<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 14:15:08 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-0623 — De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Certaines d'entre elles permettent à un at…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0623</link>
      <description>certfr-2026-avi-0623</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0623</guid>
    </item>
    <item>
      <title>EUVD-2026-362247</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-362247</link>
      <description>EUVD-2026-362247</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-362247</guid>
    </item>
    <item>
      <title>fkie_cve-2026-34956</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-34956</link>
      <description>&lt;p&gt;A flaw was found in Open vSwitch. When Open vSwitch is configured with a conntrack flow using FTP helpers over the userspace datapath, a remote attacker can send a specially crafted FTP stream with an EPASV command exceeding 255 characters. This heap access error can lead to a crash, resulting in a Denial of Service (DoS) for the affected system.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in Open vSwitch. When Open vSwitch is configured with a conntrack flow using FTP helpers over the userspace datapath, a remote attacker can send a specially crafted FTP stream with an EPASV command exceeding 255 characters. This heap access error can lead to a crash, resulting in a Denial of Service (DoS) for the affected system.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-34956</guid>
    </item>
    <item>
      <title>GHSA-q5f5-xxh8-jx9h</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-q5f5-xxh8-jx9h</link>
      <description>&lt;p&gt;A flaw was found in Open vSwitch. When Open vSwitch is configured with a conntrack flow using FTP helpers over the userspace datapath, a remote attacker can send a specially crafted FTP stream with an EPASV command exceeding 255 characters. This heap access error can lead to a crash, resulting in a Denial of Service (DoS) for the affected system.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in Open vSwitch. When Open vSwitch is configured with a conntrack flow using FTP helpers over the userspace datapath, a remote attacker can send a specially crafted FTP stream with an EPASV command exceeding 255 characters. This heap access error can lead to a crash, resulting in a Denial of Service (DoS) for the affected system.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-q5f5-xxh8-jx9h</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-34956 — Openvswitch: open vswitch: denial of service via malformed ftp epasv command</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-34956</link>
      <description>msrc_CVE-2026-34956</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-34956</guid>
    </item>
    <item>
      <title>OESA-2026-1871 — openvswitch security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-1871</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: openvswitch&lt;/p&gt;
&lt;p&gt;Open vSwitch provides standard network bridging functions and support for the OpenFlow protocol for remote per-flow control of traffic.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;[&amp;amp;quot;Description\n===========\n\nMultiple versions of Open vSwitch are vulnerable to crafted FTP payloads\ncausing invalid memory accesses, potential denial of service, and possible\nremote code execution.  This impacts the userspace implementation of\nconntrack.  Triggering the vulnerability requires that Open vSwitch has\nconfigured conntrack flows specifying the FTP alg handler.  Conntrack\nhandlers in userspace are not automatically applied.\n\nThe issue is caused by type narrowing when copying FTP substrings.  It\nhas existed in all versions of the userspace conntrack supporting the\nFTP handler.  This was introduced with Open vSwitch version 2.8.0 and\naffects all versions up to 3.7.0.\n\nThe Common Vulnerabilities and Exposures project (cve.mitre.org) has\nassigned CVE-2026-34956 identifier to this issue.  At the time of writing\nthe flaw is considered with Moderate impact and 5.9 CVSS.\n\n\nMitigation\n==========\n\nFor any affected version of Open vSwitch, avoiding the FTP alg will\nprevent the issue from triggering.  The Open vSwitch team does not\nrecommend attempting to mitigate the vulnerability this way because it\nmay impact packet forwarding.\n\nBy default, alg handlers are not installed, and must be added as part\nof the OpenFlow rules (via &amp;amp;apos;ct(alg=ftp)&amp;amp;apos; for example).\n\nUsers can check if t…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: openvswitch&lt;/p&gt;
&lt;p&gt;Open vSwitch provides standard network bridging functions and support for the OpenFlow protocol for remote per-flow control of traffic.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;[&amp;amp;quot;Description\n===========\n\nMultiple versions of Open vSwitch are vulnerable to crafted FTP payloads\ncausing invalid memory accesses, potential denial of service, and possible\nremote code execution.  This impacts the userspace implementation of\nconntrack.  Triggering the vulnerability requires that Open vSwitch has\nconfigured conntrack flows specifying the FTP alg handler.  Conntrack\nhandlers in userspace are not automatically applied.\n\nThe issue is caused by type narrowing when copying FTP substrings.  It\nhas existed in all versions of the userspace conntrack supporting the\nFTP handler.  This was introduced with Open vSwitch version 2.8.0 and\naffects all versions up to 3.7.0.\n\nThe Common Vulnerabilities and Exposures project (cve.mitre.org) has\nassigned CVE-2026-34956 identifier to this issue.  At the time of writing\nthe flaw is considered with Moderate impact and 5.9 CVSS.\n\n\nMitigation\n==========\n\nFor any affected version of Open vSwitch, avoiding the FTP alg will\nprevent the issue from triggering.  The Open vSwitch team does not\nrecommend attempting to mitigate the vulnerability this way because it\nmay impact packet forwarding.\n\nBy default, alg handlers are not installed, and must be added as part\nof the OpenFlow rules (via &amp;amp;apos;ct(alg=ftp)&amp;amp;apos; for example).\n\nUsers can check if t…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-1871</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10534-1 — libopenvswitch-3_7-0-3.7.1-33.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10534-1</link>
      <description>&lt;p&gt;libopenvswitch-3_7-0-3.7.1-33.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libopenvswitch-3_7-0-3.7.1-33.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10534-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:1440-1 — Security update for openvswitch3</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:1440-1</link>
      <description>&lt;p&gt;Security update for openvswitch3&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for openvswitch3&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:1440-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-34956</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-34956</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:18.04:LTS: openvswitch, Ubuntu:20.04:LTS: openvswitch, Ubuntu:22.04:LTS: openvswitch, Ubuntu:24.04:LTS: openvswitch, Ubuntu:25.10: openvswitch, Ubuntu:26.04:LTS: openvswitch&lt;/p&gt;
&lt;p&gt;A flaw was found in Open vSwitch. When Open vSwitch is configured with a conntrack flow using FTP helpers over the userspace datapath, a remote attacker can send a specially crafted FTP stream with an EPASV command exceeding 255 characters. This heap access error can lead to a crash, resulting in a Denial of Service (DoS) for the affected system.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:18.04:LTS: openvswitch, Ubuntu:20.04:LTS: openvswitch, Ubuntu:22.04:LTS: openvswitch, Ubuntu:24.04:LTS: openvswitch, Ubuntu:25.10: openvswitch, Ubuntu:26.04:LTS: openvswitch&lt;/p&gt;
&lt;p&gt;A flaw was found in Open vSwitch. When Open vSwitch is configured with a conntrack flow using FTP helpers over the userspace datapath, a remote attacker can send a specially crafted FTP stream with an EPASV command exceeding 255 characters. This heap access error can lead to a crash, resulting in a Denial of Service (DoS) for the affected system.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-34956</guid>
    </item>
  </channel>
</rss>
