<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 12:48:11 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:1334 — Moderate: glibc security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:1334</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: glibc-doc&lt;/p&gt;
&lt;p&gt;The glibc packages provide the standard C libraries (libc), POSIX thread libraries (libpthread), standard math libraries (libm), and the name service cache daemon (nscd) used by multiple programs on the system. Without these libraries, the Linux system cannot function correctly.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* glibc: Integer overflow in memalign leads to heap corruption (CVE-2026-0861)
  * glibc: glibc: Information disclosure via zero-valued network query (CVE-2026-0915)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: glibc-doc&lt;/p&gt;
&lt;p&gt;The glibc packages provide the standard C libraries (libc), POSIX thread libraries (libpthread), standard math libraries (libm), and the name service cache daemon (nscd) used by multiple programs on the system. Without these libraries, the Linux system cannot function correctly.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* glibc: Integer overflow in memalign leads to heap corruption (CVE-2026-0861)
  * glibc: glibc: Information disclosure via zero-valued network query (CVE-2026-0915)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:1334</guid>
    </item>
    <item>
      <title>bdu:2026-00915</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-00915</link>
      <description>bdu:2026-00915</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-00915</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-0861</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-0861</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: glibc, Alpaquita:25: glibc, Alpaquita:stream: glibc, BellSoft Hardened Containers:23: glibc, BellSoft Hardened Containers:25: glibc, BellSoft Hardened Containers:stream: glibc&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: glibc, Alpaquita:25: glibc, Alpaquita:stream: glibc, BellSoft Hardened Containers:23: glibc, BellSoft Hardened Containers:25: glibc, BellSoft Hardened Containers:stream: glibc&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-0861</guid>
    </item>
    <item>
      <title>BREW-glibc-CVE-2026-0861 — Integer overflow in memalign leads to heap corruption</title>
      <link>https://cve.radiocsirt.org/vuln/brew-glibc-cve-2026-0861</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: glibc&lt;/p&gt;
&lt;p&gt;Passing too large an alignment to the memalign suite of functions (memalign, posix_memalign, aligned_alloc) in the GNU C Library version 2.30 to 2.42 may result in an integer overflow, which could consequently result in a heap corruption.&lt;/p&gt;
&lt;p&gt;Note that the attacker must have control over both, the size as well as the alignment arguments of the memalign function to be able to exploit this.  The size parameter must be close enough to PTRDIFF_MAX so as to overflow size_t along with the large alignment argument.  This limits the malicious inputs for the alignment for memalign to the range [1&amp;lt;&amp;lt;62+ 1, 1&amp;lt;&amp;lt;63] and exactly 1&amp;lt;&amp;lt;63 for posix_memalign and aligned_alloc.&lt;/p&gt;
&lt;p&gt;Typically the alignment argument passed to such functions is a known constrained quantity (e.g. page size, block size, struct sizes) and is not attacker controlled, because of which this may not be easily exploitable in practice.  An application bug could potentially result in the input alignment being too large, e.g. due to a different buffer overflow or integer overflow in the application or its dependent libraries, but that is again an uncommon usage pattern given typical sources of alignments.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: glibc&lt;/p&gt;
&lt;p&gt;Passing too large an alignment to the memalign suite of functions (memalign, posix_memalign, aligned_alloc) in the GNU C Library version 2.30 to 2.42 may result in an integer overflow, which could consequently result in a heap corruption.&lt;/p&gt;
&lt;p&gt;Note that the attacker must have control over both, the size as well as the alignment arguments of the memalign function to be able to exploit this.  The size parameter must be close enough to PTRDIFF_MAX so as to overflow size_t along with the large alignment argument.  This limits the malicious inputs for the alignment for memalign to the range [1&amp;lt;&amp;lt;62+ 1, 1&amp;lt;&amp;lt;63] and exactly 1&amp;lt;&amp;lt;63 for posix_memalign and aligned_alloc.&lt;/p&gt;
&lt;p&gt;Typically the alignment argument passed to such functions is a known constrained quantity (e.g. page size, block size, struct sizes) and is not attacker controlled, because of which this may not be easily exploitable in practice.  An application bug could potentially result in the input alignment being too large, e.g. due to a different buffer overflow or integer overflow in the application or its dependent libraries, but that is again an uncommon usage pattern given typical sources of alignments.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-glibc-cve-2026-0861</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0199 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Certaines d'entre elles permettent à un attaq…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0199</link>
      <description>certfr-2026-avi-0199</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0199</guid>
    </item>
    <item>
      <title>EUVD-2026-307834</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-307834</link>
      <description>EUVD-2026-307834</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-307834</guid>
    </item>
    <item>
      <title>fkie_cve-2026-0861</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-0861</link>
      <description>&lt;p&gt;Passing too large an alignment to the memalign suite of functions (memalign, posix_memalign, aligned_alloc) in the GNU C Library version 2.30 to 2.42 may result in an integer overflow, which could consequently result in a heap corruption.&lt;/p&gt;
&lt;p&gt;Note that the attacker must have control over both, the size as well as the alignment arguments of the memalign function to be able to exploit this.  The size parameter must be close enough to PTRDIFF_MAX so as to overflow size_t along with the large alignment argument.  This limits the malicious inputs for the alignment for memalign to the range [1&amp;lt;&amp;lt;62+ 1, 1&amp;lt;&amp;lt;63] and exactly 1&amp;lt;&amp;lt;63 for posix_memalign and aligned_alloc.&lt;/p&gt;
&lt;p&gt;Typically the alignment argument passed to such functions is a known constrained quantity (e.g. page size, block size, struct sizes) and is not attacker controlled, because of which this may not be easily exploitable in practice.  An application bug could potentially result in the input alignment being too large, e.g. due to a different buffer overflow or integer overflow in the application or its dependent libraries, but that is again an uncommon usage pattern given typical sources of alignments.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Passing too large an alignment to the memalign suite of functions (memalign, posix_memalign, aligned_alloc) in the GNU C Library version 2.30 to 2.42 may result in an integer overflow, which could consequently result in a heap corruption.&lt;/p&gt;
&lt;p&gt;Note that the attacker must have control over both, the size as well as the alignment arguments of the memalign function to be able to exploit this.  The size parameter must be close enough to PTRDIFF_MAX so as to overflow size_t along with the large alignment argument.  This limits the malicious inputs for the alignment for memalign to the range [1&amp;lt;&amp;lt;62+ 1, 1&amp;lt;&amp;lt;63] and exactly 1&amp;lt;&amp;lt;63 for posix_memalign and aligned_alloc.&lt;/p&gt;
&lt;p&gt;Typically the alignment argument passed to such functions is a known constrained quantity (e.g. page size, block size, struct sizes) and is not attacker controlled, because of which this may not be easily exploitable in practice.  An application bug could potentially result in the input alignment being too large, e.g. due to a different buffer overflow or integer overflow in the application or its dependent libraries, but that is again an uncommon usage pattern given typical sources of alignments.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-0861</guid>
    </item>
    <item>
      <title>GHSA-5pf6-63v3-88hw</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-5pf6-63v3-88hw</link>
      <description>&lt;p&gt;Passing too large an alignment to the memalign suite of functions (memalign, posix_memalign, aligned_alloc, valloc, pvalloc) in the GNU C Library version 2.30 to 2.42 may result in an integer overflow, which could consequently result in a heap corruption.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Passing too large an alignment to the memalign suite of functions (memalign, posix_memalign, aligned_alloc, valloc, pvalloc) in the GNU C Library version 2.30 to 2.42 may result in an integer overflow, which could consequently result in a heap corruption.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-5pf6-63v3-88hw</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-0861 — Integer overflow in memalign leads to heap corruption</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-0861</link>
      <description>msrc_CVE-2026-0861</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-0861</guid>
    </item>
    <item>
      <title>OESA-2026-1198 — glibc security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-1198</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: glibc&lt;/p&gt;
&lt;p&gt;The GNU C Library project provides the core libraries for the GNU system and GNU/Linux systems, as well as many other systems that use Linux as the kernel. These libraries provide critical APIs including ISO C11, POSIX.1-2008, BSD, OS-specific APIs and more. These APIs include such foundational facilities as open, read, write, malloc, printf, getaddrinfo, dlopen, pthread_create, crypt,  login, exit and more.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Passing too large an alignment to the memalign suite of functions (memalign, posix_memalign, aligned_alloc) in the GNU C Library version 2.30 to 2.42 may result in an integer overflow, which could consequently result in a heap corruption.&lt;/p&gt;
&lt;p&gt;Note that the attacker must have control over both, the size as well as the alignment arguments of the memalign function to be able to exploit this.  The size parameter must be close enough to PTRDIFF_MAX so as to overflow size_t along with the large alignment argument.  This limits the malicious inputs for the alignment for memalign to the range [1&amp;amp;lt;&amp;amp;lt;62+ 1, 1&amp;amp;lt;&amp;amp;lt;63] and exactly 1&amp;amp;lt;&amp;amp;lt;63 for posix_memalign and aligned_alloc.&lt;/p&gt;
&lt;p&gt;Typically the alignment argument passed to such functions is a known constrained quantity (e.g. page size, block size, struct sizes) and is not attacker controlled, because of which this may not be easily exploitable in practice.  An application bug could potentially result in the input alignment being too large, e.g. due to a different buffer overflow or integer overflow in the a…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: glibc&lt;/p&gt;
&lt;p&gt;The GNU C Library project provides the core libraries for the GNU system and GNU/Linux systems, as well as many other systems that use Linux as the kernel. These libraries provide critical APIs including ISO C11, POSIX.1-2008, BSD, OS-specific APIs and more. These APIs include such foundational facilities as open, read, write, malloc, printf, getaddrinfo, dlopen, pthread_create, crypt,  login, exit and more.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Passing too large an alignment to the memalign suite of functions (memalign, posix_memalign, aligned_alloc) in the GNU C Library version 2.30 to 2.42 may result in an integer overflow, which could consequently result in a heap corruption.&lt;/p&gt;
&lt;p&gt;Note that the attacker must have control over both, the size as well as the alignment arguments of the memalign function to be able to exploit this.  The size parameter must be close enough to PTRDIFF_MAX so as to overflow size_t along with the large alignment argument.  This limits the malicious inputs for the alignment for memalign to the range [1&amp;amp;lt;&amp;amp;lt;62+ 1, 1&amp;amp;lt;&amp;amp;lt;63] and exactly 1&amp;amp;lt;&amp;amp;lt;63 for posix_memalign and aligned_alloc.&lt;/p&gt;
&lt;p&gt;Typically the alignment argument passed to such functions is a known constrained quantity (e.g. page size, block size, struct sizes) and is not attacker controlled, because of which this may not be easily exploitable in practice.  An application bug could potentially result in the input alignment being too large, e.g. due to a different buffer overflow or integer overflow in the a…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-1198</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10662-1 — glibc-2.43-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10662-1</link>
      <description>&lt;p&gt;glibc-2.43-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;glibc-2.43-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10662-1</guid>
    </item>
    <item>
      <title>RHSA-2026:3228 — Red Hat Security Advisory: Cost Management Metrics Operator Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:3228</link>
      <description>&lt;p&gt;openssl: OpenSSL: Arbitrary code execution or denial of service through crafted PKCS#12 file glibc: wordexp with WRDE_REUSE and WRDE_APPEND may return uninitialized memory openssl: OpenSSL: Remote code execution or Denial of Service via oversized Initialization Vector in CMS parsing openssl: OpenSSL: Denial of Service via NULL pointer dereference in QUIC protocol handling openssl: OpenSSL: Data integrity bypass in `openssl dgst` command due to silent truncation openssl: OpenSSL: Denial of Service due to excessive memory allocation in TLS 1.3 certificate compression openssl: OpenSSL: Denial of Service due to out-of-bounds write in BIO filter openssl: OpenSSL: Information disclosure and data tampering via specific low-level OCB encryption/decryption calls openssl: OpenSSL: Arbitrary code execution due to out-of-bounds write in PKCS#12 processing openssl: OpenSSL: Denial of Service via malformed TimeStamp Response openssl: OpenSSL: Denial of Service via malformed PKCS#12 file processing glibc: Integer overflow in memalign leads to heap corruption glibc: glibc: Information disclosure via zero-valued network query openssl: OpenSSL: Denial of Service due to type confusion in PKCS#12 file processing openssl: OpenSSL: Denial of Service via type confusion in PKCS#7 signature verification&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;openssl: OpenSSL: Arbitrary code execution or denial of service through crafted PKCS#12 file glibc: wordexp with WRDE_REUSE and WRDE_APPEND may return uninitialized memory openssl: OpenSSL: Remote code execution or Denial of Service via oversized Initialization Vector in CMS parsing openssl: OpenSSL: Denial of Service via NULL pointer dereference in QUIC protocol handling openssl: OpenSSL: Data integrity bypass in `openssl dgst` command due to silent truncation openssl: OpenSSL: Denial of Service due to excessive memory allocation in TLS 1.3 certificate compression openssl: OpenSSL: Denial of Service due to out-of-bounds write in BIO filter openssl: OpenSSL: Information disclosure and data tampering via specific low-level OCB encryption/decryption calls openssl: OpenSSL: Arbitrary code execution due to out-of-bounds write in PKCS#12 processing openssl: OpenSSL: Denial of Service via malformed TimeStamp Response openssl: OpenSSL: Denial of Service via malformed PKCS#12 file processing glibc: Integer overflow in memalign leads to heap corruption glibc: glibc: Information disclosure via zero-valued network query openssl: OpenSSL: Denial of Service due to type confusion in PKCS#12 file processing openssl: OpenSSL: Denial of Service via type confusion in PKCS#7 signature verification&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:3228</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:0347-1 — Security update for glibc-livepatches</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:0347-1</link>
      <description>&lt;p&gt;Security update for glibc-livepatches&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for glibc-livepatches&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:0347-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-0861</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-0861</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:20.04:LTS: glibc, Ubuntu:22.04:LTS: glibc, Ubuntu:24.04:LTS: glibc, Ubuntu:25.10: glibc&lt;/p&gt;
&lt;p&gt;Passing too large an alignment to the memalign suite of functions (memalign, posix_memalign, aligned_alloc) in the GNU C Library version 2.30 to 2.42 may result in an integer overflow, which could consequently result in a heap corruption. Note that the attacker must have control over both, the size as well as the alignment arguments of the memalign function to be able to exploit this. The size parameter must be close enough to PTRDIFF_MAX so as to overflow size_t along with the large alignment argument.  This limits the malicious inputs for the alignment for memalign to the range [1&amp;lt;&amp;lt;62+ 1, 1&amp;lt;&amp;lt;63] and exactly 1&amp;lt;&amp;lt;63 for posix_memalign and aligned_alloc. Typically the alignment argument passed to such functions is a known constrained quantity (e.g. page size, block size, struct sizes) and is not attacker controlled, because of which this may not be easily exploitable in practice.  An application bug could potentially result in the input alignment being too large, e.g. due to a different buffer overflow or integer overflow in the application or its dependent libraries, but that is again an uncommon usage pattern given typical sources of alignments.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:20.04:LTS: glibc, Ubuntu:22.04:LTS: glibc, Ubuntu:24.04:LTS: glibc, Ubuntu:25.10: glibc&lt;/p&gt;
&lt;p&gt;Passing too large an alignment to the memalign suite of functions (memalign, posix_memalign, aligned_alloc) in the GNU C Library version 2.30 to 2.42 may result in an integer overflow, which could consequently result in a heap corruption. Note that the attacker must have control over both, the size as well as the alignment arguments of the memalign function to be able to exploit this. The size parameter must be close enough to PTRDIFF_MAX so as to overflow size_t along with the large alignment argument.  This limits the malicious inputs for the alignment for memalign to the range [1&amp;lt;&amp;lt;62+ 1, 1&amp;lt;&amp;lt;63] and exactly 1&amp;lt;&amp;lt;63 for posix_memalign and aligned_alloc. Typically the alignment argument passed to such functions is a known constrained quantity (e.g. page size, block size, struct sizes) and is not attacker controlled, because of which this may not be easily exploitable in practice.  An application bug could potentially result in the input alignment being too large, e.g. due to a different buffer overflow or integer overflow in the application or its dependent libraries, but that is again an uncommon usage pattern given typical sources of alignments.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-0861</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0118 — GNU libc: Schwachstelle ermöglicht Codeausführung</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0118</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in GNU libc ausnutzen, um beliebigen Programmcode auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in GNU libc ausnutzen, um beliebigen Programmcode auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0118</guid>
    </item>
  </channel>
</rss>
