<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 05:06:49 +0000</lastBuildDate>
    <item>
      <title>BELL-CVE-2026-18374</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-18374</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: glibc, Alpaquita:25: glibc, Alpaquita:stream: glibc, BellSoft Hardened Containers:23: glibc, BellSoft Hardened Containers:25: glibc, BellSoft Hardened Containers:stream: glibc&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: glibc, Alpaquita:25: glibc, Alpaquita:stream: glibc, BellSoft Hardened Containers:23: glibc, BellSoft Hardened Containers:25: glibc, BellSoft Hardened Containers:stream: glibc&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-18374</guid>
    </item>
    <item>
      <title>EUVD-2026-361184</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-361184</link>
      <description>EUVD-2026-361184</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-361184</guid>
    </item>
    <item>
      <title>fkie_cve-2026-18374</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-18374</link>
      <description>&lt;p&gt;Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled.&lt;/p&gt;
&lt;p&gt;This usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled.&lt;/p&gt;
&lt;p&gt;This usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-18374</guid>
    </item>
    <item>
      <title>GHSA-qg52-8pr2-xj9v</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-qg52-8pr2-xj9v</link>
      <description>&lt;p&gt;Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled.&lt;/p&gt;
&lt;p&gt;This usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled.&lt;/p&gt;
&lt;p&gt;This usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-qg52-8pr2-xj9v</guid>
    </item>
    <item>
      <title>OESA-2026-3792 — glibc security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-3792</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP4: glibc&lt;/p&gt;
&lt;p&gt;The GNU C Library project provides the core libraries for the GNU system and GNU/Linux systems, as well as many other systems that use Linux as the kernel. These libraries provide critical APIs including ISO C11, POSIX.1-2008, BSD, OS-specific APIs and more. These APIs include such foundational facilities as open, read, write, malloc, printf, getaddrinfo, dlopen, pthread_create, crypt,  login, exit and more.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled. This usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation.(CVE-2026-18374)&lt;/p&gt;
&lt;p&gt;A flaw was found in glibc. The strfmon and strfmon_l functions are vulnerable to a buffer overflow when processing right-justified width padding. This occurs because an incorrect length is used for an internal memory operation, causing data to be written beyond its intended buffer. An attacker could exploit this by providing specially crafted input, potentially leading to arbitrary code execution or other severe impacts.(CVE-2026-19499)&lt;/p&gt;
&lt;p&gt;A flaw was found in glibc. A remote attacker could exploit this vulnerability by providing specially crafted input during SHIFT_JISX0213 to UCS-4 text co…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP4: glibc&lt;/p&gt;
&lt;p&gt;The GNU C Library project provides the core libraries for the GNU system and GNU/Linux systems, as well as many other systems that use Linux as the kernel. These libraries provide critical APIs including ISO C11, POSIX.1-2008, BSD, OS-specific APIs and more. These APIs include such foundational facilities as open, read, write, malloc, printf, getaddrinfo, dlopen, pthread_create, crypt,  login, exit and more.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled. This usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation.(CVE-2026-18374)&lt;/p&gt;
&lt;p&gt;A flaw was found in glibc. The strfmon and strfmon_l functions are vulnerable to a buffer overflow when processing right-justified width padding. This occurs because an incorrect length is used for an internal memory operation, causing data to be written beyond its intended buffer. An attacker could exploit this by providing specially crafted input, potentially leading to arbitrary code execution or other severe impacts.(CVE-2026-19499)&lt;/p&gt;
&lt;p&gt;A flaw was found in glibc. A remote attacker could exploit this vulnerability by providing specially crafted input during SHIFT_JISX0213 to UCS-4 text co…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-3792</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11787-1 — glibc-2.44-2.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11787-1</link>
      <description>&lt;p&gt;glibc-2.44-2.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;glibc-2.44-2.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11787-1</guid>
    </item>
    <item>
      <title>RHSA-2026:65339 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:65339</link>
      <description>&lt;p&gt;glibc: glibc: Heap buffer overflow via attacker-controlled fopen mode string&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;glibc: glibc: Heap buffer overflow via attacker-controlled fopen mode string&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:65339</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:23738-1 — Security update for glibc</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:23738-1</link>
      <description>&lt;p&gt;Security update for glibc&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for glibc&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:23738-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-18374</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-18374</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: eglibc, Ubuntu:Pro:16.04:LTS: glibc, Ubuntu:Pro:18.04:LTS: glibc, Ubuntu:Pro:20.04:LTS: glibc, Ubuntu:22.04:LTS: glibc, Ubuntu:24.04:LTS: glibc, Ubuntu:26.04:LTS: glibc&lt;/p&gt;
&lt;p&gt;Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled. This usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: eglibc, Ubuntu:Pro:16.04:LTS: glibc, Ubuntu:Pro:18.04:LTS: glibc, Ubuntu:Pro:20.04:LTS: glibc, Ubuntu:22.04:LTS: glibc, Ubuntu:24.04:LTS: glibc, Ubuntu:26.04:LTS: glibc&lt;/p&gt;
&lt;p&gt;Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled. This usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for `ccs` should not pass them through without validation.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-18374</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3063 — GNU libc: Schwachstelle ermöglicht nicht spezifizierten Angriff</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3063</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in GNU libc ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in GNU libc ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3063</guid>
    </item>
  </channel>
</rss>
