<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T17:44:58.723998+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2022:0892</id>
    <title>ALSA-2022:0892 — Moderate: libarchive security update</title>
    <updated>2026-10-04T17:44:58.939710+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: bsdtar, AlmaLinux:8: libarchive, AlmaLinux:8: libarchive-devel</p>
<p>The libarchive programming library can create and read several different streaming archive formats, including GNU tar, cpio, and ISO 9660 CD-ROM images. Libarchive is used notably in the bsdtar utility, scripting language bindings such as python-libarchive, and several popular desktop file managers.</p>
<p>Security Fix(es):</p>
<p>* libarchive: extracting a symlink with ACLs modifies ACLs of target (CVE-2021-23177)</p>
<p>* libarchive: symbolic links incorrectly followed when changing modes, times, ACL and flags of a file while extracting an archive (CVE-2021-31566)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2022:0892"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2022-01464</id>
    <title>bdu:2022-01464</title>
    <updated>2026-10-04T17:44:58.939783+00:00</updated>
    <content>bdu:2022-01464</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2022-01464"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2022-avi-683</id>
    <title>certfr-2022-avi-683 — De multiples vulnérabilités ont été découvertes dans IBM QRadar SIEM.
Certaines d'entre elles permettent à un attaquant…</title>
    <updated>2026-10-04T17:44:58.939800+00:00</updated>
    <content>certfr-2022-avi-683</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2022-avi-683"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-27553</id>
    <title>EUVD-2026-27553</title>
    <updated>2026-10-04T17:44:58.939816+00:00</updated>
    <content>EUVD-2026-27553</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-27553"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-31566</id>
    <title>fkie_cve-2021-31566</title>
    <updated>2026-10-04T17:44:58.939827+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An improper link resolution flaw can occur while extracting an archive leading to changing modes, times, access control lists, and flags of a file outside of the archive. An attacker may provide a malicious archive to a victim user, who would trigger this flaw when trying to extract the archive. A local attacker may use this flaw to gain more privileges in a system.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-31566"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-mg62-fpgc-6hjj</id>
    <title>GHSA-mg62-fpgc-6hjj</title>
    <updated>2026-10-04T17:44:58.939849+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An improper link resolution flaw can occur while extracting an archive leading to changing modes, times, access control lists, and flags of a file outside of the archive. An attacker may provide a malicious archive to a victim user, who would trigger this flaw when trying to extract the archive. A local attacker may use this flaw to gain more privileges in a system.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-mg62-fpgc-6hjj"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-31566</id>
    <title>gsd-2021-31566</title>
    <updated>2026-10-04T17:44:58.939863+00:00</updated>
    <content>gsd-2021-31566</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-31566"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2022-1494</id>
    <title>OESA-2022-1494 — libarchive security update</title>
    <updated>2026-10-04T17:44:58.939873+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: libarchive, openEuler:20.03-LTS-SP2: libarchive, openEuler:20.03-LTS-SP3: libarchive</p>
<p>is an open-source BSD-licensed C programming library that  provides streaming access to a variety of different archive formats, including tar, cpio, pax, zip, and ISO9660 images. The distribution  also includes bsdtar and bsdcpio, full-featured implementations of  tar and cpio that use .

Security Fix(es):

Incorrect link resolution flaws can occur when extracting archives, resulting in changes to the mode, time, access control list, and flags of files outside the archive. An attacker could deliver malicious archives to victim users, triggering this vulnerability when they attempt to extract the archives. A local attacker could exploit this vulnerability to gain additional privileges on the system.(CVE-2021-31566)

Incorrect link resolution flaws when using ACLs to extract symbolic links can lead to changes to the access control list (ACL) of the link target. An attacker could deliver malicious archives to victim users, triggering this vulnerability when they attempt to extract the archives. A local attacker could exploit this vulnerability to change the ACL of a file on the system and gain more permissions.(CVE-2021-23177)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2022-1494"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:11894-1</id>
    <title>openSUSE-SU-2024:11894-1 — bsdtar-3.6.0-1.1 on GA media</title>
    <updated>2026-10-04T17:44:58.939903+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>bsdtar-3.6.0-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:11894-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2022:3935-1</id>
    <title>SUSE-SU-2022:3935-1 — Security update for libarchive</title>
    <updated>2026-10-04T17:44:58.939921+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for libarchive</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2022:3935-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-31566</id>
    <title>UBUNTU-CVE-2021-31566</title>
    <updated>2026-10-04T17:44:58.939935+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: libarchive, Ubuntu:Pro:16.04:LTS: libarchive, Ubuntu:Pro:18.04:LTS: libarchive, Ubuntu:20.04:LTS: libarchive</p>
<p>An improper link resolution flaw can occur while extracting an archive leading to changing modes, times, access control lists, and flags of a file outside of the archive. An attacker may provide a malicious archive to a victim user, who would trigger this flaw when trying to extract the archive. A local attacker may use this flaw to gain more privileges in a system.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-31566"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1130</id>
    <title>WID-SEC-W-2022-1130 — Red Hat Enterprise Linux: Mehrere Schwachstellen ermöglichen Umgehen von Sicherheitsvorkehrungen</title>
    <updated>2026-10-04T17:44:58.939957+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um Sicherheitsvorkehrungen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1130"/>
  </entry>
</feed>
