<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 20:33:30 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-0540 — De multiples vulnérabilités ont été découvertes dans VMware Tanzu Gemfire. Elles permettent à un attaquant de provoquer…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0540</link>
      <description>certfr-2026-avi-0540</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0540</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-AD69953 — Security fixes in argo-cd-fips 3.1.14-r0</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ad69953</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: argo-cd-fips&lt;/p&gt;
&lt;p&gt;Package argo-cd-fips version 3.1.14-r0 fixes 14 vulnerabilities: ghsa-mh2q-q3fh-2475, ghsa-p77j-4mvh-x3m3, ghsa-pc3f-x583-g7j2, ghsa-78h2-9frx-2jm8, ghsa-hfvc-g4fc-pqhx...&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: argo-cd-fips&lt;/p&gt;
&lt;p&gt;Package argo-cd-fips version 3.1.14-r0 fixes 14 vulnerabilities: ghsa-mh2q-q3fh-2475, ghsa-p77j-4mvh-x3m3, ghsa-pc3f-x583-g7j2, ghsa-78h2-9frx-2jm8, ghsa-hfvc-g4fc-pqhx...&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ad69953</guid>
    </item>
    <item>
      <title>EUVD-2026-365483</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-365483</link>
      <description>EUVD-2026-365483</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-365483</guid>
    </item>
    <item>
      <title>fkie_cve-2026-39883</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-39883</link>
      <description>&lt;p&gt;OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.15.0 to 1.42.0, the fix for CVE-2026-24051 changed the Darwin ioreg command to use an absolute path but left the BSD kenv command using a bare name, allowing the same PATH hijacking attack on BSD and Solaris platforms. This vulnerability is fixed in 1.43.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.15.0 to 1.42.0, the fix for CVE-2026-24051 changed the Darwin ioreg command to use an absolute path but left the BSD kenv command using a bare name, allowing the same PATH hijacking attack on BSD and Solaris platforms. This vulnerability is fixed in 1.43.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-39883</guid>
    </item>
    <item>
      <title>GHSA-hfvc-g4fc-pqhx — opentelemetry-go: BSD kenv command not using absolute path enables PATH hijacking</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hfvc-g4fc-pqhx</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: go.opentelemetry.io/otel/sdk&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The fix for GHSA-9h8m-3fm2-qjrq (CVE-2026-24051) changed the Darwin `ioreg` command to use an absolute path but left the BSD `kenv` command using a bare name, allowing the same PATH hijacking attack on BSD and Solaris platforms.&lt;/p&gt;
&lt;p&gt;## Root Cause&lt;/p&gt;
&lt;p&gt;`sdk/resource/host_id.go` line 42:&lt;/p&gt;
&lt;p&gt;if result, err := r.execCommand(&amp;#34;kenv&amp;#34;, &amp;#34;-q&amp;#34;, &amp;#34;smbios.system.uuid&amp;#34;); err == nil {&lt;/p&gt;
&lt;p&gt;Compare with the fixed Darwin path at line 58:&lt;/p&gt;
&lt;p&gt;result, err := r.execCommand(&amp;#34;/usr/sbin/ioreg&amp;#34;, &amp;#34;-rd1&amp;#34;, &amp;#34;-c&amp;#34;, &amp;#34;IOPlatformExpertDevice&amp;#34;)&lt;/p&gt;
&lt;p&gt;The `execCommand` helper at `sdk/resource/host_id_exec.go` uses `exec.Command(name, arg...)` which searches `$PATH` when the command name contains no path separator.&lt;/p&gt;
&lt;p&gt;Affected platforms (per build tag in `host_id_bsd.go:4`): DragonFly BSD, FreeBSD, NetBSD, OpenBSD, Solaris.&lt;/p&gt;
&lt;p&gt;The `kenv` path is reached when `/etc/hostid` does not exist (line 38-40), which is common on FreeBSD systems.&lt;/p&gt;
&lt;p&gt;## Attack&lt;/p&gt;
&lt;p&gt;1. Attacker has local access to a system running a Go application that imports `go.opentelemetry.io/otel/sdk`
2. Attacker places a malicious `kenv` binary earlier in `$PATH`
3. Application initializes OpenTelemetry resource detection at startup
4. `hostIDReaderBSD.read()` calls `exec.Command(&amp;#34;kenv&amp;#34;, ...)` which resolves to the malicious binary
5. Arbitrary code executes in the context of the application&lt;/p&gt;
&lt;p&gt;Same attack vector and impact as CVE-2026-24051.&lt;/p&gt;
&lt;p&gt;## Suggested Fix&lt;/p&gt;
&lt;p&gt;Use the absolute path:&lt;/p&gt;
&lt;p&gt;if result, err := r.execCommand(&amp;#34;/bin/kenv&amp;#34;, &amp;#34;-q&amp;#34;, &amp;#34;smbios.system.uuid&amp;#34;); e…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: go.opentelemetry.io/otel/sdk&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The fix for GHSA-9h8m-3fm2-qjrq (CVE-2026-24051) changed the Darwin `ioreg` command to use an absolute path but left the BSD `kenv` command using a bare name, allowing the same PATH hijacking attack on BSD and Solaris platforms.&lt;/p&gt;
&lt;p&gt;## Root Cause&lt;/p&gt;
&lt;p&gt;`sdk/resource/host_id.go` line 42:&lt;/p&gt;
&lt;p&gt;if result, err := r.execCommand(&amp;#34;kenv&amp;#34;, &amp;#34;-q&amp;#34;, &amp;#34;smbios.system.uuid&amp;#34;); err == nil {&lt;/p&gt;
&lt;p&gt;Compare with the fixed Darwin path at line 58:&lt;/p&gt;
&lt;p&gt;result, err := r.execCommand(&amp;#34;/usr/sbin/ioreg&amp;#34;, &amp;#34;-rd1&amp;#34;, &amp;#34;-c&amp;#34;, &amp;#34;IOPlatformExpertDevice&amp;#34;)&lt;/p&gt;
&lt;p&gt;The `execCommand` helper at `sdk/resource/host_id_exec.go` uses `exec.Command(name, arg...)` which searches `$PATH` when the command name contains no path separator.&lt;/p&gt;
&lt;p&gt;Affected platforms (per build tag in `host_id_bsd.go:4`): DragonFly BSD, FreeBSD, NetBSD, OpenBSD, Solaris.&lt;/p&gt;
&lt;p&gt;The `kenv` path is reached when `/etc/hostid` does not exist (line 38-40), which is common on FreeBSD systems.&lt;/p&gt;
&lt;p&gt;## Attack&lt;/p&gt;
&lt;p&gt;1. Attacker has local access to a system running a Go application that imports `go.opentelemetry.io/otel/sdk`
2. Attacker places a malicious `kenv` binary earlier in `$PATH`
3. Application initializes OpenTelemetry resource detection at startup
4. `hostIDReaderBSD.read()` calls `exec.Command(&amp;#34;kenv&amp;#34;, ...)` which resolves to the malicious binary
5. Arbitrary code executes in the context of the application&lt;/p&gt;
&lt;p&gt;Same attack vector and impact as CVE-2026-24051.&lt;/p&gt;
&lt;p&gt;## Suggested Fix&lt;/p&gt;
&lt;p&gt;Use the absolute path:&lt;/p&gt;
&lt;p&gt;if result, err := r.execCommand(&amp;#34;/bin/kenv&amp;#34;, &amp;#34;-q&amp;#34;, &amp;#34;smbios.system.uuid&amp;#34;); e…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hfvc-g4fc-pqhx</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11173-1 — etcd-3.6.13-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11173-1</link>
      <description>&lt;p&gt;etcd-3.6.13-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;etcd-3.6.13-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11173-1</guid>
    </item>
    <item>
      <title>RHSA-2026:26254 — Red Hat Security Advisory: Assisted Installer RHEL 9 components for Multicluster Engine for Kubernetes 2.8.8</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:26254</link>
      <description>&lt;p&gt;github.com/ulikunitz/xz: github.com/ulikunitz/xz leaks memory github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Arbitrary code execution via PATH hijacking on BSD/Solaris&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;github.com/ulikunitz/xz: github.com/ulikunitz/xz leaks memory github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Arbitrary code execution via PATH hijacking on BSD/Solaris&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:26254</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-39883</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-39883</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: golang-opentelemetry-otel, Ubuntu:24.04:LTS: golang-opentelemetry-otel, Ubuntu:25.10: golang-opentelemetry-otel, Ubuntu:26.04:LTS: golang-opentelemetry-otel&lt;/p&gt;
&lt;p&gt;OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.15.0 to 1.42.0, the fix for CVE-2026-24051 changed the Darwin ioreg command to use an absolute path but left the BSD kenv command using a bare name, allowing the same PATH hijacking attack on BSD and Solaris platforms. This vulnerability is fixed in 1.43.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: golang-opentelemetry-otel, Ubuntu:24.04:LTS: golang-opentelemetry-otel, Ubuntu:25.10: golang-opentelemetry-otel, Ubuntu:26.04:LTS: golang-opentelemetry-otel&lt;/p&gt;
&lt;p&gt;OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.15.0 to 1.42.0, the fix for CVE-2026-24051 changed the Darwin ioreg command to use an absolute path but left the BSD kenv command using a bare name, allowing the same PATH hijacking attack on BSD and Solaris platforms. This vulnerability is fixed in 1.43.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-39883</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2929 — Splunk Splunk Enterprise: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2929</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Splunk Splunk Enterprise ausnutzen, um beliebigen Code auszuführen, Berechtigungen zu erweitern, Sicherheitsmaßnahmen zu umgehen, SQL-Injection-, serverseitige Request-Forgery- und Cross-Site-Scripting-Angriffe durchzuführen, sensible Informationen offenzulegen oder zu manipulieren, Denial-of-Service-Zustände auszulösen oder andere, nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Splunk Splunk Enterprise ausnutzen, um beliebigen Code auszuführen, Berechtigungen zu erweitern, Sicherheitsmaßnahmen zu umgehen, SQL-Injection-, serverseitige Request-Forgery- und Cross-Site-Scripting-Angriffe durchzuführen, sensible Informationen offenzulegen oder zu manipulieren, Denial-of-Service-Zustände auszulösen oder andere, nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2929</guid>
    </item>
  </channel>
</rss>
