<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T21:16:07.606655+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2021-43816</id>
    <title>Withdrawn: BELL-CVE-2021-43816 — CVE-2021-43816 does not affect BellSoft software</title>
    <updated>2026-10-02T21:16:07.751940+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2021-43816"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0199</id>
    <title>certfr-2024-avi-0199 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;les produits IBM&lt;/span&gt;. Certaines d'entre el…</title>
    <updated>2026-10-02T21:16:07.751989+00:00</updated>
    <content>certfr-2024-avi-0199</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0199"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2025-gq42610</id>
    <title>CLEANSTART-2025-GQ42610 — containerd is an open source container runtime</title>
    <updated>2026-10-02T21:16:07.752007+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: containerd</p>
<p>Security vulnerability affects the containerd package. containerd is an open source container runtime.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2025-gq42610"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-232850</id>
    <title>EUVD-2026-232850</title>
    <updated>2026-10-02T21:16:07.752037+00:00</updated>
    <content>EUVD-2026-232850</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-232850"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-43816</id>
    <title>fkie_cve-2021-43816</title>
    <updated>2026-10-02T21:16:07.752049+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>containerd is an open source container runtime. On installations using SELinux, such as EL8 (CentOS, RHEL), Fedora, or SUSE MicroOS, with containerd since v1.5.0-beta.0 as the backing container runtime interface (CRI), an unprivileged pod scheduled to the node may bind mount, via hostPath volume, any privileged, regular file on disk for complete read/write access (sans delete). Such is achieved by placing the in-container location of the hostPath volume mount at either `/etc/hosts`, `/etc/hostname`, or `/etc/resolv.conf`. These locations are being relabeled indiscriminately to match the container process-label which effectively elevates permissions for savvy containers that would not normally be able to access privileged host files. This issue has been resolved in version 1.5.9. Users are advised to upgrade as soon as possible.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-43816"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-mvff-h3cj-wj9c</id>
    <title>GHSA-mvff-h3cj-wj9c — Unprivileged pod using `hostPath` can side-step active LSM when it is SELinux</title>
    <updated>2026-10-02T21:16:07.752075+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/containerd/containerd</p>
<p>### Impact</p>
<p>Containers launched through containerd’s CRI implementation on Linux systems which use the SELinux security module and containerd versions since v1.5.0 can cause arbitrary files and directories on the host to be relabeled to match the container process label through the use of specially-configured bind mounts in a hostPath volume. This relabeling elevates permissions for the container, granting full read/write access over the affected files and directories. Kubernetes and crictl can both be configured to use containerd’s CRI implementation.</p>
<p>If you are not using containerd’s CRI implementation (through one of the mechanisms described above), you are not affected by this issue.</p>
<p>### Patches</p>
<p>This bug has been fixed in containerd 1.5.9.  Because file labels persist independently of containerd, users should both update to these versions as soon as they are released and validate that all files on their host are correctly labeled.</p>
<p>### Workarounds</p>
<p>Ensure that no sensitive files or directories are used as a hostPath volume source location.  Policy enforcement mechanisms such a Kubernetes Pod Security Policy [AllowedHostPaths](https://kubernetes.io/docs/concepts/policy/pod-security-policy/#volumes-and-file-systems) may be specified to limit the files and directories that can be bind-mounted to containers.</p>
<p>### For more information</p>
<p>If you have any questions or comments about this advisory:</p>
<p>* Open an issue in [containerd](https://github.com/containerd/containerd/issues…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-mvff-h3cj-wj9c"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-43816</id>
    <title>gsd-2021-43816</title>
    <updated>2026-10-02T21:16:07.752118+00:00</updated>
    <content>gsd-2021-43816</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-43816"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2022:0735</id>
    <title>RHSA-2022:0735 — Red Hat Security Advisory: Red Hat Advanced Cluster Management 2.4.2 security updates and bug fixes</title>
    <updated>2026-10-02T21:16:07.752130+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>nodejs-ansi-regex: Regular expression denial of service (ReDoS) matching ANSI escape codes nodejs-json-schema: Prototype pollution vulnerability fastify-static: open redirect via an URL with double slash followed by a domain moby: `docker cp` allows unexpected chmod of host file moby: data directory contains subdirectories with insufficiently restricted permissions, which could lead to directory traversal golang.org/x/crypto: empty plaintext packet causes panic containerd: Unprivileged pod may bind mount any privileged regular file on disk minio: user privilege escalation in AddUser() admin API node-fetch: exposure of sensitive information to an unauthorized actor nats-server: misusing the "dynamically provisioned sandbox accounts" feature  authenticated user can obtain the privileges of the System account</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2022:0735"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-43816</id>
    <title>UBUNTU-CVE-2021-43816</title>
    <updated>2026-10-02T21:16:07.752167+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: containerd, Ubuntu:18.04:LTS: containerd, Ubuntu:20.04:LTS: containerd, Ubuntu:22.04:LTS: containerd</p>
<p>containerd is an open source container runtime. On installations using SELinux, such as EL8 (CentOS, RHEL), Fedora, or SUSE MicroOS, with containerd since v1.5.0-beta.0 as the backing container runtime interface (CRI), an unprivileged pod scheduled to the node may bind mount, via hostPath volume, any privileged, regular file on disk for complete read/write access (sans delete). Such is achieved by placing the in-container location of the hostPath volume mount at either `/etc/hosts`, `/etc/hostname`, or `/etc/resolv.conf`. These locations are being relabeled indiscriminately to match the container process-label which effectively elevates permissions for savvy containers that would not normally be able to access privileged host files. This issue has been resolved in version 1.5.9. Users are advised to upgrade as soon as possible.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-43816"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0235</id>
    <title>WID-SEC-W-2022-0235 — Red Hat Advanced Cluster Management: Mehrere Schwachstellen ermöglichen Privilegieneskalation</title>
    <updated>2026-10-02T21:16:07.752195+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Advanced Cluster Management ausnutzen, um seine Privilegien zu erhöhen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0235"/>
  </entry>
</feed>
