<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 21:15:24 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-15350</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-15350</link>
      <description>bdu:2026-15350</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-15350</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0873 — De multiples vulnérabilités ont été découvertes dans Microsoft Azure Linux. Elles permettent à un attaquant de provoque…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0873</link>
      <description>certfr-2026-avi-0873</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0873</guid>
    </item>
    <item>
      <title>EUVD-2026-340584</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-340584</link>
      <description>EUVD-2026-340584</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-340584</guid>
    </item>
    <item>
      <title>fkie_cve-2026-54886</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-54886</link>
      <description>&lt;p&gt;Loop with Unreachable Exit Condition (&amp;#39;Infinite Loop&amp;#39;) vulnerability in Erlang OTP ssh (ssh_sftpd module) allows an authenticated SFTP user to render an SFTP channel permanently unresponsive.&lt;/p&gt;
&lt;p&gt;The handle_data/4 function in ssh_sftpd contains a catch-all clause that accepts channel data of any type. When channel data with a non-zero type code (SSH_MSG_CHANNEL_EXTENDED_DATA) arrives with an empty pending buffer and a payload at or below the SFTP packet size limit, the clause tail-calls itself with identical arguments, creating an infinite loop.&lt;/p&gt;
&lt;p&gt;The SFTP protocol operates exclusively on normal channel data (type 0). Extended data (non-zero type) is meaningless for SFTP and is never sent by conforming clients. However, the SSH protocol permits any channel participant to send extended data on an open channel, so an authenticated SFTP client can trigger the loop by sending SSH_MSG_CHANNEL_EXTENDED_DATA with any data_type_code and any non-empty payload at or below the size limit.&lt;/p&gt;
&lt;p&gt;The targeted ssh_sftpd process enters an infinite tail-recursive loop. It never processes another message, its message queue grows without bound, and it can only be stopped by killing the process. BEAM&amp;#39;s reduction-based scheduler preemption continues to function, so other processes on the node are not starved, but each stuck channel process consumes its full CPU time share continuously and accumulates unbounded message queue memory. Opening many channels amplifies the CPU and memory impact.&lt;/p&gt;
&lt;p&gt;Erlang/OTP S…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Loop with Unreachable Exit Condition (&amp;#39;Infinite Loop&amp;#39;) vulnerability in Erlang OTP ssh (ssh_sftpd module) allows an authenticated SFTP user to render an SFTP channel permanently unresponsive.&lt;/p&gt;
&lt;p&gt;The handle_data/4 function in ssh_sftpd contains a catch-all clause that accepts channel data of any type. When channel data with a non-zero type code (SSH_MSG_CHANNEL_EXTENDED_DATA) arrives with an empty pending buffer and a payload at or below the SFTP packet size limit, the clause tail-calls itself with identical arguments, creating an infinite loop.&lt;/p&gt;
&lt;p&gt;The SFTP protocol operates exclusively on normal channel data (type 0). Extended data (non-zero type) is meaningless for SFTP and is never sent by conforming clients. However, the SSH protocol permits any channel participant to send extended data on an open channel, so an authenticated SFTP client can trigger the loop by sending SSH_MSG_CHANNEL_EXTENDED_DATA with any data_type_code and any non-empty payload at or below the size limit.&lt;/p&gt;
&lt;p&gt;The targeted ssh_sftpd process enters an infinite tail-recursive loop. It never processes another message, its message queue grows without bound, and it can only be stopped by killing the process. BEAM&amp;#39;s reduction-based scheduler preemption continues to function, so other processes on the node are not starved, but each stuck channel process consumes its full CPU time share continuously and accumulates unbounded message queue memory. Opening many channels amplifies the CPU and memory impact.&lt;/p&gt;
&lt;p&gt;Erlang/OTP S…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-54886</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-54886 — SSH SFTP server denial of service via extended channel data infinite loop</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-54886</link>
      <description>msrc_CVE-2026-54886</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-54886</guid>
    </item>
    <item>
      <title>OESA-2026-3041 — erlang security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-3041</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP3: erlang&lt;/p&gt;
&lt;p&gt;Erlang is a general-purpose programming language and runtime environment. Erlang has built-in support for concurrency, distribution and fault tolerance. Erlang is used in several large telecommunication systems from Ericsson.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Erlang OTP ssh (ssh_sftpd module) allows File Discovery.&lt;/p&gt;
&lt;p&gt;The SSH_FXP_READLINK handler in ssh_sftpd sends the raw result of file:read_link/2 to the client without calling chroot_filename/2 to strip the backend root prefix. An authenticated SFTP client can create a symlink inside the chroot pointing to /; ssh_sftpd resolves the target to the absolute backend root and stores it on disk. Reading the symlink back via SSH_FXP_READLINK returns that absolute path, for example /data/sftp, instead of the chrooted value /.&lt;/p&gt;
&lt;p&gt;The information disclosed is the absolute filesystem path of the SFTP root directory and of any symlink targets within it. No file contents, credentials, or access to paths outside the root directory are obtainable through this issue alone.&lt;/p&gt;
&lt;p&gt;This vulnerability is associated with program files lib/ssh/src/ssh_sftpd.erl.&lt;/p&gt;
&lt;p&gt;This issue affects OTP from OTP 17.0 before 29.0.2, 28.5.0.2 and 27.3.4.13 corresponding to ssh from 3.0.1 before 6.0.1, 5.5.2.1 and 5.2.11.8.(CVE-2026-48855)&lt;/p&gt;
&lt;p&gt;Sensitive Data Exposure vulnerability in Erlang OTP inets (httpc_response module) allows Retrieve Embedded Sensitive Data.&lt;/p&gt;
&lt;p&gt;The httpc client forwards the Authorization and P…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP3: erlang&lt;/p&gt;
&lt;p&gt;Erlang is a general-purpose programming language and runtime environment. Erlang has built-in support for concurrency, distribution and fault tolerance. Erlang is used in several large telecommunication systems from Ericsson.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Erlang OTP ssh (ssh_sftpd module) allows File Discovery.&lt;/p&gt;
&lt;p&gt;The SSH_FXP_READLINK handler in ssh_sftpd sends the raw result of file:read_link/2 to the client without calling chroot_filename/2 to strip the backend root prefix. An authenticated SFTP client can create a symlink inside the chroot pointing to /; ssh_sftpd resolves the target to the absolute backend root and stores it on disk. Reading the symlink back via SSH_FXP_READLINK returns that absolute path, for example /data/sftp, instead of the chrooted value /.&lt;/p&gt;
&lt;p&gt;The information disclosed is the absolute filesystem path of the SFTP root directory and of any symlink targets within it. No file contents, credentials, or access to paths outside the root directory are obtainable through this issue alone.&lt;/p&gt;
&lt;p&gt;This vulnerability is associated with program files lib/ssh/src/ssh_sftpd.erl.&lt;/p&gt;
&lt;p&gt;This issue affects OTP from OTP 17.0 before 29.0.2, 28.5.0.2 and 27.3.4.13 corresponding to ssh from 3.0.1 before 6.0.1, 5.5.2.1 and 5.2.11.8.(CVE-2026-48855)&lt;/p&gt;
&lt;p&gt;Sensitive Data Exposure vulnerability in Erlang OTP inets (httpc_response module) allows Retrieve Embedded Sensitive Data.&lt;/p&gt;
&lt;p&gt;The httpc client forwards the Authorization and P…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-3041</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11559-1 — erlang-28.5.0.4-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11559-1</link>
      <description>&lt;p&gt;erlang-28.5.0.4-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;erlang-28.5.0.4-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11559-1</guid>
    </item>
    <item>
      <title>RHSA-2026:63160 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:63160</link>
      <description>&lt;p&gt;erlang: Erlang OTP public_key: Certificate chain forgery via improper trust chain validation erlang: Erlang OTP public_key: Certificate validation bypass allows hostname spoofing erlang: Erlang OTP: Authentication bypass due to improper OCSP certificate validation erlang: Erlang OTP ssh: Information disclosure via symlink resolution in SFTP erlang: erlang-inets: erlang-ftp: Erlang/OTP ftp: Server-Side Request Forgery (SSRF) via unvalidated PASV response IP address erlang: Erlang/OTP: Authentication bypass allows arbitrary code execution via improper IP address validation erlang: Erlang OTP: Denial of Service via crafted SCTP ERROR chunk erlang: Erlang OTP ssh: Denial of Service via infinite loop in SFTP channel erlang: Erlang SSL: Unauthenticated data injection during TLS handshake erlang: Erlang/OTP: Denial of Service in TLS 1.3 session ticket handling erlang: Erlang/OTP: Remote denial of service via signed length overflow in TCP driver&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;erlang: Erlang OTP public_key: Certificate chain forgery via improper trust chain validation erlang: Erlang OTP public_key: Certificate validation bypass allows hostname spoofing erlang: Erlang OTP: Authentication bypass due to improper OCSP certificate validation erlang: Erlang OTP ssh: Information disclosure via symlink resolution in SFTP erlang: erlang-inets: erlang-ftp: Erlang/OTP ftp: Server-Side Request Forgery (SSRF) via unvalidated PASV response IP address erlang: Erlang/OTP: Authentication bypass allows arbitrary code execution via improper IP address validation erlang: Erlang OTP: Denial of Service via crafted SCTP ERROR chunk erlang: Erlang OTP ssh: Denial of Service via infinite loop in SFTP channel erlang: Erlang SSL: Unauthenticated data injection during TLS handshake erlang: Erlang/OTP: Denial of Service in TLS 1.3 session ticket handling erlang: Erlang/OTP: Remote denial of service via signed length overflow in TCP driver&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:63160</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-54886</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-54886</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: erlang, Ubuntu:Pro:16.04:LTS: erlang, Ubuntu:Pro:18.04:LTS: erlang, Ubuntu:Pro:20.04:LTS: erlang, Ubuntu:22.04:LTS: erlang, Ubuntu:24.04:LTS: erlang, Ubuntu:25.10: erlang, Ubuntu:26.04:LTS: erlang&lt;/p&gt;
&lt;p&gt;Loop with Unreachable Exit Condition (&amp;#39;Infinite Loop&amp;#39;) vulnerability in Erlang OTP ssh (ssh_sftpd module) allows an authenticated SFTP user to render an SFTP channel permanently unresponsive. The handle_data/4 function in ssh_sftpd contains a catch-all clause that accepts channel data of any type. When channel data with a non-zero type code (SSH_MSG_CHANNEL_EXTENDED_DATA) arrives with an empty pending buffer and a payload at or below the SFTP packet size limit, the clause tail-calls itself with identical arguments, creating an infinite loop. The SFTP protocol operates exclusively on normal channel data (type 0). Extended data (non-zero type) is meaningless for SFTP and is never sent by conforming clients. However, the SSH protocol permits any channel participant to send extended data on an open channel, so an authenticated SFTP client can trigger the loop by sending SSH_MSG_CHANNEL_EXTENDED_DATA with any data_type_code and any non-empty payload at or below the size limit. The targeted ssh_sftpd process enters an infinite tail-recursive loop. It never processes another message, its message queue grows without bound, and it can only be stopped by killing the process. BEAM&amp;#39;s reduction-based scheduler preemption continues to function, so other processes on the node are not starved, but each stuck channel process consumes its full CPU time share continuously and accumulates unbounded message queue memory. Opening many channels amplifies the CPU and memory impact. Erlang/OTP SSH c…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: erlang, Ubuntu:Pro:16.04:LTS: erlang, Ubuntu:Pro:18.04:LTS: erlang, Ubuntu:Pro:20.04:LTS: erlang, Ubuntu:22.04:LTS: erlang, Ubuntu:24.04:LTS: erlang, Ubuntu:25.10: erlang, Ubuntu:26.04:LTS: erlang&lt;/p&gt;
&lt;p&gt;Loop with Unreachable Exit Condition (&amp;#39;Infinite Loop&amp;#39;) vulnerability in Erlang OTP ssh (ssh_sftpd module) allows an authenticated SFTP user to render an SFTP channel permanently unresponsive. The handle_data/4 function in ssh_sftpd contains a catch-all clause that accepts channel data of any type. When channel data with a non-zero type code (SSH_MSG_CHANNEL_EXTENDED_DATA) arrives with an empty pending buffer and a payload at or below the SFTP packet size limit, the clause tail-calls itself with identical arguments, creating an infinite loop. The SFTP protocol operates exclusively on normal channel data (type 0). Extended data (non-zero type) is meaningless for SFTP and is never sent by conforming clients. However, the SSH protocol permits any channel participant to send extended data on an open channel, so an authenticated SFTP client can trigger the loop by sending SSH_MSG_CHANNEL_EXTENDED_DATA with any data_type_code and any non-empty payload at or below the size limit. The targeted ssh_sftpd process enters an infinite tail-recursive loop. It never processes another message, its message queue grows without bound, and it can only be stopped by killing the process. BEAM&amp;#39;s reduction-based scheduler preemption continues to function, so other processes on the node are not starved, but each stuck channel process consumes its full CPU time share continuously and accumulates unbounded message queue memory. Opening many channels amplifies the CPU and memory impact. Erlang/OTP SSH c…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-54886</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2194 — Erlang/OTP: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2194</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Erlang/OTP ausnutzen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Erlang/OTP ausnutzen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2194</guid>
    </item>
  </channel>
</rss>
