<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 22:10:18 +0000</lastBuildDate>
    <item>
      <title>Withdrawn: BELL-CVE-2026-3904 — CVE-2026-3904 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-3904</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-3904</guid>
    </item>
    <item>
      <title>EUVD-2026-336365</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-336365</link>
      <description>EUVD-2026-336365</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-336365</guid>
    </item>
    <item>
      <title>fkie_cve-2026-3904</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-3904</link>
      <description>&lt;p&gt;Calling NSS-backed functions that support caching via nscd may call the 
nscd client side code and in the GNU C Library version 2.36 under high 
load on x86_64 systems, the client may call memcmp on inputs that are 
concurrently modified by other processes or threads and crash.&lt;/p&gt;
&lt;p&gt;The nscd client in the GNU C Library uses the memcmp function with 
inputs that may be concurrently modified by another thread, potentially 
resulting in spurious cache misses, which in itself is not a security 
issue.  However in the GNU C Library version 2.36 an optimized 
implementation of memcmp was introduced for x86_64 which could crash 
when invoked with such undefined behaviour, turning this into a 
potential crash of the nscd client and the application that uses it. 
This implementation was backported to the 2.35 branch, making the nscd 
client in that branch vulnerable as well.  Subsequently, the fix for 
this issue was backported to all vulnerable branches in the GNU C 
Library repository.&lt;/p&gt;
&lt;p&gt;It is advised that distributions that may have cherry-picked the memcpy 
SSE2 optimization in their copy of the GNU C Library, also apply the fix 
to avoid the potential crash in the nscd client.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Calling NSS-backed functions that support caching via nscd may call the 
nscd client side code and in the GNU C Library version 2.36 under high 
load on x86_64 systems, the client may call memcmp on inputs that are 
concurrently modified by other processes or threads and crash.&lt;/p&gt;
&lt;p&gt;The nscd client in the GNU C Library uses the memcmp function with 
inputs that may be concurrently modified by another thread, potentially 
resulting in spurious cache misses, which in itself is not a security 
issue.  However in the GNU C Library version 2.36 an optimized 
implementation of memcmp was introduced for x86_64 which could crash 
when invoked with such undefined behaviour, turning this into a 
potential crash of the nscd client and the application that uses it. 
This implementation was backported to the 2.35 branch, making the nscd 
client in that branch vulnerable as well.  Subsequently, the fix for 
this issue was backported to all vulnerable branches in the GNU C 
Library repository.&lt;/p&gt;
&lt;p&gt;It is advised that distributions that may have cherry-picked the memcpy 
SSE2 optimization in their copy of the GNU C Library, also apply the fix 
to avoid the potential crash in the nscd client.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-3904</guid>
    </item>
    <item>
      <title>GHSA-3584-5r39-4gm3</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3584-5r39-4gm3</link>
      <description>&lt;p&gt;Calling NSS-backed functions that support caching via nscd may call the 
nscd client side code and in the GNU C Library version 2.36 under high 
load on x86_64 systems, the client may call memcmp on inputs that are 
concurrently modified by other processes or threads and crash.&lt;/p&gt;
&lt;p&gt;The nscd client in the GNU C Library uses the memcmp function with 
inputs that may be concurrently modified by another thread, potentially 
resulting in spurious cache misses, which in itself is not a security 
issue.  However in the GNU C Library version 2.36 an optimized 
implementation of memcmp was introduced for x86_64 which could crash 
when invoked with such undefined behaviour, turning this into a 
potential crash of the nscd client and the application that uses it. 
This implementation was backported to the 2.35 branch, making the nscd 
client in that branch vulnerable as well.  Subsequently, the fix for 
this issue was backported to all vulnerable branches in the GNU C 
Library repository.&lt;/p&gt;
&lt;p&gt;It is advised that distributions that may have cherry-picked the memcpy 
SSE2 optimization in their copy of the GNU C Library, also apply the fix 
to avoid the potential crash in the nscd client.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Calling NSS-backed functions that support caching via nscd may call the 
nscd client side code and in the GNU C Library version 2.36 under high 
load on x86_64 systems, the client may call memcmp on inputs that are 
concurrently modified by other processes or threads and crash.&lt;/p&gt;
&lt;p&gt;The nscd client in the GNU C Library uses the memcmp function with 
inputs that may be concurrently modified by another thread, potentially 
resulting in spurious cache misses, which in itself is not a security 
issue.  However in the GNU C Library version 2.36 an optimized 
implementation of memcmp was introduced for x86_64 which could crash 
when invoked with such undefined behaviour, turning this into a 
potential crash of the nscd client and the application that uses it. 
This implementation was backported to the 2.35 branch, making the nscd 
client in that branch vulnerable as well.  Subsequently, the fix for 
this issue was backported to all vulnerable branches in the GNU C 
Library repository.&lt;/p&gt;
&lt;p&gt;It is advised that distributions that may have cherry-picked the memcpy 
SSE2 optimization in their copy of the GNU C Library, also apply the fix 
to avoid the potential crash in the nscd client.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3584-5r39-4gm3</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-3904 — Calling NSS-backed functions that support caching via nscd may call the 
nscd client side code and in the GNU C Library…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-3904</link>
      <description>msrc_CVE-2026-3904</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-3904</guid>
    </item>
    <item>
      <title>RHSA-2026:7316 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:7316</link>
      <description>&lt;p&gt;glibc: wordexp with WRDE_REUSE and WRDE_APPEND may return uninitialized memory glibc: Integer overflow in memalign leads to heap corruption glibc: glibc: Information disclosure via zero-valued network query glibc: nscd client crash on x86_64 under high nscd load glibc: glibc: Incorrect DNS response parsing via crafted DNS server response glibc: glibc: Invalid DNS hostname returned via gethostbyaddr functions&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;glibc: wordexp with WRDE_REUSE and WRDE_APPEND may return uninitialized memory glibc: Integer overflow in memalign leads to heap corruption glibc: glibc: Information disclosure via zero-valued network query glibc: nscd client crash on x86_64 under high nscd load glibc: glibc: Incorrect DNS response parsing via crafted DNS server response glibc: glibc: Invalid DNS hostname returned via gethostbyaddr functions&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:7316</guid>
    </item>
    <item>
      <title>SSA-082556 — SSA-082556: Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1.5</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-082556</link>
      <description>&lt;p&gt;Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.5 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;
&lt;p&gt;Note: This SSA advises vulnerabilities for firmware version V3.1.5 only; for version V3.1.6 refer to SSA-019113.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.5 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).&lt;/p&gt;
&lt;p&gt;Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.&lt;/p&gt;
&lt;p&gt;Note: This SSA advises vulnerabilities for firmware version V3.1.5 only; for version V3.1.6 refer to SSA-019113.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-082556</guid>
    </item>
    <item>
      <title>Withdrawn: UBUNTU-CVE-2026-3904</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-3904</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: eglibc, Ubuntu:Pro:16.04:LTS: glibc, Ubuntu:Pro:18.04:LTS: glibc, Ubuntu:Pro:20.04:LTS: glibc, Ubuntu:22.04:LTS: glibc, Ubuntu:24.04:LTS: glibc, Ubuntu:25.10: glibc&lt;/p&gt;
&lt;p&gt;(Calling NSS-backed functions that support caching via nscd may call th ...)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: eglibc, Ubuntu:Pro:16.04:LTS: glibc, Ubuntu:Pro:18.04:LTS: glibc, Ubuntu:Pro:20.04:LTS: glibc, Ubuntu:22.04:LTS: glibc, Ubuntu:24.04:LTS: glibc, Ubuntu:25.10: glibc&lt;/p&gt;
&lt;p&gt;(Calling NSS-backed functions that support caching via nscd may call th ...)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-3904</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0695 — GNU libc: Schwachstelle ermöglicht Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0695</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in GNU libc ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in GNU libc ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0695</guid>
    </item>
  </channel>
</rss>
