<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T16:26:10.800802+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-01031</id>
    <title>bdu:2024-01031</title>
    <updated>2026-10-03T16:26:11.060705+00:00</updated>
    <content>bdu:2024-01031</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-01031"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2024-23651</id>
    <title>BELL-CVE-2024-23651</title>
    <updated>2026-10-03T16:26:11.060789+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: podman, Alpaquita:stream: docker, Alpaquita:stream: podman</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2024-23651"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0841</id>
    <title>certfr-2024-avi-0841 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-03T16:26:11.060821+00:00</updated>
    <content>certfr-2024-avi-0841</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0841"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2025-mu54155</id>
    <title>CLEANSTART-2025-MU54155 — BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner</title>
    <updated>2026-10-03T16:26:11.060838+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: buildkit, CleanStart: buildkitd</p>
<p>CVE-2024-23651 affects multiple packages. BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2025-mu54155"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-241769</id>
    <title>EUVD-2026-241769</title>
    <updated>2026-10-03T16:26:11.060863+00:00</updated>
    <content>EUVD-2026-241769</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-241769"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-23651</id>
    <title>fkie_cve-2024-23651</title>
    <updated>2026-10-03T16:26:11.060875+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Two malicious build steps running in parallel sharing the same cache mounts with subpaths could cause a race condition that can lead to files from the host system being accessible to the build container. The issue has been fixed in v0.12.5. Workarounds include, avoiding using BuildKit frontend from an untrusted source or building an untrusted Dockerfile containing cache mounts with --mount=type=cache,source=... options.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-23651"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-m3r6-h7wv-7xxv</id>
    <title>GHSA-m3r6-h7wv-7xxv — BuildKit vulnerable to possible race condition with accessing subpaths from cache mounts</title>
    <updated>2026-10-03T16:26:11.060898+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/moby/buildkit</p>
<p>### Impact
Two malicious build steps running in parallel sharing the same cache mounts with subpaths could cause a race condition that can lead to files from the host system being accessible to the build container.</p>
<p>### Patches
The issue has been fixed in v0.12.5</p>
<p>### Workarounds
Avoid using BuildKit frontend from an untrusted source or building an untrusted Dockerfile containing cache mounts with `--mount=type=cache,source=...` options.</p>
<p>### References
https://www.openwall.com/lists/oss-security/2019/05/28/1</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-m3r6-h7wv-7xxv"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2024-23651</id>
    <title>gsd-2024-23651</title>
    <updated>2026-10-03T16:26:11.060925+00:00</updated>
    <content>gsd-2024-23651</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2024-23651"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2024-23651</id>
    <title>msrc_CVE-2024-23651 — BuildKit possible race condition with accessing subpaths from cache mounts</title>
    <updated>2026-10-03T16:26:11.060936+00:00</updated>
    <content>msrc_CVE-2024-23651</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2024-23651"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13651-1</id>
    <title>openSUSE-SU-2024:13651-1 — buildkit-0.12.5-1.1 on GA media</title>
    <updated>2026-10-03T16:26:11.060952+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>buildkit-0.12.5-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:13651-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2024:0587-1</id>
    <title>SUSE-SU-2024:0587-1 — Security update for docker</title>
    <updated>2026-10-03T16:26:11.060968+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for docker</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2024:0587-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-23651</id>
    <title>UBUNTU-CVE-2024-23651</title>
    <updated>2026-10-03T16:26:11.060984+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:18.04:LTS: docker.io, Ubuntu:Pro:20.04:LTS: docker.io, Ubuntu:Pro:20.04:LTS: docker.io-app, Ubuntu:22.04:LTS: docker.io-app, Ubuntu:Pro:22.04:LTS: docker.io, Ubuntu:24.04:LTS: docker.io-app, Ubuntu:Pro:24.04:LTS: docker.io</p>
<p>BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Two malicious build steps running in parallel sharing the same cache mounts with subpaths could cause a race condition that can lead to files from the host system being accessible to the build container. The issue has been fixed in v0.12.5. Workarounds include, avoiding using BuildKit frontend from an untrusted source or building an untrusted Dockerfile containing cache mounts with --mount=type=cache,source=... options.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-23651"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0272</id>
    <title>WID-SEC-W-2024-0272 — docker: Mehrere Schwachstellen</title>
    <updated>2026-10-03T16:26:11.061014+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter Angreifer kann mehrere Schwachstellen in Docker ausnutzen, um seine Privilegien zu erhöhen, einen Denial-of-Service-Zustand zu verursachen, vertrauliche Informationen offenzulegen, Sicherheitsmaßnahmen zu umgehen oder Dateien zu manipulieren.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0272"/>
  </entry>
</feed>
