<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T04:58:01.913602+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2022:8100</id>
    <title>ALSA-2022:8100 — Low: swtpm security and bug fix update</title>
    <updated>2026-10-03T04:58:01.940696+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: swtpm, AlmaLinux:9: swtpm-libs, AlmaLinux:9: swtpm-tools</p>
<p>SWTPM is a TPM emulator built on libtpms providing TPM functionality for QEMU VMs.</p>
<p>Security Fix(es):</p>
<p>* swtpm: Unchecked header size indicator against expected size (CVE-2022-23645)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p>
<p>Additional Changes:</p>
<p>For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2022:8100"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2022-06088</id>
    <title>bdu:2022-06088</title>
    <updated>2026-10-03T04:58:01.940758+00:00</updated>
    <content>bdu:2022-06088</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2022-06088"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/essa-2022:0193</id>
    <title>ESSA-2022:0193 — security update for</title>
    <updated>2026-10-03T04:58:01.940776+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>security update for</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/essa-2022:0193"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-234422</id>
    <title>EUVD-2026-234422</title>
    <updated>2026-10-03T04:58:01.940798+00:00</updated>
    <content>EUVD-2026-234422</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-234422"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-23645</id>
    <title>fkie_cve-2022-23645</title>
    <updated>2026-10-03T04:58:01.940810+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>swtpm is a libtpms-based TPM emulator with socket, character device, and Linux CUSE interface. Versions prior to 0.5.3, 0.6.2, and 0.7.1 are vulnerable to out-of-bounds read. A specially crafted header of swtpm's state, where the blobheader's hdrsize indicator has an invalid value, may cause an out-of-bounds access when the byte array representing the state of the TPM is accessed. This will likely crash swtpm or prevent it from starting since the state cannot be understood. Users should upgrade to swtpm v0.5.3, v0.6.2, or v0.7.1 to receive a patch. There are currently no known workarounds.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-23645"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-23645</id>
    <title>gsd-2022-23645</title>
    <updated>2026-10-03T04:58:01.940835+00:00</updated>
    <content>gsd-2022-23645</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-23645"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2022-1576</id>
    <title>OESA-2022-1576 — swtpm security update</title>
    <updated>2026-10-03T04:58:01.940845+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: swtpm, openEuler:20.03-LTS-SP2: swtpm, openEuler:20.03-LTS-SP3: swtpm</p>
<p>TPM emulator built on libtpms providing TPM functionality for QEMU VMs

Security Fix(es):

swtpm is a libtpms-based TPM emulator with socket, character device, and Linux CUSE interface. Versions prior to 0.5.3, 0.6.2, and 0.7.1 are vulnerable to out-of-bounds read. A specially crafted header of swtpm&amp;apos;s state, where the blobheader&amp;apos;s hdrsize indicator has an invalid value, may cause an out-of-bounds access when the byte array representing the state of the TPM is accessed. This will likely crash swtpm or prevent it from starting since the state cannot be understood. Users should upgrade to swtpm v0.5.3, v0.6.2, or v0.7.1 to receive a patch. There are currently no known workarounds.(CVE-2022-23645)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2022-1576"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2022:7472</id>
    <title>RHSA-2022:7472 — Red Hat Security Advisory: virt:rhel and virt-devel:rhel security, bug fix, and enhancement update</title>
    <updated>2026-10-03T04:58:01.940886+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>QEMU: fdc: heap buffer overflow in DMA read data transfers libvirt: missing locking in nwfilterConnectNumOfNWFilters can lead to denial of service libguestfs: Buffer overflow in get_keys leads to DoS swtpm: Unchecked header size indicator against expected size</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2022:7472"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2022:1297-1</id>
    <title>SUSE-SU-2022:1297-1 — Security update for swtpm</title>
    <updated>2026-10-03T04:58:01.940913+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for swtpm</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2022:1297-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-23645</id>
    <title>Withdrawn: UBUNTU-CVE-2022-23645</title>
    <updated>2026-10-03T04:58:01.940928+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> Ubuntu:22.04:LTS: swtpm</p>
<p>swtpm is a libtpms-based TPM emulator with socket, character device, and Linux CUSE interface. Versions prior to 0.5.3, 0.6.2, and 0.7.1 are vulnerable to out-of-bounds read. A specially crafted header of swtpm's state, where the blobheader's hdrsize indicator has an invalid value, may cause an out-of-bounds access when the byte array representing the state of the TPM is accessed. This will likely crash swtpm or prevent it from starting since the state cannot be understood. Users should upgrade to swtpm v0.5.3, v0.6.2, or v0.7.1 to receive a patch. There are currently no known workarounds.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-23645"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2052</id>
    <title>WID-SEC-W-2022-2052 — Mehrere Red Hat Enterprise Linux Pakete: Mehrere Schwachstellen</title>
    <updated>2026-10-03T04:58:01.940950+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um einen Denial of Service Angriff durchzuführen, Sicherheitsvorkehrungen zu umgehen oder sonstige Auswirkungen zu verursachen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2052"/>
  </entry>
</feed>
