<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T22:39:42.828093+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-15321</id>
    <title>bdu:2026-15321</title>
    <updated>2026-10-02T22:39:42.956038+00:00</updated>
    <content>bdu:2026-15321</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-15321"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-glances-cve-2026-46607</id>
    <title>BREW-glances-CVE-2026-46607 — Glances: Insecure Pickle Deserialization in Version Cache Leads to Arbitrary Code Execution</title>
    <updated>2026-10-02T22:39:42.956082+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: glances</p>
<p>Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.5, glances/outdated.py uses pickle.load() to read a version-check cache file stored at a predictable, world-accessible path (~/.cache/glances/glances-version.db or $XDG_CACHE_HOME/glances/glances-version.db). No integrity check, signature verification, or format validation is performed before deserialization. An attacker with write access to that path — through any of several realistic local or container-level scenarios — can plant a malicious pickle file and achieve arbitrary code execution as the OS user running Glances the next time it starts with version checking enabled (the default). This vulnerability is fixed in 4.5.5.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-glances-cve-2026-46607"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-330382</id>
    <title>EUVD-2026-330382</title>
    <updated>2026-10-02T22:39:42.956125+00:00</updated>
    <content>EUVD-2026-330382</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-330382"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-46607</id>
    <title>fkie_cve-2026-46607</title>
    <updated>2026-10-02T22:39:42.956140+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.5, glances/outdated.py uses pickle.load() to read a version-check cache file stored at a predictable, world-accessible path (~/.cache/glances/glances-version.db or $XDG_CACHE_HOME/glances/glances-version.db). No integrity check, signature verification, or format validation is performed before deserialization. An attacker with write access to that path — through any of several realistic local or container-level scenarios — can plant a malicious pickle file and achieve arbitrary code execution as the OS user running Glances the next time it starts with version checking enabled (the default). This vulnerability is fixed in 4.5.5.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-46607"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-9837-48hr-q32j</id>
    <title>GHSA-9837-48hr-q32j — Glances has Insecure Pickle Deserialization in its Version Cache that Leads to Arbitrary Code Execution</title>
    <updated>2026-10-02T22:39:42.956167+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: glances</p>
<p>### Summary</p>
<p>`glances/outdated.py` uses `pickle.load()` to read a version-check cache file stored at a predictable, world-accessible path (`~/.cache/glances/glances-version.db` or `$XDG_CACHE_HOME/glances/glances-version.db`). No integrity check, signature verification, or format validation is performed before deserialization.  An attacker with write access to that path — through any of several realistic local or container-level scenarios — can plant a malicious pickle file and achieve arbitrary code execution as the OS user running Glances the next time it starts with version checking enabled (the default).</p>
<p>---</p>
<p>### Details</p>
<p>**Affected file:** `glances/outdated.py`, method `Outdated._load_cache()`, line 121</p>
<p>**Direct URL (commit 04579778e733d705898a169e049dc84772c852da):**
- https://github.com/nicolargo/glances/blob/04579778e733d705898a169e049dc84772c852da/glances/outdated.py#L121</p>
<p>```python
# outdated.py  (_load_cache, line 119-127)
try:
    with open(self.cache_file, 'rb') as f:
        cached_data = pickle.load(f)          # ← no integrity check
except Exception as e:
    logger.debug(f"Cannot read version from cache file: {self.cache_file} ({e})")
    ...
```</p>
<p>`self.cache_file` is constructed from the XDG cache directory path at `Outdated.__init__()`:</p>
<p>```python
# outdated.py  (__init__)
self.cache_file = os.path.join(
    user_cache_dir('glances')[0],
    'glances-version.db'
)
```</p>
<p>On a default Linux installation this resolves to `/home/john/.cache/glances/glances-ve…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-9837-48hr-q32j"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11122-1</id>
    <title>openSUSE-SU-2026:11122-1 — glances-common-4.5.5-1.1 on GA media</title>
    <updated>2026-10-02T22:39:42.956244+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>glances-common-4.5.5-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11122-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-2496</id>
    <title>PYSEC-2026-2496 — Glances has Insecure Pickle Deserialization in its Version Cache that Leads to Arbitrary Code Execution</title>
    <updated>2026-10-02T22:39:42.956267+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: glances</p>
<p>### Summary</p>
<p>`glances/outdated.py` uses `pickle.load()` to read a version-check cache file stored at a predictable, world-accessible path (`~/.cache/glances/glances-version.db` or `$XDG_CACHE_HOME/glances/glances-version.db`). No integrity check, signature verification, or format validation is performed before deserialization.  An attacker with write access to that path — through any of several realistic local or container-level scenarios — can plant a malicious pickle file and achieve arbitrary code execution as the OS user running Glances the next time it starts with version checking enabled (the default).</p>
<p>---</p>
<p>### Details</p>
<p>**Affected file:** `glances/outdated.py`, method `Outdated._load_cache()`, line 121</p>
<p>**Direct URL (commit 04579778e733d705898a169e049dc84772c852da):**
- https://github.com/nicolargo/glances/blob/04579778e733d705898a169e049dc84772c852da/glances/outdated.py#L121</p>
<p>```python
# outdated.py  (_load_cache, line 119-127)
try:
    with open(self.cache_file, 'rb') as f:
        cached_data = pickle.load(f)          # ← no integrity check
except Exception as e:
    logger.debug(f"Cannot read version from cache file: {self.cache_file} ({e})")
    ...
```</p>
<p>`self.cache_file` is constructed from the XDG cache directory path at `Outdated.__init__()`:</p>
<p>```python
# outdated.py  (__init__)
self.cache_file = os.path.join(
    user_cache_dir('glances')[0],
    'glances-version.db'
)
```</p>
<p>On a default Linux installation this resolves to `/home/john/.cache/glances/glances-ve…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-2496"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-46607</id>
    <title>UBUNTU-CVE-2026-46607</title>
    <updated>2026-10-02T22:39:42.956336+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: glances, Ubuntu:Pro:18.04:LTS: glances, Ubuntu:Pro:20.04:LTS: glances, Ubuntu:22.04:LTS: glances, Ubuntu:24.04:LTS: glances, Ubuntu:25.10: glances, Ubuntu:26.04:LTS: glances</p>
<p>Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.5, glances/outdated.py uses pickle.load() to read a version-check cache file stored at a predictable, world-accessible path (~/.cache/glances/glances-version.db or $XDG_CACHE_HOME/glances/glances-version.db). No integrity check, signature verification, or format validation is performed before deserialization. An attacker with write access to that path — through any of several realistic local or container-level scenarios — can plant a malicious pickle file and achieve arbitrary code execution as the OS user running Glances the next time it starts with version checking enabled (the default). This vulnerability is fixed in 4.5.5.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-46607"/>
  </entry>
</feed>
