<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T17:32:32.511878+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2022:6463</id>
    <title>ALSA-2022:6463 — Moderate: gnupg2 security update</title>
    <updated>2026-10-02T17:32:32.928191+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: gnupg2, AlmaLinux:8: gnupg2-smime</p>
<p>The GNU Privacy Guard (GnuPG or GPG) is a tool for encrypting data and creating digital signatures, compliant with OpenPGP and S/MIME standards.</p>
<p>Security Fix(es):</p>
<p>* gpg: Signature spoofing via status line injection (CVE-2022-34903)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2022:6463"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-03850</id>
    <title>bdu:2023-03850</title>
    <updated>2026-10-02T17:32:32.928258+00:00</updated>
    <content>bdu:2023-03850</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-03850"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2022-34903</id>
    <title>Withdrawn: BELL-CVE-2022-34903 — CVE-2022-34903 does not affect BellSoft software</title>
    <updated>2026-10-02T17:32:32.928276+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2022-34903"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2022-avi-1069</id>
    <title>certfr-2022-avi-1069 — De multiples vulnérabilités ont été découvertes dans les produits IBM.
Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-02T17:32:32.928292+00:00</updated>
    <content>certfr-2022-avi-1069</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2022-avi-1069"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ks26224</id>
    <title>Withdrawn: CLEANSTART-2026-KS26224 — Security fixes in gnupg 2.2.35-r4</title>
    <updated>2026-10-02T17:32:32.928306+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: gnupg</p>
<p>Package gnupg version 2.2.35-r4 fixes 1 vulnerabilities: CVE-2022-34903</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ks26224"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-18011</id>
    <title>EUVD-2026-18011</title>
    <updated>2026-10-02T17:32:32.928327+00:00</updated>
    <content>EUVD-2026-18011</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-18011"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-34903</id>
    <title>fkie_cve-2022-34903</title>
    <updated>2026-10-02T17:32:32.928338+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>GnuPG through 2.3.6, in unusual situations where an attacker possesses any secret-key information from a victim's keyring and other constraints (e.g., use of GPGME) are met, allows signature forgery via injection into the status line.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-34903"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-356p-pg27-x2cf</id>
    <title>GHSA-356p-pg27-x2cf</title>
    <updated>2026-10-02T17:32:32.928360+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>GnuPG through 2.3.6, in unusual situations where an attacker possesses any secret-key information from a victim's keyring and other constraints (e.g., use of GPGME) are met, allows signature forgery via injection into the status line.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-356p-pg27-x2cf"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-34903</id>
    <title>gsd-2022-34903</title>
    <updated>2026-10-02T17:32:32.928375+00:00</updated>
    <content>gsd-2022-34903</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-34903"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-24-046-11</id>
    <title>ICSA-24-046-11 — Siemens SCALANCE XCM-/XRM-300</title>
    <updated>2026-10-02T17:32:32.928386+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>A carefully crafted If: request header can cause a memory read, or write of a single zero byte, in a pool (heap) memory location beyond the header value sent. This could cause the process to crash.</p>
<p>This issue affects Apache HTTP Server 2.4.54 and earlier. A flaw was found in python. In algorithms with quadratic time complexity using non-binary bases, when using int("text"), a system could take 50ms to parse an int string with 100,000 digits and 5s for 1,000,000 digits (float, decimal, int.from_bytes(), and int() for binary bases 2, 4, 8, 16, and 32 are not affected). The highest threat from this vulnerability is to system availability. A flaw was found in libdnf's signature verification functionality in versions before 0.60.1. This flaw allows an attacker to achieve code execution if they can alter the header information of an RPM package and then trick a user or system into installing it. The highest risk of this vulnerability is to confidentiality, integrity, as well as system availability. An out-of-bounds memory access flaw was found in the ATI VGA device emulation of QEMU. This flaw occurs in the ati_2d_blt() routine while handling MMIO write operations when the guest provides invalid values for the destination display parameters. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service. A vulnerability was found in the fs/inode.c:inode_init_owner() function logic of the LInux kernel that allows local users to create…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-24-046-11"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2022-34903</id>
    <title>msrc_CVE-2022-34903 — GnuPG through 2.3.6 in unusual situations where an attacker possesses any secret-key information from a victim's keyrin…</title>
    <updated>2026-10-02T17:32:32.928821+00:00</updated>
    <content>msrc_CVE-2022-34903</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2022-34903"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2022-1847</id>
    <title>OESA-2022-1847 — gnupg2 security update</title>
    <updated>2026-10-02T17:32:32.928840+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: gnupg2, openEuler:20.03-LTS-SP3: gnupg2, openEuler:22.03-LTS: gnupg2</p>
<p>GnuPG is a complete and free implementation of the OpenPGP standard as defined by RFC4880 (also known as PGP).  GnuPG enables encryption and signing of data and communication, and features a versatile key management system as well as access modules for public key directories.

Security Fix(es):

GnuPG through 2.3.6, in unusual situations where an attacker possesses any secret-key information from a victim&amp;apos;s keyring and other constraints (e.g., use of GPGME) are met, allows signature forgery via injection into the status line.(CVE-2022-34903)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2022-1847"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2022:2546-1</id>
    <title>openSUSE-SU-2022:2546-1 — Security update for gpg2</title>
    <updated>2026-10-02T17:32:32.928868+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for gpg2</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2022:2546-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ssa-202008</id>
    <title>SSA-202008 — SSA-202008: Multiple Vulnerabilities in Ruggedcom Rox Before V2.17.0</title>
    <updated>2026-10-02T17:32:32.928884+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An issue was discovered in shadow 4.5. newgidmap (in shadow-utils) is setuid and allows an unprivileged user to be placed in a user namespace where setgroups(2) is permitted. This allows an attacker to remove themselves from a supplementary group, which may allow access to certain filesystem paths if the administrator has used "group blacklisting" (e.g., chmod g-rwx) to restrict access to paths. This flaw effectively reverts a security feature in the kernel (in particular, the /proc/self/setgroups knob) to prevent this sort of privilege escalation. GnuPG 2.2.4 and 2.2.5 does not enforce a configuration in which key certification requires an offline master Certify key, which results in apparently valid certifications that occurred only with access to a signing subkey. remember_Ktype in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30, allows attackers to trigger excessive memory consumption (aka OOM). This can occur during execution of cxxfilt. binutils version 2.32 and earlier contains a Integer Overflow vulnerability in objdump, bfd_get_dynamic_reloc_upper_bound,bfd_canonicalize_dynamic_reloc that can result in Integer overflow trigger heap overflow. Successful exploitation allows execution of arbitrary code.. This attack appear to be exploitable via Local. This vulnerability appears to have been fixed in after commit 3a551c7a1b80fca579461774860574eabfd7f18f. libseccomp before 2.4.0 did not correctly generate 64-bit syscall argument comparisons using the ar…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ssa-202008"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2022:2529-1</id>
    <title>SUSE-SU-2022:2529-1 — Security update for gpg2</title>
    <updated>2026-10-02T17:32:32.929160+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for gpg2</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2022:2529-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-34903</id>
    <title>UBUNTU-CVE-2022-34903</title>
    <updated>2026-10-02T17:32:32.929177+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: gnupg, Ubuntu:Pro:16.04:LTS: gnupg, Ubuntu:Pro:16.04:LTS: gnupg2, Ubuntu:18.04:LTS: gnupg2, Ubuntu:20.04:LTS: gnupg2, Ubuntu:22.04:LTS: gnupg2</p>
<p>GnuPG through 2.3.6, in unusual situations where an attacker possesses any secret-key information from a victim's keyring and other constraints (e.g., use of GPGME) are met, allows signature forgery via injection into the status line.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-34903"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0511</id>
    <title>WID-SEC-W-2022-0511 — GnuPGP: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen</title>
    <updated>2026-10-02T17:32:32.929203+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in GnuPGP ausnutzen, um Sicherheitsvorkehrungen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0511"/>
  </entry>
</feed>
