<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 02:21:34 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-07368</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-07368</link>
      <description>bdu:2026-07368</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-07368</guid>
    </item>
    <item>
      <title>EUVD-2026-277741</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-277741</link>
      <description>EUVD-2026-277741</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-277741</guid>
    </item>
    <item>
      <title>fkie_cve-2026-33743</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-33743</link>
      <description>&lt;p&gt;Incus is a system container and virtual machine manager. Prior to version 6.23.0, a specially crafted storage bucket backup can be used by an user with access to Incus&amp;#39; storage bucket feature to crash the Incus daemon. Repeated use of this attack can be used to keep the server offline causing a denial of service of the control plane API. This does not impact any running workload, existing containers and virtual machines will keep operating. Version 6.23.0 fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Incus is a system container and virtual machine manager. Prior to version 6.23.0, a specially crafted storage bucket backup can be used by an user with access to Incus&amp;#39; storage bucket feature to crash the Incus daemon. Repeated use of this attack can be used to keep the server offline causing a denial of service of the control plane API. This does not impact any running workload, existing containers and virtual machines will keep operating. Version 6.23.0 fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-33743</guid>
    </item>
    <item>
      <title>GHSA-vg76-xmhg-j5x3 — Incus vulnerable to denial of source through crafted bucket backup file</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-vg76-xmhg-j5x3</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/lxc/incus/v6, Go: github.com/lxc/incus&lt;/p&gt;
&lt;p&gt;### Summary
A specially crafted storage bucket backup can be used by an user with access to Incus&amp;#39; storage bucket feature to crash the Incus daemon. Repeated use of this attack can be used to keep the server offline causing a denial of service of the control plane API.&lt;/p&gt;
&lt;p&gt;This does not impact any running workload, existing containers and virtual machines will keep operating.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The S3 transfer manager contains an unchecked string slicing vulnerability that allows an authenticated attacker to crash the daemon during S3 restore operations. While processing tar headers from a supplied backup archive, the code skips only the index entry and strips the expected bucket prefix from all other entries without first validating the header name.&lt;/p&gt;
&lt;p&gt;In Go, slicing a string with a starting index beyond the string length triggers a runtime panic. Because no prefix or length validation is performed before this operation, a malicious archive containing a non-index entry with a shorter-than-expected header name can trigger a slice-bounds panic and terminate the daemon. This results in immediate denial of service on the node.&lt;/p&gt;
&lt;p&gt;Affected File:
https://github.com/lxc/incus/blob/v6.20.0/internal/server/storage/s3/transfer_manager.go&lt;/p&gt;
&lt;p&gt;Affected Code:
```
func (t TransferManager) UploadAllFiles(bucketName string, srcData io.ReadSeeker) error {
    [...]
    for {
        hdr, err := tr.Next()
        if err == io.EOF {
            break // End of archive.
        }&lt;/p&gt;
&lt;p&gt;// Skip index.yaml…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/lxc/incus/v6, Go: github.com/lxc/incus&lt;/p&gt;
&lt;p&gt;### Summary
A specially crafted storage bucket backup can be used by an user with access to Incus&amp;#39; storage bucket feature to crash the Incus daemon. Repeated use of this attack can be used to keep the server offline causing a denial of service of the control plane API.&lt;/p&gt;
&lt;p&gt;This does not impact any running workload, existing containers and virtual machines will keep operating.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The S3 transfer manager contains an unchecked string slicing vulnerability that allows an authenticated attacker to crash the daemon during S3 restore operations. While processing tar headers from a supplied backup archive, the code skips only the index entry and strips the expected bucket prefix from all other entries without first validating the header name.&lt;/p&gt;
&lt;p&gt;In Go, slicing a string with a starting index beyond the string length triggers a runtime panic. Because no prefix or length validation is performed before this operation, a malicious archive containing a non-index entry with a shorter-than-expected header name can trigger a slice-bounds panic and terminate the daemon. This results in immediate denial of service on the node.&lt;/p&gt;
&lt;p&gt;Affected File:
https://github.com/lxc/incus/blob/v6.20.0/internal/server/storage/s3/transfer_manager.go&lt;/p&gt;
&lt;p&gt;Affected Code:
```
func (t TransferManager) UploadAllFiles(bucketName string, srcData io.ReadSeeker) error {
    [...]
    for {
        hdr, err := tr.Next()
        if err == io.EOF {
            break // End of archive.
        }&lt;/p&gt;
&lt;p&gt;// Skip index.yaml…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-vg76-xmhg-j5x3</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10450-1 — incus-6.23-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10450-1</link>
      <description>&lt;p&gt;incus-6.23-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;incus-6.23-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10450-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-33743</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-33743</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:24.04:LTS: incus, Ubuntu:25.10: incus, Ubuntu:Pro:26.04:LTS: incus&lt;/p&gt;
&lt;p&gt;Incus is a system container and virtual machine manager. Prior to version 6.23.0, a specially crafted storage bucket backup can be used by an user with access to Incus&amp;#39; storage bucket feature to crash the Incus daemon. Repeated use of this attack can be used to keep the server offline causing a denial of service of the control plane API. This does not impact any running workload, existing containers and virtual machines will keep operating. Version 6.23.0 fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:24.04:LTS: incus, Ubuntu:25.10: incus, Ubuntu:Pro:26.04:LTS: incus&lt;/p&gt;
&lt;p&gt;Incus is a system container and virtual machine manager. Prior to version 6.23.0, a specially crafted storage bucket backup can be used by an user with access to Incus&amp;#39; storage bucket feature to crash the Incus daemon. Repeated use of this attack can be used to keep the server offline causing a denial of service of the control plane API. This does not impact any running workload, existing containers and virtual machines will keep operating. Version 6.23.0 fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-33743</guid>
    </item>
  </channel>
</rss>
