<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T19:53:41.096966+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2022:1759</id>
    <title>ALSA-2022:1759 — Moderate: virt:rhel and virt-devel:rhel security, bug fix, and enhancement update</title>
    <updated>2026-10-02T19:53:41.311188+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: SLOF, AlmaLinux:8: hivex, AlmaLinux:8: hivex-devel, AlmaLinux:8: libguestfs, AlmaLinux:8: libguestfs-appliance, AlmaLinux:8: libguestfs-bash-completion, AlmaLinux:8: libguestfs-devel, AlmaLinux:8: libguestfs-gfs2, AlmaLinux:8: libguestfs-gobject, AlmaLinux:8: libguestfs-gobject-devel and 120 more</p>
<p>Kernel-based Virtual Machine (KVM) offers a full virtualization solution for Linux on numerous hardware platforms. The virt:rhel module contains packages which provide user-space components used to run virtual machines using KVM. The packages also provide APIs for managing and interacting with the virtualized systems.</p>
<p>The following packages have been upgraded to a later upstream version: qemu-kvm (6.2.0), libvirt (8.0.0), libvirt-python (8.0.0), perl-Sys-Virt (8.0.0), seabios (1.15.0), libtpms (0.9.1). (BZ#1997410, BZ#2012802, BZ#2012806, BZ#2012813, BZ#2018392, BZ#2027716, BZ#2029355)</p>
<p>Security Fix(es):</p>
<p>* QEMU: virtio-net: heap use-after-free in virtio_net_receive_rcu (CVE-2021-3748)</p>
<p>* ntfs-3g: Out-of-bounds heap buffer access in ntfs_get_attribute_value() due to incorrect check of bytes_in_use value in MFT records (CVE-2021-33285)</p>
<p>* ntfs-3g: Heap buffer overflow triggered by a specially crafted Unicode string (CVE-2021-33286)</p>
<p>* ntfs-3g: Heap buffer overflow in ntfs_attr_pread_i() triggered by specially crafted NTFS attributes (CVE-2021-33287)</p>
<p>* ntfs-3g: Heap buffer overflow triggered by a specially crafted MFT section (CVE-2021-33289)</p>
<p>* ntfs-3g: Heap buffer overflow triggered by a specially crafted NTFS inode pathname (CVE-2021-35266)</p>
<p>* ntfs-3g: Stack buffer overflow triggered when correcting differences between MFT and MFTMirror sections (CVE-2021-35267)</p>
<p>* ntfs-3g: Heap buffer overflow in ntfs_inode_real_open() triggered by a specially crafted NTFS inode (CVE-202…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2022:1759"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2022-00753</id>
    <title>bdu:2022-00753</title>
    <updated>2026-10-02T19:53:41.311464+00:00</updated>
    <content>bdu:2022-00753</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2022-00753"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-21065</id>
    <title>EUVD-2026-21065</title>
    <updated>2026-10-02T19:53:41.311514+00:00</updated>
    <content>EUVD-2026-21065</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-21065"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-3748</id>
    <title>fkie_cve-2021-3748</title>
    <updated>2026-10-02T19:53:41.311528+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A use-after-free vulnerability was found in the virtio-net device of QEMU. It could occur when the descriptor's address belongs to the non direct access region, due to num_buffers being set after the virtqueue elem has been unmapped. A malicious guest could use this flaw to crash QEMU, resulting in a denial of service condition, or potentially execute code on the host with the privileges of the QEMU process.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-3748"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-4f87-mww8-gm8x</id>
    <title>GHSA-4f87-mww8-gm8x</title>
    <updated>2026-10-02T19:53:41.311586+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A use-after-free vulnerability was found in the virtio-net device of QEMU. It could occur when the descriptor's address belongs to the non direct access region, due to num_buffers being set after the virtqueue elem has been unmapped. A malicious guest could use this flaw to crash QEMU, resulting in a denial of service condition, or potentially execute code on the host with the privileges of the QEMU process.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-4f87-mww8-gm8x"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-3748</id>
    <title>gsd-2021-3748</title>
    <updated>2026-10-02T19:53:41.311604+00:00</updated>
    <content>gsd-2021-3748</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-3748"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2021-3748</id>
    <title>msrc_CVE-2021-3748 — A use-after-free vulnerability was found in the virtio-net device of QEMU. It could occur when the descriptor's address…</title>
    <updated>2026-10-02T19:53:41.311616+00:00</updated>
    <content>msrc_CVE-2021-3748</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2021-3748"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2021-1371</id>
    <title>OESA-2021-1371 — qemu security update</title>
    <updated>2026-10-02T19:53:41.311634+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: qemu, openEuler:20.03-LTS-SP2: qemu</p>
<p>QEMU is a FAST! processor emulator using dynamic translation to achieve good emulation speed.

Security Fix(es):

A use-after-free vulnerability was found in the virtio-net device of QEMU. It could occur when the descriptor&amp;apos;s address belongs to the non direct access region, due to num_buffers being set after the virtqueue elem has been unmapped. A malicious guest could use this flaw to crash QEMU, resulting in a denial of service condition, or potentially execute code on the host with the privileges of the QEMU process. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.(CVE-2021-3748)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2021-1371"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2021:3604-1</id>
    <title>openSUSE-SU-2021:3604-1 — Security update for qemu</title>
    <updated>2026-10-02T19:53:41.311676+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for qemu</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2021:3604-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2021:4112</id>
    <title>RHSA-2021:4112 — Red Hat Security Advisory: virt:av and virt-devel:av security and bug fix update</title>
    <updated>2026-10-02T19:53:41.311695+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>QEMU: virtio-net: heap use-after-free in virtio_net_receive_rcu</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2021:4112"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-3748</id>
    <title>UBUNTU-CVE-2021-3748</title>
    <updated>2026-10-02T19:53:41.311711+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:18.04:LTS: qemu, Ubuntu:20.04:LTS: qemu, Ubuntu:22.04:LTS: qemu</p>
<p>A use-after-free vulnerability was found in the virtio-net device of QEMU. It could occur when the descriptor's address belongs to the non direct access region, due to num_buffers being set after the virtqueue elem has been unmapped. A malicious guest could use this flaw to crash QEMU, resulting in a denial of service condition, or potentially execute code on the host with the privileges of the QEMU process.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-3748"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0096</id>
    <title>WID-SEC-W-2022-0096 — Red Hat Enterprise Linux: Schwachstelle ermöglicht Ausführen von beliebigem Programmcode mit den Rechten des Dienstes</title>
    <updated>2026-10-02T19:53:41.311735+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um beliebigen Programmcode mit den Rechten des Dienstes auszuführen oder einen Denial of Service Zustand herbeizuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0096"/>
  </entry>
</feed>
