<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T06:04:45.420458+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2020-52439</id>
    <title>cnvd-2020-52439</title>
    <updated>2026-10-06T06:04:45.427393+00:00</updated>
    <content>cnvd-2020-52439</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2020-52439"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-42036</id>
    <title>EUVD-2026-42036</title>
    <updated>2026-10-06T06:04:45.427426+00:00</updated>
    <content>EUVD-2026-42036</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-42036"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-13846</id>
    <title>fkie_cve-2020-13846</title>
    <updated>2026-10-06T06:04:45.427440+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Sylabs Singularity 3.5.0 through 3.5.3 fails to report an error in a Status Code.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-13846"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-6w7g-p4jh-rf92</id>
    <title>GHSA-6w7g-p4jh-rf92 — "Verify All" Returns Success Despite Validation Failures in Singularity</title>
    <updated>2026-10-06T06:04:45.427467+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/sylabs/singularity</p>
<p>### Impact</p>
<p>The `--all / -a` option to `singularity verify` returns success even when some objects in a SIF container are not signed, or cannot be verified.</p>
<p>The SIF objects that are not verified are reported in `WARNING` log messages, but a `Container Verified` message and exit code of `0`  are returned.</p>
<p>Workflows that verify a container using `--all / -a` and use the exit code as an indicator of success are vulnerable to running SIF containers that have unsigned, or modified, objects that may be exploited to introduce malicious behavior.</p>
<p>```
$ singularity verify -a image.sif 
WARNING: Missing signature for SIF descriptor 2 (JSON.Generic)
WARNING: Missing signature for SIF descriptor 3 (FS)
Container is signed by 1 key(s):</p>
<p>Verifying partition: Def.FILE:
12045C8C0B1004D058DE4BEDA20C27EE7FF7BA84
[LOCAL]   Unit Test &lt;unit@test.com&gt;
[OK]      Data integrity verified</p>
<p>INFO:    Container verified: image.sif</p>
<p>$ echo $?
0
```</p>
<p>### Patches</p>
<p>Singularity 3.6.0 has a new implementation of sign/verify that fixes this issue.</p>
<p>All users are advised to upgrade to 3.6.0. Note that Singularity 3.6.0 uses a new signature format that is necessarily incompatible with Singularity &lt; 3.6.0 - e.g. Singularity 3.5.3 cannot verify containers signed by 3.6.0.</p>
<p>Version 3.6.0 includes a `--legacy-insecure` flag for the `singularity verify` command, that will perform verification of the older, and insecure, legacy signatures for compatibility with existing containers. This does not guarantee that con…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-6w7g-p4jh-rf92"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-13846</id>
    <title>gsd-2020-13846</title>
    <updated>2026-10-06T06:04:45.427515+00:00</updated>
    <content>gsd-2020-13846</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-13846"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2020:1011-1</id>
    <title>openSUSE-SU-2020:1011-1 — Security update for singularity</title>
    <updated>2026-10-06T06:04:45.427528+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for singularity</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2020:1011-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-13846</id>
    <title>UBUNTU-CVE-2020-13846</title>
    <updated>2026-10-06T06:04:45.427545+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:18.04:LTS: singularity-container, Ubuntu:Pro:24.04:LTS: singularity-container, Ubuntu:25.10: singularity-container, Ubuntu:26.04:LTS: singularity-container</p>
<p>Sylabs Singularity 3.5.0 through 3.5.3 fails to report an error in a Status Code.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-13846"/>
  </entry>
</feed>
