<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 05:57:23 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-266875</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-266875</link>
      <description>EUVD-2026-266875</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-266875</guid>
    </item>
    <item>
      <title>fkie_cve-2026-24783</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-24783</link>
      <description>&lt;p&gt;soroban-fixed-point-math is a fixed-point math library for Soroban smart contacts. In versions 1.3.0 and 1.4.0, the `mulDiv(x, y, z)` function incorrectly handled cases where both the intermediate product $x * y$ and the divisor $z$ were negative. The logic assumed that if the intermediate product was negative, the final result must also be negative, neglecting the sign of $z$. This resulted in rounding being applied in the wrong direction for cases where both $x * y$ and $z$ were negative. The functions most at risk are `fixed_div_floor` and `fixed_div_ceil`, as they often use non-constant numbers as the divisor $z$ in `mulDiv`.  This error is present in all signed `FixedPoint` and `SorobanFixedPoint` implementations, including `i64`, `i128`, and `I256`. Versions 1.3.1 and 1.4.1 contain a patch. No known workarounds for this issue are available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;soroban-fixed-point-math is a fixed-point math library for Soroban smart contacts. In versions 1.3.0 and 1.4.0, the `mulDiv(x, y, z)` function incorrectly handled cases where both the intermediate product $x * y$ and the divisor $z$ were negative. The logic assumed that if the intermediate product was negative, the final result must also be negative, neglecting the sign of $z$. This resulted in rounding being applied in the wrong direction for cases where both $x * y$ and $z$ were negative. The functions most at risk are `fixed_div_floor` and `fixed_div_ceil`, as they often use non-constant numbers as the divisor $z$ in `mulDiv`.  This error is present in all signed `FixedPoint` and `SorobanFixedPoint` implementations, including `i64`, `i128`, and `I256`. Versions 1.3.1 and 1.4.1 contain a patch. No known workarounds for this issue are available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-24783</guid>
    </item>
    <item>
      <title>GHSA-x5m4-43jf-hh65 — soroban-fixed-point-math has Incorrect Rounding and Overflow Handling in Signed Fixed-Point Math with Negatives</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-x5m4-43jf-hh65</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: soroban-fixed-point-math&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;#### Incorrect rounding direction for signed mul and div operations&lt;/p&gt;
&lt;p&gt;The `mulDiv(x, y, z)` function incorrectly handled cases where both the intermediate product $x * y$ and the divisor $z$ were negative. The logic assumed that if the intermediate product was negative, the final result must also be negative, neglecting the sign of $z$.&lt;/p&gt;
&lt;p&gt;This resulted in rounding being applied in the wrong direction for cases where both $x * y$ and $z$ were negative. The functions most at risk are `fixed_div_floor` and `fixed_div_ceil`, as they often use non-constant numbers as the divisor $z$ in `mulDiv`.&lt;/p&gt;
&lt;p&gt;This error is present in all signed `FixedPoint` and `SorobanFixedPoint` implementations, including `i64`, `i128`, and `I256`.&lt;/p&gt;
&lt;p&gt;#### Negative Overflow in `i64`&lt;/p&gt;
&lt;p&gt;The `mulDiv(x, y, z)` function for `i64` used the `i128` type to handle &amp;#34;phantom overflows&amp;#34;. These are overflows that occur intermediately during a calculation, like when computing the intermediate product $x * y$. When the final result of `mulDiv` was computed in `i128`, it was scaled back down to `i64` before returning. While the code verified that the result did not exceed `i64::MAX`, it did not check against `i64::MIN`.&lt;/p&gt;
&lt;p&gt;This caused negative results smaller than `i64:MIN` to wrap around to a large positive number instead of being caught as an overflow.&lt;/p&gt;
&lt;p&gt;This error only exists for the `FixedPoint` implementation of `i64`.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;* v1.3.0 users should upgrade to patch v1.3.1
* v1.4.0 users should upgrade to p…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: soroban-fixed-point-math&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;#### Incorrect rounding direction for signed mul and div operations&lt;/p&gt;
&lt;p&gt;The `mulDiv(x, y, z)` function incorrectly handled cases where both the intermediate product $x * y$ and the divisor $z$ were negative. The logic assumed that if the intermediate product was negative, the final result must also be negative, neglecting the sign of $z$.&lt;/p&gt;
&lt;p&gt;This resulted in rounding being applied in the wrong direction for cases where both $x * y$ and $z$ were negative. The functions most at risk are `fixed_div_floor` and `fixed_div_ceil`, as they often use non-constant numbers as the divisor $z$ in `mulDiv`.&lt;/p&gt;
&lt;p&gt;This error is present in all signed `FixedPoint` and `SorobanFixedPoint` implementations, including `i64`, `i128`, and `I256`.&lt;/p&gt;
&lt;p&gt;#### Negative Overflow in `i64`&lt;/p&gt;
&lt;p&gt;The `mulDiv(x, y, z)` function for `i64` used the `i128` type to handle &amp;#34;phantom overflows&amp;#34;. These are overflows that occur intermediately during a calculation, like when computing the intermediate product $x * y$. When the final result of `mulDiv` was computed in `i128`, it was scaled back down to `i64` before returning. While the code verified that the result did not exceed `i64::MAX`, it did not check against `i64::MIN`.&lt;/p&gt;
&lt;p&gt;This caused negative results smaller than `i64:MIN` to wrap around to a large positive number instead of being caught as an overflow.&lt;/p&gt;
&lt;p&gt;This error only exists for the `FixedPoint` implementation of `i64`.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;* v1.3.0 users should upgrade to patch v1.3.1
* v1.4.0 users should upgrade to p…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-x5m4-43jf-hh65</guid>
    </item>
  </channel>
</rss>
