<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 03:16:34 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-46385 — iskorotkov/avro: CPU Exhaustion in Avro Decoder</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-46385</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; iskorotkov avro, Red Hat Cryostat 4 on RHEL 9, Red Hat Multicluster Global Hub 1.4.5, Red Hat Multicluster Global Hub 1.6.5, Red Hat Multicluster Global Hub 1.7.0, Red Hat Advanced Cluster Management for Kubernetes 2.11, Red Hat Advanced Cluster Management for Kubernetes 2.13, Red Hat Advanced Cluster Management for Kubernetes 2.16, Red Hat Advanced Cluster Management for Kubernetes 2.17, Red Hat multicluster global hub 1.5.3 and 4 more&lt;/p&gt;
&lt;p&gt;iskorotkov/avro is a fast Go Avro codec. Prior to 2.33.0, the Avro array and map decoders looped over an attacker-controlled block-count value without checking the underlying reader&amp;#39;s error state inside the loop body. Reader.ReadBlockHeader returns the count as a Go int, which is 64-bit on amd64 / arm64 targets — so a producer can declare a block of up to math.MaxInt64 (~9.2 × 10¹⁸) elements followed by EOF (or any truncated payload), and the decoder will attempt that many no-op iterations before propagating the error. The realistic ceiling is &amp;#34;indefinite until the worker is killed externally&amp;#34; — a single hostile payload pins a CPU core until the process is OOM-killed, deadline-cancelled, or terminated. Remote, unauthenticated denial-of-service. This vulnerability is fixed in 2.33.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; iskorotkov avro, Red Hat Cryostat 4 on RHEL 9, Red Hat Multicluster Global Hub 1.4.5, Red Hat Multicluster Global Hub 1.6.5, Red Hat Multicluster Global Hub 1.7.0, Red Hat Advanced Cluster Management for Kubernetes 2.11, Red Hat Advanced Cluster Management for Kubernetes 2.13, Red Hat Advanced Cluster Management for Kubernetes 2.16, Red Hat Advanced Cluster Management for Kubernetes 2.17, Red Hat multicluster global hub 1.5.3 and 4 more&lt;/p&gt;
&lt;p&gt;iskorotkov/avro is a fast Go Avro codec. Prior to 2.33.0, the Avro array and map decoders looped over an attacker-controlled block-count value without checking the underlying reader&amp;#39;s error state inside the loop body. Reader.ReadBlockHeader returns the count as a Go int, which is 64-bit on amd64 / arm64 targets — so a producer can declare a block of up to math.MaxInt64 (~9.2 × 10¹⁸) elements followed by EOF (or any truncated payload), and the decoder will attempt that many no-op iterations before propagating the error. The realistic ceiling is &amp;#34;indefinite until the worker is killed externally&amp;#34; — a single hostile payload pins a CPU core until the process is OOM-killed, deadline-cancelled, or terminated. Remote, unauthenticated denial-of-service. This vulnerability is fixed in 2.33.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-46385</guid>
    </item>
  </channel>
</rss>
