<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T10:59:50.106559+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2021:1734</id>
    <title>ALSA-2021:1734 — Moderate: shim security update</title>
    <updated>2026-10-03T10:59:50.149592+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: shim-aa64, AlmaLinux:8: shim-ia32, AlmaLinux:8: shim-unsigned-aarch64, AlmaLinux:8: shim-unsigned-x64, AlmaLinux:8: shim-x64</p>
<p>The shim package contains a first-stage UEFI boot loader that handles chaining to a trusted full boot loader under secure boot environments.</p>
<p>Security Fix(es):</p>
<p>* grub2: acpi command allows privileged user to load crafted ACPI tables when Secure Boot is enabled (CVE-2020-14372)</p>
<p>* grub2: Use-after-free in rmmod command (CVE-2020-25632)</p>
<p>* grub2: Out-of-bounds write in grub_usb_device_initialize() (CVE-2020-25647)</p>
<p>* grub2: Stack buffer overflow in grub_parser_split_cmdline() (CVE-2020-27749)</p>
<p>* grub2: cutmem command allows privileged user to remove memory regions when Secure Boot is enabled (CVE-2020-27779)</p>
<p>* grub2: Heap out-of-bounds write in short form option parser (CVE-2021-20225)</p>
<p>* grub2: Heap out-of-bounds write due to miscalculation of space required for quoting (CVE-2021-20233)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p>
<p>Additional Changes:</p>
<p>For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2021:1734"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2022-00341</id>
    <title>bdu:2022-00341</title>
    <updated>2026-10-03T10:59:50.149694+00:00</updated>
    <content>bdu:2022-00341</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2022-00341"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2020-27779</id>
    <title>Withdrawn: BELL-CVE-2020-27779 — CVE-2020-27779 does not affect BellSoft software</title>
    <updated>2026-10-03T10:59:50.149712+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2020-27779"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2021-avi-172</id>
    <title>certfr-2021-avi-172 — GRUB2 est le bootloader le plus couramment utilisé par les distributions
Linux pour démarrer le système d'exploitation.…</title>
    <updated>2026-10-03T10:59:50.149729+00:00</updated>
    <content>certfr-2021-avi-172</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2021-avi-172"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2021-16916</id>
    <title>cnvd-2021-16916</title>
    <updated>2026-10-03T10:59:50.149746+00:00</updated>
    <content>cnvd-2021-16916</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2021-16916"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-46696</id>
    <title>EUVD-2026-46696</title>
    <updated>2026-10-03T10:59:50.149758+00:00</updated>
    <content>EUVD-2026-46696</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-46696"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-27779</id>
    <title>fkie_cve-2020-27779</title>
    <updated>2026-10-03T10:59:50.149768+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in grub2 in versions prior to 2.06. The cutmem command does not honor secure boot locking allowing an privileged attacker to remove address ranges from memory creating an opportunity to circumvent SecureBoot protections after proper triage about grub's memory layout. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-27779"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-7p29-8vr2-rmvx</id>
    <title>GHSA-7p29-8vr2-rmvx</title>
    <updated>2026-10-03T10:59:50.149791+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in grub2 in versions prior to 2.06. The cutmem command does not honor secure boot locking allowing an privileged attacker to remove address ranges from memory creating an opportunity to circumvent SecureBoot protections after proper triage about grub's memory layout. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-7p29-8vr2-rmvx"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-27779</id>
    <title>gsd-2020-27779</title>
    <updated>2026-10-03T10:59:50.149807+00:00</updated>
    <content>gsd-2020-27779</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-27779"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-21-336-06</id>
    <title>ICSA-21-336-06 — Hitachi Energy APM Edge</title>
    <updated>2026-10-03T10:59:50.149817+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer dereference will result, leading to a crash and a denial of service attack. A server is only vulnerable if it has TLSv1.2 and renegotiation enabled (which is the default configuration). OpenSSL TLS clients are not impacted by this issue. All OpenSSL 1.1.1 versions are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1k. OpenSSL 1.0.2 is not impacted by this issue. Fixed in OpenSSL 1.1.1k (Affected 1.1.1-1.1.1j). Hitachi Energy is aware of public reports of this vulnerability in the following open-source software components: OpenSSL, LibSSL, libxml2 and GRUB2 bootloader. The vulnerability also affects some APM Edge products. An attacker who successfully exploits this vulnerability could cause the product to become inaccessible. SEE NVD for full Description. In situations where an attacker receives automated notification of the success or failure of a decryption attempt an attacker, after sending a very large number of messages to be decrypted, can recover a CMS/PKCS7 transported encryption key or decrypt any RSA encrypted message that was encrypted with the public RSA key, using a Bleichenbacher padding oracle attack. Applications are not a…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-21-336-06"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2020-27779</id>
    <title>msrc_CVE-2020-27779 — A flaw was found in grub2 in versions prior to 2.06. The cutmem command does not honor secure boot locking allowing an…</title>
    <updated>2026-10-03T10:59:50.149924+00:00</updated>
    <content>msrc_CVE-2020-27779</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2020-27779"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2021-1095</id>
    <title>OESA-2021-1095 — grub2 security update</title>
    <updated>2026-10-03T10:59:50.149943+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS: grub2, openEuler:20.03-LTS-SP1: grub2</p>
<p>GNU GRUB is a Multiboot boot loader. It was derived from GRUB, the GRand Unified Bootloader, which was originally designed and implemented by Erich Stefan Boleyn. Briefly, a boot loader is the first software program that runs when a computer starts. It is responsible for loading and transferring control to the operating system kernel software (such as the Hurd or Linux). The kernel, in turn, initializes the rest of the operating system (e.g. GNU).

Security Fix(es):

A flaw was found in grub2 in versions prior to 2.06. The rmmod implementation allows the unloading of a module used as a dependency without checking if any other dependent module is still loaded leading to a use-after-free scenario. This could allow arbitrary code to be executed or a bypass of Secure Boot protections. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.(CVE-2020-25632)

A flaw was found in grub2 in versions prior to 2.06. During USB device initialization, descriptors are read with very little bounds checking and assumes the USB device is providing sane values. If properly exploited, an attacker could trigger memory corruption leading to arbitrary code execution allowing a bypass of the Secure Boot mechanism. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.(CVE-2020-25647)

A flaw was found in grub2 in versions prior to 2.06. Variable names present are expanded…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2021-1095"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2021:0462-1</id>
    <title>openSUSE-SU-2021:0462-1 — Security update for grub2</title>
    <updated>2026-10-03T10:59:50.149985+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for grub2</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2021:0462-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2021:0697</id>
    <title>RHSA-2021:0697 — Red Hat Security Advisory: grub2 security update</title>
    <updated>2026-10-03T10:59:50.150005+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>grub2: acpi command allows privileged user to load crafted ACPI tables when Secure Boot is enabled grub2: Use-after-free in rmmod command grub2: Out-of-bounds write in grub_usb_device_initialize() grub2: Stack buffer overflow in grub_parser_split_cmdline() grub2: cutmem command allows privileged user to remove memory regions when Secure Boot is enabled grub2: Heap out-of-bounds write in short form option parser grub2: Heap out-of-bounds write due to miscalculation of space required for quoting</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2021:0697"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2021:0679-1</id>
    <title>SUSE-SU-2021:0679-1 — Security update for grub2</title>
    <updated>2026-10-03T10:59:50.150033+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for grub2</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2021:0679-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-27779</id>
    <title>UBUNTU-CVE-2020-27779</title>
    <updated>2026-10-03T10:59:50.150050+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: grub2-signed, Ubuntu:18.04:LTS: grub2-signed, Ubuntu:18.04:LTS: grub2-unsigned, Ubuntu:20.04:LTS: grub2-signed, Ubuntu:20.04:LTS: grub2-unsigned</p>
<p>A flaw was found in grub2 in versions prior to 2.06. The cutmem command does not honor secure boot locking allowing an privileged attacker to remove address ranges from memory creating an opportunity to circumvent SecureBoot protections after proper triage about grub's memory layout. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-27779"/>
  </entry>
</feed>
