<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 01:01:47 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:53363 — Important: fence-agents security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:53363</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: fence-agents-aliyun, AlmaLinux:8: fence-agents-all, AlmaLinux:8: fence-agents-amt-ws, AlmaLinux:8: fence-agents-apc, AlmaLinux:8: fence-agents-apc-snmp, AlmaLinux:8: fence-agents-aws, AlmaLinux:8: fence-agents-azure-arm, AlmaLinux:8: fence-agents-bladecenter, AlmaLinux:8: fence-agents-brocade, AlmaLinux:8: fence-agents-cisco-mds and 38 more&lt;/p&gt;
&lt;p&gt;The fence-agents packages provide a collection of scripts for handling remote power management for cluster devices. They allow failed or unreachable nodes to be forcibly restarted and removed from the cluster.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* pyasn1: pyasn1: Denial of Service via crafted ASN.1 REAL values (CVE-2026-59886)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: fence-agents-aliyun, AlmaLinux:8: fence-agents-all, AlmaLinux:8: fence-agents-amt-ws, AlmaLinux:8: fence-agents-apc, AlmaLinux:8: fence-agents-apc-snmp, AlmaLinux:8: fence-agents-aws, AlmaLinux:8: fence-agents-azure-arm, AlmaLinux:8: fence-agents-bladecenter, AlmaLinux:8: fence-agents-brocade, AlmaLinux:8: fence-agents-cisco-mds and 38 more&lt;/p&gt;
&lt;p&gt;The fence-agents packages provide a collection of scripts for handling remote power management for cluster devices. They allow failed or unreachable nodes to be forcibly restarted and removed from the cluster.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* pyasn1: pyasn1: Denial of Service via crafted ASN.1 REAL values (CVE-2026-59886)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:53363</guid>
    </item>
    <item>
      <title>bdu:2026-15017</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-15017</link>
      <description>bdu:2026-15017</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-15017</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-59886</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-59886</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: py3-asn1, Alpaquita:25: py3-asn1, Alpaquita:stream: py3-asn1&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: py3-asn1, Alpaquita:25: py3-asn1, Alpaquita:stream: py3-asn1&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-59886</guid>
    </item>
    <item>
      <title>BREW-ansible-CVE-2026-59886 — pyasn1: Uncontrolled resource consumption when converting decoded REAL values</title>
      <link>https://cve.radiocsirt.org/vuln/brew-ansible-cve-2026-59886</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: ansible&lt;/p&gt;
&lt;p&gt;### Impact
The univ.Real type converted its (mantissa, base, exponent) value to a Python float using exact big-integer exponentiation. A BER/CER/DER-encoded REAL value only a few bytes long can carry a very large exponent, causing this computation to attempt to materialize an astronomically large integer.&lt;/p&gt;
&lt;p&gt;Any operation that triggers float conversion on such a decoded value — prettyPrint(), str(), comparison, arithmetic, or an explicit float() call — consumes excessive CPU and memory, hanging the process. Applications that decode untrusted ASN.1 data and then print, log, or compare the decoded objects are vulnerable to denial of service. Decoding alone does not trigger the issue.&lt;/p&gt;
&lt;p&gt;### Affected components
- pyasn1.type.univ.Real — float conversion (__float__() and everything built on it: prettyPrint(), str(), comparisons, arithmetic, int())
- Reachable through the pyasn1.codec.ber, cer, and der decoders, which produce Real objects from untrusted input; also via directly constructed Real values&lt;/p&gt;
&lt;p&gt;The encoders and the native codec are not affected. Applications that never handle ASN.1 REAL values are not affected.&lt;/p&gt;
&lt;p&gt;### Patches
Fixed in pyasn1 0.6.4. Binary (base-2) values are now converted with math.ldexp(), and decimal (base-10) values with exponents beyond float range raise OverflowError without constructing huge intermediate integers. Existing behavior is preserved: out-of-range values raise OverflowError and prettyPrint() renders them as &amp;lt;overflow&amp;gt;.&lt;/p&gt;
&lt;p&gt;### Workarounds
Avoid co…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: ansible&lt;/p&gt;
&lt;p&gt;### Impact
The univ.Real type converted its (mantissa, base, exponent) value to a Python float using exact big-integer exponentiation. A BER/CER/DER-encoded REAL value only a few bytes long can carry a very large exponent, causing this computation to attempt to materialize an astronomically large integer.&lt;/p&gt;
&lt;p&gt;Any operation that triggers float conversion on such a decoded value — prettyPrint(), str(), comparison, arithmetic, or an explicit float() call — consumes excessive CPU and memory, hanging the process. Applications that decode untrusted ASN.1 data and then print, log, or compare the decoded objects are vulnerable to denial of service. Decoding alone does not trigger the issue.&lt;/p&gt;
&lt;p&gt;### Affected components
- pyasn1.type.univ.Real — float conversion (__float__() and everything built on it: prettyPrint(), str(), comparisons, arithmetic, int())
- Reachable through the pyasn1.codec.ber, cer, and der decoders, which produce Real objects from untrusted input; also via directly constructed Real values&lt;/p&gt;
&lt;p&gt;The encoders and the native codec are not affected. Applications that never handle ASN.1 REAL values are not affected.&lt;/p&gt;
&lt;p&gt;### Patches
Fixed in pyasn1 0.6.4. Binary (base-2) values are now converted with math.ldexp(), and decimal (base-10) values with exponents beyond float range raise OverflowError without constructing huge intermediate integers. Existing behavior is preserved: out-of-range values raise OverflowError and prettyPrint() renders them as &amp;lt;overflow&amp;gt;.&lt;/p&gt;
&lt;p&gt;### Workarounds
Avoid co…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-ansible-cve-2026-59886</guid>
    </item>
    <item>
      <title>certfr-2026-avi-1249 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1249</link>
      <description>certfr-2026-avi-1249</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1249</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-BC02149 — Security fixes in airflow-3 3.1.8-r6</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-bc02149</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: airflow-3&lt;/p&gt;
&lt;p&gt;Package airflow-3 version 3.1.8-r6 fixes 13 vulnerabilities: CVE-2026-53533, CVE-2026-59885, CVE-2026-59886, CVE-2026-59890, CVE-2026-49476...&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: airflow-3&lt;/p&gt;
&lt;p&gt;Package airflow-3 version 3.1.8-r6 fixes 13 vulnerabilities: CVE-2026-53533, CVE-2026-59885, CVE-2026-59886, CVE-2026-59890, CVE-2026-49476...&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-bc02149</guid>
    </item>
    <item>
      <title>EUVD-2026-338060</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-338060</link>
      <description>EUVD-2026-338060</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-338060</guid>
    </item>
    <item>
      <title>fkie_cve-2026-59886</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-59886</link>
      <description>&lt;p&gt;pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the univ.Real type converted its mantissa, base, and exponent value to a Python float using exact big-integer exponentiation. A BER, CER, or DER encoded REAL value only a few bytes long can carry a very large exponent, causing float conversion through prettyPrint(), str(), comparison, arithmetic, int(), or an explicit float() call to consume excessive CPU and memory and hang applications that decode untrusted ASN.1 data and then print, log, or compare decoded objects. This issue is fixed in version 0.6.4.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the univ.Real type converted its mantissa, base, and exponent value to a Python float using exact big-integer exponentiation. A BER, CER, or DER encoded REAL value only a few bytes long can carry a very large exponent, causing float conversion through prettyPrint(), str(), comparison, arithmetic, int(), or an explicit float() call to consume excessive CPU and memory and hang applications that decode untrusted ASN.1 data and then print, log, or compare decoded objects. This issue is fixed in version 0.6.4.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-59886</guid>
    </item>
    <item>
      <title>GHSA-hm4w-wwcw-mr6r — pyasn1: Uncontrolled resource consumption when converting decoded REAL values</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hm4w-wwcw-mr6r</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pyasn1&lt;/p&gt;
&lt;p&gt;### Impact
The univ.Real type converted its (mantissa, base, exponent) value to a Python float using exact big-integer exponentiation. A BER/CER/DER-encoded REAL value only a few bytes long can carry a very large exponent, causing this computation to attempt to materialize an astronomically large integer.&lt;/p&gt;
&lt;p&gt;Any operation that triggers float conversion on such a decoded value — prettyPrint(), str(), comparison, arithmetic, or an explicit float() call — consumes excessive CPU and memory, hanging the process. Applications that decode untrusted ASN.1 data and then print, log, or compare the decoded objects are vulnerable to denial of service. Decoding alone does not trigger the issue.&lt;/p&gt;
&lt;p&gt;### Affected components
- pyasn1.type.univ.Real — float conversion (__float__() and everything built on it: prettyPrint(), str(), comparisons, arithmetic, int())
- Reachable through the pyasn1.codec.ber, cer, and der decoders, which produce Real objects from untrusted input; also via directly constructed Real values&lt;/p&gt;
&lt;p&gt;The encoders and the native codec are not affected. Applications that never handle ASN.1 REAL values are not affected.&lt;/p&gt;
&lt;p&gt;### Patches
Fixed in pyasn1 0.6.4. Binary (base-2) values are now converted with math.ldexp(), and decimal (base-10) values with exponents beyond float range raise OverflowError without constructing huge intermediate integers. Existing behavior is preserved: out-of-range values raise OverflowError and prettyPrint() renders them as &amp;lt;overflow&amp;gt;.&lt;/p&gt;
&lt;p&gt;### Workarounds
Avoid co…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pyasn1&lt;/p&gt;
&lt;p&gt;### Impact
The univ.Real type converted its (mantissa, base, exponent) value to a Python float using exact big-integer exponentiation. A BER/CER/DER-encoded REAL value only a few bytes long can carry a very large exponent, causing this computation to attempt to materialize an astronomically large integer.&lt;/p&gt;
&lt;p&gt;Any operation that triggers float conversion on such a decoded value — prettyPrint(), str(), comparison, arithmetic, or an explicit float() call — consumes excessive CPU and memory, hanging the process. Applications that decode untrusted ASN.1 data and then print, log, or compare the decoded objects are vulnerable to denial of service. Decoding alone does not trigger the issue.&lt;/p&gt;
&lt;p&gt;### Affected components
- pyasn1.type.univ.Real — float conversion (__float__() and everything built on it: prettyPrint(), str(), comparisons, arithmetic, int())
- Reachable through the pyasn1.codec.ber, cer, and der decoders, which produce Real objects from untrusted input; also via directly constructed Real values&lt;/p&gt;
&lt;p&gt;The encoders and the native codec are not affected. Applications that never handle ASN.1 REAL values are not affected.&lt;/p&gt;
&lt;p&gt;### Patches
Fixed in pyasn1 0.6.4. Binary (base-2) values are now converted with math.ldexp(), and decimal (base-10) values with exponents beyond float range raise OverflowError without constructing huge intermediate integers. Existing behavior is preserved: out-of-range values raise OverflowError and prettyPrint() renders them as &amp;lt;overflow&amp;gt;.&lt;/p&gt;
&lt;p&gt;### Workarounds
Avoid co…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hm4w-wwcw-mr6r</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-59886 — pyasn1: Uncontrolled resource consumption when converting decoded REAL values</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-59886</link>
      <description>msrc_CVE-2026-59886</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-59886</guid>
    </item>
    <item>
      <title>OESA-2026-3198 — python-pyasn1 security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-3198</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: python-pyasn1, openEuler:22.03-LTS-SP4: python-pyasn1, openEuler:24.03-LTS-SP1: python-pyasn1, openEuler:24.03-LTS-SP3: python-pyasn1, openEuler:24.03-LTS-SP4: python-pyasn1&lt;/p&gt;
&lt;p&gt;Abstract Syntax Notation One (ASN.1) is a technology for exchanging structured data in a universally understood, hardware agnostic way. Many industrial, security and telephony applications heavily rely on ASN.1. The pyasn1 library implements ASN.1 support in pure-Python.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER decoder shared by the CER and DER codecs parses long-form tags by accumulating continuation octets without an upper bound on the tag ID size, allowing a crafted input to force construction of an arbitrarily large integer with CPU cost growing quadratically and to trigger unhandled ValueError exceptions in Python 3.11+ error formatting paths. Any application decoding untrusted BER, CER, or DER input is affected. This issue is fixed in version 0.6.4.(CVE-2026-59884)&lt;/p&gt;
&lt;p&gt;pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER, CER, and DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in quadratic time relative to the number of arcs, so a small crafted payload containing an OID with many arcs consumes excessive CPU per decode() call and can deny service to applications that decode untrusted ASN.1 data. The corresponding encoders have the same quadratic behavior when an application re-encodes previously decoded attacker-supplied values. This issue is fixed in version 0.6.4.(CVE-2026-59885)&lt;/p&gt;
&lt;p&gt;pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the univ.Real type converted its mantissa, base…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: python-pyasn1, openEuler:22.03-LTS-SP4: python-pyasn1, openEuler:24.03-LTS-SP1: python-pyasn1, openEuler:24.03-LTS-SP3: python-pyasn1, openEuler:24.03-LTS-SP4: python-pyasn1&lt;/p&gt;
&lt;p&gt;Abstract Syntax Notation One (ASN.1) is a technology for exchanging structured data in a universally understood, hardware agnostic way. Many industrial, security and telephony applications heavily rely on ASN.1. The pyasn1 library implements ASN.1 support in pure-Python.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER decoder shared by the CER and DER codecs parses long-form tags by accumulating continuation octets without an upper bound on the tag ID size, allowing a crafted input to force construction of an arbitrarily large integer with CPU cost growing quadratically and to trigger unhandled ValueError exceptions in Python 3.11+ error formatting paths. Any application decoding untrusted BER, CER, or DER input is affected. This issue is fixed in version 0.6.4.(CVE-2026-59884)&lt;/p&gt;
&lt;p&gt;pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER, CER, and DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in quadratic time relative to the number of arcs, so a small crafted payload containing an OID with many arcs consumes excessive CPU per decode() call and can deny service to applications that decode untrusted ASN.1 data. The corresponding encoders have the same quadratic behavior when an application re-encodes previously decoded attacker-supplied values. This issue is fixed in version 0.6.4.(CVE-2026-59885)&lt;/p&gt;
&lt;p&gt;pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the univ.Real type converted its mantissa, base…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-3198</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11318-1 — python313-pyasn1-0.6.4-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11318-1</link>
      <description>&lt;p&gt;python313-pyasn1-0.6.4-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python313-pyasn1-0.6.4-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11318-1</guid>
    </item>
    <item>
      <title>PYSEC-2026-3457</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-3457</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pyasn1&lt;/p&gt;
&lt;p&gt;pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the univ.Real type converted its mantissa, base, and exponent value to a Python float using exact big-integer exponentiation. A BER, CER, or DER encoded REAL value only a few bytes long can carry a very large exponent, causing float conversion through prettyPrint(), str(), comparison, arithmetic, int(), or an explicit float() call to consume excessive CPU and memory and hang applications that decode untrusted ASN.1 data and then print, log, or compare decoded objects. This issue is fixed in version 0.6.4.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pyasn1&lt;/p&gt;
&lt;p&gt;pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the univ.Real type converted its mantissa, base, and exponent value to a Python float using exact big-integer exponentiation. A BER, CER, or DER encoded REAL value only a few bytes long can carry a very large exponent, causing float conversion through prettyPrint(), str(), comparison, arithmetic, int(), or an explicit float() call to consume excessive CPU and memory and hang applications that decode untrusted ASN.1 data and then print, log, or compare decoded objects. This issue is fixed in version 0.6.4.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-3457</guid>
    </item>
    <item>
      <title>RHSA-2026:37094 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:37094</link>
      <description>&lt;p&gt;urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers pyasn1: pyasn1: Denial of Service via crafted ASN.1 REAL values&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers pyasn1: pyasn1: Denial of Service via crafted ASN.1 REAL values&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:37094</guid>
    </item>
    <item>
      <title>RLSA-2026:53363 — Important: fence-agents security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:53363</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: fence-agents&lt;/p&gt;
&lt;p&gt;The fence-agents packages provide a collection of scripts for handling remote power management for cluster devices. They allow failed or unreachable nodes to be forcibly restarted and removed from the cluster.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* pyasn1: pyasn1: Denial of Service via crafted ASN.1 REAL values (CVE-2026-59886)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: fence-agents&lt;/p&gt;
&lt;p&gt;The fence-agents packages provide a collection of scripts for handling remote power management for cluster devices. They allow failed or unreachable nodes to be forcibly restarted and removed from the cluster.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* pyasn1: pyasn1: Denial of Service via crafted ASN.1 REAL values (CVE-2026-59886)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:53363</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:22765-1 — Security update for python-pyasn1</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:22765-1</link>
      <description>&lt;p&gt;Security update for python-pyasn1&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for python-pyasn1&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:22765-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-59886</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-59886</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: pyasn1, Ubuntu:Pro:16.04:LTS: pyasn1, Ubuntu:Pro:18.04:LTS: pyasn1, Ubuntu:Pro:20.04:LTS: pyasn1, Ubuntu:22.04:LTS: pyasn1, Ubuntu:24.04:LTS: pyasn1, Ubuntu:26.04:LTS: pyasn1&lt;/p&gt;
&lt;p&gt;pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the univ.Real type converted its mantissa, base, and exponent value to a Python float using exact big-integer exponentiation. A BER, CER, or DER encoded REAL value only a few bytes long can carry a very large exponent, causing float conversion through prettyPrint(), str(), comparison, arithmetic, int(), or an explicit float() call to consume excessive CPU and memory and hang applications that decode untrusted ASN.1 data and then print, log, or compare decoded objects. This issue is fixed in version 0.6.4.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: pyasn1, Ubuntu:Pro:16.04:LTS: pyasn1, Ubuntu:Pro:18.04:LTS: pyasn1, Ubuntu:Pro:20.04:LTS: pyasn1, Ubuntu:22.04:LTS: pyasn1, Ubuntu:24.04:LTS: pyasn1, Ubuntu:26.04:LTS: pyasn1&lt;/p&gt;
&lt;p&gt;pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the univ.Real type converted its mantissa, base, and exponent value to a Python float using exact big-integer exponentiation. A BER, CER, or DER encoded REAL value only a few bytes long can carry a very large exponent, causing float conversion through prettyPrint(), str(), comparison, arithmetic, int(), or an explicit float() call to consume excessive CPU and memory and hang applications that decode untrusted ASN.1 data and then print, log, or compare decoded objects. This issue is fixed in version 0.6.4.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-59886</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2748 — Red Hat Enterprise Linux (pyasn1): Schwachstelle ermöglicht Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2748</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux (pyasn1) ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux (pyasn1) ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2748</guid>
    </item>
  </channel>
</rss>
