<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T01:49:02.966477+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2022:7954</id>
    <title>ALSA-2022:7954 — Moderate: podman security and bug fix update</title>
    <updated>2026-10-03T01:49:03.202415+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: podman, AlmaLinux:9: podman-docker, AlmaLinux:9: podman-gvproxy, AlmaLinux:9: podman-plugins, AlmaLinux:9: podman-remote, AlmaLinux:9: podman-tests</p>
<p>The podman tool manages pods, container images, and containers. It is part of the libpod library, which is for applications that use container pods. Container pods is a concept in Kubernetes.</p>
<p>Security Fix(es):</p>
<p>* golang.org/x/text: Panic in language.ParseAcceptLanguage while parsing -u- extension (CVE-2020-28851)
* golang.org/x/text: Panic in language.ParseAcceptLanguage while processing bcp47 tag (CVE-2020-28852)
* podman: podman machine spawns gvproxy with port bound to all IPs (CVE-2021-4024)
* podman: Remote traffic to rootless containers is seen as orginating from localhost (CVE-2021-20199)
* containers/storage: DoS via malicious image (CVE-2021-20291)
* golang: net/http/httputil: ReverseProxy forwards connection headers if first one is empty (CVE-2021-33197)
* golang: crypto/tls: certificate of wrong type is causing TLS client to panic (CVE-2021-34558)
* golang: crash in a golang.org/x/crypto/ssh server (CVE-2022-27191)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p>
<p>Additional Changes:</p>
<p>For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2022:7954"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-03676</id>
    <title>bdu:2023-03676</title>
    <updated>2026-10-03T01:49:03.202503+00:00</updated>
    <content>bdu:2023-03676</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-03676"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2021-4024</id>
    <title>Withdrawn: BELL-CVE-2021-4024 — CVE-2021-4024 does not affect BellSoft software</title>
    <updated>2026-10-03T01:49:03.202541+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2021-4024"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-21241</id>
    <title>EUVD-2026-21241</title>
    <updated>2026-10-03T01:49:03.202587+00:00</updated>
    <content>EUVD-2026-21241</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-21241"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-4024</id>
    <title>fkie_cve-2021-4024</title>
    <updated>2026-10-03T01:49:03.202610+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in podman. The `podman machine` function (used to create and manage Podman virtual machine containing a Podman process) spawns a `gvproxy` process on the host system. The `gvproxy` API is accessible on port 7777 on all IP addresses on the host. If that port is open on the host's firewall, an attacker can potentially use the `gvproxy` API to forward ports on the host to ports in the VM, making private services on the VM accessible to the network. This issue could be also used to interrupt the host's services by forwarding all ports to the VM.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-4024"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3cf2-x423-x582</id>
    <title>GHSA-3cf2-x423-x582 — Exposure of Sensitive Information to an Unauthorized Actor and Origin Validation Error in podman</title>
    <updated>2026-10-03T01:49:03.202669+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/containers/podman/v3</p>
<p>A flaw was found in podman. The `podman machine` function (used to create and manage Podman virtual machine containing a Podman process) spawns a `gvproxy` process on the host system. The `gvproxy` API is accessible on port 7777 on all IP addresses on the host. If that port is open on the host's firewall, an attacker can potentially use the `gvproxy` API to forward ports on the host to ports in the VM, making private services on the VM accessible to the network. This issue could be also used to interrupt the host's services by forwarding all ports to the VM.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3cf2-x423-x582"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-4024</id>
    <title>gsd-2021-4024</title>
    <updated>2026-10-03T01:49:03.202707+00:00</updated>
    <content>gsd-2021-4024</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-4024"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2022:23018-1</id>
    <title>openSUSE-SU-2022:23018-1 — Security update for conmon, libcontainers-common, libseccomp, podman</title>
    <updated>2026-10-03T01:49:03.202720+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for conmon, libcontainers-common, libseccomp, podman</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2022:23018-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2022:23018-1</id>
    <title>SUSE-SU-2022:23018-1 — Security update for conmon, libcontainers-common, libseccomp, podman</title>
    <updated>2026-10-03T01:49:03.202742+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for conmon, libcontainers-common, libseccomp, podman</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2022:23018-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-4024</id>
    <title>UBUNTU-CVE-2021-4024</title>
    <updated>2026-10-03T01:49:03.202762+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:22.04:LTS: libpod, Ubuntu:Pro:24.04:LTS: libpod</p>
<p>A flaw was found in podman. The `podman machine` function (used to create and manage Podman virtual machine containing a Podman process) spawns a `gvproxy` process on the host system. The `gvproxy` API is accessible on port 7777 on all IP addresses on the host. If that port is open on the host's firewall, an attacker can potentially use the `gvproxy` API to forward ports on the host to ports in the VM, making private services on the VM accessible to the network. This issue could be also used to interrupt the host's services by forwarding all ports to the VM.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-4024"/>
  </entry>
</feed>
