<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 12:38:52 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:67154 — Important: openssl security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:67154</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: openssl, AlmaLinux:10: openssl-devel, AlmaLinux:10: openssl-libs, AlmaLinux:10: openssl-perl&lt;/p&gt;
&lt;p&gt;OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, as well as a full-strength general-purpose cryptography library.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* openssl: OpenSSL: Denial of Service via unbounded memory growth in QUIC server (CVE-2026-14456)
  * openssl: QUIC server may trigger double free when processing INITIAL packet (CVE-2026-18798)
  * openssl: heap buffer overflow in CMS key unwrapping (CVE-2026-63072)
  * openssl: invalid pointer dereference in CMP server via crafted protectionAlg (CVE-2026-63076)
  * openssl: RPK server signature algorithm selection can dereference a missing certificate (CVE-2026-14457)
  * openssl: excessive memory use buffering DTLS records for a future epoch (CVE-2026-54874)
  * openssl: untrusted sender DN used as format string in CMP response validation (CVE-2026-63073)
  * openssl: CMP indefinite cache growth of ExtraCerts (CVE-2026-63074)
  * openssl: QUIC ACK-only packet retention can cause memory exhaustion (CVE-2026-63075)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* openssl: HollowByte remote memory-exhaustion DoS fix may be missing [AlmaLinux 10.2.z] (JIRA:AlmaLinux-212362)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: openssl, AlmaLinux:10: openssl-devel, AlmaLinux:10: openssl-libs, AlmaLinux:10: openssl-perl&lt;/p&gt;
&lt;p&gt;OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, as well as a full-strength general-purpose cryptography library.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* openssl: OpenSSL: Denial of Service via unbounded memory growth in QUIC server (CVE-2026-14456)
  * openssl: QUIC server may trigger double free when processing INITIAL packet (CVE-2026-18798)
  * openssl: heap buffer overflow in CMS key unwrapping (CVE-2026-63072)
  * openssl: invalid pointer dereference in CMP server via crafted protectionAlg (CVE-2026-63076)
  * openssl: RPK server signature algorithm selection can dereference a missing certificate (CVE-2026-14457)
  * openssl: excessive memory use buffering DTLS records for a future epoch (CVE-2026-54874)
  * openssl: untrusted sender DN used as format string in CMP response validation (CVE-2026-63073)
  * openssl: CMP indefinite cache growth of ExtraCerts (CVE-2026-63074)
  * openssl: QUIC ACK-only packet retention can cause memory exhaustion (CVE-2026-63075)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* openssl: HollowByte remote memory-exhaustion DoS fix may be missing [AlmaLinux 10.2.z] (JIRA:AlmaLinux-212362)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:67154</guid>
    </item>
    <item>
      <title>bdu:2026-14721</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-14721</link>
      <description>bdu:2026-14721</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-14721</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-18798</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-18798</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: openssl, Alpaquita:stream: openssl, BellSoft Hardened Containers:25: openssl, BellSoft Hardened Containers:stream: openssl&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: openssl, Alpaquita:stream: openssl, BellSoft Hardened Containers:25: openssl, BellSoft Hardened Containers:stream: openssl&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-18798</guid>
    </item>
    <item>
      <title>certfr-2026-avi-1079 — De multiples vulnérabilités ont été découvertes dans OpenSSL. Elles permettent à un attaquant de provoquer un déni de s…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1079</link>
      <description>certfr-2026-avi-1079</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1079</guid>
    </item>
    <item>
      <title>EUVD-2026-358648</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-358648</link>
      <description>EUVD-2026-358648</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-358648</guid>
    </item>
    <item>
      <title>fkie_cve-2026-18798</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-18798</link>
      <description>&lt;p&gt;Issue summary: QUIC server may double free QRX (QUIC record layer RX) object
when channel creation fails for initial packet.&lt;/p&gt;
&lt;p&gt;Impact summary: Double free leads to heap corruption, which typically results in 
termination of QUIC server process, leading to Denial of Service. There is so
far no evidence that this double free is exploitable for remote code execution,
thus it is considered highly improbable.&lt;/p&gt;
&lt;p&gt;CWE: CWE-415: Double Free&lt;/p&gt;
&lt;p&gt;Description: In order to validate initial packet, OpenSSL QUIC stack default
packet handler (port_default_packet_handler()) creates a so-called QRX object.
If the initial packet validates successfully with QRX object, the default packet
handler proceeds to channel (connection object) creation. The QRX object used
for packet validation is passed to port_bind_channel(), so it becomes part of
the newly created connection. If port_bind_channel() fails, then it also frees
the QRX object. Once port_bind_channel() returns, the port_default_packet_handler()
detects the failure and proceeds to the error branch, where the same QRX object is
freed for the second time.&lt;/p&gt;
&lt;p&gt;The failure in port_bind_channel() function can be induced with a relatively
low effort by a malformed (non RFC 9000 compliant) INITIAL packet. If the packet
carries DCID (destination connection ID) which is shorter than 8 bytes, then
port_bind_channel() jumps to the error path after ossl_quic_lcidm_enrol_odcid()
detects that the DCID has invalid length.&lt;/p&gt;
&lt;p&gt;FIPS impact: no
The FIPS module is not…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Issue summary: QUIC server may double free QRX (QUIC record layer RX) object
when channel creation fails for initial packet.&lt;/p&gt;
&lt;p&gt;Impact summary: Double free leads to heap corruption, which typically results in 
termination of QUIC server process, leading to Denial of Service. There is so
far no evidence that this double free is exploitable for remote code execution,
thus it is considered highly improbable.&lt;/p&gt;
&lt;p&gt;CWE: CWE-415: Double Free&lt;/p&gt;
&lt;p&gt;Description: In order to validate initial packet, OpenSSL QUIC stack default
packet handler (port_default_packet_handler()) creates a so-called QRX object.
If the initial packet validates successfully with QRX object, the default packet
handler proceeds to channel (connection object) creation. The QRX object used
for packet validation is passed to port_bind_channel(), so it becomes part of
the newly created connection. If port_bind_channel() fails, then it also frees
the QRX object. Once port_bind_channel() returns, the port_default_packet_handler()
detects the failure and proceeds to the error branch, where the same QRX object is
freed for the second time.&lt;/p&gt;
&lt;p&gt;The failure in port_bind_channel() function can be induced with a relatively
low effort by a malformed (non RFC 9000 compliant) INITIAL packet. If the packet
carries DCID (destination connection ID) which is shorter than 8 bytes, then
port_bind_channel() jumps to the error path after ossl_quic_lcidm_enrol_odcid()
detects that the DCID has invalid length.&lt;/p&gt;
&lt;p&gt;FIPS impact: no
The FIPS module is not…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-18798</guid>
    </item>
    <item>
      <title>GHSA-3j55-qf57-hqc2</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3j55-qf57-hqc2</link>
      <description>&lt;p&gt;Issue summary: QUIC server may double free QRX (QUIC record layer RX) object
when channel creation fails for initial packet.&lt;/p&gt;
&lt;p&gt;Impact summary: Double free leads to heap corruption, which typically results in 
termination of QUIC server process, leading to Denial of Service. There is so
far no evidence that this double free is exploitable for remote code execution,
thus it is considered highly improbable.&lt;/p&gt;
&lt;p&gt;CWE: CWE-415: Double Free&lt;/p&gt;
&lt;p&gt;Description: In order to validate initial packet, OpenSSL QUIC stack default
packet handler (port_default_packet_handler()) creates a so-called QRX object.
If the initial packet validates successfully with QRX object, the default packet
handler proceeds to channel (connection object) creation. The QRX object used
for packet validation is passed to port_bind_channel(), so it becomes part of
the newly created connection. If port_bind_channel() fails, then it also frees
the QRX object. Once port_bind_channel() returns, the port_default_packet_handler()
detects the failure and proceeds to the error branch, where the same QRX object is
freed for the second time.&lt;/p&gt;
&lt;p&gt;The failure in port_bind_channel() function can be induced with a relatively
low effort by a malformed (non RFC 9000 compliant) INITIAL packet. If the packet
carries DCID (destination connection ID) which is shorter than 8 bytes, then
port_bind_channel() jumps to the error path after ossl_quic_lcidm_enrol_odcid()
detects that the DCID has invalid length.&lt;/p&gt;
&lt;p&gt;FIPS impact: no
The FIPS module is not…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Issue summary: QUIC server may double free QRX (QUIC record layer RX) object
when channel creation fails for initial packet.&lt;/p&gt;
&lt;p&gt;Impact summary: Double free leads to heap corruption, which typically results in 
termination of QUIC server process, leading to Denial of Service. There is so
far no evidence that this double free is exploitable for remote code execution,
thus it is considered highly improbable.&lt;/p&gt;
&lt;p&gt;CWE: CWE-415: Double Free&lt;/p&gt;
&lt;p&gt;Description: In order to validate initial packet, OpenSSL QUIC stack default
packet handler (port_default_packet_handler()) creates a so-called QRX object.
If the initial packet validates successfully with QRX object, the default packet
handler proceeds to channel (connection object) creation. The QRX object used
for packet validation is passed to port_bind_channel(), so it becomes part of
the newly created connection. If port_bind_channel() fails, then it also frees
the QRX object. Once port_bind_channel() returns, the port_default_packet_handler()
detects the failure and proceeds to the error branch, where the same QRX object is
freed for the second time.&lt;/p&gt;
&lt;p&gt;The failure in port_bind_channel() function can be induced with a relatively
low effort by a malformed (non RFC 9000 compliant) INITIAL packet. If the packet
carries DCID (destination connection ID) which is shorter than 8 bytes, then
port_bind_channel() jumps to the error path after ossl_quic_lcidm_enrol_odcid()
detects that the DCID has invalid length.&lt;/p&gt;
&lt;p&gt;FIPS impact: no
The FIPS module is not…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3j55-qf57-hqc2</guid>
    </item>
    <item>
      <title>OESA-2026-3830 — openssl security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-3830</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP4: openssl&lt;/p&gt;
&lt;p&gt;OpenSSL is a robust, commercial-grade, and full-featured toolkit for the Transport Layer Security (TLS) and Secure Sockets Layer (SSL) protocols.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs)
enabled, and only the private key (with no associated certificate) configured locally,
a NULL pointer dereference may occur when the remote peer solicits raw public keys and
also sends the typically omitted &amp;amp;quot;signature_algorithms_cert&amp;amp;quot; TLS extension.&lt;/p&gt;
&lt;p&gt;Impact summary: The impact is limited to a possible Denial of Service as a result of
an application abort, no data disclosure or remote command execution are possible.&lt;/p&gt;
&lt;p&gt;CWE: CWE-476: NULL Pointer Dereference&lt;/p&gt;
&lt;p&gt;Description: While a passing comment in sample code in the documentation suggests
that key-only RPK configurations are supported, the best-practice RPK configuration
is to always configure a corresponding certificate (possibly self-signed or
signed by any convenient CA).&lt;/p&gt;
&lt;p&gt;When the private key is configured along with a matching certificate, the
&amp;amp;quot;signature_algorithms_cert&amp;amp;quot; extension is handled reliably even without the
fix, and peer clients or servers that don&amp;amp;apos;t support raw public keys may be
able to complete a TLS connection by pinning or verifying the corresponding
certificate or its public key.&lt;/p&gt;
&lt;p&gt;Deployments that prefer to configure just a private key with no certificate
need to upgrade to an updated release as noted below.&lt;/p&gt;
&lt;p&gt;FIPS impact: no&lt;/p&gt;
&lt;p&gt;No FIP…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP4: openssl&lt;/p&gt;
&lt;p&gt;OpenSSL is a robust, commercial-grade, and full-featured toolkit for the Transport Layer Security (TLS) and Secure Sockets Layer (SSL) protocols.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs)
enabled, and only the private key (with no associated certificate) configured locally,
a NULL pointer dereference may occur when the remote peer solicits raw public keys and
also sends the typically omitted &amp;amp;quot;signature_algorithms_cert&amp;amp;quot; TLS extension.&lt;/p&gt;
&lt;p&gt;Impact summary: The impact is limited to a possible Denial of Service as a result of
an application abort, no data disclosure or remote command execution are possible.&lt;/p&gt;
&lt;p&gt;CWE: CWE-476: NULL Pointer Dereference&lt;/p&gt;
&lt;p&gt;Description: While a passing comment in sample code in the documentation suggests
that key-only RPK configurations are supported, the best-practice RPK configuration
is to always configure a corresponding certificate (possibly self-signed or
signed by any convenient CA).&lt;/p&gt;
&lt;p&gt;When the private key is configured along with a matching certificate, the
&amp;amp;quot;signature_algorithms_cert&amp;amp;quot; extension is handled reliably even without the
fix, and peer clients or servers that don&amp;amp;apos;t support raw public keys may be
able to complete a TLS connection by pinning or verifying the corresponding
certificate or its public key.&lt;/p&gt;
&lt;p&gt;Deployments that prefer to configure just a private key with no certificate
need to upgrade to an updated release as noted below.&lt;/p&gt;
&lt;p&gt;FIPS impact: no&lt;/p&gt;
&lt;p&gt;No FIP…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-3830</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11623-1 — libopenssl-3-devel-3.5.3-8.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11623-1</link>
      <description>&lt;p&gt;libopenssl-3-devel-3.5.3-8.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libopenssl-3-devel-3.5.3-8.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11623-1</guid>
    </item>
    <item>
      <title>RHSA-2026:59635 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:59635</link>
      <description>&lt;p&gt;openssl: OpenSSL: Heap buffer overflow due to signed integer overflow in Unicode output sizing openssl: OpenSSL: Denial of Service due to heap out-of-bounds read in CMS password-based decryption openssl: RPK server signature algorithm selection can dereference a missing certificate openssl: QUIC server may trigger double free when processing INITIAL packet openssl: OpenSSL: Heap buffer over-read in ASN.1 decoding can lead to denial of service or information disclosure. openssl: PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC Keys openssl: CMS AuthEnvelopedData Processing May Accept Forged Messages openssl: Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler openssl: Double-free When Checking OCSP Stapled Response openssl: NULL pointer dereference in QUIC server initial packet handling openssl: NULL Dereference in Certificate Verification with OCSP Checking openssl: Possible NULL Dereference in Password-Based CMS Decryption openssl: NULL Pointer Dereference in CRMF EncryptedValue Decryption openssl: Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt() openssl: Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate openssl: FFC-DH Peer Validation Uses Attacker-Supplied q openssl: Possible Out of Bounds Read in X509_VERIFY_PARAM_set1_email() openssl: AES-OCB IV Ignored on EVP_Cipher() Path openssl: Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes openssl: Heap Use-After-Free in OpenSSL PKCS7_veri…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;openssl: OpenSSL: Heap buffer overflow due to signed integer overflow in Unicode output sizing openssl: OpenSSL: Denial of Service due to heap out-of-bounds read in CMS password-based decryption openssl: RPK server signature algorithm selection can dereference a missing certificate openssl: QUIC server may trigger double free when processing INITIAL packet openssl: OpenSSL: Heap buffer over-read in ASN.1 decoding can lead to denial of service or information disclosure. openssl: PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC Keys openssl: CMS AuthEnvelopedData Processing May Accept Forged Messages openssl: Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler openssl: Double-free When Checking OCSP Stapled Response openssl: NULL pointer dereference in QUIC server initial packet handling openssl: NULL Dereference in Certificate Verification with OCSP Checking openssl: Possible NULL Dereference in Password-Based CMS Decryption openssl: NULL Pointer Dereference in CRMF EncryptedValue Decryption openssl: Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt() openssl: Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate openssl: FFC-DH Peer Validation Uses Attacker-Supplied q openssl: Possible Out of Bounds Read in X509_VERIFY_PARAM_set1_email() openssl: AES-OCB IV Ignored on EVP_Cipher() Path openssl: Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes openssl: Heap Use-After-Free in OpenSSL PKCS7_veri…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:59635</guid>
    </item>
    <item>
      <title>RLSA-2026:67154 — Important: openssl security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:67154</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: openssl&lt;/p&gt;
&lt;p&gt;OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, as well as a full-strength general-purpose cryptography library.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* openssl: OpenSSL: Denial of Service via unbounded memory growth in QUIC server (CVE-2026-14456)&lt;/p&gt;
&lt;p&gt;* openssl: QUIC server may trigger double free when processing INITIAL packet (CVE-2026-18798)&lt;/p&gt;
&lt;p&gt;* openssl: heap buffer overflow in CMS key unwrapping (CVE-2026-63072)&lt;/p&gt;
&lt;p&gt;* openssl: invalid pointer dereference in CMP server via crafted protectionAlg (CVE-2026-63076)&lt;/p&gt;
&lt;p&gt;* openssl: RPK server signature algorithm selection can dereference a missing certificate (CVE-2026-14457)&lt;/p&gt;
&lt;p&gt;* openssl: excessive memory use buffering DTLS records for a future epoch (CVE-2026-54874)&lt;/p&gt;
&lt;p&gt;* openssl: untrusted sender DN used as format string in CMP response validation (CVE-2026-63073)&lt;/p&gt;
&lt;p&gt;* openssl: CMP indefinite cache growth of ExtraCerts (CVE-2026-63074)&lt;/p&gt;
&lt;p&gt;* openssl: QUIC ACK-only packet retention can cause memory exhaustion (CVE-2026-63075)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* openssl: HollowByte remote memory-exhaustion DoS fix may be missing [Rocky Linux 10.2.z] (JIRA:Rocky Linux-212362)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: openssl&lt;/p&gt;
&lt;p&gt;OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, as well as a full-strength general-purpose cryptography library.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* openssl: OpenSSL: Denial of Service via unbounded memory growth in QUIC server (CVE-2026-14456)&lt;/p&gt;
&lt;p&gt;* openssl: QUIC server may trigger double free when processing INITIAL packet (CVE-2026-18798)&lt;/p&gt;
&lt;p&gt;* openssl: heap buffer overflow in CMS key unwrapping (CVE-2026-63072)&lt;/p&gt;
&lt;p&gt;* openssl: invalid pointer dereference in CMP server via crafted protectionAlg (CVE-2026-63076)&lt;/p&gt;
&lt;p&gt;* openssl: RPK server signature algorithm selection can dereference a missing certificate (CVE-2026-14457)&lt;/p&gt;
&lt;p&gt;* openssl: excessive memory use buffering DTLS records for a future epoch (CVE-2026-54874)&lt;/p&gt;
&lt;p&gt;* openssl: untrusted sender DN used as format string in CMP response validation (CVE-2026-63073)&lt;/p&gt;
&lt;p&gt;* openssl: CMP indefinite cache growth of ExtraCerts (CVE-2026-63074)&lt;/p&gt;
&lt;p&gt;* openssl: QUIC ACK-only packet retention can cause memory exhaustion (CVE-2026-63075)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* openssl: HollowByte remote memory-exhaustion DoS fix may be missing [Rocky Linux 10.2.z] (JIRA:Rocky Linux-212362)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:67154</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:23463-1 — Security update for openssl-3</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:23463-1</link>
      <description>&lt;p&gt;Security update for openssl-3&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for openssl-3&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:23463-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-18798</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-18798</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: nodejs, Ubuntu:Pro:18.04:LTS: nodejs, Ubuntu:26.04:LTS: edk2, Ubuntu:26.04:LTS: edk2-hwe, Ubuntu:26.04:LTS: openssl&lt;/p&gt;
&lt;p&gt;Issue summary: QUIC server may double free QRX (QUIC record layer RX) object when channel creation fails for initial packet. Impact summary: Double free leads to heap corruption, which typically results in termination of QUIC server process, leading to Denial of Service. There is so far no evidence that this double free is exploitable for remote code execution, thus it is considered highly improbable. CWE: CWE-415: Double Free Description: In order to validate initial packet, OpenSSL QUIC stack default packet handler (port_default_packet_handler()) creates a so-called QRX object. If the initial packet validates successfully with QRX object, the default packet handler proceeds to channel (connection object) creation. The QRX object used for packet validation is passed to port_bind_channel(), so it becomes part of the newly created connection. If port_bind_channel() fails, then it also frees the QRX object. Once port_bind_channel() returns, the port_default_packet_handler() detects the failure and proceeds to the error branch, where the same QRX object is freed for the second time. The failure in port_bind_channel() function can be induced with a relatively low effort by a malformed (non RFC 9000 compliant) INITIAL packet. If the packet carries DCID (destination connection ID) which is shorter than 8 bytes, then port_bind_channel() jumps to the error path after ossl_quic_lcidm_enrol_odcid() detects that the DCID has invalid length. FIPS impact: no The FIPS module is not affect…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: nodejs, Ubuntu:Pro:18.04:LTS: nodejs, Ubuntu:26.04:LTS: edk2, Ubuntu:26.04:LTS: edk2-hwe, Ubuntu:26.04:LTS: openssl&lt;/p&gt;
&lt;p&gt;Issue summary: QUIC server may double free QRX (QUIC record layer RX) object when channel creation fails for initial packet. Impact summary: Double free leads to heap corruption, which typically results in termination of QUIC server process, leading to Denial of Service. There is so far no evidence that this double free is exploitable for remote code execution, thus it is considered highly improbable. CWE: CWE-415: Double Free Description: In order to validate initial packet, OpenSSL QUIC stack default packet handler (port_default_packet_handler()) creates a so-called QRX object. If the initial packet validates successfully with QRX object, the default packet handler proceeds to channel (connection object) creation. The QRX object used for packet validation is passed to port_bind_channel(), so it becomes part of the newly created connection. If port_bind_channel() fails, then it also frees the QRX object. Once port_bind_channel() returns, the port_default_packet_handler() detects the failure and proceeds to the error branch, where the same QRX object is freed for the second time. The failure in port_bind_channel() function can be induced with a relatively low effort by a malformed (non RFC 9000 compliant) INITIAL packet. If the packet carries DCID (destination connection ID) which is shorter than 8 bytes, then port_bind_channel() jumps to the error path after ossl_quic_lcidm_enrol_odcid() detects that the DCID has invalid length. FIPS impact: no The FIPS module is not affect…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-18798</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3005 — OpenSSL: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3005</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenSSL ausnutzen, um Sicherheitsvorkehrungen zu umgehen, Daten zu manipulieren oder offenzulegen oder einen Denial-of-Service-Zustand herbeizuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenSSL ausnutzen, um Sicherheitsvorkehrungen zu umgehen, Daten zu manipulieren oder offenzulegen oder einen Denial-of-Service-Zustand herbeizuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3005</guid>
    </item>
  </channel>
</rss>
