<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T17:07:12.094558+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2023:5061</id>
    <title>ALSA-2023:5061 — Moderate: dmidecode security update</title>
    <updated>2026-10-03T17:07:12.375824+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: dmidecode</p>
<p>The dmidecode packages provide utilities for extracting Intel 64 and Intel Itanium hardware information from the system BIOS or Extensible Firmware Interface (EFI), depending on the SMBIOS/DMI standard. This information typically includes system manufacturer, model name, serial number, BIOS version, and asset tag, as well as other details, depending on the manufacturer.</p>
<p>Security Fix(es):</p>
<p>* dmidecode: dump-bin to overwrite a local file (CVE-2023-30630)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2023:5061"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-07470</id>
    <title>bdu:2023-07470</title>
    <updated>2026-10-03T17:07:12.375888+00:00</updated>
    <content>bdu:2023-07470</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-07470"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2023-30630</id>
    <title>BELL-CVE-2023-30630</title>
    <updated>2026-10-03T17:07:12.375906+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: dmidecode</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2023-30630"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0575</id>
    <title>certfr-2024-avi-0575 — De multiples vulnérabilités ont été découvertes dans les produits Juniper Networks. Certaines d'entre elles permettent…</title>
    <updated>2026-10-03T17:07:12.375923+00:00</updated>
    <content>certfr-2024-avi-0575</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0575"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-220474</id>
    <title>EUVD-2026-220474</title>
    <updated>2026-10-03T17:07:12.375939+00:00</updated>
    <content>EUVD-2026-220474</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-220474"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-30630</id>
    <title>fkie_cve-2023-30630</title>
    <updated>2026-10-03T17:07:12.375949+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Dmidecode before 3.5 allows -dump-bin to overwrite a local file. This has security relevance because, for example, execution of Dmidecode via Sudo is plausible. NOTE: Some third parties have indicated the fix in 3.5 does not adequately address the vulnerability. The argument is that the proposed patch prevents dmidecode from writing to an existing file. However, there are multiple attack vectors that would not require overwriting an existing file that would provide the same level of unauthorized privilege escalation (e.g. creating a new file in /etc/cron.hourly).</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-30630"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-9r2p-xmm5-5ppg</id>
    <title>GHSA-9r2p-xmm5-5ppg</title>
    <updated>2026-10-03T17:07:12.375972+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Dmidecode before 3.5 allows -dump-bin to overwrite a local file. This has security relevance because, for example, execution of Dmidecode via Sudo is plausible.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-9r2p-xmm5-5ppg"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-30630</id>
    <title>gsd-2023-30630</title>
    <updated>2026-10-03T17:07:12.375986+00:00</updated>
    <content>gsd-2023-30630</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-30630"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2023-30630</id>
    <title>msrc_CVE-2023-30630 — Dmidecode before 3.5 allows -dump-bin to overwrite a local file. This has security relevance because for example execut…</title>
    <updated>2026-10-03T17:07:12.375995+00:00</updated>
    <content>msrc_CVE-2023-30630</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2023-30630"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2023-1264</id>
    <title>OESA-2023-1264 — dmidecode security update</title>
    <updated>2026-10-03T17:07:12.376010+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: dmidecode, openEuler:20.03-LTS-SP3: dmidecode, openEuler:22.03-LTS: dmidecode, openEuler:22.03-LTS-SP1: dmidecode</p>
<p>Dmidecode reports information about your system's hardware as described in your system BIOS according to the SMBIOS/DMI standard (see a sample output). This information typically includes system manufacturer, model name, serial number, BIOS version, asset tag as well as a lot of other details of varying level of interest and reliability depending on the manufacturer. This will often include usage status for the CPU sockets, expansion slots (e.g. AGP, PCI, ISA) and memory module slots, and the list of I/O ports (e.g. serial, parallel, USB).DMI data can be used to enable or disable specific portions of kernel code depending on the specific hardware. Thus, one use of dmidecode is for kernel developers to detect system "signatures" and add them to the kernel source code when needed.

Security Fix(es):

Dmidecode before 3.5 allows -dump-bin to overwrite a local file. This has security relevance because, for example, execution of Dmidecode via Sudo is plausible.(CVE-2023-30630)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2023-1264"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2023:5061</id>
    <title>RHSA-2023:5061 — Red Hat Security Advisory: dmidecode security update</title>
    <updated>2026-10-03T17:07:12.376043+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>dmidecode: dump-bin to overwrite a local file</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2023:5061"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2023:2044-1</id>
    <title>SUSE-SU-2023:2044-1 — Security update for dmidecode</title>
    <updated>2026-10-03T17:07:12.376059+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for dmidecode</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2023:2044-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-30630</id>
    <title>UBUNTU-CVE-2023-30630</title>
    <updated>2026-10-03T17:07:12.376073+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: dmidecode, Ubuntu:16.04:LTS: dmidecode, Ubuntu:18.04:LTS: dmidecode, Ubuntu:20.04:LTS: dmidecode, Ubuntu:20.04:LTS: cpu-x, Ubuntu:22.04:LTS: cpu-x, Ubuntu:22.04:LTS: dmidecode, Ubuntu:24.04:LTS: cpu-x, Ubuntu:25.10: cpu-x, Ubuntu:26.04:LTS: cpu-x</p>
<p>Dmidecode before 3.5 allows -dump-bin to overwrite a local file. This has security relevance because, for example, execution of Dmidecode via Sudo is plausible. NOTE: Some third parties have indicated the fix in 3.5 does not adequately address the vulnerability. The argument is that the proposed patch prevents dmidecode from writing to an existing file. However, there are multiple attack vectors that would not require overwriting an existing file that would provide the same level of unauthorized privilege escalation (e.g. creating a new file in /etc/cron.hourly).</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-30630"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2320</id>
    <title>WID-SEC-W-2023-2320 — Red Hat Enterprise Linux(dmidecode): Schwachstelle ermöglicht Codeausführung</title>
    <updated>2026-10-03T17:07:12.376106+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um beliebigen Programmcode auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2320"/>
  </entry>
</feed>
