<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T14:54:38.632594+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-01029</id>
    <title>bdu:2024-01029</title>
    <updated>2026-10-02T14:54:38.656004+00:00</updated>
    <content>bdu:2024-01029</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-01029"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2024-23652</id>
    <title>BELL-CVE-2024-23652</title>
    <updated>2026-10-02T14:54:38.656047+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: podman, Alpaquita:stream: docker, Alpaquita:stream: podman</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2024-23652"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0841</id>
    <title>certfr-2024-avi-0841 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-02T14:54:38.656077+00:00</updated>
    <content>certfr-2024-avi-0841</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0841"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2025-vo24808</id>
    <title>CLEANSTART-2025-VO24808 — BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner</title>
    <updated>2026-10-02T14:54:38.656094+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: buildkit, CleanStart: buildkitd</p>
<p>CVE-2024-23652 affects multiple packages. BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2025-vo24808"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-244986</id>
    <title>EUVD-2026-244986</title>
    <updated>2026-10-02T14:54:38.656117+00:00</updated>
    <content>EUVD-2026-244986</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-244986"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-23652</id>
    <title>fkie_cve-2024-23652</title>
    <updated>2026-10-02T14:54:38.656129+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. A malicious BuildKit frontend or Dockerfile using RUN --mount could trick the feature that removes empty files created for the mountpoints into removing a file outside the container, from the host system. The issue has been fixed in v0.12.5. Workarounds include avoiding using BuildKit frontends from an untrusted source or building an untrusted Dockerfile containing RUN --mount feature.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-23652"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-4v98-7qmw-rqr8</id>
    <title>GHSA-4v98-7qmw-rqr8 — BuildKit vulnerable to possible host system access from mount stub cleaner</title>
    <updated>2026-10-02T14:54:38.656151+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/moby/buildkit</p>
<p>### Impact
A malicious BuildKit frontend or Dockerfile using `RUN --mount` could trick the feature that removes empty files created for the mountpoints into removing a file outside the container, from the host system.</p>
<p>### Patches
The issue has been fixed in v0.12.5</p>
<p>### Workarounds
Avoid using BuildKit frontend from an untrusted source or building an untrusted Dockerfile containing `RUN --mount` feature.</p>
<p>### References</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-4v98-7qmw-rqr8"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2024-23652</id>
    <title>gsd-2024-23652</title>
    <updated>2026-10-02T14:54:38.656173+00:00</updated>
    <content>gsd-2024-23652</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2024-23652"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2024-23652</id>
    <title>msrc_CVE-2024-23652 — BuildKit possible host system access from mount stub cleaner</title>
    <updated>2026-10-02T14:54:38.656184+00:00</updated>
    <content>msrc_CVE-2024-23652</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2024-23652"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13651-1</id>
    <title>openSUSE-SU-2024:13651-1 — buildkit-0.12.5-1.1 on GA media</title>
    <updated>2026-10-02T14:54:38.656199+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>buildkit-0.12.5-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:13651-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2024:0587-1</id>
    <title>SUSE-SU-2024:0587-1 — Security update for docker</title>
    <updated>2026-10-02T14:54:38.656214+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for docker</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2024:0587-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-23652</id>
    <title>UBUNTU-CVE-2024-23652</title>
    <updated>2026-10-02T14:54:38.656228+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: docker.io, Ubuntu:Pro:18.04:LTS: docker.io, Ubuntu:Pro:20.04:LTS: docker.io, Ubuntu:Pro:20.04:LTS: docker.io-app, Ubuntu:22.04:LTS: docker.io-app, Ubuntu:Pro:22.04:LTS: docker.io, Ubuntu:24.04:LTS: docker.io-app, Ubuntu:Pro:24.04:LTS: docker.io</p>
<p>BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. A malicious BuildKit frontend or Dockerfile using RUN --mount could trick the feature that removes empty files created for the mountpoints into removing a file outside the container, from the host system. The issue has been fixed in v0.12.5. Workarounds include avoiding using BuildKit frontends from an untrusted source or building an untrusted Dockerfile containing RUN --mount feature.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-23652"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0272</id>
    <title>WID-SEC-W-2024-0272 — docker: Mehrere Schwachstellen</title>
    <updated>2026-10-02T14:54:38.656256+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter Angreifer kann mehrere Schwachstellen in Docker ausnutzen, um seine Privilegien zu erhöhen, einen Denial-of-Service-Zustand zu verursachen, vertrauliche Informationen offenzulegen, Sicherheitsmaßnahmen zu umgehen oder Dateien zu manipulieren.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0272"/>
  </entry>
</feed>
