<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T10:54:44.132610+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2021:4191</id>
    <title>ALSA-2021:4191 — Moderate: virt:rhel and virt-devel:rhel security, bug fix, and enhancement update</title>
    <updated>2026-10-03T10:54:44.461431+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: hivex, AlmaLinux:8: hivex-devel, AlmaLinux:8: libguestfs, AlmaLinux:8: libguestfs-bash-completion, AlmaLinux:8: libguestfs-benchmarking, AlmaLinux:8: libguestfs-devel, AlmaLinux:8: libguestfs-gfs2, AlmaLinux:8: libguestfs-gobject, AlmaLinux:8: libguestfs-gobject-devel, AlmaLinux:8: libguestfs-inspect-icons and 83 more</p>
<p>Kernel-based Virtual Machine (KVM) offers a full virtualization solution for Linux on numerous hardware platforms. The virt:rhel module contains packages which provide user-space components used to run virtual machines using KVM. The packages also provide APIs for managing and interacting with the virtualized systems.</p>
<p>Security Fix(es):</p>
<p>* QEMU: net: e1000e: use-after-free while sending packets (CVE-2020-15859)</p>
<p>* QEMU: slirp: invalid pointer initialization may lead to information disclosure (bootp) (CVE-2021-3592)</p>
<p>* QEMU: slirp: invalid pointer initialization may lead to information disclosure (udp6) (CVE-2021-3593)</p>
<p>* QEMU: slirp: invalid pointer initialization may lead to information disclosure (udp) (CVE-2021-3594)</p>
<p>* QEMU: slirp: invalid pointer initialization may lead to information disclosure (tftp) (CVE-2021-3595)</p>
<p>* libvirt: Insecure sVirt label generation (CVE-2021-3631)</p>
<p>* libvirt: Improper locking on ACL failure in virStoragePoolLookupByTargetPath API (CVE-2021-3667)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p>
<p>Additional Changes:</p>
<p>For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2021:4191"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-02428</id>
    <title>bdu:2024-02428</title>
    <updated>2026-10-03T10:54:44.461605+00:00</updated>
    <content>bdu:2024-02428</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-02428"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2021-3631</id>
    <title>Withdrawn: BELL-CVE-2021-3631 — CVE-2021-3631 does not affect BellSoft software</title>
    <updated>2026-10-03T10:54:44.461624+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2021-3631"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0380</id>
    <title>certfr-2024-avi-0380 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;les produits NetApp&lt;/span&gt;. Elles permettent…</title>
    <updated>2026-10-03T10:54:44.461640+00:00</updated>
    <content>certfr-2024-avi-0380</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0380"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-202784</id>
    <title>EUVD-2026-202784</title>
    <updated>2026-10-03T10:54:44.461654+00:00</updated>
    <content>EUVD-2026-202784</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-202784"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-3631</id>
    <title>fkie_cve-2021-3631</title>
    <updated>2026-10-03T10:54:44.461665+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw allows one exploited guest to access files labeled for another guest, resulting in the breaking out of sVirt confinement. The highest threat from this vulnerability is to confidentiality and integrity.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-3631"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-4225-xq9f-4ww3</id>
    <title>GHSA-4225-xq9f-4ww3</title>
    <updated>2026-10-03T10:54:44.461688+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw allows one exploited guest to access files labeled for another guest, resulting in the breaking out of sVirt confinement. The highest threat from this vulnerability is to confidentiality and integrity.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-4225-xq9f-4ww3"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-3631</id>
    <title>gsd-2021-3631</title>
    <updated>2026-10-03T10:54:44.461704+00:00</updated>
    <content>gsd-2021-3631</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-3631"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2021-3631</id>
    <title>msrc_CVE-2021-3631 — A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw allows one…</title>
    <updated>2026-10-03T10:54:44.461714+00:00</updated>
    <content>msrc_CVE-2021-3631</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2021-3631"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2021-1385</id>
    <title>OESA-2021-1385 — libvirt security update</title>
    <updated>2026-10-03T10:54:44.461730+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: libvirt, openEuler:20.03-LTS-SP2: libvirt</p>
<p>Libvirt is a C toolkit to interact with the virtualization capabilities of recent versions of Linux (and other OSes). The main package includes the libvirtd server exporting the virtualization support.

Security Fix(es):

An improper locking issue was found in the virStoragePoolLookupByTargetPath API of libvirt. It occurs in the storagePoolLookupByTargetPath function where a locked virStoragePoolObj object is not properly released on ACL permission failure. Clients connecting to the read-write socket with limited ACL permissions could use this flaw to acquire the lock and prevent other users from accessing storage pool/volume APIs, resulting in a denial of service condition. The highest threat from this vulnerability is to system availability.(CVE-2021-3667)

A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs&amp;apos; dynamic labels. This flaw allows one exploited guest to access files labeled for another guest, resulting in the breaking out of sVirt confinement. The highest threat from this vulnerability is to confidentiality and integrity.(CVE-2021-3631)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2021-1385"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2021:1119-1</id>
    <title>openSUSE-SU-2021:1119-1 — Security update for libvirt</title>
    <updated>2026-10-03T10:54:44.461760+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for libvirt</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2021:1119-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2021:3703</id>
    <title>RHSA-2021:3703 — Red Hat Security Advisory: virt:av and virt-devel:av security and bug fix update</title>
    <updated>2026-10-03T10:54:44.461776+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>QEMU: net: Infinite loop in loopback mode may lead to stack overflow libvirt: Insecure sVirt label generation libvirt: Improper locking on ACL failure in virStoragePoolLookupByTargetPath API QEMU: usbredir: free() call on invalid pointer in bufp_alloc() ntfs-3g: Out-of-bounds heap buffer access in ntfs_get_attribute_value() due to incorrect check of bytes_in_use value in MFT records ntfs-3g: Heap buffer overflow triggered by a specially crafted Unicode string ntfs-3g: Heap buffer overflow in ntfs_attr_pread_i() triggered by specially crafted NTFS attributes ntfs-3g: Heap buffer overflow triggered by a specially crafted MFT section ntfs-3g: Heap buffer overflow triggered by a specially crafted NTFS inode pathname ntfs-3g: Stack buffer overflow triggered when correcting differences between MFT and MFTMirror sections ntfs-3g: Heap buffer overflow in ntfs_inode_real_open() triggered by a specially crafted NTFS inode ntfs-3g: Heap buffer overflow in ntfs_attr_setup_flag() triggered by a specially crafted NTFS attribute from MFT ntfs-3g: NULL pointer dereference in ntfs_extent_inode_open() ntfs-3g: Out-of-bounds read in ntfs_ie_lookup() ntfs-3g: Out-of-bounds read in ntfs_runlists_merge_i() ntfs-3g: Integer overflow in memmove() leading to heap buffer overflow in ntfs_attr_record_resize() ntfs-3g: Out-of-bounds read ntfs_attr_find_in_attrdef() triggered by an invalid attribute ntfs-3g: Heap buffer overflow in ntfs_inode_lookup_by_name() ntfs-3g: Endless recursion from ntfs_attr_pw…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2021:3703"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2021:2471-1</id>
    <title>SUSE-SU-2021:2471-1 — Security update for libvirt</title>
    <updated>2026-10-03T10:54:44.461833+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for libvirt</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2021:2471-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-3631</id>
    <title>UBUNTU-CVE-2021-3631</title>
    <updated>2026-10-03T10:54:44.461849+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: libvirt, Ubuntu:Pro:16.04:LTS: libvirt, Ubuntu:18.04:LTS: libvirt, Ubuntu:20.04:LTS: libvirt, Ubuntu:22.04:LTS: libvirt</p>
<p>A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw allows one exploited guest to access files labeled for another guest, resulting in the breaking out of sVirt confinement. The highest threat from this vulnerability is to confidentiality and integrity.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-3631"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1725</id>
    <title>WID-SEC-W-2022-1725 — libvirt: Schwachstelle ermöglicht Offenlegung von Informationen</title>
    <updated>2026-10-03T10:54:44.461875+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann eine Schwachstelle in libvirt ausnutzen, um Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1725"/>
  </entry>
</feed>
