<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 11:36:24 +0000</lastBuildDate>
    <item>
      <title>BELL-CVE-2026-13574</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-13574</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: llvm15, Alpaquita:25: llvm19, Alpaquita:stream: llvm19, Alpaquita:stream: llvm21, Alpaquita:stream: llvm22&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: llvm15, Alpaquita:25: llvm19, Alpaquita:stream: llvm19, Alpaquita:stream: llvm21, Alpaquita:stream: llvm22&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-13574</guid>
    </item>
    <item>
      <title>EUVD-2026-333686</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-333686</link>
      <description>EUVD-2026-333686</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-333686</guid>
    </item>
    <item>
      <title>fkie_cve-2026-13574</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-13574</link>
      <description>&lt;p&gt;A vulnerability was determined in llvm llvm-project up to 22.1.6. This impacts the function GCRelocateInst::getBasePtr in the library llvm/lib/IR/IntrinsicInst.cpp of the component Bitcode File Handler. This manipulation causes heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been publicly disclosed and may be utilized. There are still doubts about whether this vulnerability truly exists. The LLVM project explains, that the reported behavior is outside its documented security scope and therefore not considered a security vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability was determined in llvm llvm-project up to 22.1.6. This impacts the function GCRelocateInst::getBasePtr in the library llvm/lib/IR/IntrinsicInst.cpp of the component Bitcode File Handler. This manipulation causes heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been publicly disclosed and may be utilized. There are still doubts about whether this vulnerability truly exists. The LLVM project explains, that the reported behavior is outside its documented security scope and therefore not considered a security vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-13574</guid>
    </item>
    <item>
      <title>GHSA-pf97-7r98-qpj7</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-pf97-7r98-qpj7</link>
      <description>&lt;p&gt;A vulnerability was determined in llvm llvm-project up to 22.1.6. This impacts the function GCRelocateInst::getBasePtr in the library llvm/lib/IR/IntrinsicInst.cpp of the component Bitcode File Handler. This manipulation causes heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability was determined in llvm llvm-project up to 22.1.6. This impacts the function GCRelocateInst::getBasePtr in the library llvm/lib/IR/IntrinsicInst.cpp of the component Bitcode File Handler. This manipulation causes heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-pf97-7r98-qpj7</guid>
    </item>
    <item>
      <title>RHSA-2026:24069 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:24069</link>
      <description>&lt;p&gt;llvm: llvm: Denial of Service via stack-based buffer overflow in StringMap::insert llvm: llvm-project: LLVM: Denial of service via heap-based buffer overflow in Bitcode File Handler urllib3: urllib3: Denial of Service due to excessive HTTP response decompression brace-expansion: brace-expansion: Denial of Service due to excessive memory allocation when expanding large numeric ranges&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;llvm: llvm: Denial of Service via stack-based buffer overflow in StringMap::insert llvm: llvm-project: LLVM: Denial of service via heap-based buffer overflow in Bitcode File Handler urllib3: urllib3: Denial of Service due to excessive HTTP response decompression brace-expansion: brace-expansion: Denial of Service due to excessive memory allocation when expanding large numeric ranges&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:24069</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-13574</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-13574</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: llvm-toolchain-18, Ubuntu:24.04:LTS: llvm-toolchain-18, Ubuntu:24.04:LTS: llvm-toolchain-19, Ubuntu:25.10: llvm-toolchain-18, Ubuntu:25.10: llvm-toolchain-19, Ubuntu:25.10: llvm-toolchain-21, Ubuntu:26.04:LTS: llvm-toolchain-18, Ubuntu:26.04:LTS: llvm-toolchain-19, Ubuntu:26.04:LTS: llvm-toolchain-21, Ubuntu:26.04:LTS: llvm-toolchain-22&lt;/p&gt;
&lt;p&gt;A vulnerability was determined in llvm llvm-project up to 22.1.6. This impacts the function GCRelocateInst::getBasePtr in the library llvm/lib/IR/IntrinsicInst.cpp of the component Bitcode File Handler. This manipulation causes heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been publicly disclosed and may be utilized. There are still doubts about whether this vulnerability truly exists. The LLVM project explains, that the reported behavior is outside its documented security scope and therefore not considered a security vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: llvm-toolchain-18, Ubuntu:24.04:LTS: llvm-toolchain-18, Ubuntu:24.04:LTS: llvm-toolchain-19, Ubuntu:25.10: llvm-toolchain-18, Ubuntu:25.10: llvm-toolchain-19, Ubuntu:25.10: llvm-toolchain-21, Ubuntu:26.04:LTS: llvm-toolchain-18, Ubuntu:26.04:LTS: llvm-toolchain-19, Ubuntu:26.04:LTS: llvm-toolchain-21, Ubuntu:26.04:LTS: llvm-toolchain-22&lt;/p&gt;
&lt;p&gt;A vulnerability was determined in llvm llvm-project up to 22.1.6. This impacts the function GCRelocateInst::getBasePtr in the library llvm/lib/IR/IntrinsicInst.cpp of the component Bitcode File Handler. This manipulation causes heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been publicly disclosed and may be utilized. There are still doubts about whether this vulnerability truly exists. The LLVM project explains, that the reported behavior is outside its documented security scope and therefore not considered a security vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-13574</guid>
    </item>
  </channel>
</rss>
