<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T11:59:00.490103+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-04481</id>
    <title>bdu:2024-04481</title>
    <updated>2026-10-03T11:59:00.736461+00:00</updated>
    <content>bdu:2024-04481</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-04481"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2024-29040</id>
    <title>BELL-CVE-2024-29040</title>
    <updated>2026-10-03T11:59:00.736495+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: tpm2-tss, Alpaquita:stream: tpm2-tss</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2024-29040"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0585</id>
    <title>certfr-2025-avi-0585 — De multiples vulnérabilités ont été découvertes dans VMware Tanzu. Certaines d'entre elles permettent à un attaquant de…</title>
    <updated>2026-10-03T11:59:00.736524+00:00</updated>
    <content>certfr-2025-avi-0585</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0585"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-259040</id>
    <title>EUVD-2026-259040</title>
    <updated>2026-10-03T11:59:00.736542+00:00</updated>
    <content>EUVD-2026-259040</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-259040"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-29040</id>
    <title>fkie_cve-2024-29040</title>
    <updated>2026-10-03T11:59:00.736554+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>This repository hosts source code implementing the Trusted Computing Group's (TCG) TPM2 Software Stack (TSS). The JSON Quote Info returned by Fapi_Quote has to be deserialized by Fapi_VerifyQuote to the TPM Structure `TPMS_ATTEST`. For the field `TPM2_GENERATED magic` of this structure any number can be used in the JSON structure. The verifier can receive a state which does not represent the actual, possibly malicious state of the device under test. The malicious device might get access to data it shouldn't, or can use services it shouldn't be able to. This 
issue has been patched in version 4.1.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-29040"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2024-29040</id>
    <title>gsd-2024-29040</title>
    <updated>2026-10-03T11:59:00.736582+00:00</updated>
    <content>gsd-2024-29040</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2024-29040"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2024-29040</id>
    <title>msrc_CVE-2024-29040 — Fapi Verify Quote: Does not detect if quote was not generated by TPM</title>
    <updated>2026-10-03T11:59:00.736593+00:00</updated>
    <content>msrc_CVE-2024-29040</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2024-29040"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2024-1613</id>
    <title>OESA-2024-1613 — tpm2-tss security update</title>
    <updated>2026-10-03T11:59:00.736610+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: tpm2-tss, openEuler:22.03-LTS: tpm2-tss, openEuler:22.03-LTS-SP2: tpm2-tss, openEuler:22.03-LTS-SP3: tpm2-tss</p>
<p>tpm2-tss is a software stack supporting Trusted Platform Module(TPM) 2.0 system APIs which provides TPM2.0 specified APIs for applications to access TPM module through kernel TPM drivers.

Security Fix(es):

A flaw was found in the tpm2-tss package, where it was not checked to see if the magic number in the attest is equal to the TPM2_GENERATED_VALUE. This flaw allows an attacker to generate arbitrary quote data, which may not be detected by Fapi_VerifyQuote.(CVE-2024-29040)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2024-1613"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13933-1</id>
    <title>openSUSE-SU-2024:13933-1 — libtss2-esys0-32bit-4.1.0-1.1 on GA media</title>
    <updated>2026-10-03T11:59:00.736638+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libtss2-esys0-32bit-4.1.0-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:13933-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2024:1635-1</id>
    <title>SUSE-SU-2024:1635-1 — Security update for tpm2-0-tss</title>
    <updated>2026-10-03T11:59:00.736656+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for tpm2-0-tss</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2024:1635-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-29040</id>
    <title>UBUNTU-CVE-2024-29040</title>
    <updated>2026-10-03T11:59:00.736671+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:22.04:LTS: tpm2-tss, Ubuntu:24.04:LTS: tpm2-tss</p>
<p>This repository hosts source code implementing the Trusted Computing Group's (TCG) TPM2 Software Stack (TSS). The JSON Quote Info returned by Fapi_Quote has to be deserialized by Fapi_VerifyQuote to the TPM Structure `TPMS_ATTEST`. For the field `TPM2_GENERATED magic` of this structure any number can be used in the JSON structure. The verifier can receive a state which does not represent the actual, possibly malicious state of the device under test. The malicious device might get access to data it shouldn't, or can use services it shouldn't be able to. This issue has been patched in version 4.1.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-29040"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0778</id>
    <title>WID-SEC-W-2026-0778 — Dell Secure Connect Gateway Policy Manager: Mehrere Schwachstellen</title>
    <updated>2026-10-03T11:59:00.736706+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Dell Secure Connect Gateway Policy Manager ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0778"/>
  </entry>
</feed>
