<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T18:51:50.082219+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2020:4676</id>
    <title>ALSA-2020:4676 — Moderate: virt:rhel and virt-devel:rhel security, bug fix, and enhancement update</title>
    <updated>2026-10-03T18:51:50.418569+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: hivex, AlmaLinux:8: hivex-devel, AlmaLinux:8: libguestfs-winsupport, AlmaLinux:8: libiscsi, AlmaLinux:8: libiscsi-devel, AlmaLinux:8: libiscsi-utils, AlmaLinux:8: libnbd, AlmaLinux:8: libnbd-devel, AlmaLinux:8: libvirt, AlmaLinux:8: libvirt-admin and 61 more</p>
<p>Kernel-based Virtual Machine (KVM) offers a full virtualization solution for Linux on numerous hardware platforms. The virt:rhel module contains packages which provide user-space components used to run virtual machines using KVM. The packages also provide APIs for managing and interacting with the virtualized systems.</p>
<p>The following packages have been upgraded to a later upstream version: hivex (1.3.18), libguestfs (1.40.2), libguestfs-winsupport (8.2), libvirt (6.0.0), libvirt-dbus (1.3.0), libvirt-python (6.0.0), nbdkit (1.16.2), perl-Sys-Virt (6.0.0), qemu-kvm (4.2.0), seabios (1.13.0), SLOF (20191022). (BZ#1810193, BZ#1844296)</p>
<p>Security Fix(es):</p>
<p>* libvirt: leak of /dev/mapper/control into QEMU guests (CVE-2020-14339)</p>
<p>* QEMU: Slirp: use-after-free during packet reassembly (CVE-2019-15890)</p>
<p>* libvirt: Potential DoS by holding a monitor job while querying QEMU guest-agent (CVE-2019-20485)</p>
<p>* QEMU: slirp: use-after-free in ip_reass() function in ip_input.c (CVE-2020-1983)</p>
<p>* libvirt: Potential denial of service via active pool without target path (CVE-2020-10703)</p>
<p>* libvirt: leak of sensitive cookie information via dumpxml (CVE-2020-14301)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p>
<p>Additional Changes:</p>
<p>For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2020:4676"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2020-14339</id>
    <title>Withdrawn: BELL-CVE-2020-14339 — CVE-2020-14339 does not affect BellSoft software</title>
    <updated>2026-10-03T18:51:50.418744+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2020-14339"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2020-47042</id>
    <title>cnvd-2020-47042</title>
    <updated>2026-10-03T18:51:50.418765+00:00</updated>
    <content>cnvd-2020-47042</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2020-47042"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-42373</id>
    <title>EUVD-2026-42373</title>
    <updated>2026-10-03T18:51:50.418780+00:00</updated>
    <content>EUVD-2026-42373</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-42373"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-14339</id>
    <title>fkie_cve-2020-14339</title>
    <updated>2026-10-03T18:51:50.418790+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in libvirt, where it leaked a file descriptor for `/dev/mapper/control` into the QEMU process. This file descriptor allows for privileged operations to happen against the device-mapper on the host. This flaw allows a malicious guest user or process to perform operations outside of their standard permissions, potentially causing serious damage to the host operating system. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-14339"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-c772-g5j9-w9w8</id>
    <title>GHSA-c772-g5j9-w9w8</title>
    <updated>2026-10-03T18:51:50.418814+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in libvirt, where it leaked a file descriptor for `/dev/mapper/control` into the QEMU process. This file descriptor allows for privileged operations to happen against the device-mapper on the host. This flaw allows a malicious guest user or process to perform operations outside of their standard permissions, potentially causing serious damage to the host operating system. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-c772-g5j9-w9w8"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-14339</id>
    <title>gsd-2020-14339</title>
    <updated>2026-10-03T18:51:50.418830+00:00</updated>
    <content>gsd-2020-14339</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-14339"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2021-1010</id>
    <title>OESA-2021-1010 — libvirt security update</title>
    <updated>2026-10-03T18:51:50.418841+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS: libvirt, openEuler:20.03-LTS-SP1: libvirt</p>
<p>Libvirt is a C toolkit to interact with the virtualization capabilities of recent versions of Linux (and other OSes). The main package includes the libvirtd server exporting the virtualization support.\r\n\r\n
Security Fix(es):\r\n\r\n
A flaw was found in libvirt, where it leaked a file descriptor for `/dev/mapper/control` into the QEMU process. This file descriptor allows for privileged operations to happen against the device-mapper on the host. This flaw allows a malicious guest user or process to perform operations outside of their standard permissions, potentially causing serious damage to the host operating system. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.(CVE-2020-14339)\r\n\r\n</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2021-1010"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2020:1455-1</id>
    <title>openSUSE-SU-2020:1455-1 — Security update for libvirt</title>
    <updated>2026-10-03T18:51:50.418865+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for libvirt</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2020:1455-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2020:3586</id>
    <title>RHSA-2020:3586 — Red Hat Security Advisory: virt:8.2 and virt-devel:8.2 security and bug fix update</title>
    <updated>2026-10-03T18:51:50.418882+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>QEMU: slirp: networking out-of-bounds read information disclosure vulnerability libvirt: leak of /dev/mapper/control into QEMU guests</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2020:3586"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2020:2233-1</id>
    <title>SUSE-SU-2020:2233-1 — Security update for libvirt</title>
    <updated>2026-10-03T18:51:50.418900+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for libvirt</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2020:2233-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1722</id>
    <title>WID-SEC-W-2022-1722 — QEMU und libvirt: Mehrere Schwachstellen</title>
    <updated>2026-10-03T18:51:50.418913+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann mehrere Schwachstellen in QEMU und libvirt ausnutzen, um Informationen offenzulegen und um Sicherheitsmechanismen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1722"/>
  </entry>
</feed>
