<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 21:43:28 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-27143 — Missing bound checks can lead to memory corruption in safe Go in cmd/compile</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-27143</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go toolchain cmd/compile&lt;/p&gt;
&lt;p&gt;Arithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the compiler would allow for invalid indexing to occur at runtime, potentially leading to memory corruption.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go toolchain cmd/compile&lt;/p&gt;
&lt;p&gt;Arithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the compiler would allow for invalid indexing to occur at runtime, potentially leading to memory corruption.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-27143</guid>
    </item>
    <item>
      <title>GHSA-hfvc-g4fc-pqhx — opentelemetry-go: BSD kenv command not using absolute path enables PATH hijacking</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hfvc-g4fc-pqhx</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: go.opentelemetry.io/otel/sdk&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The fix for GHSA-9h8m-3fm2-qjrq (CVE-2026-24051) changed the Darwin `ioreg` command to use an absolute path but left the BSD `kenv` command using a bare name, allowing the same PATH hijacking attack on BSD and Solaris platforms.&lt;/p&gt;
&lt;p&gt;## Root Cause&lt;/p&gt;
&lt;p&gt;`sdk/resource/host_id.go` line 42:&lt;/p&gt;
&lt;p&gt;if result, err := r.execCommand(&amp;#34;kenv&amp;#34;, &amp;#34;-q&amp;#34;, &amp;#34;smbios.system.uuid&amp;#34;); err == nil {&lt;/p&gt;
&lt;p&gt;Compare with the fixed Darwin path at line 58:&lt;/p&gt;
&lt;p&gt;result, err := r.execCommand(&amp;#34;/usr/sbin/ioreg&amp;#34;, &amp;#34;-rd1&amp;#34;, &amp;#34;-c&amp;#34;, &amp;#34;IOPlatformExpertDevice&amp;#34;)&lt;/p&gt;
&lt;p&gt;The `execCommand` helper at `sdk/resource/host_id_exec.go` uses `exec.Command(name, arg...)` which searches `$PATH` when the command name contains no path separator.&lt;/p&gt;
&lt;p&gt;Affected platforms (per build tag in `host_id_bsd.go:4`): DragonFly BSD, FreeBSD, NetBSD, OpenBSD, Solaris.&lt;/p&gt;
&lt;p&gt;The `kenv` path is reached when `/etc/hostid` does not exist (line 38-40), which is common on FreeBSD systems.&lt;/p&gt;
&lt;p&gt;## Attack&lt;/p&gt;
&lt;p&gt;1. Attacker has local access to a system running a Go application that imports `go.opentelemetry.io/otel/sdk`
2. Attacker places a malicious `kenv` binary earlier in `$PATH`
3. Application initializes OpenTelemetry resource detection at startup
4. `hostIDReaderBSD.read()` calls `exec.Command(&amp;#34;kenv&amp;#34;, ...)` which resolves to the malicious binary
5. Arbitrary code executes in the context of the application&lt;/p&gt;
&lt;p&gt;Same attack vector and impact as CVE-2026-24051.&lt;/p&gt;
&lt;p&gt;## Suggested Fix&lt;/p&gt;
&lt;p&gt;Use the absolute path:&lt;/p&gt;
&lt;p&gt;if result, err := r.execCommand(&amp;#34;/bin/kenv&amp;#34;, &amp;#34;-q&amp;#34;, &amp;#34;smbios.system.uuid&amp;#34;); e…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: go.opentelemetry.io/otel/sdk&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The fix for GHSA-9h8m-3fm2-qjrq (CVE-2026-24051) changed the Darwin `ioreg` command to use an absolute path but left the BSD `kenv` command using a bare name, allowing the same PATH hijacking attack on BSD and Solaris platforms.&lt;/p&gt;
&lt;p&gt;## Root Cause&lt;/p&gt;
&lt;p&gt;`sdk/resource/host_id.go` line 42:&lt;/p&gt;
&lt;p&gt;if result, err := r.execCommand(&amp;#34;kenv&amp;#34;, &amp;#34;-q&amp;#34;, &amp;#34;smbios.system.uuid&amp;#34;); err == nil {&lt;/p&gt;
&lt;p&gt;Compare with the fixed Darwin path at line 58:&lt;/p&gt;
&lt;p&gt;result, err := r.execCommand(&amp;#34;/usr/sbin/ioreg&amp;#34;, &amp;#34;-rd1&amp;#34;, &amp;#34;-c&amp;#34;, &amp;#34;IOPlatformExpertDevice&amp;#34;)&lt;/p&gt;
&lt;p&gt;The `execCommand` helper at `sdk/resource/host_id_exec.go` uses `exec.Command(name, arg...)` which searches `$PATH` when the command name contains no path separator.&lt;/p&gt;
&lt;p&gt;Affected platforms (per build tag in `host_id_bsd.go:4`): DragonFly BSD, FreeBSD, NetBSD, OpenBSD, Solaris.&lt;/p&gt;
&lt;p&gt;The `kenv` path is reached when `/etc/hostid` does not exist (line 38-40), which is common on FreeBSD systems.&lt;/p&gt;
&lt;p&gt;## Attack&lt;/p&gt;
&lt;p&gt;1. Attacker has local access to a system running a Go application that imports `go.opentelemetry.io/otel/sdk`
2. Attacker places a malicious `kenv` binary earlier in `$PATH`
3. Application initializes OpenTelemetry resource detection at startup
4. `hostIDReaderBSD.read()` calls `exec.Command(&amp;#34;kenv&amp;#34;, ...)` which resolves to the malicious binary
5. Arbitrary code executes in the context of the application&lt;/p&gt;
&lt;p&gt;Same attack vector and impact as CVE-2026-24051.&lt;/p&gt;
&lt;p&gt;## Suggested Fix&lt;/p&gt;
&lt;p&gt;Use the absolute path:&lt;/p&gt;
&lt;p&gt;if result, err := r.execCommand(&amp;#34;/bin/kenv&amp;#34;, &amp;#34;-q&amp;#34;, &amp;#34;smbios.system.uuid&amp;#34;); e…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hfvc-g4fc-pqhx</guid>
    </item>
  </channel>
</rss>
