<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T08:48:57.176252+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2020:4436</id>
    <title>ALSA-2020:4436 — Low: gnome-software and fwupd security, bug fix, and enhancement update</title>
    <updated>2026-10-04T08:48:57.189432+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: appstream-data, AlmaLinux:8: libxmlb</p>
<p>The gnome-software packages contain an application that makes it easy to add, remove, and update software in the GNOME desktop.</p>
<p>The appstream-data package provides the distribution specific AppStream metadata required for the GNOME and KDE software centers.</p>
<p>The fwupd packages provide a service that allows session software to update device firmware.</p>
<p>The following packages have been upgraded to a later upstream version: gnome-software (3.36.1), fwupd (1.4.2).</p>
<p>Security Fix(es):</p>
<p>* fwupd: Possible bypass in signature verification (CVE-2020-10759)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p>
<p>Additional Changes:</p>
<p>For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2020:4436"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2020-37942</id>
    <title>cnvd-2020-37942</title>
    <updated>2026-10-04T08:48:57.189510+00:00</updated>
    <content>cnvd-2020-37942</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2020-37942"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-40046</id>
    <title>EUVD-2026-40046</title>
    <updated>2026-10-04T08:48:57.189536+00:00</updated>
    <content>EUVD-2026-40046</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-40046"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-10759</id>
    <title>fkie_cve-2020-10759</title>
    <updated>2026-10-04T08:48:57.189559+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A PGP signature bypass flaw was found in fwupd (all versions), which could lead to the installation of unsigned firmware. As per upstream, a signature bypass is theoretically possible, but not practical because the Linux Vendor Firmware Service (LVFS) is either not implemented or enabled in versions of fwupd shipped with Red Hat Enterprise Linux 7 and 8. The highest threat from this vulnerability is to confidentiality and integrity.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-10759"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-phhj-vpf5-5666</id>
    <title>GHSA-phhj-vpf5-5666</title>
    <updated>2026-10-04T08:48:57.189608+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A PGP signature bypass flaw was found in fwupd (all versions), which could lead to the installation of unsigned firmware. As per upstream, a signature bypass is theoretically possible, but not practical because the Linux Vendor Firmware Service (LVFS) is either not implemented or enabled in versions of fwupd shipped with Red Hat Enterprise Linux 7 and 8. The highest threat from this vulnerability is to confidentiality and integrity.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-phhj-vpf5-5666"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-10759</id>
    <title>gsd-2020-10759</title>
    <updated>2026-10-04T08:48:57.189639+00:00</updated>
    <content>gsd-2020-10759</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-10759"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2022-1801</id>
    <title>OESA-2022-1801 — fwupd security update</title>
    <updated>2026-10-04T08:48:57.189658+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: fwupd, openEuler:20.03-LTS-SP3: fwupd, openEuler:22.03-LTS: fwupd</p>
<p>aims to make updating firmware on Linux automatic, safe and reliable.

Security Fix(es):

A PGP signature bypass flaw was found in fwupd (all versions), which could lead to the installation of unsigned firmware. As per upstream, a signature bypass is theoretically possible, but not practical because the Linux Vendor Firmware Service (LVFS) is either not implemented or enabled in versions of fwupd shipped with Red Hat Enterprise Linux 7 and 8. The highest threat from this vulnerability is to confidentiality and integrity.(CVE-2020-10759)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2022-1801"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2020:0849-1</id>
    <title>openSUSE-SU-2020:0849-1 — Security update for fwupd</title>
    <updated>2026-10-04T08:48:57.189707+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for fwupd</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2020:0849-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2020:1681-1</id>
    <title>SUSE-SU-2020:1681-1 — Security update for fwupd</title>
    <updated>2026-10-04T08:48:57.189738+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for fwupd</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2020:1681-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-10759</id>
    <title>UBUNTU-CVE-2020-10759</title>
    <updated>2026-10-04T08:48:57.189765+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: fwupd, Ubuntu:18.04:LTS: fwupd, Ubuntu:20.04:LTS: fwupd</p>
<p>A PGP signature bypass flaw was found in fwupd (all versions), which could lead to the installation of unsigned firmware. As per upstream, a signature bypass is theoretically possible, but not practical because the Linux Vendor Firmware Service (LVFS) is either not implemented or enabled in versions of fwupd shipped with Red Hat Enterprise Linux 7 and 8. The highest threat from this vulnerability is to confidentiality and integrity.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-10759"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0193</id>
    <title>WID-SEC-W-2022-0193 — Red Hat Enterprise Linux: Mehrere Schwachstellen</title>
    <updated>2026-10-04T08:48:57.189814+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um die Verfügbarkeit, Integrität und Vertraulichkeit zu gefährden.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0193"/>
  </entry>
</feed>
