<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T22:28:53.951136+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2024:8039</id>
    <title>ALSA-2024:8039 — Important: podman security update</title>
    <updated>2026-10-02T22:28:54.094903+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: podman, AlmaLinux:9: podman-docker, AlmaLinux:9: podman-plugins, AlmaLinux:9: podman-remote, AlmaLinux:9: podman-tests</p>
<p>The podman tool manages pods, container images, and containers. It is part of the libpod library, which is for applications that use container pods. Container pods is a concept in Kubernetes.</p>
<p>Security Fix(es):</p>
<p>* go/parser: golang: Calling any of the Parse functions containing deeply nested literals can cause a panic/stack exhaustion (CVE-2024-34155)
* encoding/gob: golang: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion (CVE-2024-34156)
* go/build/constraint: golang: Calling Parse on a "// +build" build tag line with deeply nested expressions can cause a panic due to stack exhaustion (CVE-2024-34158)
* Podman: Buildah: cri-o: FIPS Crypto-Policy Directory Mounting Issue in containers/common Go Library (CVE-2024-9341)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2024:8039"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-09461</id>
    <title>bdu:2024-09461</title>
    <updated>2026-10-02T22:28:54.095023+00:00</updated>
    <content>bdu:2024-09461</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-09461"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2024-9341</id>
    <title>BELL-CVE-2024-9341</title>
    <updated>2026-10-02T22:28:54.095049+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: buildah, Alpaquita:23: podman, Alpaquita:stream: buildah, Alpaquita:stream: containers-common, Alpaquita:stream: podman</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2024-9341"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2024-zt93221</id>
    <title>CLEANSTART-2024-ZT93221 — flaw was found in Go</title>
    <updated>2026-10-02T22:28:54.095077+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: buildah</p>
<p>Security vulnerability affects the buildah package. A flaw was found in Go.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2024-zt93221"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-351147</id>
    <title>EUVD-2026-351147</title>
    <updated>2026-10-02T22:28:54.095098+00:00</updated>
    <content>EUVD-2026-351147</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-351147"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-9341</id>
    <title>fkie_cve-2024-9341</title>
    <updated>2026-10-02T22:28:54.095110+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A flaw was found in Go. When FIPS mode is enabled on a system, container runtimes may incorrectly handle certain file paths due to improper validation in the containers/common Go library. This flaw allows an attacker to exploit symbolic links and trick the system into mounting sensitive host directories inside a container. This issue also allows attackers to access critical host files, bypassing the intended isolation between containers and the host system.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-9341"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-mc76-5925-c5p6</id>
    <title>GHSA-mc76-5925-c5p6 — Link Following in github.com/containers/common</title>
    <updated>2026-10-02T22:28:54.095149+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/containers/common</p>
<p>A flaw was found in Go. When FIPS mode is enabled on a system, container runtimes may incorrectly handle certain file paths due to improper validation in the containers/common Go library. This flaw allows an attacker to exploit symbolic links and trick the system into mounting sensitive host directories inside a container. This issue also allows attackers to access critical host files, bypassing the intended isolation between containers and the host system.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-mc76-5925-c5p6"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2024-9341</id>
    <title>msrc_CVE-2024-9341 — Podman: buildah: cri-o: fips crypto-policy directory mounting issue in containers/common go library</title>
    <updated>2026-10-02T22:28:54.095183+00:00</updated>
    <content>msrc_CVE-2024-9341</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2024-9341"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-1053</id>
    <title>OESA-2025-1053 — podman security update</title>
    <updated>2026-10-02T22:28:54.095204+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS: podman</p>
<p>Podman manages the entire container ecosystem which includes pods, containers, container images, and container volumes using the libpod library.

Security Fix(es):

Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream of RST_STREAM frames from the peer. Depending on how the peer queues the RST_STREAM frames, this can consume excess memory, CPU, or both.(CVE-2019-9514)

Uncontrolled recursion in the Parse functions in go/parser before Go 1.17.12 and Go 1.18.4 allow an attacker to cause a panic due to stack exhaustion via deeply nested types or declarations.(CVE-2022-1962)

Requests forwarded by ReverseProxy include the raw query parameters from the inbound request, including unparsable parameters rejected by net/http. This could permit query parameter smuggling when a Go proxy forwards a parameter with an unparsable value. After fix, ReverseProxy sanitizes the query parameters in the forwarded query when the outbound request&amp;apos;s Form field is set after the ReverseProxy. Director function returns, indicating that the proxy has parsed the query parameters. Proxies which do not parse query parameters continue to forward the original query parameters unchanged.(CVE-2022-2880)

A too-short encoded message can cause a panic in Float.GobDecode and Rat GobDecode in math/big in Go before 1.17.13 and 1.18.5, p…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-1053"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:0350-1</id>
    <title>openSUSE-SU-2024:0350-1 — Security update for govulncheck-vulndb</title>
    <updated>2026-10-02T22:28:54.095282+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for govulncheck-vulndb</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:0350-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:10147</id>
    <title>RHSA-2024:10147 — Red Hat Security Advisory: OpenShift Container Platform 4.16.24 security update</title>
    <updated>2026-10-02T22:28:54.095331+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Podman: Buildah: cri-o: FIPS Crypto-Policy Directory Mounting Issue in containers/common Go Library Buildah: Podman: Improper Input Validation in bind-propagation Option of Dockerfile RUN --mount Instruction golang-protobuf: encoding/protojson, internal/encoding/json: infinite loop in protojson.Unmarshal when unmarshaling certain forms of invalid JSON</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:10147"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2024:3545-1</id>
    <title>SUSE-SU-2024:3545-1 — Security update for buildah</title>
    <updated>2026-10-02T22:28:54.095354+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for buildah</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2024:3545-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-9341</id>
    <title>UBUNTU-CVE-2024-9341</title>
    <updated>2026-10-02T22:28:54.095370+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:22.04:LTS: golang-github-containers-common, Ubuntu:24.04:LTS: golang-github-containers-common, Ubuntu:25.10: golang-github-containers-common, Ubuntu:26.04:LTS: golang-github-containers-common</p>
<p>A flaw was found in Go. When FIPS mode is enabled on a system, container runtimes may incorrectly handle certain file paths due to improper validation in the containers/common Go library. This flaw allows an attacker to exploit symbolic links and trick the system into mounting sensitive host directories inside a container. This issue also allows attackers to access critical host files, bypassing the intended isolation between containers and the host system.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-9341"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2025-053</id>
    <title>VDE-2025-053 — Phoenix Contact: Multiple Vulnerabilities in PLCnext Firmware</title>
    <updated>2026-10-02T22:28:54.095396+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Coreutils: heap overflow in split --line-bytes with very long lines Unprivileged overlay + shiftfs read access Nano: running `chmod` and `chown` on the filename allows malicious user to replace the emergency file with a malicious symlink to a root-owned file SSL_select_next_proto buffer overread Remote Code Execution in pypa/setuptools</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2025-053"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3215</id>
    <title>WID-SEC-W-2024-3215 — Red Hat OpenShift: Schwachstelle ermöglicht Offenlegung von Informationen</title>
    <updated>2026-10-02T22:28:54.095449+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Red Hat OpenShift ausnutzen, um Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3215"/>
  </entry>
</feed>
