<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 15:15:52 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-324315</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-324315</link>
      <description>EUVD-2026-324315</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-324315</guid>
    </item>
    <item>
      <title>fkie_cve-2026-45686</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-45686</link>
      <description>&lt;p&gt;OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.7.0 to before version 0.9.0, a remotely reachable integer overflow in OBI&amp;#39;s memcached text protocol parser can crash the OBI process and cause denial of service. When parsing memcached storage commands such as set, add, replace, append, prepend, or cas, OBI accepts extremely large &amp;lt;bytes&amp;gt; values and adds the payload delimiter length without checking for overflow. A crafted request with &amp;lt;bytes&amp;gt; set to math.MaxInt or math.MaxInt-1 causes the computed payload length to wrap negative and triggers a runtime panic in LargeBufferReader.Peek. This issue has been patched in version 0.9.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.7.0 to before version 0.9.0, a remotely reachable integer overflow in OBI&amp;#39;s memcached text protocol parser can crash the OBI process and cause denial of service. When parsing memcached storage commands such as set, add, replace, append, prepend, or cas, OBI accepts extremely large &amp;lt;bytes&amp;gt; values and adds the payload delimiter length without checking for overflow. A crafted request with &amp;lt;bytes&amp;gt; set to math.MaxInt or math.MaxInt-1 causes the computed payload length to wrap negative and triggers a runtime panic in LargeBufferReader.Peek. This issue has been patched in version 0.9.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-45686</guid>
    </item>
    <item>
      <title>GHSA-43g7-cwr8-q3jh — OpenTelemetry eBPF Instrumentation: Memcached payload length overflow can crash OBI</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-43g7-cwr8-q3jh</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: go.opentelemetry.io/obi&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;A remotely reachable integer overflow in OBI&amp;#39;s memcached text protocol parser can crash the OBI process and cause denial of service. When parsing memcached storage commands such as `set`, `add`, `replace`, `append`, `prepend`, or `cas`, OBI accepts extremely large `&amp;lt;bytes&amp;gt;` values and adds the payload delimiter length without checking for overflow. A crafted request with `&amp;lt;bytes&amp;gt;` set to `math.MaxInt` or `math.MaxInt-1` causes the computed payload length to wrap negative and triggers a runtime panic in `LargeBufferReader.Peek`.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The issue is in the memcached request parser at `pkg/ebpf/common/memcached_detect_transform.go`.&lt;/p&gt;
&lt;p&gt;`memcachedCommandBytesField` parses the storage command `&amp;lt;bytes&amp;gt;` field with `strconv.Atoi` and only rejects negative values:&lt;/p&gt;
&lt;p&gt;```go
size, err := strconv.Atoi(string(fields[4]))
if err != nil || size &amp;lt; 0 {
	return 0, false
}
```&lt;/p&gt;
&lt;p&gt;Because there is no upper bound check, values up to `math.MaxInt` are accepted.&lt;/p&gt;
&lt;p&gt;`memcachedConsumeStoragePayload` then computes the payload length by adding the trailing `\r\n` delimiter length:&lt;/p&gt;
&lt;p&gt;```go
payloadLen := bytesField + len(memcachedDelimBytes)
payload, err := r.Peek(payloadLen)
```&lt;/p&gt;
&lt;p&gt;If `bytesField` is `math.MaxInt` or `math.MaxInt-1`, this addition overflows the signed `int` and produces a negative `payloadLen`.&lt;/p&gt;
&lt;p&gt;That negative length is passed into `LargeBufferReader.Peek` in `pkg/internal/largebuf/large_buffer.go`. `Peek` checks whether `n &amp;gt; Remaining()` but does not reject negative values be…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: go.opentelemetry.io/obi&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;A remotely reachable integer overflow in OBI&amp;#39;s memcached text protocol parser can crash the OBI process and cause denial of service. When parsing memcached storage commands such as `set`, `add`, `replace`, `append`, `prepend`, or `cas`, OBI accepts extremely large `&amp;lt;bytes&amp;gt;` values and adds the payload delimiter length without checking for overflow. A crafted request with `&amp;lt;bytes&amp;gt;` set to `math.MaxInt` or `math.MaxInt-1` causes the computed payload length to wrap negative and triggers a runtime panic in `LargeBufferReader.Peek`.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The issue is in the memcached request parser at `pkg/ebpf/common/memcached_detect_transform.go`.&lt;/p&gt;
&lt;p&gt;`memcachedCommandBytesField` parses the storage command `&amp;lt;bytes&amp;gt;` field with `strconv.Atoi` and only rejects negative values:&lt;/p&gt;
&lt;p&gt;```go
size, err := strconv.Atoi(string(fields[4]))
if err != nil || size &amp;lt; 0 {
	return 0, false
}
```&lt;/p&gt;
&lt;p&gt;Because there is no upper bound check, values up to `math.MaxInt` are accepted.&lt;/p&gt;
&lt;p&gt;`memcachedConsumeStoragePayload` then computes the payload length by adding the trailing `\r\n` delimiter length:&lt;/p&gt;
&lt;p&gt;```go
payloadLen := bytesField + len(memcachedDelimBytes)
payload, err := r.Peek(payloadLen)
```&lt;/p&gt;
&lt;p&gt;If `bytesField` is `math.MaxInt` or `math.MaxInt-1`, this addition overflows the signed `int` and produces a negative `payloadLen`.&lt;/p&gt;
&lt;p&gt;That negative length is passed into `LargeBufferReader.Peek` in `pkg/internal/largebuf/large_buffer.go`. `Peek` checks whether `n &amp;gt; Remaining()` but does not reject negative values be…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-43g7-cwr8-q3jh</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11053-1 — alloy-1.17.0-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11053-1</link>
      <description>&lt;p&gt;alloy-1.17.0-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;alloy-1.17.0-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11053-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:22575-1 — Security update for alloy</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:22575-1</link>
      <description>&lt;p&gt;Security update for alloy&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for alloy&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:22575-1</guid>
    </item>
  </channel>
</rss>
