<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 14:10:11 +0000</lastBuildDate>
    <item>
      <title>BELL-CVE-2026-19499</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-19499</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: glibc, Alpaquita:25: glibc, Alpaquita:stream: glibc, BellSoft Hardened Containers:23: glibc, BellSoft Hardened Containers:25: glibc, BellSoft Hardened Containers:stream: glibc&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: glibc, Alpaquita:25: glibc, Alpaquita:stream: glibc, BellSoft Hardened Containers:23: glibc, BellSoft Hardened Containers:25: glibc, BellSoft Hardened Containers:stream: glibc&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-19499</guid>
    </item>
    <item>
      <title>EUVD-2026-368229</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-368229</link>
      <description>EUVD-2026-368229</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-368229</guid>
    </item>
    <item>
      <title>fkie_cve-2026-19499</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-19499</link>
      <description>&lt;p&gt;Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding.&lt;/p&gt;
&lt;p&gt;Exploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller.&lt;/p&gt;
&lt;p&gt;At the time of publication, no network-facing application impact is known.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding.&lt;/p&gt;
&lt;p&gt;Exploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller.&lt;/p&gt;
&lt;p&gt;At the time of publication, no network-facing application impact is known.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-19499</guid>
    </item>
    <item>
      <title>GHSA-3vcj-mghm-mw9p</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3vcj-mghm-mw9p</link>
      <description>&lt;p&gt;Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding.&lt;/p&gt;
&lt;p&gt;Exploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller.&lt;/p&gt;
&lt;p&gt;At the time of publication, no network-facing application impact is known.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding.&lt;/p&gt;
&lt;p&gt;Exploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller.&lt;/p&gt;
&lt;p&gt;At the time of publication, no network-facing application impact is known.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3vcj-mghm-mw9p</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-19499 — Buffer overflow in strfmon and strfmon_l right-justification padding</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-19499</link>
      <description>msrc_CVE-2026-19499</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-19499</guid>
    </item>
    <item>
      <title>OESA-2026-3617 — glibc security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-3617</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: glibc&lt;/p&gt;
&lt;p&gt;The GNU C Library project provides the core libraries for the GNU system and GNU/Linux systems, as well as many other systems that use Linux as the kernel. These libraries provide critical APIs including ISO C11, POSIX.1-2008, BSD, OS-specific APIs and more. These APIs include such foundational facilities as open, read, write, malloc, printf, getaddrinfo, dlopen, pthread_create, crypt,  login, exit and more.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A flaw was found in glibc. The strfmon and strfmon_l functions are vulnerable to a buffer overflow when processing right-justified width padding. This occurs because an incorrect length is used for an internal memory operation, causing data to be written beyond its intended buffer. An attacker could exploit this by providing specially crafted input, potentially leading to arbitrary code execution or other severe impacts.(CVE-2026-19499)&lt;/p&gt;
&lt;p&gt;A flaw was found in glibc. A remote attacker could exploit this vulnerability by providing specially crafted input during SHIFT_JISX0213 to UCS-4 text conversion. This crafted input can cause the application to repeatedly emit a buffered code point without consuming further input, leading to persistent retry churn. This can result in a denial of service (DoS) for callers converting untrusted text.(CVE-2026-77117)&lt;/p&gt;
&lt;p&gt;A flaw was found in glibc. This vulnerability allows a remote attacker to cause a denial of service (DoS) by providing specially crafted text to an application that converts text from SHIFT_JISX0213 to UCS…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: glibc&lt;/p&gt;
&lt;p&gt;The GNU C Library project provides the core libraries for the GNU system and GNU/Linux systems, as well as many other systems that use Linux as the kernel. These libraries provide critical APIs including ISO C11, POSIX.1-2008, BSD, OS-specific APIs and more. These APIs include such foundational facilities as open, read, write, malloc, printf, getaddrinfo, dlopen, pthread_create, crypt,  login, exit and more.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A flaw was found in glibc. The strfmon and strfmon_l functions are vulnerable to a buffer overflow when processing right-justified width padding. This occurs because an incorrect length is used for an internal memory operation, causing data to be written beyond its intended buffer. An attacker could exploit this by providing specially crafted input, potentially leading to arbitrary code execution or other severe impacts.(CVE-2026-19499)&lt;/p&gt;
&lt;p&gt;A flaw was found in glibc. A remote attacker could exploit this vulnerability by providing specially crafted input during SHIFT_JISX0213 to UCS-4 text conversion. This crafted input can cause the application to repeatedly emit a buffered code point without consuming further input, leading to persistent retry churn. This can result in a denial of service (DoS) for callers converting untrusted text.(CVE-2026-77117)&lt;/p&gt;
&lt;p&gt;A flaw was found in glibc. This vulnerability allows a remote attacker to cause a denial of service (DoS) by providing specially crafted text to an application that converts text from SHIFT_JISX0213 to UCS…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-3617</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11787-1 — glibc-2.44-2.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11787-1</link>
      <description>&lt;p&gt;glibc-2.44-2.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;glibc-2.44-2.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11787-1</guid>
    </item>
    <item>
      <title>RHSA-2026:60865 — Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:60865</link>
      <description>&lt;p&gt;glibc: Buffer Overflow in strfmon right-justification padding&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;glibc: Buffer Overflow in strfmon right-justification padding&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:60865</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:23738-1 — Security update for glibc</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:23738-1</link>
      <description>&lt;p&gt;Security update for glibc&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for glibc&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:23738-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-19499</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-19499</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: glibc, Ubuntu:26.04:LTS: glibc&lt;/p&gt;
&lt;p&gt;Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding. Exploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller. At the time of publication, no network-facing application impact is known.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: glibc, Ubuntu:26.04:LTS: glibc&lt;/p&gt;
&lt;p&gt;Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding. Exploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller. At the time of publication, no network-facing application impact is known.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-19499</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3014 — GNU libc: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3014</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in GNU libc ausnutzen, um beliebigen Programmcode auszuführen, vertrauliche Informationen offenzulegen, Daten zu manipulieren, einen Denial-of-Service-Zustand auszulösen oder andere, nicht näher bezeichnete Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in GNU libc ausnutzen, um beliebigen Programmcode auszuführen, vertrauliche Informationen offenzulegen, Daten zu manipulieren, einen Denial-of-Service-Zustand auszulösen oder andere, nicht näher bezeichnete Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3014</guid>
    </item>
  </channel>
</rss>
