<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T12:00:20.236662+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-02430</id>
    <title>bdu:2024-02430</title>
    <updated>2026-10-03T12:00:20.244514+00:00</updated>
    <content>bdu:2024-02430</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-02430"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-12730</id>
    <title>EUVD-2026-12730</title>
    <updated>2026-10-03T12:00:20.244554+00:00</updated>
    <content>EUVD-2026-12730</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-12730"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-4318</id>
    <title>fkie_cve-2022-4318</title>
    <updated>2026-10-03T12:00:20.244569+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability was found in cri-o. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment variable.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-4318"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-cm9x-c3rh-7rc4</id>
    <title>GHSA-cm9x-c3rh-7rc4 — CRI-O vulnerable to /etc/passwd tampering resulting in Privilege Escalation</title>
    <updated>2026-10-03T12:00:20.244598+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/cri-o/cri-o</p>
<p>### Impact
It is possible to craft an environment variable with newlines to add entries to a container's /etc/passwd. It is possible to circumvent admission validation of username/UID by adding such an entry.</p>
<p>Note: because the pod author is in control of the container's /etc/passwd, this is not considered a new risk factor. However, this advisory is being opened for transparency and as a way of tracking fixes.</p>
<p>### Patches
1.26.0 will have the fix. More patches will be posted as they're available.</p>
<p>### Workarounds
Additional security controls like SELinux should prevent any damage a container is able to do with root on the host. Using SELinux is recommended because this class of attack is already possible by manually editing the container's /etc/passwd</p>
<p>### References</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-cm9x-c3rh-7rc4"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-4318</id>
    <title>gsd-2022-4318</title>
    <updated>2026-10-03T12:00:20.244630+00:00</updated>
    <content>gsd-2022-4318</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-4318"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2022-4318</id>
    <title>msrc_CVE-2022-4318 — Cri-o: /etc/passwd tampering privesc</title>
    <updated>2026-10-03T12:00:20.244642+00:00</updated>
    <content>msrc_CVE-2022-4318</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2022-4318"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2024-1406</id>
    <title>OESA-2024-1406 — cri-o security update</title>
    <updated>2026-10-03T12:00:20.244660+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP1: cri-o</p>
<p>Open Container Initiative-based implementation of Kubernetes Container Runtime Interface.

Security Fix(es):

A maliciously crafted HTTP/2 stream could cause excessive CPU consumption in the HPACK decoder, sufficient to cause a denial of service from a small number of small requests.(CVE-2022-41723)

A vulnerability was found in cri-o. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment variable.(CVE-2022-4318)

A malicious HTTP/2 client which rapidly creates requests and immediately resets them can cause excessive server resource consumption. While the total number of requests is bounded by the http2.Server.MaxConcurrentStreams setting, resetting an in-progress request allows the attacker to create a new request while the existing one is still executing. With the fix applied, HTTP/2 servers now bound the number of simultaneously executing handler goroutines to the stream concurrency limit (MaxConcurrentStreams). New requests arriving when at the limit (which can only happen after the client has reset an existing, in-flight request) will be queued until a handler exits. If the request queue grows too large, the server will terminate the connection. This issue is also fixed in golang.org/x/net/http2 for users manually configuring HTTP/2. The default stream concurrency limit is 250 streams (requests) per HTTP/2 connection. This value may be adjusted using the golang.org/x/net/http2 package; see the Server.MaxConc…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2024-1406"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2023:1033</id>
    <title>RHSA-2023:1033 — Red Hat Security Advisory: OpenShift Container Platform 4.12.6 packages and security update</title>
    <updated>2026-10-03T12:00:20.244704+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>cri-o: /etc/passwd tampering privesc</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2023:1033"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0600</id>
    <title>WID-SEC-W-2023-0600 — Red Hat OpenShift: Schwachstelle ermöglicht Manipulation von Dateien</title>
    <updated>2026-10-03T12:00:20.244721+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Red Hat OpenShift ausnutzen, um Dateien zu manipulieren.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0600"/>
  </entry>
</feed>
