<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T22:10:10.379383+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2022-00757</id>
    <title>bdu:2022-00757</title>
    <updated>2026-10-02T22:10:10.638797+00:00</updated>
    <content>bdu:2022-00757</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2022-00757"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2021-41103</id>
    <title>Withdrawn: BELL-CVE-2021-41103 — CVE-2021-41103 does not affect BellSoft software</title>
    <updated>2026-10-02T22:10:10.638839+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2021-41103"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2022-avi-547</id>
    <title>certfr-2022-avi-547 — De multiples vulnérabilités ont été découvertes dans les produits
Siemens. Certaines d'entre elles permettent à un atta…</title>
    <updated>2026-10-02T22:10:10.638859+00:00</updated>
    <content>certfr-2022-avi-547</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2022-avi-547"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2025-sc08629</id>
    <title>CLEANSTART-2025-SC08629 — containerd is an open source container runtime with an emphasis on simplicity, robustness and portability</title>
    <updated>2026-10-02T22:10:10.638875+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: containerd</p>
<p>Security vulnerability affects the containerd package. containerd is an open source container runtime with an emphasis on simplicity, robustness and portability.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2025-sc08629"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-31511</id>
    <title>EUVD-2026-31511</title>
    <updated>2026-10-02T22:10:10.638904+00:00</updated>
    <content>EUVD-2026-31511</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-31511"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-41103</id>
    <title>fkie_cve-2021-41103</title>
    <updated>2026-10-02T22:10:10.638916+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>containerd is an open source container runtime with an emphasis on simplicity, robustness and portability. A bug was found in containerd where container root directories and some plugins had insufficiently restricted permissions, allowing otherwise unprivileged Linux users to traverse directory contents and execute programs. When containers included executable programs with extended permission bits (such as setuid), unprivileged Linux users could discover and execute those programs. When the UID of an unprivileged Linux user on the host collided with the file owner or group inside a container, the unprivileged Linux user on the host could discover, read, and modify those files. This vulnerability has been fixed in containerd 1.4.11 and containerd 1.5.7. Users should update to these version when they are released and may restart containers or update directory permissions to mitigate the vulnerability. Users unable to update should limit access to the host to trusted users. Update directory permission on container bundles directories.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-41103"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-c2h3-6mxw-7mvq</id>
    <title>GHSA-c2h3-6mxw-7mvq — Insufficiently restricted permissions on plugin directories</title>
    <updated>2026-10-02T22:10:10.638942+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/containerd/containerd</p>
<p>### Impact
A bug was found in containerd where container root directories and some plugins had insufficiently restricted permissions, allowing otherwise unprivileged Linux users to traverse directory contents and execute programs. When containers included executable programs with extended permission bits (such as setuid), unprivileged Linux users could discover and execute those programs. When the UID of an unprivileged Linux user on the host collided with the file owner or group inside a container, the unprivileged Linux user on the host could discover, read, and modify those files.</p>
<p>### Patches
This vulnerability has been fixed in containerd 1.4.11 and containerd 1.5.7. Users should update to these version when they are released and may restart containers or update directory permissions to mitigate the vulnerability.</p>
<p>### Workarounds
Limit access to the host to trusted users. Update directory permission on container bundles directories.</p>
<p>### For more information
If you have any questions or comments about this advisory: 
* Open an issue in [github.com/containerd/containerd](https://github.com/containerd/containerd/issues/new/choose)
* Email us at [security@containerd.io](mailto:security@containerd.io)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-c2h3-6mxw-7mvq"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-41103</id>
    <title>gsd-2021-41103</title>
    <updated>2026-10-02T22:10:10.638974+00:00</updated>
    <content>gsd-2021-41103</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-41103"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-22-167-09</id>
    <title>ICSA-22-167-09 — Siemens SCALANCE LPE9403 Third-Party Vulnerabilities</title>
    <updated>2026-10-02T22:10:10.638985+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The CivetWeb web library does not validate uploaded filepaths when running on an OS other than Windows, when using the built-in HTTP form-based file upload mechanism, via the mg_handle_form_request API. Web applications that use the file upload form handler, and use parts of the user-controlled filename in the output path, are susceptible to directory traversal A corrupted timer tree caused the task wakeup to be missing in the timerqueue_add function in lib/timerqueue.c. This flaw allows a local attacker with special user privileges to cause a denial of service, slowing and eventually stopping the system while running OSP. The use of alloca function with an uncontrolled size in function unit_name_path_escape allows a local attacker, able to mount a filesystem on a very long path, to crash systemd and the whole system by allocating a very large space in the stack. A race condition vulnerability was found in Go. The incoming requests body weren't closed after the handler panic and as a consequence this could lead to ReverseProxy crash. The fix for CVE-2021-33196 can be bypassed by crafted inputs. As a result, the NewReader and OpenReader functions in archive/zip can still cause a panic or an unrecoverable fatal error when reading an archive that claims to contain a large number of files, regardless of its actual size. A vulnerability was found in Moby (Docker Engine) where attempting to copy files using docker cp into a specially-crafted container can result in Unix file permi…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-22-167-09"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2021-41103</id>
    <title>msrc_CVE-2021-41103 — Insufficiently restricted permissions on plugin directories</title>
    <updated>2026-10-02T22:10:10.639037+00:00</updated>
    <content>msrc_CVE-2021-41103</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2021-41103"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2021-1428</id>
    <title>OESA-2021-1428 — containerd security update</title>
    <updated>2026-10-02T22:10:10.639053+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: containerd, openEuler:20.03-LTS-SP2: containerd</p>
<p>containerd is an industry-standard container runtime with an emphasis on simplicity, robustness and portability.  It is available as a daemon for Linux and Windows, which can manage the complete container lifecycle of its host system: image transfer and storage, container execution and supervision, low-level storage and network attachments, etc.

Security Fix(es):

containerd is an open source container runtime with an emphasis on simplicity, robustness and portability. A bug was found in containerd where container root directories and some plugins had insufficiently restricted permissions, allowing otherwise unprivileged Linux users to traverse directory contents and execute programs. When containers included executable programs with extended permission bits (such as setuid), unprivileged Linux users could discover and execute those programs. When the UID of an unprivileged Linux user on the host collided with the file owner or group inside a container, the unprivileged Linux user on the host could discover, read, and modify those files. This vulnerability has been fixed in containerd 1.4.11 and containerd 1.5.7. Users should update to these version when they are released and may restart containers or update directory permissions to mitigate the vulnerability. Users unable to update should limit access to the host to trusted users. Update directory permission on container bundles directories.(CVE-2021-41103)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2021-1428"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2021:1404-1</id>
    <title>openSUSE-SU-2021:1404-1 — Security update for containerd, docker, runc</title>
    <updated>2026-10-02T22:10:10.639081+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for containerd, docker, runc</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2021:1404-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2022:5673</id>
    <title>RHSA-2022:5673 — Red Hat Security Advisory: Release of containers for OSP 16.2.z director operator tech preview</title>
    <updated>2026-10-02T22:10:10.639100+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>containerd: insufficiently restricted permissions on container root and plugin directories golang.org/x/crypto: empty plaintext packet causes panic go-getter: command injection vulnerability go-getter: unsafe download (issue 1 of 3) go-getter: unsafe download (issue 2 of 3) go-getter: unsafe download (issue 3 of 3)</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2022:5673"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2021:3336-1</id>
    <title>SUSE-SU-2021:3336-1 — Security update for containerd, docker, runc</title>
    <updated>2026-10-02T22:10:10.639123+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for containerd, docker, runc</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2021:3336-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-41103</id>
    <title>UBUNTU-CVE-2021-41103</title>
    <updated>2026-10-02T22:10:10.639139+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: containerd, Ubuntu:18.04:LTS: containerd, Ubuntu:20.04:LTS: containerd, Ubuntu:22.04:LTS: containerd</p>
<p>containerd is an open source container runtime with an emphasis on simplicity, robustness and portability. A bug was found in containerd where container root directories and some plugins had insufficiently restricted permissions, allowing otherwise unprivileged Linux users to traverse directory contents and execute programs. When containers included executable programs with extended permission bits (such as setuid), unprivileged Linux users could discover and execute those programs. When the UID of an unprivileged Linux user on the host collided with the file owner or group inside a container, the unprivileged Linux user on the host could discover, read, and modify those files. This vulnerability has been fixed in containerd 1.4.11 and containerd 1.5.7. Users should update to these version when they are released and may restart containers or update directory permissions to mitigate the vulnerability. Users unable to update should limit access to the host to trusted users. Update directory permission on container bundles directories.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-41103"/>
  </entry>
</feed>
