<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T04:58:19.033281+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2021:1796</id>
    <title>ALSA-2021:1796 — Moderate: container-tools:rhel8 security, bug fix, and enhancement update</title>
    <updated>2026-10-03T04:58:19.052910+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: cockpit-podman, AlmaLinux:8: conmon, AlmaLinux:8: containernetworking-plugins, AlmaLinux:8: crit, AlmaLinux:8: criu, AlmaLinux:8: fuse-overlayfs, AlmaLinux:8: libslirp, AlmaLinux:8: libslirp-devel, AlmaLinux:8: python3-criu, AlmaLinux:8: slirp4netns and 1 more</p>
<p>The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.</p>
<p>Security Fix(es):</p>
<p>* golang: crypto/ssh: crafted authentication request can lead to nil pointer dereference (CVE-2020-29652)</p>
<p>* podman: Remote traffic to rootless containers is seen as orginating from localhost (CVE-2021-20199)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p>
<p>Additional Changes:</p>
<p>For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2021:1796"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2021-20199</id>
    <title>Withdrawn: BELL-CVE-2021-20199 — CVE-2021-20199 does not affect BellSoft software</title>
    <updated>2026-10-03T04:58:19.053041+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2021-20199"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-21513</id>
    <title>EUVD-2026-21513</title>
    <updated>2026-10-03T04:58:19.053062+00:00</updated>
    <content>EUVD-2026-21513</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-21513"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-20199</id>
    <title>fkie_cve-2021-20199</title>
    <updated>2026-10-03T04:58:19.053075+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Rootless containers run with Podman, receive all traffic with a source IP address of 127.0.0.1 (including from remote hosts). This impacts containerized applications that trust localhost (127.0.01) connections by default and do not require authentication. This issue affects Podman 1.8.0 onwards.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-20199"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-grh6-q6m2-rh72</id>
    <title>GHSA-grh6-q6m2-rh72 — Podman Origin Validation Error</title>
    <updated>2026-10-03T04:58:19.053098+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/containers/podman/v3</p>
<p>Rootless containers run with Podman, receive all traffic with a source IP address of 127.0.0.1 (including from remote hosts). This impacts containerized applications that trust localhost (127.0.01) connections by default and do not require authentication. This issue affects Podman versions from 1.8.0 to 3.0.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-grh6-q6m2-rh72"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-20199</id>
    <title>gsd-2021-20199</title>
    <updated>2026-10-03T04:58:19.053120+00:00</updated>
    <content>gsd-2021-20199</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-20199"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2021-20199</id>
    <title>msrc_CVE-2021-20199 — Rootless containers run with Podman receive all traffic with a source IP address of 127.0.0.1 (including from remote ho…</title>
    <updated>2026-10-03T04:58:19.053132+00:00</updated>
    <content>msrc_CVE-2021-20199</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2021-20199"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2022:23018-1</id>
    <title>openSUSE-SU-2022:23018-1 — Security update for conmon, libcontainers-common, libseccomp, podman</title>
    <updated>2026-10-03T04:58:19.053151+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for conmon, libcontainers-common, libseccomp, podman</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2022:23018-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2022:23018-1</id>
    <title>SUSE-SU-2022:23018-1 — Security update for conmon, libcontainers-common, libseccomp, podman</title>
    <updated>2026-10-03T04:58:19.053170+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for conmon, libcontainers-common, libseccomp, podman</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2022:23018-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-20199</id>
    <title>UBUNTU-CVE-2021-20199</title>
    <updated>2026-10-03T04:58:19.053190+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:22.04:LTS: libpod, Ubuntu:Pro:24.04:LTS: libpod</p>
<p>Rootless containers run with Podman, receive all traffic with a source IP address of 127.0.0.1 (including from remote hosts). This impacts containerized applications that trust localhost (127.0.01) connections by default and do not require authentication. This issue affects Podman 1.8.0 onwards.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-20199"/>
  </entry>
</feed>
