p&gt;[   29.610324] BUG: KASAN: null-ptr-deref in kmemdup+0x30/0x40
[   29.610730] Read of size 40 at addr 0000000000000000 by task bash/414
[   29.612820] Call Trace:
[   29.613030]  &amp;lt;TASK&amp;gt;
[   29.613201]  dump_stack_lvl+0x56/0x6f
[   29.613496]  ? kmemdup+0x30/0x40
[   29.613754]  print_report.cold+0x494/0x6b7
[   29.614082]  ? kmemdup+0x30/0x40
[   29.614340]  kasan_report+0x8a/0x190
[   29.614628]  ? kmemdup+0x30/0x40
[   29.614888]  kasan_check_range+0x14d/0x1d0
[   29.615213]  memcpy+0x20/0x60
[   29.615454]  kmemdup+0x30/0x40
[   29.615700]  lgdt3306a_probe+0x52/0x310
[   29.616339]  i2c_device_probe+0x951/0xa90 In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
netfilter:…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In gc_data_segment in fs/f2fs/gc.c in the Linux kernel before 5.16.3, special files are not considered, leading to a move_data_page NULL pointer dereference. In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;firmware: arm_scmi: Harden accesses to the reset domains&lt;/p&gt;
&lt;p&gt;Accessing reset domains descriptors by the index upon the SCMI drivers
requests through the SCMI reset operations interface can potentially
lead to out-of-bound violations if the SCMI driver misbehave.&lt;/p&gt;
&lt;p&gt;Add an internal consistency check before any such domains descriptors
accesses. In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;media: lgdt3306a: Add a check against null-pointer-def&lt;/p&gt;
&lt;p&gt;The driver should check whether the client provides the platform_data.&lt;/p&gt;
&lt;p&gt;The following log reveals it:&lt;/p&gt;
&lt;p&gt;[   29.610324] BUG: KASAN: null-ptr-deref in kmemdup+0x30/0x40
[   29.610730] Read of size 40 at addr 0000000000000000 by task bash/414
[   29.612820] Call Trace:
[   29.613030]  &amp;lt;TASK&amp;gt;
[   29.613201]  dump_stack_lvl+0x56/0x6f
[   29.613496]  ? kmemdup+0x30/0x40
[   29.613754]  print_report.cold+0x494/0x6b7
[   29.614082]  ? kmemdup+0x30/0x40
[   29.614340]  kasan_report+0x8a/0x190
[   29.614628]  ? kmemdup+0x30/0x40
[   29.614888]  kasan_check_range+0x14d/0x1d0
[   29.615213]  memcpy+0x20/0x60
[   29.615454]  kmemdup+0x30/0x40
[   29.615700]  lgdt3306a_probe+0x52/0x310
[   29.616339]  i2c_device_probe+0x951/0xa90 In the Linux kernel, the following vulnerability has been resolved:&#13;
&#13;
netfilter:…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-613116</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:2020-1 — Security update for openssl-3</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:2020-1</link>
      <description>&lt;p&gt;Security update for openssl-3&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for openssl-3&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:2020-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-4741</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-4741</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: openssl, Ubuntu:Pro:16.04:LTS: openssl, Ubuntu:Pro:16.04:LTS: edk2, Ubuntu:Pro:16.04:LTS: nodejs, Ubuntu:Pro:FIPS:16.04:LTS: openssl, Ubuntu:Pro:18.04:LTS: openssl, Ubuntu:Pro:18.04:LTS: edk2, Ubuntu:Pro:18.04:LTS: nodejs, Ubuntu:Pro:FIPS-updates:18.04:LTS: openssl, Ubuntu:Pro:FIPS:18.04:LTS: openssl and 13 more&lt;/p&gt;
&lt;p&gt;Issue summary: Calling the OpenSSL API function SSL_free_buffers may cause memory to be accessed that was previously freed in some situations Impact summary: A use after free can have a range of potential consequences such as the corruption of valid data, crashes or execution of arbitrary code. However, only applications that directly call the SSL_free_buffers function are affected by this issue. Applications that do not call this function are not vulnerable. Our investigations indicate that this function is rarely used by applications. The SSL_free_buffers function is used to free the internal OpenSSL buffer used when processing an incoming record from the network. The call is only expected to succeed if the buffer is not currently in use. However, two scenarios have been identified where the buffer is freed even when still in use. The first scenario occurs where a record header has been received from the network and processed by OpenSSL, but the full record body has not yet arrived. In this case calling SSL_free_buffers will succeed even though a record has only been partially processed and the buffer is still in use. The second scenario occurs where a full record containing application data has been received and processed by OpenSSL but the application has only read part of this data. Again a call to SSL_free_buffers will succeed even though the buffer is still in use. While these scenarios could occur accidentally during normal operation a malicious attacker could attemp…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: openssl, Ubuntu:Pro:16.04:LTS: openssl, Ubuntu:Pro:16.04:LTS: edk2, Ubuntu:Pro:16.04:LTS: nodejs, Ubuntu:Pro:FIPS:16.04:LTS: openssl, Ubuntu:Pro:18.04:LTS: openssl, Ubuntu:Pro:18.04:LTS: edk2, Ubuntu:Pro:18.04:LTS: nodejs, Ubuntu:Pro:FIPS-updates:18.04:LTS: openssl, Ubuntu:Pro:FIPS:18.04:LTS: openssl and 13 more&lt;/p&gt;
&lt;p&gt;Issue summary: Calling the OpenSSL API function SSL_free_buffers may cause memory to be accessed that was previously freed in some situations Impact summary: A use after free can have a range of potential consequences such as the corruption of valid data, crashes or execution of arbitrary code. However, only applications that directly call the SSL_free_buffers function are affected by this issue. Applications that do not call this function are not vulnerable. Our investigations indicate that this function is rarely used by applications. The SSL_free_buffers function is used to free the internal OpenSSL buffer used when processing an incoming record from the network. The call is only expected to succeed if the buffer is not currently in use. However, two scenarios have been identified where the buffer is freed even when still in use. The first scenario occurs where a record header has been received from the network and processed by OpenSSL, but the full record body has not yet arrived. In this case calling SSL_free_buffers will succeed even though a record has only been partially processed and the buffer is still in use. The second scenario occurs where a full record containing application data has been received and processed by OpenSSL but the application has only read part of this data. Again a call to SSL_free_buffers will succeed even though the buffer is still in use. While these scenarios could occur accidentally during normal operation a malicious attacker could attemp…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-4741</guid>
    </item>
    <item>
      <title>VDE-2024-071 — Phoenix Contact: Multiple Vulnerabilities in PLCnext Firmware</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2024-071</link>
      <description>&lt;p&gt;Git&amp;#39;s recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution Excessive time spent checking DSA keys and parameters Unbounded memory growth with session handling in TLSv1.3&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Git&amp;#39;s recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution Excessive time spent checking DSA keys and parameters Unbounded memory growth with session handling in TLSv1.3&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2024-071</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-1240 — OpenSSL: Schwachstelle ermöglicht Codeausführung, Datenmanipulation, Offenlegung von Informationen und Dos</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1240</link>
      <description>&lt;p&gt;Ein entfernter anonymer Angreifer kann eine Schwachstelle in OpenSSL ausnutzen, um beliebigen Code auszuführen, einen Denial-of-Service-Zustand zu verursachen, vertrauliche Informationen offenzulegen und Daten zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter anonymer Angreifer kann eine Schwachstelle in OpenSSL ausnutzen, um beliebigen Code auszuführen, einen Denial-of-Service-Zustand zu verursachen, vertrauliche Informationen offenzulegen und Daten zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1240</guid>
    </item>
  </channel>
</rss>
