<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T08:47:05.406908+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-373052</id>
    <title>EUVD-2026-373052</title>
    <updated>2026-10-03T08:47:05.787014+00:00</updated>
    <content>EUVD-2026-373052</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-373052"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-7195</id>
    <title>fkie_cve-2025-7195</title>
    <updated>2026-10-03T08:47:05.787078+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Early versions of Operator-SDK provided an insecure method to allow operator containers to run in environments that used a random UID. Operator-SDK before 0.15.2 provided a script, user_setup, which modifies the permissions of the /etc/passwd file to 664 during build time. Developers who used Operator-SDK before 0.15.2 to scaffold their operator may still be impacted by this if the insecure user_setup script is still being used to build new container images.</p>
<p>In affected images, the /etc/passwd file is created during build time with group-writable permissions and a group ownership of root (gid=0). An attacker who can execute commands within an affected container, even as a non-root user, may be able to leverage their membership in the root group to modify the /etc/passwd file. This could allow the attacker to add a new user with any arbitrary UID, including UID 0, leading to full root privileges within the container.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-7195"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-856v-8qm2-9wjv</id>
    <title>GHSA-856v-8qm2-9wjv — operator-sdk: privilege escalation due to incorrect permissions of /etc/passwd</title>
    <updated>2026-10-03T08:47:05.787120+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/operator-framework/operator-sdk</p>
<p>Early versions of Operator-SDK provided an insecure method to allow operator containers to run in environments that used a random UID. Operator-SDK before 0.15.2 provided a script, user_setup, which modifies the permissions of the /etc/passwd file to 664 during build time. Developers who used Operator-SDK before 0.15.2 to scaffold their operator may still be impacted by this if the insecure user_setup script is still being used to build new container images. In affected images, the /etc/passwd file was created during build time with group-writable permissions and a group ownership of root (gid=0). An attacker who can execute commands within an affected container, even as a non-root user, may be able to leverage their membership in the root group to modify the /etc/passwd file. This could allow the attacker to add a new user with any arbitrary UID, including UID 0, leading to full root privileges within the container.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-856v-8qm2-9wjv"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15434-1</id>
    <title>openSUSE-SU-2025:15434-1 — govulncheck-vulndb-0.0.20250811T192933-1.1 on GA media</title>
    <updated>2026-10-03T08:47:05.787151+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>govulncheck-vulndb-0.0.20250811T192933-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15434-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhea-2025:23406</id>
    <title>RHEA-2025:23406 — Red Hat Enhancement Advisory: OpenShift Virtualization 4.20.3 Images</title>
    <updated>2026-10-03T08:47:05.787186+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>operator-sdk: privilege escalation due to incorrect permissions of /etc/passwd</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhea-2025:23406"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2533</id>
    <title>WID-SEC-W-2025-2533 — RedHat Multicluster Engine for Kubernetes: Schwachstelle ermöglicht Privilegieneskalation</title>
    <updated>2026-10-03T08:47:05.787205+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann eine Schwachstelle in RedHat Multicluster Engine for Kubernetes ausnutzen, um seine Privilegien zu erhöhen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2533"/>
  </entry>
</feed>
