<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 10:02:40 +0000</lastBuildDate>
    <item>
      <title>ALSA-2024:1462 — Important: golang security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2024:1462</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: go-toolset, AlmaLinux:9: golang, AlmaLinux:9: golang-bin, AlmaLinux:9: golang-docs, AlmaLinux:9: golang-misc, AlmaLinux:9: golang-src, AlmaLinux:9: golang-tests&lt;/p&gt;
&lt;p&gt;The golang packages provide the Go programming language compiler.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* golang: golang-fips/openssl: Memory leaks in code encrypting and decrypting RSA payloads (CVE-2024-1394)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: go-toolset, AlmaLinux:9: golang, AlmaLinux:9: golang-bin, AlmaLinux:9: golang-docs, AlmaLinux:9: golang-misc, AlmaLinux:9: golang-src, AlmaLinux:9: golang-tests&lt;/p&gt;
&lt;p&gt;The golang packages provide the Go programming language compiler.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* golang: golang-fips/openssl: Memory leaks in code encrypting and decrypting RSA payloads (CVE-2024-1394)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2024:1462</guid>
    </item>
    <item>
      <title>bdu:2024-02371</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-02371</link>
      <description>bdu:2024-02371</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-02371</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0646 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0646</link>
      <description>certfr-2024-avi-0646</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0646</guid>
    </item>
    <item>
      <title>EUVD-2026-357256</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-357256</link>
      <description>EUVD-2026-357256</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-357256</guid>
    </item>
    <item>
      <title>fkie_cve-2024-1394</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-1394</link>
      <description>&lt;p&gt;A memory leak flaw was found in Golang in the RSA encrypting/decrypting code, which might lead to a resource exhaustion vulnerability using attacker-controlled inputs​. The memory leak happens in github.com/golang-fips/openssl/openssl/rsa.go#L113. The objects leaked are pkey​ and ctx​. That function uses named return parameters to free pkey​ and ctx​ if there is an error initializing the context or setting the different properties. All return statements related to error cases follow the &amp;#34;return nil, nil, fail(...)&amp;#34; pattern, meaning that pkey​ and ctx​ will be nil inside the deferred function that should free them.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A memory leak flaw was found in Golang in the RSA encrypting/decrypting code, which might lead to a resource exhaustion vulnerability using attacker-controlled inputs​. The memory leak happens in github.com/golang-fips/openssl/openssl/rsa.go#L113. The objects leaked are pkey​ and ctx​. That function uses named return parameters to free pkey​ and ctx​ if there is an error initializing the context or setting the different properties. All return statements related to error cases follow the &amp;#34;return nil, nil, fail(...)&amp;#34; pattern, meaning that pkey​ and ctx​ will be nil inside the deferred function that should free them.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-1394</guid>
    </item>
    <item>
      <title>GHSA-78hx-gp6g-7mj6 — Memory leaks in code encrypting and verifying RSA payloads</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-78hx-gp6g-7mj6</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/golang-fips/go, Go: github.com/golang-fips/openssl/v2, Go: github.com/microsoft/go-crypto-openssl, Go: github.com/microsoft/go-crypto-openssl/openssl&lt;/p&gt;
&lt;p&gt;Using crafted public RSA keys which are not compliant with SP 800-56B can cause a small memory leak when encrypting and verifying payloads.&lt;/p&gt;
&lt;p&gt;An attacker can leverage this flaw to gradually erode available memory to the point where the host crashes for lack of resources. Upon restart the attacker would have to begin again, but nevertheless there is the potential to deny service.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/golang-fips/go, Go: github.com/golang-fips/openssl/v2, Go: github.com/microsoft/go-crypto-openssl, Go: github.com/microsoft/go-crypto-openssl/openssl&lt;/p&gt;
&lt;p&gt;Using crafted public RSA keys which are not compliant with SP 800-56B can cause a small memory leak when encrypting and verifying payloads.&lt;/p&gt;
&lt;p&gt;An attacker can leverage this flaw to gradually erode available memory to the point where the host crashes for lack of resources. Upon restart the attacker would have to begin again, but nevertheless there is the potential to deny service.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-78hx-gp6g-7mj6</guid>
    </item>
    <item>
      <title>gsd-2024-1394</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-1394</link>
      <description>gsd-2024-1394</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-1394</guid>
    </item>
    <item>
      <title>RHSA-2024:1462 — Red Hat Security Advisory: golang security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:1462</link>
      <description>&lt;p&gt;golang-fips/openssl: Memory leaks in code encrypting and decrypting RSA payloads&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;golang-fips/openssl: Memory leaks in code encrypting and decrypting RSA payloads&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:1462</guid>
    </item>
    <item>
      <title>RHSA-2024:1468 — Red Hat Security Advisory: go-toolset-1.19-golang security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:1468</link>
      <description>&lt;p&gt;golang-fips/openssl: Memory leaks in code encrypting and decrypting RSA payloads&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;golang-fips/openssl: Memory leaks in code encrypting and decrypting RSA payloads&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:1468</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-0681 — Red Hat Enterprise Linux: Golang-Komponenten-Schwachstelle ermöglicht Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0681</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat OpenShift, Red Hat Ansible Automation Platform und Red Hat Enterprise Linux ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat OpenShift, Red Hat Ansible Automation Platform und Red Hat Enterprise Linux ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0681</guid>
    </item>
  </channel>
</rss>
