<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T10:28:05.936787+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2021:4191</id>
    <title>ALSA-2021:4191 — Moderate: virt:rhel and virt-devel:rhel security, bug fix, and enhancement update</title>
    <updated>2026-10-03T10:28:05.972585+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: hivex, AlmaLinux:8: hivex-devel, AlmaLinux:8: libguestfs, AlmaLinux:8: libguestfs-bash-completion, AlmaLinux:8: libguestfs-benchmarking, AlmaLinux:8: libguestfs-devel, AlmaLinux:8: libguestfs-gfs2, AlmaLinux:8: libguestfs-gobject, AlmaLinux:8: libguestfs-gobject-devel, AlmaLinux:8: libguestfs-inspect-icons and 83 more</p>
<p>Kernel-based Virtual Machine (KVM) offers a full virtualization solution for Linux on numerous hardware platforms. The virt:rhel module contains packages which provide user-space components used to run virtual machines using KVM. The packages also provide APIs for managing and interacting with the virtualized systems.</p>
<p>Security Fix(es):</p>
<p>* QEMU: net: e1000e: use-after-free while sending packets (CVE-2020-15859)</p>
<p>* QEMU: slirp: invalid pointer initialization may lead to information disclosure (bootp) (CVE-2021-3592)</p>
<p>* QEMU: slirp: invalid pointer initialization may lead to information disclosure (udp6) (CVE-2021-3593)</p>
<p>* QEMU: slirp: invalid pointer initialization may lead to information disclosure (udp) (CVE-2021-3594)</p>
<p>* QEMU: slirp: invalid pointer initialization may lead to information disclosure (tftp) (CVE-2021-3595)</p>
<p>* libvirt: Insecure sVirt label generation (CVE-2021-3631)</p>
<p>* libvirt: Improper locking on ACL failure in virStoragePoolLookupByTargetPath API (CVE-2021-3667)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p>
<p>Additional Changes:</p>
<p>For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2021:4191"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-01495</id>
    <title>bdu:2024-01495</title>
    <updated>2026-10-03T10:28:05.972762+00:00</updated>
    <content>bdu:2024-01495</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-01495"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2021-3592</id>
    <title>Withdrawn: BELL-CVE-2021-3592 — CVE-2021-3592 does not affect BellSoft software</title>
    <updated>2026-10-03T10:28:05.972781+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2021-3592"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0997</id>
    <title>certfr-2024-avi-0997 — De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Certaines d'entre elles permettent à un a…</title>
    <updated>2026-10-03T10:28:05.972797+00:00</updated>
    <content>certfr-2024-avi-0997</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0997"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2021-45152</id>
    <title>cnvd-2021-45152</title>
    <updated>2026-10-03T10:28:05.972811+00:00</updated>
    <content>cnvd-2021-45152</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2021-45152"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-20907</id>
    <title>EUVD-2026-20907</title>
    <updated>2026-10-03T10:28:05.972832+00:00</updated>
    <content>EUVD-2026-20907</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-20907"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-3592</id>
    <title>fkie_cve-2021-3592</title>
    <updated>2026-10-03T10:28:05.972842+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the bootp_input() function and could occur while processing a udp packet that is smaller than the size of the 'bootp_t' structure. A malicious guest could use this flaw to leak 10 bytes of uninitialized heap memory from the host. The highest threat from this vulnerability is to data confidentiality. This flaw affects libslirp versions prior to 4.6.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-3592"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xrpp-vwp4-q9hp</id>
    <title>GHSA-xrpp-vwp4-q9hp</title>
    <updated>2026-10-03T10:28:05.972867+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the bootp_input() function and could occur while processing a udp packet that is smaller than the size of the 'bootp_t' structure. A malicious guest could use this flaw to leak 10 bytes of uninitialized heap memory from the host. The highest threat from this vulnerability is to data confidentiality. This flaw affects libslirp versions prior to 4.6.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xrpp-vwp4-q9hp"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-3592</id>
    <title>gsd-2021-3592</title>
    <updated>2026-10-03T10:28:05.972884+00:00</updated>
    <content>gsd-2021-3592</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-3592"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2021-1411</id>
    <title>OESA-2021-1411 — qemu security update</title>
    <updated>2026-10-03T10:28:05.972894+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: qemu, openEuler:20.03-LTS-SP2: qemu</p>
<p>QEMU is a FAST! processor emulator using dynamic translation to achieve good emulation speed.

Security Fix(es):

An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the udp6_input() function and could occur while processing a udp packet that is smaller than the size of the &amp;apos;udphdr&amp;apos; structure. This issue may lead to out-of-bounds read access or indirect host memory disclosure to the guest. The highest threat from this vulnerability is to data confidentiality.(CVE-2021-3593)

An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the bootp_input() function and could occur while processing a udp packet that is smaller than the size of the &amp;apos;bootp_t&amp;apos; structure. A malicious guest could use this flaw to leak 10 bytes of uninitialized heap memory from the host. The highest threat from this vulnerability is to data confidentiality.(CVE-2021-3592)

An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the tftp_input() function and could occur while processing a udp packet that is smaller than the size of the &amp;apos;tftp_t&amp;apos; structure. This issue may lead to out-of-bounds read access or indirect host memory disclosure to the guest. The highest threat from this vulnerability is to data confidentiality.(CVE-2021-3595)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2021-1411"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2021:2474-1</id>
    <title>openSUSE-SU-2021:2474-1 — Security update for qemu</title>
    <updated>2026-10-03T10:28:05.972927+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for qemu</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2021:2474-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2021:4191</id>
    <title>RHSA-2021:4191 — Red Hat Security Advisory: virt:rhel and virt-devel:rhel security, bug fix, and enhancement update</title>
    <updated>2026-10-03T10:28:05.972948+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>QEMU: net: e1000e: use-after-free while sending packets QEMU: slirp: invalid pointer initialization may lead to information disclosure (bootp) QEMU: slirp: invalid pointer initialization may lead to information disclosure (udp6) QEMU: slirp: invalid pointer initialization may lead to information disclosure (udp) QEMU: slirp: invalid pointer initialization may lead to information disclosure (tftp) libvirt: Insecure sVirt label generation libvirt: Improper locking on ACL failure in virStoragePoolLookupByTargetPath API</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2021:4191"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2021:14772-1</id>
    <title>SUSE-SU-2021:14772-1 — Security update for kvm</title>
    <updated>2026-10-03T10:28:05.972978+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for kvm</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2021:14772-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-3592</id>
    <title>UBUNTU-CVE-2021-3592</title>
    <updated>2026-10-03T10:28:05.972995+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: qemu, Ubuntu:Pro:16.04:LTS: qemu, Ubuntu:18.04:LTS: qemu, Ubuntu:20.04:LTS: libslirp, Ubuntu:22.04:LTS: libslirp</p>
<p>An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the bootp_input() function and could occur while processing a udp packet that is smaller than the size of the 'bootp_t' structure. A malicious guest could use this flaw to leak 10 bytes of uninitialized heap memory from the host. The highest threat from this vulnerability is to data confidentiality. This flaw affects libslirp versions prior to 4.6.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-3592"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1219</id>
    <title>WID-SEC-W-2022-1219 — QEMU: Mehrere Schwachstellen ermöglichen Offenlegung von Informationen</title>
    <updated>2026-10-03T10:28:05.973021+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann mehrere Schwachstellen in QEMU ausnutzen, um Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1219"/>
  </entry>
</feed>
