<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T05:46:12.917418+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2022-01715</id>
    <title>bdu:2022-01715</title>
    <updated>2026-10-04T05:46:13.207315+00:00</updated>
    <content>bdu:2022-01715</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2022-01715"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2022-23648</id>
    <title>Withdrawn: BELL-CVE-2022-23648 — CVE-2022-23648 does not affect BellSoft software</title>
    <updated>2026-10-04T05:46:13.207359+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2022-23648"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0199</id>
    <title>certfr-2024-avi-0199 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;les produits IBM&lt;/span&gt;. Certaines d'entre el…</title>
    <updated>2026-10-04T05:46:13.207378+00:00</updated>
    <content>certfr-2024-avi-0199</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0199"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2025-xk69277</id>
    <title>CLEANSTART-2025-XK69277 — containerd is a container runtime available as a daemon for Linux and Windows</title>
    <updated>2026-10-04T05:46:13.207393+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: containerd</p>
<p>Security vulnerability affects the containerd package. containerd is a container runtime available as a daemon for Linux and Windows.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2025-xk69277"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2022-29292</id>
    <title>cnvd-2022-29292</title>
    <updated>2026-10-04T05:46:13.207420+00:00</updated>
    <content>cnvd-2022-29292</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2022-29292"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-13838</id>
    <title>EUVD-2026-13838</title>
    <updated>2026-10-04T05:46:13.207432+00:00</updated>
    <content>EUVD-2026-13838</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-13838"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-23648</id>
    <title>fkie_cve-2022-23648</title>
    <updated>2026-10-04T05:46:13.207442+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>containerd is a container runtime available as a daemon for Linux and Windows. A bug was found in containerd prior to versions 1.6.1, 1.5.10, and 1.14.12 where containers launched through containerd’s CRI implementation on Linux with a specially-crafted image configuration could gain access to read-only copies of arbitrary files and directories on the host. This may bypass any policy-based enforcement on container setup (including a Kubernetes Pod Security Policy) and expose potentially sensitive information. Kubernetes and crictl can both be configured to use containerd’s CRI implementation. This bug has been fixed in containerd 1.6.1, 1.5.10, and 1.4.12. Users should update to these versions to resolve the issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-23648"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-crp2-qrr5-8pq7</id>
    <title>GHSA-crp2-qrr5-8pq7 — containerd CRI plugin: Insecure handling of image volumes</title>
    <updated>2026-10-04T05:46:13.207468+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/containerd/containerd</p>
<p>### Impact</p>
<p>A bug was found in containerd where containers launched through containerd’s CRI implementation with a specially-crafted image configuration could gain access to read-only copies of arbitrary files and directories on the host.  This may bypass any policy-based enforcement on container setup (including a Kubernetes Pod Security Policy) and expose potentially sensitive information.  Kubernetes and crictl can both be configured to use containerd’s CRI implementation.</p>
<p>### Patches</p>
<p>This bug has been fixed in containerd 1.6.1, 1.5.10 and 1.4.13.  Users should update to these versions to resolve the issue.</p>
<p>### Workarounds</p>
<p>Ensure that only trusted images are used.</p>
<p>### Credits</p>
<p>The containerd project would like to thank Felix Wilhelm of Google Project Zero for responsibly disclosing this issue in accordance with the [containerd security policy](https://github.com/containerd/project/blob/main/SECURITY.md).</p>
<p>### For more information</p>
<p>If you have any questions or comments about this advisory:</p>
<p>* Open an issue in [containerd](https://github.com/containerd/containerd/issues/new/choose)
* Email us at [security@containerd.io](mailto:security@containerd.io)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-crp2-qrr5-8pq7"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-23648</id>
    <title>gsd-2022-23648</title>
    <updated>2026-10-04T05:46:13.207533+00:00</updated>
    <content>gsd-2022-23648</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-23648"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2022-23648</id>
    <title>msrc_CVE-2022-23648 — Insecure handling of image volumes in containerd CRI plugin</title>
    <updated>2026-10-04T05:46:13.207559+00:00</updated>
    <content>msrc_CVE-2022-23648</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2022-23648"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2022-1671</id>
    <title>OESA-2022-1671 — containerd security update</title>
    <updated>2026-10-04T05:46:13.207573+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: containerd, openEuler:20.03-LTS-SP3: containerd, openEuler:22.03-LTS: containerd</p>
<p>containerd is an industry-standard container runtime with an emphasis on simplicity, robustness and portability.  It is available as a daemon for Linux and Windows, which can manage the complete container lifecycle of its host system: image transfer and storage, container execution and supervision, low-level storage and network attachments, etc.</p>
<p>Security Fix(es):</p>
<p>containerd is a container runtime available as a daemon for Linux and Windows. A bug was found in containerd prior to versions 1.6.1, 1.5.10, and 1.14.12 where containers launched through containerd’s CRI implementation on Linux with a specially-crafted image configuration could gain access to read-only copies of arbitrary files and directories on the host. This may bypass any policy-based enforcement on container setup (including a Kubernetes Pod Security Policy) and expose potentially sensitive information. Kubernetes and crictl can both be configured to use containerd’s CRI implementation. This bug has been fixed in containerd 1.6.1, 1.5.10, and 1.4.12. Users should update to these versions to resolve the issue.(CVE-2022-23648)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2022-1671"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2022:0720-1</id>
    <title>openSUSE-SU-2022:0720-1 — Security update for containerd</title>
    <updated>2026-10-04T05:46:13.207605+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for containerd</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2022:0720-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2022:0719-1</id>
    <title>SUSE-SU-2022:0719-1 — Security update for containerd</title>
    <updated>2026-10-04T05:46:13.207620+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for containerd</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2022:0719-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-23648</id>
    <title>UBUNTU-CVE-2022-23648</title>
    <updated>2026-10-04T05:46:13.207633+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:18.04:LTS: containerd, Ubuntu:20.04:LTS: containerd, Ubuntu:22.04:LTS: containerd</p>
<p>containerd is a container runtime available as a daemon for Linux and Windows. A bug was found in containerd prior to versions 1.6.1, 1.5.10, and 1.14.12 where containers launched through containerd’s CRI implementation on Linux with a specially-crafted image configuration could gain access to read-only copies of arbitrary files and directories on the host. This may bypass any policy-based enforcement on container setup (including a Kubernetes Pod Security Policy) and expose potentially sensitive information. Kubernetes and crictl can both be configured to use containerd’s CRI implementation. This bug has been fixed in containerd 1.6.1, 1.5.10, and 1.4.12. Users should update to these versions to resolve the issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-23648"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1375</id>
    <title>WID-SEC-W-2022-1375 — JFrog Artifactory: Mehrere Schwachstellen</title>
    <updated>2026-10-04T05:46:13.207658+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in JFrog Artifactory ausnutzen, um seine Privilegien zu erweitern, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen und einen Denial-of-Service-Zustand auszulösen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1375"/>
  </entry>
</feed>
