<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T04:49:02.370858+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2020:1650</id>
    <title>ALSA-2020:1650 — Moderate: container-tools:rhel8 security, bug fix, and enhancement update</title>
    <updated>2026-10-04T04:49:02.631000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: crit, AlmaLinux:8: criu, AlmaLinux:8: python-podman-api, AlmaLinux:8: python3-criu, AlmaLinux:8: slirp4netns, AlmaLinux:8: toolbox, AlmaLinux:8: udica</p>
<p>The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.</p>
<p>Security Fix(es):</p>
<p>* runc: volume mount race condition with shared mounts leads to information leak/integrity manipulation (CVE-2019-19921)</p>
<p>* containers/image: Container images read entire image manifest into memory (CVE-2020-1702)</p>
<p>* podman: incorrectly allows existing files in volumes to be overwritten by a container when it is created (CVE-2020-1726)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p>
<p>Additional Changes:</p>
<p>For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2020:1650"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2019-19921</id>
    <title>Withdrawn: BELL-CVE-2019-19921 — CVE-2019-19921 does not affect BellSoft software</title>
    <updated>2026-10-04T04:49:02.631080+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2019-19921"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0590</id>
    <title>certfr-2025-avi-0590 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-04T04:49:02.631098+00:00</updated>
    <content>certfr-2025-avi-0590</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0590"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2025-nr50910</id>
    <title>CLEANSTART-2025-NR50910 — runc through 1</title>
    <updated>2026-10-04T04:49:02.631114+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: containerd</p>
<p>Security vulnerability affects the containerd package. runc through 1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2025-nr50910"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-59626</id>
    <title>EUVD-2026-59626</title>
    <updated>2026-10-04T04:49:02.631132+00:00</updated>
    <content>EUVD-2026-59626</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-59626"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2019-19921</id>
    <title>fkie_cve-2019-19921</title>
    <updated>2026-10-04T04:49:02.631144+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. (This vulnerability does not affect Docker due to an implementation detail that happens to block the attack.)</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2019-19921"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-fh74-hm69-rqjw</id>
    <title>GHSA-fh74-hm69-rqjw — opencontainers runc contains procfs race condition with a shared volume mount</title>
    <updated>2026-10-04T04:49:02.631166+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/opencontainers/runc</p>
<p>### Impact
By crafting a malicious root filesystem (with `/proc` being a symlink to a directory which was inside a volume shared with another running container), an attacker in control of both containers can trick `runc` into not correctly configuring the container's security labels and not correctly masking paths inside `/proc` which contain potentially-sensitive information about the host (or even allow for direct attacks against the host).</p>
<p>In order to exploit this bug, an untrusted user must be able to spawn custom containers with custom mount configurations (such that a volume is shared between two containers). It should be noted that we consider this to be a fairly high level of access for an untrusted user -- and we do not recommend allowing completely untrusted users to have such degrees of access without further restrictions.</p>
<p>### Specific Go Package Affected
github.com/opencontainers/runc/libcontainer</p>
<p>### Patches
This vulnerability has been fixed in `1.0.0-rc10`. It should be noted that the current fix is effectively a hot-fix, and there are known ways for it to be worked around (such as making the entire root filesystem a shared volume controlled by another container). We recommend that users review their access policies to ensure that untrusted users do not have such high levels of controls over container mount configuration.</p>
<p>### Workarounds
If you are not providing the ability for untrusted users to configure mountpoints for `runc` (or through a higher-level t…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-fh74-hm69-rqjw"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2019-19921</id>
    <title>gsd-2019-19921</title>
    <updated>2026-10-04T04:49:02.631206+00:00</updated>
    <content>gsd-2019-19921</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2019-19921"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2020:0219-1</id>
    <title>openSUSE-SU-2020:0219-1 — Security update for docker-runc</title>
    <updated>2026-10-04T04:49:02.631229+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for docker-runc</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2020:0219-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2020:0688</id>
    <title>RHSA-2020:0688 — Red Hat Security Advisory: OpenShift Container Platform 4.2.22 runc security update</title>
    <updated>2026-10-04T04:49:02.631246+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>runc: volume mount race condition with shared mounts leads to information leak/integrity manipulation</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2020:0688"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2020:0375-1</id>
    <title>SUSE-SU-2020:0375-1 — Security update for docker-runc</title>
    <updated>2026-10-04T04:49:02.631261+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for docker-runc</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2020:0375-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-19921</id>
    <title>UBUNTU-CVE-2019-19921</title>
    <updated>2026-10-04T04:49:02.631274+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: runc, Ubuntu:18.04:LTS: runc, Ubuntu:20.04:LTS: runc</p>
<p>runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. (This vulnerability does not affect Docker due to an implementation detail that happens to block the attack.)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-19921"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1089</id>
    <title>WID-SEC-W-2022-1089 — Red Hat OpenShift Container Platform: Mehrere Schwachstellen</title>
    <updated>2026-10-04T04:49:02.631296+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler oder entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat OpenShift Container Platform ausnutzen, um seine Privilegien zu erhöhen, Code zur Ausführung zu bringen oder Dateien zu manipulieren</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1089"/>
  </entry>
</feed>
