<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 12:49:11 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-324008</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-324008</link>
      <description>EUVD-2026-324008</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-324008</guid>
    </item>
    <item>
      <title>fkie_cve-2026-45678</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-45678</link>
      <description>&lt;p&gt;OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the Postgres protocol parser assumes BIND message payloads contain a valid NUL-terminated portal name. A crafted empty or unterminated payload can make OBI slice beyond the end of the captured buffer and panic. This issue has been patched in version 0.9.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the Postgres protocol parser assumes BIND message payloads contain a valid NUL-terminated portal name. A crafted empty or unterminated payload can make OBI slice beyond the end of the captured buffer and panic. This issue has been patched in version 0.9.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-45678</guid>
    </item>
    <item>
      <title>GHSA-pgvv-q3wf-mm9m — OpenTelemetry eBPF Instrumentation: Postgres BIND parsing can panic on malformed payloads</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-pgvv-q3wf-mm9m</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: go.opentelemetry.io/obi&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The Postgres protocol parser assumes `BIND` message payloads contain a valid NUL-terminated portal name. A crafted empty or unterminated payload can make OBI slice beyond the end of the captured buffer and panic.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The vulnerable logic is in [pkg/ebpf/common/sql_detect_postgres.go](https://github.com/open-telemetry/opentelemetry-ebpf-instrumentation/blob/d5691806adc98008bacd2b7a4a4e0cd38ea51227/pkg/components/ebpf/common/sql_detect_postgres.go#L286-L294). In the `BIND` case, OBI converts the full payload to a string with `unix.ByteSliceToString(msg.data)`, computes `portalLen := len(portal) + 1`, and then slices `msg.data[portalLen:]` to derive the statement name.&lt;/p&gt;
&lt;p&gt;There is no check that `msg.data` actually contains a NUL terminator or even enough bytes for `portalLen`. With an empty payload or a truncated message, `portalLen` can exceed the slice length and trigger a runtime panic.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;Local testing with a minimal reproducer showed the expected `slice bounds out of range` crash for an empty BIND payload.&lt;/p&gt;
&lt;p&gt;Use a vulnerable build:&lt;/p&gt;
&lt;p&gt;```bash
git checkout v0.0.0-rc.1+build
make build
```&lt;/p&gt;
&lt;p&gt;Start a local Postgres instance and OBI:&lt;/p&gt;
&lt;p&gt;```bash
docker run --rm -e POSTGRES_PASSWORD=postgres -p 5432:5432 postgres:17
sudo ./bin/obi
```&lt;/p&gt;
&lt;p&gt;Send a malformed `BIND` frame with an empty payload:&lt;/p&gt;
&lt;p&gt;```python
# save as /tmp/pg-bind-poc.py
import socket, struct&lt;/p&gt;
&lt;p&gt;tag = b&amp;#39;B&amp;#39;
length = struct.pack(&amp;#34;&amp;gt;I&amp;#34;, 4)
payload = b&amp;#34;&amp;#34;&lt;/p&gt;
&lt;p&gt;s = socket.create_connection((&amp;#34;127.0.0.1&amp;#34;, 5432))
s.…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: go.opentelemetry.io/obi&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The Postgres protocol parser assumes `BIND` message payloads contain a valid NUL-terminated portal name. A crafted empty or unterminated payload can make OBI slice beyond the end of the captured buffer and panic.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The vulnerable logic is in [pkg/ebpf/common/sql_detect_postgres.go](https://github.com/open-telemetry/opentelemetry-ebpf-instrumentation/blob/d5691806adc98008bacd2b7a4a4e0cd38ea51227/pkg/components/ebpf/common/sql_detect_postgres.go#L286-L294). In the `BIND` case, OBI converts the full payload to a string with `unix.ByteSliceToString(msg.data)`, computes `portalLen := len(portal) + 1`, and then slices `msg.data[portalLen:]` to derive the statement name.&lt;/p&gt;
&lt;p&gt;There is no check that `msg.data` actually contains a NUL terminator or even enough bytes for `portalLen`. With an empty payload or a truncated message, `portalLen` can exceed the slice length and trigger a runtime panic.&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;Local testing with a minimal reproducer showed the expected `slice bounds out of range` crash for an empty BIND payload.&lt;/p&gt;
&lt;p&gt;Use a vulnerable build:&lt;/p&gt;
&lt;p&gt;```bash
git checkout v0.0.0-rc.1+build
make build
```&lt;/p&gt;
&lt;p&gt;Start a local Postgres instance and OBI:&lt;/p&gt;
&lt;p&gt;```bash
docker run --rm -e POSTGRES_PASSWORD=postgres -p 5432:5432 postgres:17
sudo ./bin/obi
```&lt;/p&gt;
&lt;p&gt;Send a malformed `BIND` frame with an empty payload:&lt;/p&gt;
&lt;p&gt;```python
# save as /tmp/pg-bind-poc.py
import socket, struct&lt;/p&gt;
&lt;p&gt;tag = b&amp;#39;B&amp;#39;
length = struct.pack(&amp;#34;&amp;gt;I&amp;#34;, 4)
payload = b&amp;#34;&amp;#34;&lt;/p&gt;
&lt;p&gt;s = socket.create_connection((&amp;#34;127.0.0.1&amp;#34;, 5432))
s.…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-pgvv-q3wf-mm9m</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11053-1 — alloy-1.17.0-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11053-1</link>
      <description>&lt;p&gt;alloy-1.17.0-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;alloy-1.17.0-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11053-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:22575-1 — Security update for alloy</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:22575-1</link>
      <description>&lt;p&gt;Security update for alloy&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for alloy&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:22575-1</guid>
    </item>
  </channel>
</rss>
