<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T07:01:08.862710+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2024:1139</id>
    <title>ALSA-2024:1139 — Low: keylime security update</title>
    <updated>2026-10-03T07:01:08.962938+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: keylime, AlmaLinux:9: keylime-base, AlmaLinux:9: keylime-registrar, AlmaLinux:9: keylime-selinux, AlmaLinux:9: keylime-tenant, AlmaLinux:9: keylime-verifier, AlmaLinux:9: python3-keylime</p>
<p>Keylime is a TPM based highly scalable remote boot attestation and runtime integrity measurement solution.</p>
<p>Security Fix(es):</p>
<p>* keylime: Attestation failure when the quote's signature does not validate (CVE-2023-3674)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2024:1139"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-261608</id>
    <title>EUVD-2026-261608</title>
    <updated>2026-10-03T07:01:08.963005+00:00</updated>
    <content>EUVD-2026-261608</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-261608"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-3674</id>
    <title>fkie_cve-2023-3674</title>
    <updated>2026-10-03T07:01:08.963022+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in the keylime attestation verifier, which fails to flag a device's submitted TPM quote as faulty when the quote's signature does not validate for some reason. Instead, it will only emit an error in the log without flagging the device as untrusted.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-3674"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-g4wg-cfpf-9689</id>
    <title>GHSA-g4wg-cfpf-9689 — keylime fails to flag device as untrusted when signature does not validate</title>
    <updated>2026-10-03T07:01:08.963046+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: keylime</p>
<p>A flaw was found in the keylime attestation verifier, which fails to flag a device's submitted TPM quote as faulty when the quote's signature does not validate for some reason. Instead, it will only emit an error in the log without flagging the device as untrusted.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-g4wg-cfpf-9689"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-3674</id>
    <title>gsd-2023-3674</title>
    <updated>2026-10-03T07:01:08.963068+00:00</updated>
    <content>gsd-2023-3674</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-3674"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:14051-1</id>
    <title>openSUSE-SU-2024:14051-1 — keylime-config-7.11.0-1.1 on GA media</title>
    <updated>2026-10-03T07:01:08.963080+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>keylime-config-7.11.0-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:14051-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2023-128</id>
    <title>PYSEC-2023-128</title>
    <updated>2026-10-03T07:01:08.963098+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: keylime</p>
<p>A flaw was found in the keylime attestation verifier, which fails to flag a device's submitted TPM quote as faulty when the quote's signature does not validate for some reason. Instead, it will only emit an error in the log without flagging the device as untrusted.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2023-128"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0558</id>
    <title>WID-SEC-W-2024-0558 — Red Hat Enterprise Linux: Mehrere Schwachstellen</title>
    <updated>2026-10-03T07:01:08.963116+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um Dateien zu manipulieren oder um vertrauliche Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0558"/>
  </entry>
</feed>
