<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T04:03:49.678133+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2022:5095</id>
    <title>ALSA-2022:5095 — Important: grub2, mokutil, shim, and shim-unsigned-x64 security update</title>
    <updated>2026-10-03T04:03:49.941660+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: grub2-common, AlmaLinux:8: grub2-efi-aa64, AlmaLinux:8: grub2-efi-aa64-cdboot, AlmaLinux:8: grub2-efi-aa64-modules, AlmaLinux:8: grub2-efi-ia32, AlmaLinux:8: grub2-efi-ia32-cdboot, AlmaLinux:8: grub2-efi-ia32-modules, AlmaLinux:8: grub2-efi-x64, AlmaLinux:8: grub2-efi-x64-cdboot, AlmaLinux:8: grub2-efi-x64-modules and 11 more</p>
<p>The grub2 packages provide version 2 of the Grand Unified Boot Loader (GRUB), a highly configurable and customizable boot loader with modular architecture. The packages support a variety of kernel formats, file systems, computer architectures, and hardware devices.
The shim package contains a first-stage UEFI boot loader that handles chaining to a trusted full boot loader under secure boot environments.
Security Fix(es):
* grub2: Integer underflow in grub_net_recv_ip4_packets (CVE-2022-28733)
* grub2: Crafted PNG grayscale images may lead to out-of-bounds write in heap (CVE-2021-3695)
* grub2: Crafted PNG image may lead to out-of-bound write during huffman table handling (CVE-2021-3696)
* grub2: Crafted JPEG image can lead to buffer underflow write in the heap (CVE-2021-3697)
* grub2: Out-of-bound write when handling split HTTP headers (CVE-2022-28734)
* grub2: shim_lock verifier allows non-kernel files to be loaded (CVE-2022-28735)
* grub2: use-after-free in grub_cmd_chainloader() (CVE-2022-28736)
* shim: Buffer overflow when loading crafted EFI images (CVE-2022-28737)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2022:5095"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-05303</id>
    <title>bdu:2023-05303</title>
    <updated>2026-10-03T04:03:49.941749+00:00</updated>
    <content>bdu:2023-05303</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-05303"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0726</id>
    <title>certfr-2023-avi-0726 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;le noyau Linux d'Ubuntu&lt;/span&gt;. Certaines d'e…</title>
    <updated>2026-10-03T04:03:49.941768+00:00</updated>
    <content>certfr-2023-avi-0726</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2023-avi-0726"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-196701</id>
    <title>EUVD-2026-196701</title>
    <updated>2026-10-03T04:03:49.941784+00:00</updated>
    <content>EUVD-2026-196701</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-196701"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-28737</id>
    <title>fkie_cve-2022-28737</title>
    <updated>2026-10-03T04:03:49.941796+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>There's a possible overflow in handle_image() when shim tries to load and execute crafted EFI executables; The handle_image() function takes into account the SizeOfRawData field from each section to be loaded. An attacker can leverage this to perform out-of-bound writes into memory. Arbitrary code execution is not discarded in such scenario.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-28737"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-hmxr-46w2-jjwh</id>
    <title>GHSA-hmxr-46w2-jjwh</title>
    <updated>2026-10-03T04:03:49.941819+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>There's a possible overflow in handle_image() when shim tries to load and execute crafted EFI executables; The handle_image() function takes into account the SizeOfRawData field from each section to be loaded. An attacker can leverage this to perform out-of-bound writes into memory. Arbitrary code execution is not discarded in such scenario.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-hmxr-46w2-jjwh"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-28737</id>
    <title>gsd-2022-28737</title>
    <updated>2026-10-03T04:03:49.941835+00:00</updated>
    <content>gsd-2022-28737</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-28737"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-24-046-11</id>
    <title>ICSA-24-046-11 — Siemens SCALANCE XCM-/XRM-300</title>
    <updated>2026-10-03T04:03:49.941845+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>A carefully crafted If: request header can cause a memory read, or write of a single zero byte, in a pool (heap) memory location beyond the header value sent. This could cause the process to crash.</p>
<p>This issue affects Apache HTTP Server 2.4.54 and earlier. A flaw was found in python. In algorithms with quadratic time complexity using non-binary bases, when using int("text"), a system could take 50ms to parse an int string with 100,000 digits and 5s for 1,000,000 digits (float, decimal, int.from_bytes(), and int() for binary bases 2, 4, 8, 16, and 32 are not affected). The highest threat from this vulnerability is to system availability. A flaw was found in libdnf's signature verification functionality in versions before 0.60.1. This flaw allows an attacker to achieve code execution if they can alter the header information of an RPM package and then trick a user or system into installing it. The highest risk of this vulnerability is to confidentiality, integrity, as well as system availability. An out-of-bounds memory access flaw was found in the ATI VGA device emulation of QEMU. This flaw occurs in the ati_2d_blt() routine while handling MMIO write operations when the guest provides invalid values for the destination display parameters. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service. A vulnerability was found in the fs/inode.c:inode_init_owner() function logic of the LInux kernel that allows local users to create…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-24-046-11"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2022-28737</id>
    <title>msrc_CVE-2022-28737 — There's a possible overflow in handle_image() when shim tries to load and execute crafted EFI executables</title>
    <updated>2026-10-03T04:03:49.942271+00:00</updated>
    <content>msrc_CVE-2022-28737</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2022-28737"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2022-1799</id>
    <title>OESA-2022-1799 — shim security update</title>
    <updated>2026-10-03T04:03:49.942290+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: shim, openEuler:20.03-LTS-SP3: shim, openEuler:22.03-LTS: shim</p>
<p>Initial UEFI bootloader that handles chaining to a trusted full bootloader under secure boot environments.

Security Fix(es):

No description is available for this CVE.(CVE-2022-28737)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2022-1799"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2022:5095</id>
    <title>RHSA-2022:5095 — Red Hat Security Advisory: grub2, mokutil, shim, and shim-unsigned-x64 security update</title>
    <updated>2026-10-03T04:03:49.942315+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>grub2: Crafted PNG grayscale images may lead to out-of-bounds write in heap grub2: Crafted PNG image may lead to out-of-bound write during huffman table handling grub2: Crafted JPEG image can lead to buffer underflow write in the heap grub2: Integer underflow in grub_net_recv_ip4_packets grub2: Out-of-bound write when handling split HTTP headers grub2: shim_lock verifier allows non-kernel files to be loaded grub2: use-after-free in grub_cmd_chainloader() shim: Buffer overflow when loading crafted EFI images</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2022:5095"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2023:1863-1</id>
    <title>SUSE-SU-2023:1863-1 — Security update for shim</title>
    <updated>2026-10-03T04:03:49.942345+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for shim</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2023:1863-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-28737</id>
    <title>UBUNTU-CVE-2022-28737</title>
    <updated>2026-10-03T04:03:49.942360+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: shim, Ubuntu:16.04:LTS: shim, Ubuntu:18.04:LTS: shim, Ubuntu:20.04:LTS: shim, Ubuntu:22.04:LTS: shim</p>
<p>There's a possible overflow in handle_image() when shim tries to load and execute crafted EFI executables; The handle_image() function takes into account the SizeOfRawData field from each section to be loaded. An attacker can leverage this to perform out-of-bound writes into memory. Arbitrary code execution is not discarded in such scenario.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-28737"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0181</id>
    <title>WID-SEC-W-2022-0181 — Grub2: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff</title>
    <updated>2026-10-03T04:03:49.942384+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Oracle Linux ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0181"/>
  </entry>
</feed>
