<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T06:13:02.339049+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2023:5094</id>
    <title>ALSA-2023:5094 — Important: qemu-kvm security and bug fix update</title>
    <updated>2026-10-03T06:13:02.388361+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: qemu-guest-agent, AlmaLinux:9: qemu-img, AlmaLinux:9: qemu-kvm, AlmaLinux:9: qemu-kvm-audio-pa, AlmaLinux:9: qemu-kvm-block-curl, AlmaLinux:9: qemu-kvm-block-rbd, AlmaLinux:9: qemu-kvm-common, AlmaLinux:9: qemu-kvm-core, AlmaLinux:9: qemu-kvm-device-display-virtio-gpu, AlmaLinux:9: qemu-kvm-device-display-virtio-gpu-ccw and 9 more</p>
<p>Kernel-based Virtual Machine (KVM) is a full virtualization solution for Linux on a variety of architectures. The qemu-kvm packages provide the user-space component for running virtual machines that use KVM.</p>
<p>Security Fix(es):</p>
<p>* QEMU: VNC: improper I/O watch removal in TLS handshake can lead to remote unauthenticated denial of service (CVE-2023-3354)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p>
<p>Bug Fix(es):</p>
<p>* [qemu-kvm] rhel guest failed boot with multi disks on error Failed to start udev Wait for Complete Device Initialization (BZ#2211923)
* [almalinux9.2] hotplug/hotunplug mlx vdpa device to the occupied addr port, then qemu core dump occurs after shutdown guest (BZ#2227721)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2023:5094"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-05003</id>
    <title>bdu:2023-05003</title>
    <updated>2026-10-03T06:13:02.388466+00:00</updated>
    <content>bdu:2023-05003</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-05003"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2023-3354</id>
    <title>BELL-CVE-2023-3354</title>
    <updated>2026-10-03T06:13:02.388486+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: qemu, Alpaquita:stream: qemu</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2023-3354"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0619</id>
    <title>certfr-2024-avi-0619 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Certaines d'entre elles permettent à un attaq…</title>
    <updated>2026-10-03T06:13:02.388507+00:00</updated>
    <content>certfr-2024-avi-0619</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0619"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/essa-2023:0374</id>
    <title>ESSA-2023:0374 — security update for virt:rhel module</title>
    <updated>2026-10-03T06:13:02.388523+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>security update for virt:rhel module</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/essa-2023:0374"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-216524</id>
    <title>EUVD-2026-216524</title>
    <updated>2026-10-03T06:13:02.388542+00:00</updated>
    <content>EUVD-2026-216524</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-216524"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-3354</id>
    <title>fkie_cve-2023-3354</title>
    <updated>2026-10-03T06:13:02.388554+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in the QEMU built-in VNC server. When a client connects to the VNC server, QEMU checks whether the current number of connections crosses a certain threshold and if so, cleans up the previous connection. If the previous connection happens to be in the handshake phase and fails, QEMU cleans up the connection again, resulting in a NULL pointer dereference issue. This could allow a remote unauthenticated client to cause a denial of service.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-3354"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-vhf9-5f69-9hjm</id>
    <title>GHSA-vhf9-5f69-9hjm</title>
    <updated>2026-10-03T06:13:02.388577+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in the QEMU built-in VNC server. When a client connects to the VNC server, QEMU checks whether the current number of connections crosses a certain threshold and if so, cleans up the previous connection. If the previous connection happens to be in the handshake phase and fails, QEMU cleans up the connection again, resulting in a NULL pointer dereference issue. This could allow a remote unauthenticated client to cause a denial of service.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-vhf9-5f69-9hjm"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-3354</id>
    <title>gsd-2023-3354</title>
    <updated>2026-10-03T06:13:02.388592+00:00</updated>
    <content>gsd-2023-3354</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-3354"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2023-3354</id>
    <title>msrc_CVE-2023-3354 — Improper i/o watch removal in tls handshake can lead to remote unauthenticated denial of service</title>
    <updated>2026-10-03T06:13:02.388603+00:00</updated>
    <content>msrc_CVE-2023-3354</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2023-3354"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2023-1657</id>
    <title>OESA-2023-1657 — qemu security update</title>
    <updated>2026-10-03T06:13:02.388619+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: qemu, openEuler:20.03-LTS-SP3: qemu, openEuler:22.03-LTS-SP1: qemu, openEuler:22.03-LTS-SP2: qemu</p>
<p>QEMU is a FAST! processor emulator using dynamic translation to achieve good emulation speed.

Security Fix(es):

A flaw was found in the QEMU built-in VNC server. When a client connects to the VNC server, QEMU checks whether the current number of connections crosses a certain threshold and if so, cleans up the previous connection. If the previous connection happens to be in the handshake phase and fails, QEMU cleans up the connection again, resulting in a NULL pointer dereference issue. This could allow a remote unauthenticated client to cause a denial of service.(CVE-2023-3354)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2023-1657"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2023:5239</id>
    <title>RHSA-2023:5239 — Red Hat Security Advisory: virt:rhel and virt-devel:rhel security update</title>
    <updated>2026-10-03T06:13:02.388646+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>NTFS-3G: buffer overflow issue in NTFS-3G can cause code execution via crafted metadata in an NTFS image QEMU: VNC: improper I/O watch removal in TLS handshake can lead to remote unauthenticated denial of service</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2023:5239"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2024:0589-1</id>
    <title>SUSE-SU-2024:0589-1 — Security update for qemu</title>
    <updated>2026-10-03T06:13:02.388666+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for qemu</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2024:0589-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-3354</id>
    <title>UBUNTU-CVE-2023-3354</title>
    <updated>2026-10-03T06:13:02.388682+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:18.04:LTS: qemu, Ubuntu:20.04:LTS: qemu, Ubuntu:22.04:LTS: qemu</p>
<p>A flaw was found in the QEMU built-in VNC server. When a client connects to the VNC server, QEMU checks whether the current number of connections crosses a certain threshold and if so, cleans up the previous connection. If the previous connection happens to be in the handshake phase and fails, QEMU cleans up the connection again, resulting in a NULL pointer dereference issue. This could allow a remote unauthenticated client to cause a denial of service.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-3354"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1709</id>
    <title>WID-SEC-W-2023-1709 — QEMU: Schwachstelle ermöglicht Denial of Service</title>
    <updated>2026-10-03T06:13:02.388704+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in QEMU ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1709"/>
  </entry>
</feed>
