<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T19:42:23.320396+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2022:1759</id>
    <title>ALSA-2022:1759 — Moderate: virt:rhel and virt-devel:rhel security, bug fix, and enhancement update</title>
    <updated>2026-10-02T19:42:23.480293+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: SLOF, AlmaLinux:8: hivex, AlmaLinux:8: hivex-devel, AlmaLinux:8: libguestfs, AlmaLinux:8: libguestfs-appliance, AlmaLinux:8: libguestfs-bash-completion, AlmaLinux:8: libguestfs-devel, AlmaLinux:8: libguestfs-gfs2, AlmaLinux:8: libguestfs-gobject, AlmaLinux:8: libguestfs-gobject-devel and 120 more</p>
<p>Kernel-based Virtual Machine (KVM) offers a full virtualization solution for Linux on numerous hardware platforms. The virt:rhel module contains packages which provide user-space components used to run virtual machines using KVM. The packages also provide APIs for managing and interacting with the virtualized systems.</p>
<p>The following packages have been upgraded to a later upstream version: qemu-kvm (6.2.0), libvirt (8.0.0), libvirt-python (8.0.0), perl-Sys-Virt (8.0.0), seabios (1.15.0), libtpms (0.9.1). (BZ#1997410, BZ#2012802, BZ#2012806, BZ#2012813, BZ#2018392, BZ#2027716, BZ#2029355)</p>
<p>Security Fix(es):</p>
<p>* QEMU: virtio-net: heap use-after-free in virtio_net_receive_rcu (CVE-2021-3748)</p>
<p>* ntfs-3g: Out-of-bounds heap buffer access in ntfs_get_attribute_value() due to incorrect check of bytes_in_use value in MFT records (CVE-2021-33285)</p>
<p>* ntfs-3g: Heap buffer overflow triggered by a specially crafted Unicode string (CVE-2021-33286)</p>
<p>* ntfs-3g: Heap buffer overflow in ntfs_attr_pread_i() triggered by specially crafted NTFS attributes (CVE-2021-33287)</p>
<p>* ntfs-3g: Heap buffer overflow triggered by a specially crafted MFT section (CVE-2021-33289)</p>
<p>* ntfs-3g: Heap buffer overflow triggered by a specially crafted NTFS inode pathname (CVE-2021-35266)</p>
<p>* ntfs-3g: Stack buffer overflow triggered when correcting differences between MFT and MFTMirror sections (CVE-2021-35267)</p>
<p>* ntfs-3g: Heap buffer overflow in ntfs_inode_real_open() triggered by a specially crafted NTFS inode (CVE-202…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2022:1759"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2022-00263</id>
    <title>bdu:2022-00263</title>
    <updated>2026-10-02T19:42:23.480543+00:00</updated>
    <content>bdu:2022-00263</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2022-00263"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2022-82654</id>
    <title>cnvd-2022-82654</title>
    <updated>2026-10-02T19:42:23.480568+00:00</updated>
    <content>cnvd-2022-82654</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2022-82654"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-262352</id>
    <title>EUVD-2026-262352</title>
    <updated>2026-10-02T19:42:23.480581+00:00</updated>
    <content>EUVD-2026-262352</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-262352"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-39263</id>
    <title>fkie_cve-2021-39263</title>
    <updated>2026-10-02T19:42:23.480592+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A crafted NTFS image can trigger a heap-based buffer overflow, caused by an unsanitized attribute in ntfs_get_attribute_value, in NTFS-3G &lt; 2021.8.22.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-39263"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-q88c-8w3v-7j4h</id>
    <title>GHSA-q88c-8w3v-7j4h</title>
    <updated>2026-10-02T19:42:23.480615+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A crafted NTFS image can trigger a heap-based buffer overflow, caused by an unsanitized attribute in ntfs_get_attribute_value, in NTFS-3G &lt; 2021.8.22.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-q88c-8w3v-7j4h"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-39263</id>
    <title>gsd-2021-39263</title>
    <updated>2026-10-02T19:42:23.480629+00:00</updated>
    <content>gsd-2021-39263</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-39263"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2021-39263</id>
    <title>msrc_CVE-2021-39263 — A crafted NTFS image can trigger a heap-based buffer overflow caused by an unsanitized attribute in ntfs_get_attribute_…</title>
    <updated>2026-10-02T19:42:23.480639+00:00</updated>
    <content>msrc_CVE-2021-39263</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2021-39263"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2021-1365</id>
    <title>OESA-2021-1365 — ntfs-3g security update</title>
    <updated>2026-10-02T19:42:23.480656+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: ntfs-3g, openEuler:20.03-LTS-SP2: ntfs-3g</p>
<p>NTFS-3G is a stable, open source, GPL licensed, POSIX, read/write NTFS driver for Linux and many other operating systems. It provides safe handling of the Windows XP, Windows Server 2003, Windows 2000, Windows Vista, Windows Server 2008 and Windows 7 NTFS file systems.

Security Fix(es):

In NTFS-3G versions &amp;lt; 2021.8.22, when a specially crafted NTFS attribute is supplied to the function ntfs_get_attribute_value, a heap buffer overflow can occur allowing for memory disclosure or denial of service. The vulnerability is caused by an out-of-bound buffer access which can be triggered by mounting a crafted ntfs partition. The root cause is a missing consistency check after reading an MFT record : the &amp;quot;bytes_in_use&amp;quot; field should be less than the &amp;quot;bytes_allocated&amp;quot; field. When it is not, the parsing of the records proceeds into the wild.(CVE-2021-33285)

A crafted NTFS image can cause an out-of-bounds read in ntfs_ie_lookup in NTFS-3G &amp;lt; 2021.8.22.(CVE-2021-39252)

A crafted NTFS image can trigger an out-of-bounds read, caused by an invalid attribute in ntfs_attr_find_in_attrdef, in NTFS-3G &amp;lt; 2021.8.22.(CVE-2021-39255)

In NTFS-3G versions &amp;lt; 2021.8.22, when a specially crafted MFT section is supplied in an NTFS image a heap buffer overflow can occur and allow for code execution.(CVE-2021-33289)

In NTFS-3G versions &amp;lt; 2021.8.22, when a specially crafted unicode string is supplied in an NTFS image a heap buffer overflow can occur and allow…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2021-1365"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2021:1244-1</id>
    <title>openSUSE-SU-2021:1244-1 — Security update for ntfs-3g_ntfsprogs</title>
    <updated>2026-10-02T19:42:23.480703+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for ntfs-3g_ntfsprogs</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2021:1244-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2021:3703</id>
    <title>RHSA-2021:3703 — Red Hat Security Advisory: virt:av and virt-devel:av security and bug fix update</title>
    <updated>2026-10-02T19:42:23.480732+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>QEMU: net: Infinite loop in loopback mode may lead to stack overflow libvirt: Insecure sVirt label generation libvirt: Improper locking on ACL failure in virStoragePoolLookupByTargetPath API QEMU: usbredir: free() call on invalid pointer in bufp_alloc() ntfs-3g: Out-of-bounds heap buffer access in ntfs_get_attribute_value() due to incorrect check of bytes_in_use value in MFT records ntfs-3g: Heap buffer overflow triggered by a specially crafted Unicode string ntfs-3g: Heap buffer overflow in ntfs_attr_pread_i() triggered by specially crafted NTFS attributes ntfs-3g: Heap buffer overflow triggered by a specially crafted MFT section ntfs-3g: Heap buffer overflow triggered by a specially crafted NTFS inode pathname ntfs-3g: Stack buffer overflow triggered when correcting differences between MFT and MFTMirror sections ntfs-3g: Heap buffer overflow in ntfs_inode_real_open() triggered by a specially crafted NTFS inode ntfs-3g: Heap buffer overflow in ntfs_attr_setup_flag() triggered by a specially crafted NTFS attribute from MFT ntfs-3g: NULL pointer dereference in ntfs_extent_inode_open() ntfs-3g: Out-of-bounds read in ntfs_ie_lookup() ntfs-3g: Out-of-bounds read in ntfs_runlists_merge_i() ntfs-3g: Integer overflow in memmove() leading to heap buffer overflow in ntfs_attr_record_resize() ntfs-3g: Out-of-bounds read ntfs_attr_find_in_attrdef() triggered by an invalid attribute ntfs-3g: Heap buffer overflow in ntfs_inode_lookup_by_name() ntfs-3g: Endless recursion from ntfs_attr_pw…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2021:3703"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2021:2965-1</id>
    <title>SUSE-SU-2021:2965-1 — Security update for ntfs-3g_ntfsprogs</title>
    <updated>2026-10-02T19:42:23.480789+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for ntfs-3g_ntfsprogs</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2021:2965-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-39263</id>
    <title>UBUNTU-CVE-2021-39263</title>
    <updated>2026-10-02T19:42:23.480816+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: ntfs-3g, Ubuntu:Pro:16.04:LTS: ntfs-3g, Ubuntu:18.04:LTS: ntfs-3g, Ubuntu:20.04:LTS: ntfs-3g, Ubuntu:22.04:LTS: ntfs-3g</p>
<p>A crafted NTFS image can trigger a heap-based buffer overflow, caused by an unsanitized attribute in ntfs_get_attribute_value, in NTFS-3G &lt; 2021.8.22.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-39263"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1728</id>
    <title>WID-SEC-W-2022-1728 — Red Enterprise Linux Advanced Virtualization: Mehrere Schwachstellen</title>
    <updated>2026-10-02T19:42:23.480842+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter oder lokaler, authentisierter Angreifer kann mehrere Schwachstellen in Red Enterprise Linux Advanced Virtualization ausnutzen, um einen Denial of Service zu verursachen, Sicherheitsvorkehrungen zu umgehen, beliebigen Code auszuführen und Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1728"/>
  </entry>
</feed>
