<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 20:26:43 +0000</lastBuildDate>
    <item>
      <title>Withdrawn: CLEANSTART-2026-HP09399 — ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-hp09399</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: calico&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the calico package. The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: calico&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the calico package. The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-hp09399</guid>
    </item>
    <item>
      <title>EUVD-2026-342154</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-342154</link>
      <description>EUVD-2026-342154</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-342154</guid>
    </item>
    <item>
      <title>fkie_cve-2026-54345</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-54345</link>
      <description>&lt;p&gt;gopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the Diameter AVP decoder computes an AVP data length by subtracting a fixed header size from an attacker-controlled AVP Length field, so a vendor-flagged AVP whose Length is smaller than the 12-byte header underflows the unsigned 32-bit value and drives an unbounded allocation of roughly 4 GiB, and two such messages in succession OOM-kill a collector, causing an unauthenticated remote denial of service. This issue is fixed in version 1.6.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;gopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the Diameter AVP decoder computes an AVP data length by subtracting a fixed header size from an attacker-controlled AVP Length field, so a vendor-flagged AVP whose Length is smaller than the 12-byte header underflows the unsigned 32-bit value and drives an unbounded allocation of roughly 4 GiB, and two such messages in succession OOM-kill a collector, causing an unauthenticated remote denial of service. This issue is fixed in version 1.6.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-54345</guid>
    </item>
    <item>
      <title>GHSA-6r28-9ppf-4hj5 — GoPacket's Diameter AVP decoder: uint32 underflow on vendor header size leads to unbounded ~4 GiB allocation (unauthent…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6r28-9ppf-4hj5</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/gopacket/gopacket&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The Diameter AVP decoder in `github.com/gopacket/gopacket` computes `dataLength := avp.Length - uint32(headerSize)` without first ensuring `avp.Length &amp;gt;= headerSize`. When the Vendor flag is set, `headerSize` is 12, but the only length guard upstream rejects `avp.Length &amp;lt; 8`. An AVP with the Vendor flag set and a 24-bit Length field of 8, 9, 10, or 11 therefore underflows the `uint32` subtraction to ~4,294,967,292, which is passed straight to `make([]byte, dataLength)`. A single 32-byte Diameter message forces a ~4 GiB allocation; a short burst of such messages exhausts memory and OOM-kills memory-constrained collectors. This is an unauthenticated remote denial of service (CWE-191 integer underflow -&amp;gt; CWE-770 unbounded allocation).&lt;/p&gt;
&lt;p&gt;## Root cause (file:line @ v1.6.0)&lt;/p&gt;
&lt;p&gt;`layers/diameter_avp_decoders.go`, `decodeDiameterAVP`:&lt;/p&gt;
&lt;p&gt;```go
avp.Length = uint32(data[5])&amp;lt;&amp;lt;16 | uint32(data[6])&amp;lt;&amp;lt;8 | uint32(data[7]) // 24-bit wire value&lt;/p&gt;
&lt;p&gt;if avp.Length &amp;lt; 8 {                       // only rejects &amp;lt; 8
    return DiameterAVP{}, 0, fmt.Errorf(&amp;#34;invalid AVP length: %d&amp;#34;, avp.Length)
}&lt;/p&gt;
&lt;p&gt;headerSize := 8
dataOffset := 8
if avp.Flags.Vendor {                     // Vendor flag = wire bit data[4] &amp;amp; 0x80
    if len(data) &amp;lt; 12 { ... }
    avp.VendorID = binary.BigEndian.Uint32(data[8:12])
    headerSize = 12                       // header is now 12, but only &amp;gt;= 8 was checked
    dataOffset = 12
}&lt;/p&gt;
&lt;p&gt;paddedLength := avp.Length                // equals avp.Length; for avp.Length &amp;lt;= 12
if avp.Leng…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/gopacket/gopacket&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The Diameter AVP decoder in `github.com/gopacket/gopacket` computes `dataLength := avp.Length - uint32(headerSize)` without first ensuring `avp.Length &amp;gt;= headerSize`. When the Vendor flag is set, `headerSize` is 12, but the only length guard upstream rejects `avp.Length &amp;lt; 8`. An AVP with the Vendor flag set and a 24-bit Length field of 8, 9, 10, or 11 therefore underflows the `uint32` subtraction to ~4,294,967,292, which is passed straight to `make([]byte, dataLength)`. A single 32-byte Diameter message forces a ~4 GiB allocation; a short burst of such messages exhausts memory and OOM-kills memory-constrained collectors. This is an unauthenticated remote denial of service (CWE-191 integer underflow -&amp;gt; CWE-770 unbounded allocation).&lt;/p&gt;
&lt;p&gt;## Root cause (file:line @ v1.6.0)&lt;/p&gt;
&lt;p&gt;`layers/diameter_avp_decoders.go`, `decodeDiameterAVP`:&lt;/p&gt;
&lt;p&gt;```go
avp.Length = uint32(data[5])&amp;lt;&amp;lt;16 | uint32(data[6])&amp;lt;&amp;lt;8 | uint32(data[7]) // 24-bit wire value&lt;/p&gt;
&lt;p&gt;if avp.Length &amp;lt; 8 {                       // only rejects &amp;lt; 8
    return DiameterAVP{}, 0, fmt.Errorf(&amp;#34;invalid AVP length: %d&amp;#34;, avp.Length)
}&lt;/p&gt;
&lt;p&gt;headerSize := 8
dataOffset := 8
if avp.Flags.Vendor {                     // Vendor flag = wire bit data[4] &amp;amp; 0x80
    if len(data) &amp;lt; 12 { ... }
    avp.VendorID = binary.BigEndian.Uint32(data[8:12])
    headerSize = 12                       // header is now 12, but only &amp;gt;= 8 was checked
    dataOffset = 12
}&lt;/p&gt;
&lt;p&gt;paddedLength := avp.Length                // equals avp.Length; for avp.Length &amp;lt;= 12
if avp.Leng…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6r28-9ppf-4hj5</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-54345</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-54345</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: gopacket, Ubuntu:18.04:LTS: gopacket, Ubuntu:20.04:LTS: gopacket, Ubuntu:22.04:LTS: gopacket, Ubuntu:24.04:LTS: golang-github-gopacket-gopacket, Ubuntu:24.04:LTS: gopacket, Ubuntu:26.04:LTS: golang-github-gopacket-gopacket, Ubuntu:26.04:LTS: gopacket&lt;/p&gt;
&lt;p&gt;gopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the Diameter AVP decoder computes an AVP data length by subtracting a fixed header size from an attacker-controlled AVP Length field, so a vendor-flagged AVP whose Length is smaller than the 12-byte header underflows the unsigned 32-bit value and drives an unbounded allocation of roughly 4 GiB, and two such messages in succession OOM-kill a collector, causing an unauthenticated remote denial of service. This issue is fixed in version 1.6.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: gopacket, Ubuntu:18.04:LTS: gopacket, Ubuntu:20.04:LTS: gopacket, Ubuntu:22.04:LTS: gopacket, Ubuntu:24.04:LTS: golang-github-gopacket-gopacket, Ubuntu:24.04:LTS: gopacket, Ubuntu:26.04:LTS: golang-github-gopacket-gopacket, Ubuntu:26.04:LTS: gopacket&lt;/p&gt;
&lt;p&gt;gopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the Diameter AVP decoder computes an AVP data length by subtracting a fixed header size from an attacker-controlled AVP Length field, so a vendor-flagged AVP whose Length is smaller than the 12-byte header underflows the unsigned 32-bit value and drives an unbounded allocation of roughly 4 GiB, and two such messages in succession OOM-kill a collector, causing an unauthenticated remote denial of service. This issue is fixed in version 1.6.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-54345</guid>
    </item>
  </channel>
</rss>
