<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="ja">
  <title>miso</title>
  <subtitle>セキュリティリサーチと技術メモ</subtitle>
  <id>https://hacchoomiso.github.io/feed.ja.xml</id>
  <link rel="self" type="application/atom+xml" href="https://hacchoomiso.github.io/feed.ja.xml"/>
  <link rel="alternate" type="application/atom+xml" hreflang="en" href="https://hacchoomiso.github.io/feed.xml"/>
  <link rel="alternate" type="text/html" href="https://hacchoomiso.github.io/blog/"/>
  <icon>https://hacchoomiso.github.io/favicon.svg</icon>
  <updated>2026-10-03T00:00:00+09:00</updated>
  <author><name>miso</name></author>
  <entry>
    <title>1バイトのはみ出し: Apache HTTP Server mod_heartmonitor におけるヒープバッファオーバーフロー</title>
    <link rel="alternate" type="text/html" href="https://hacchoomiso.github.io/blog/OSS/CVE-2026-46729/ja/"/>
    <link rel="alternate" type="text/html" hreflang="en" href="https://hacchoomiso.github.io/blog/OSS/CVE-2026-46729/"/>
    <id>https://hacchoomiso.github.io/blog/OSS/CVE-2026-46729/ja/</id>
    <published>2026-10-03T00:00:00+09:00</published>
    <updated>2026-10-03T00:00:00+09:00</updated>
    <summary>Apache HTTP Server の mod_heartmonitor における認証不要の1バイトヒープバッファオーバーフロー（CVE-2026-46729）。2009年から存在し、独立発見として共同発見者クレジットを受けた記録。</summary>
  </entry>
  <entry>
    <title>ガードされていない設定項目: Chrome における GTK3 Gtk/Modules XSETTING 経由の GPU→ブラウザ サンドボックス脱出</title>
    <link rel="alternate" type="text/html" href="https://hacchoomiso.github.io/blog/Chrome/CVE-2026-76023/ja/"/>
    <link rel="alternate" type="text/html" hreflang="en" href="https://hacchoomiso.github.io/blog/Chrome/CVE-2026-76023/"/>
    <id>https://hacchoomiso.github.io/blog/Chrome/CVE-2026-76023/ja/</id>
    <published>2026-09-22T00:00:00+09:00</published>
    <updated>2026-09-22T00:00:00+09:00</updated>
    <summary>侵害された Linux/X11 GPU プロセスが Gtk/Modules XSETTING を通じて、Chrome のブラウザプロセス内の GTK3 に攻撃者制御の memfd を実行させる脆弱性（CVE-2026-76023、issue 545124048）について。</summary>
  </entry>
  <entry>
    <title>4つ目のpickle: SGLang分散Diffusionサーバにおける認証不要のリモートコード実行</title>
    <link rel="alternate" type="text/html" href="https://hacchoomiso.github.io/blog/SGLang/CVE-2026-93088/ja/"/>
    <link rel="alternate" type="text/html" hreflang="en" href="https://hacchoomiso.github.io/blog/SGLang/CVE-2026-93088/"/>
    <id>https://hacchoomiso.github.io/blog/SGLang/CVE-2026-93088/ja/</id>
    <published>2026-09-22T00:00:00+09:00</published>
    <updated>2026-09-22T00:00:00+09:00</updated>
    <summary>SGLang の分散 Diffusion サーバにおける認証不要のリモートコード実行（CVE-2026-93088、VU#727584、GHSA-8374-wrr5-7q7f）と、upstream コードで動的検証した追加の発見について。</summary>
  </entry>
</feed>
