<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T20:04:29.010329+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2022:7469</id>
    <title>ALSA-2022:7469 — Moderate: container-tools:4.0 security and bug fix update</title>
    <updated>2026-10-02T20:04:29.055439+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: aardvark-dns, AlmaLinux:8: buildah, AlmaLinux:8: buildah-tests, AlmaLinux:8: cockpit-podman, AlmaLinux:8: conmon, AlmaLinux:8: container-selinux, AlmaLinux:8: containernetworking-plugins, AlmaLinux:8: containers-common, AlmaLinux:8: crit, AlmaLinux:8: criu and 24 more</p>
<p>The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.</p>
<p>Security Fix(es):</p>
<p>* cri-o: memory exhaustion on the node when access to the kube api (CVE-2022-1708)
* golang: crash in a golang.org/x/crypto/ssh server (CVE-2022-27191)
* runc: incorrect handling of inheritable capabilities (CVE-2022-29162)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p>
<p>Additional Changes:</p>
<p>For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2022:7469"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2022-05793</id>
    <title>bdu:2022-05793</title>
    <updated>2026-10-02T20:04:29.055596+00:00</updated>
    <content>bdu:2022-05793</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2022-05793"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2022-29162</id>
    <title>Withdrawn: BELL-CVE-2022-29162 — CVE-2022-29162 does not affect BellSoft software</title>
    <updated>2026-10-02T20:04:29.055625+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2022-29162"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0119</id>
    <title>certfr-2024-avi-0119 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;les produits Siemens&lt;/span&gt;. Certaines d'entr…</title>
    <updated>2026-10-02T20:04:29.055649+00:00</updated>
    <content>certfr-2024-avi-0119</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0119"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-cq48087</id>
    <title>CLEANSTART-2026-CQ48087 — Security fix for CVE-2022-29162 applied in: runc 1.1.2-r0</title>
    <updated>2026-10-02T20:04:29.055673+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: runc</p>
<p>Security vulnerability affects the runc package. This issue is resolved in later releases. See references for vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-cq48087"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-234129</id>
    <title>EUVD-2026-234129</title>
    <updated>2026-10-02T20:04:29.055704+00:00</updated>
    <content>EUVD-2026-234129</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-234129"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-29162</id>
    <title>fkie_cve-2022-29162</title>
    <updated>2026-10-02T20:04:29.055722+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. A bug was found in runc prior to version 1.1.2 where `runc exec --cap` created processes with non-empty inheritable Linux process capabilities, creating an atypical Linux environment and enabling programs with inheritable file capabilities to elevate those capabilities to the permitted set during execve(2). This bug did not affect the container security sandbox as the inheritable set never contained more capabilities than were included in the container's bounding set. This bug has been fixed in runc 1.1.2. This fix changes `runc exec --cap` behavior such that the additional capabilities granted to the process being executed (as specified via `--cap` arguments) do not include inheritable capabilities. In addition, `runc spec` is changed to not set any inheritable capabilities in the created example OCI spec (`config.json`) file.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-29162"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-f3fp-gc8g-vw66</id>
    <title>GHSA-f3fp-gc8g-vw66 — Default inheritable capabilities for linux container should be empty</title>
    <updated>2026-10-02T20:04:29.055762+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/opencontainers/runc</p>
<p>### Impact</p>
<p>A bug was found in runc where `runc exec --cap` executed processes with non-empty inheritable Linux process capabilities, creating an atypical Linux environment and enabling programs with inheritable file capabilities to elevate those capabilities to the permitted set during execve(2).</p>
<p>This bug did not affect the container security sandbox as the inheritable set never contained more capabilities than were included in the container's bounding set.</p>
<p>### Patches
This bug has been fixed in runc 1.1.2. Users should update to this version as soon as possible.</p>
<p>This fix changes `runc exec --cap` behavior such that the additional capabilities granted to the process being executed (as specified via `--cap` arguments) do not include inheritable capabilities.</p>
<p>In addition, `runc spec` is changed to not set any inheritable capabilities in the created example OCI spec (`config.json`) file.</p>
<p>### Credits
The opencontainers project would like to thank [Andrew G. Morgan](https://github.com/AndrewGMorgan) for responsibly disclosing this issue in accordance with the [opencontainers org security policy](https://github.com/opencontainers/.github/blob/master/SECURITY.md).</p>
<p>### For more information
If you have any questions or comments about this advisory:</p>
<p>* [Open an issue](https://github.com/opencontainers/runc/issues/new)
* Email us at [security@opencontainers.org](mailto:security@opencontainers.org) if you think you’ve found a security bug</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-f3fp-gc8g-vw66"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-29162</id>
    <title>gsd-2022-29162</title>
    <updated>2026-10-02T20:04:29.055822+00:00</updated>
    <content>gsd-2022-29162</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-29162"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-24-046-11</id>
    <title>ICSA-24-046-11 — Siemens SCALANCE XCM-/XRM-300</title>
    <updated>2026-10-02T20:04:29.055840+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>A carefully crafted If: request header can cause a memory read, or write of a single zero byte, in a pool (heap) memory location beyond the header value sent. This could cause the process to crash.</p>
<p>This issue affects Apache HTTP Server 2.4.54 and earlier. A flaw was found in python. In algorithms with quadratic time complexity using non-binary bases, when using int("text"), a system could take 50ms to parse an int string with 100,000 digits and 5s for 1,000,000 digits (float, decimal, int.from_bytes(), and int() for binary bases 2, 4, 8, 16, and 32 are not affected). The highest threat from this vulnerability is to system availability. A flaw was found in libdnf's signature verification functionality in versions before 0.60.1. This flaw allows an attacker to achieve code execution if they can alter the header information of an RPM package and then trick a user or system into installing it. The highest risk of this vulnerability is to confidentiality, integrity, as well as system availability. An out-of-bounds memory access flaw was found in the ATI VGA device emulation of QEMU. This flaw occurs in the ati_2d_blt() routine while handling MMIO write operations when the guest provides invalid values for the destination display parameters. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service. A vulnerability was found in the fs/inode.c:inode_init_owner() function logic of the LInux kernel that allows local users to create…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-24-046-11"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2022-29162</id>
    <title>msrc_CVE-2022-29162 — Incorrect Default Permissions in runc</title>
    <updated>2026-10-02T20:04:29.056482+00:00</updated>
    <content>msrc_CVE-2022-29162</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2022-29162"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2022-1704</id>
    <title>OESA-2022-1704 — runc security update</title>
    <updated>2026-10-02T20:04:29.056514+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: runc, openEuler:20.03-LTS-SP3: runc, openEuler:22.03-LTS: runc</p>
<p>runc is a CLI tool for spawning and running containers according to the OCI specification.

Security Fix(es):

runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. A bug was found in runc prior to version 1.1.2 where `runc exec --cap` created processes with non-empty inheritable Linux process capabilities, creating an atypical Linux environment and enabling programs with inheritable file capabilities to elevate those capabilities to the permitted set during execve(2). This bug did not affect the container security sandbox as the inheritable set never contained more capabilities than were included in the container&amp;apos;s bounding set. This bug has been fixed in runc 1.1.2. This fix changes `runc exec --cap` behavior such that the additional capabilities granted to the process being executed (as specified via `--cap` arguments) do not include inheritable capabilities. In addition, `runc spec` is changed to not set any inheritable capabilities in the created example OCI spec (`config.json`) file.(CVE-2022-29162)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2022-1704"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12074-1</id>
    <title>openSUSE-SU-2024:12074-1 — runc-1.1.2-1.1 on GA media</title>
    <updated>2026-10-02T20:04:29.056573+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>runc-1.1.2-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:12074-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2022:5068</id>
    <title>RHSA-2022:5068 — Red Hat Security Advisory: OpenShift Container Platform 4.11.0 packages and security update</title>
    <updated>2026-10-02T20:04:29.056601+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>golang.org/x/crypto: empty plaintext packet causes panic golang: net/http: improper sanitization of Transfer-Encoding header ignition: configs are accessible from unprivileged containers in VMs running on VMware products prometheus/client_golang: Denial of service using InstrumentHandlerCounter golang: math/big: uncontrolled memory consumption due to an unhandled overflow via Rat.SetString golang: cmd/go: misinterpretation of branch names can lead to incorrect access control golang: crypto/elliptic: IsOnCurve returns true for invalid field elements golang: encoding/pem: fix stack overflow in Decode golang: regexp: stack exhaustion via a deeply nested expression golang: crash in a golang.org/x/crypto/ssh server golang: crypto/elliptic: panic caused by oversized scalar runc: incorrect handling of inheritable capabilities</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2022:5068"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2022:2165-1</id>
    <title>SUSE-SU-2022:2165-1 — Security update for containerd</title>
    <updated>2026-10-02T20:04:29.056652+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for containerd</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2022:2165-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-29162</id>
    <title>UBUNTU-CVE-2022-29162</title>
    <updated>2026-10-02T20:04:29.056675+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: runc</p>
<p>runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. A bug was found in runc prior to version 1.1.2 where `runc exec --cap` created processes with non-empty inheritable Linux process capabilities, creating an atypical Linux environment and enabling programs with inheritable file capabilities to elevate those capabilities to the permitted set during execve(2). This bug did not affect the container security sandbox as the inheritable set never contained more capabilities than were included in the container's bounding set. This bug has been fixed in runc 1.1.2. This fix changes `runc exec --cap` behavior such that the additional capabilities granted to the process being executed (as specified via `--cap` arguments) do not include inheritable capabilities. In addition, `runc spec` is changed to not set any inheritable capabilities in the created example OCI spec (`config.json`) file.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-29162"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2052</id>
    <title>WID-SEC-W-2022-2052 — Mehrere Red Hat Enterprise Linux Pakete: Mehrere Schwachstellen</title>
    <updated>2026-10-02T20:04:29.056713+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um einen Denial of Service Angriff durchzuführen, Sicherheitsvorkehrungen zu umgehen oder sonstige Auswirkungen zu verursachen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2052"/>
  </entry>
</feed>
