<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T08:08:38.403498+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2022:0368</id>
    <title>ALSA-2022:0368 — Moderate: rpm security update</title>
    <updated>2026-10-05T08:08:38.432902+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: rpm-build, AlmaLinux:8: rpm-plugin-fapolicyd</p>
<p>The RPM Package Manager (RPM) is a command-line driven package management system capable of installing, uninstalling, verifying, querying, and updating software packages.</p>
<p>Security Fix(es):</p>
<p>* rpm: RPM does not require subkeys to have a valid binding signature (CVE-2021-3521)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2022:0368"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-04926</id>
    <title>bdu:2024-04926</title>
    <updated>2026-10-05T08:08:38.432992+00:00</updated>
    <content>bdu:2024-04926</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-04926"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2021-3521</id>
    <title>Withdrawn: BELL-CVE-2021-3521 — CVE-2021-3521 does not affect BellSoft software</title>
    <updated>2026-10-05T08:08:38.433018+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2021-3521"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2022-avi-544</id>
    <title>certfr-2022-avi-544 — De multiples vulnérabilités ont été découvertes dans IBM Netcool
Operations Insight. Certaines d'entre elles permettent…</title>
    <updated>2026-10-05T08:08:38.433044+00:00</updated>
    <content>certfr-2022-avi-544</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2022-avi-544"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-20999</id>
    <title>EUVD-2026-20999</title>
    <updated>2026-10-05T08:08:38.433068+00:00</updated>
    <content>EUVD-2026-20999</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-20999"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-3521</id>
    <title>fkie_cve-2021-3521</title>
    <updated>2026-10-05T08:08:38.433087+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>There is a flaw in RPM's signature functionality. OpenPGP subkeys are associated with a primary key via a "binding signature." RPM does not check the binding signature of subkeys prior to importing them. If an attacker is able to add or socially engineer another party to add a malicious subkey to a legitimate public key, RPM could wrongly trust a malicious signature. The greatest impact of this flaw is to data integrity. To exploit this flaw, an attacker must either compromise an RPM repository or convince an administrator to install an untrusted RPM or public key. It is strongly recommended to only use RPMs and public keys from trusted sources.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-3521"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-pr6x-p264-jrpq</id>
    <title>GHSA-pr6x-p264-jrpq</title>
    <updated>2026-10-05T08:08:38.433127+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>There is a flaw in RPM's signature functionality. OpenPGP subkeys are associated with a primary key via a "binding signature." RPM does not check the binding signature of subkeys prior to importing them. If an attacker is able to add or socially engineer another party to add a malicious subkey to a legitimate public key, RPM could wrongly trust a malicious signature. The greatest impact of this flaw is to data integrity. To exploit this flaw, an attacker must either compromise an RPM repository or convince an administrator to install an untrusted RPM or public key. It is strongly recommended to only use RPMs and public keys from trusted sources.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-pr6x-p264-jrpq"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-3521</id>
    <title>gsd-2021-3521</title>
    <updated>2026-10-05T08:08:38.433158+00:00</updated>
    <content>gsd-2021-3521</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-3521"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2021-3521</id>
    <title>msrc_CVE-2021-3521 — There is a flaw in RPM's signature functionality. OpenPGP subkeys are associated with a primary key via a "binding sign…</title>
    <updated>2026-10-05T08:08:38.433176+00:00</updated>
    <content>msrc_CVE-2021-3521</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2021-3521"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2021-1431</id>
    <title>OESA-2021-1431 — rpm security update</title>
    <updated>2026-10-05T08:08:38.433206+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: rpm, openEuler:20.03-LTS-SP2: rpm</p>
<p>The RPM Package Manager (RPM) is a powerful package management system capability as below

Security Fix(es):

The OpenPGP subkey is associated with the master key through a binding signature. RPM will not check their binding signature before importing the subkey; if the attacker can add it or the other party of social engineering adds the malicious subkey to the legal public Key, RPM may mistakenly trust malicious signatures.(CVE-2021-3521)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2021-1431"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12245-1</id>
    <title>openSUSE-SU-2024:12245-1 — librpmbuild9-4.17.1-1.1 on GA media</title>
    <updated>2026-10-05T08:08:38.433246+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>librpmbuild9-4.17.1-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:12245-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2022:0254</id>
    <title>RHSA-2022:0254 — Red Hat Security Advisory: rpm security update</title>
    <updated>2026-10-05T08:08:38.433274+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>rpm: RPM does not require subkeys to have a valid binding signature</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2022:0254"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2024:1557-2</id>
    <title>SUSE-SU-2024:1557-2 — Security update for rpm</title>
    <updated>2026-10-05T08:08:38.433300+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for rpm</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2024:1557-2"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-3521</id>
    <title>UBUNTU-CVE-2021-3521</title>
    <updated>2026-10-05T08:08:38.433355+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: rpm, Ubuntu:Pro:16.04:LTS: rpm, Ubuntu:Pro:18.04:LTS: rpm, Ubuntu:Pro:20.04:LTS: rpm, Ubuntu:22.04:LTS: rpm, Ubuntu:24.04:LTS: rpm, Ubuntu:25.10: rpm, Ubuntu:26.04:LTS: rpm</p>
<p>There is a flaw in RPM's signature functionality. OpenPGP subkeys are associated with a primary key via a "binding signature." RPM does not check the binding signature of subkeys prior to importing them. If an attacker is able to add or socially engineer another party to add a malicious subkey to a legitimate public key, RPM could wrongly trust a malicious signature. The greatest impact of this flaw is to data integrity. To exploit this flaw, an attacker must either compromise an RPM repository or convince an administrator to install an untrusted RPM or public key. It is strongly recommended to only use RPMs and public keys from trusted sources.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-3521"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1243</id>
    <title>WID-SEC-W-2022-1243 — RPM: Mehrere Schwachstellen</title>
    <updated>2026-10-05T08:08:38.433422+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann mehrere Schwachstellen in RPM ausnutzen, um Sicherheitsvorkehrungen zu umgehen, Dateien zu manipulieren oder sonstige Auswirkungen zu verursachen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1243"/>
  </entry>
</feed>
