<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 13:32:01 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:49520 — Important: ldns security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:49520</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: ldns, AlmaLinux:8: ldns-devel, AlmaLinux:8: ldns-doc, AlmaLinux:8: ldns-utils, AlmaLinux:8: perl-ldns, AlmaLinux:8: python3-ldns&lt;/p&gt;
&lt;p&gt;The ldns packages contain a library with the aim to simplify DNS programming in C. All low-level DNS/DNSSEC operations are supported. We also define a higher level API which allows a programmer to (for instance) create or sign packets.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* ldns: ldns: Off-path poisoning attacks due to insufficient query-response matching (CVE-2026-10846)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: ldns, AlmaLinux:8: ldns-devel, AlmaLinux:8: ldns-doc, AlmaLinux:8: ldns-utils, AlmaLinux:8: perl-ldns, AlmaLinux:8: python3-ldns&lt;/p&gt;
&lt;p&gt;The ldns packages contain a library with the aim to simplify DNS programming in C. All low-level DNS/DNSSEC operations are supported. We also define a higher level API which allows a programmer to (for instance) create or sign packets.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* ldns: ldns: Off-path poisoning attacks due to insufficient query-response matching (CVE-2026-10846)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:49520</guid>
    </item>
    <item>
      <title>bdu:2026-12817</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-12817</link>
      <description>bdu:2026-12817</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-12817</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0753 — De multiples vulnérabilités ont été découvertes dans Microsoft Azure. Elles permettent à un attaquant de provoquer un p…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0753</link>
      <description>certfr-2026-avi-0753</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0753</guid>
    </item>
    <item>
      <title>EUVD-2026-326398</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-326398</link>
      <description>EUVD-2026-326398</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-326398</guid>
    </item>
    <item>
      <title>fkie_cve-2026-10846</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-10846</link>
      <description>&lt;p&gt;NLnet Labs ldns 1.2.0 up to and including versions 1.9.0, when used in applications as (stub) resolver over UDP, lacks matching the query destination address and port with the response source address and port. Furthermore not the query ID, neither the question of the query is matched with that of the response. This makes applications, that use ldns for (stub) resolver functionality over UDP, vulnerable for off-path poisoning attacks. The drill tool, which is shipped with ldns, suffers from this vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;NLnet Labs ldns 1.2.0 up to and including versions 1.9.0, when used in applications as (stub) resolver over UDP, lacks matching the query destination address and port with the response source address and port. Furthermore not the query ID, neither the question of the query is matched with that of the response. This makes applications, that use ldns for (stub) resolver functionality over UDP, vulnerable for off-path poisoning attacks. The drill tool, which is shipped with ldns, suffers from this vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-10846</guid>
    </item>
    <item>
      <title>GHSA-x77r-8q36-8529</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-x77r-8q36-8529</link>
      <description>&lt;p&gt;NLnet Labs ldns 1.2.0 up to and including versions 1.9.0, when used in applications as (stub) resolver over UDP, lacks matching the query destination address and port with the response source address and port. Furthermore not the query ID, neither the question of the query is matched with that of the response. This makes applications, that use ldns for (stub) resolver functionality over UDP, vulnerable for off-path poisoning attacks. The drill tool, which is shipped with ldns, suffers from this vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;NLnet Labs ldns 1.2.0 up to and including versions 1.9.0, when used in applications as (stub) resolver over UDP, lacks matching the query destination address and port with the response source address and port. Furthermore not the query ID, neither the question of the query is matched with that of the response. This makes applications, that use ldns for (stub) resolver functionality over UDP, vulnerable for off-path poisoning attacks. The drill tool, which is shipped with ldns, suffers from this vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-x77r-8q36-8529</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-10846 — Insufficient verification that responses belong to a query</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-10846</link>
      <description>msrc_CVE-2026-10846</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-10846</guid>
    </item>
    <item>
      <title>OESA-2026-2788 — ldns security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-2788</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: ldns, openEuler:22.03-LTS-SP4: ldns, openEuler:24.03-LTS-SP1: ldns, openEuler:24.03-LTS-SP3: ldns&lt;/p&gt;
&lt;p&gt;The goal of ldns is to simplify DNS programming, it supports recent RFCs  like the DNSSEC documents, and allows developers to easily create software  conforming to current RFCs, and experimental software for current Internet  Drafts. A secondary benefit of using ldns is speed; ldns is written in C  it should be a lot faster than Perl.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;NLnet Labs ldns 1.2.0 up to and including versions 1.9.0, when used in applications as (stub) resolver over UDP, lacks matching the query destination address and port with the response source address and port. Furthermore not the query ID, neither the question of the query is matched with that of the response. This makes applications, that use ldns for (stub) resolver functionality over UDP, vulnerable for off-path poisoning attacks. The drill tool, which is shipped with ldns, suffers from this vulnerability.(CVE-2026-10846)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: ldns, openEuler:22.03-LTS-SP4: ldns, openEuler:24.03-LTS-SP1: ldns, openEuler:24.03-LTS-SP3: ldns&lt;/p&gt;
&lt;p&gt;The goal of ldns is to simplify DNS programming, it supports recent RFCs  like the DNSSEC documents, and allows developers to easily create software  conforming to current RFCs, and experimental software for current Internet  Drafts. A secondary benefit of using ldns is speed; ldns is written in C  it should be a lot faster than Perl.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;NLnet Labs ldns 1.2.0 up to and including versions 1.9.0, when used in applications as (stub) resolver over UDP, lacks matching the query destination address and port with the response source address and port. Furthermore not the query ID, neither the question of the query is matched with that of the response. This makes applications, that use ldns for (stub) resolver functionality over UDP, vulnerable for off-path poisoning attacks. The drill tool, which is shipped with ldns, suffers from this vulnerability.(CVE-2026-10846)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-2788</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10998-1 — ldns-1.9.2-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10998-1</link>
      <description>&lt;p&gt;ldns-1.9.2-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ldns-1.9.2-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10998-1</guid>
    </item>
    <item>
      <title>RHSA-2026:53402 — Red Hat Security Advisory: ldns security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:53402</link>
      <description>&lt;p&gt;ldns: ldns: Off-path poisoning attacks due to insufficient query-response matching&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ldns: ldns: Off-path poisoning attacks due to insufficient query-response matching&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:53402</guid>
    </item>
    <item>
      <title>RLSA-2026:49520 — Important: ldns security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:49520</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: ldns&lt;/p&gt;
&lt;p&gt;The ldns packages contain a library with the aim to simplify DNS programming in C. All low-level DNS/DNSSEC operations are supported. We also define a higher level API which allows a programmer to (for instance) create or sign packets.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* ldns: ldns: Off-path poisoning attacks due to insufficient query-response matching (CVE-2026-10846)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: ldns&lt;/p&gt;
&lt;p&gt;The ldns packages contain a library with the aim to simplify DNS programming in C. All low-level DNS/DNSSEC operations are supported. We also define a higher level API which allows a programmer to (for instance) create or sign packets.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* ldns: ldns: Off-path poisoning attacks due to insufficient query-response matching (CVE-2026-10846)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:49520</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:22167-1 — Security update for ldns</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:22167-1</link>
      <description>&lt;p&gt;Security update for ldns&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for ldns&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:22167-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-10846</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-10846</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: ldns, Ubuntu:Pro:18.04:LTS: ldns, Ubuntu:Pro:20.04:LTS: ldns, Ubuntu:Pro:22.04:LTS: ldns, Ubuntu:Pro:24.04:LTS: ldns, Ubuntu:25.10: ldns, Ubuntu:Pro:26.04:LTS: ldns&lt;/p&gt;
&lt;p&gt;NLnet Labs ldns 1.2.0 up to and including versions 1.9.0, when used in applications as (stub) resolver over UDP, lacks matching the query destination address and port with the response source address and port. Furthermore not the query ID, neither the question of the query is matched with that of the response. This makes applications, that use ldns for (stub) resolver functionality over UDP, vulnerable for off-path poisoning attacks. The drill tool, which is shipped with ldns, suffers from this vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: ldns, Ubuntu:Pro:18.04:LTS: ldns, Ubuntu:Pro:20.04:LTS: ldns, Ubuntu:Pro:22.04:LTS: ldns, Ubuntu:Pro:24.04:LTS: ldns, Ubuntu:25.10: ldns, Ubuntu:Pro:26.04:LTS: ldns&lt;/p&gt;
&lt;p&gt;NLnet Labs ldns 1.2.0 up to and including versions 1.9.0, when used in applications as (stub) resolver over UDP, lacks matching the query destination address and port with the response source address and port. Furthermore not the query ID, neither the question of the query is matched with that of the response. This makes applications, that use ldns for (stub) resolver functionality over UDP, vulnerable for off-path poisoning attacks. The drill tool, which is shipped with ldns, suffers from this vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-10846</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1871 — FreeBSD Project FreeBSD OS: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1871</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in FreeBSD Project FreeBSD OS ausnutzen, um erweiterte Rechte zu erlangen – möglicherweise sogar Administratorrechte –, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, Daten zu manipulieren oder andere, nicht näher definierte Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in FreeBSD Project FreeBSD OS ausnutzen, um erweiterte Rechte zu erlangen – möglicherweise sogar Administratorrechte –, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, Daten zu manipulieren oder andere, nicht näher definierte Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1871</guid>
    </item>
  </channel>
</rss>
