<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 22:55:23 +0000</lastBuildDate>
    <item>
      <title>ALSA-2020:1650 — Moderate: container-tools:rhel8 security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2020:1650</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: crit, AlmaLinux:8: criu, AlmaLinux:8: python-podman-api, AlmaLinux:8: python3-criu, AlmaLinux:8: slirp4netns, AlmaLinux:8: toolbox, AlmaLinux:8: udica&lt;/p&gt;
&lt;p&gt;The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* runc: volume mount race condition with shared mounts leads to information leak/integrity manipulation (CVE-2019-19921)&lt;/p&gt;
&lt;p&gt;* containers/image: Container images read entire image manifest into memory (CVE-2020-1702)&lt;/p&gt;
&lt;p&gt;* podman: incorrectly allows existing files in volumes to be overwritten by a container when it is created (CVE-2020-1726)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: crit, AlmaLinux:8: criu, AlmaLinux:8: python-podman-api, AlmaLinux:8: python3-criu, AlmaLinux:8: slirp4netns, AlmaLinux:8: toolbox, AlmaLinux:8: udica&lt;/p&gt;
&lt;p&gt;The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* runc: volume mount race condition with shared mounts leads to information leak/integrity manipulation (CVE-2019-19921)&lt;/p&gt;
&lt;p&gt;* containers/image: Container images read entire image manifest into memory (CVE-2020-1702)&lt;/p&gt;
&lt;p&gt;* podman: incorrectly allows existing files in volumes to be overwritten by a container when it is created (CVE-2020-1726)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2020:1650</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2019-19921 — CVE-2019-19921 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2019-19921</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2019-19921</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0590 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0590</link>
      <description>certfr-2025-avi-0590</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0590</guid>
    </item>
    <item>
      <title>CLEANSTART-2025-NR50910 — runc through 1</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2025-nr50910</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: containerd&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the containerd package. runc through 1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: containerd&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the containerd package. runc through 1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2025-nr50910</guid>
    </item>
    <item>
      <title>EUVD-2026-59626</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-59626</link>
      <description>EUVD-2026-59626</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-59626</guid>
    </item>
    <item>
      <title>fkie_cve-2019-19921</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2019-19921</link>
      <description>&lt;p&gt;runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. (This vulnerability does not affect Docker due to an implementation detail that happens to block the attack.)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. (This vulnerability does not affect Docker due to an implementation detail that happens to block the attack.)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2019-19921</guid>
    </item>
    <item>
      <title>GHSA-fh74-hm69-rqjw — opencontainers runc contains procfs race condition with a shared volume mount</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-fh74-hm69-rqjw</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/opencontainers/runc&lt;/p&gt;
&lt;p&gt;### Impact
By crafting a malicious root filesystem (with `/proc` being a symlink to a directory which was inside a volume shared with another running container), an attacker in control of both containers can trick `runc` into not correctly configuring the container&amp;#39;s security labels and not correctly masking paths inside `/proc` which contain potentially-sensitive information about the host (or even allow for direct attacks against the host).&lt;/p&gt;
&lt;p&gt;In order to exploit this bug, an untrusted user must be able to spawn custom containers with custom mount configurations (such that a volume is shared between two containers). It should be noted that we consider this to be a fairly high level of access for an untrusted user -- and we do not recommend allowing completely untrusted users to have such degrees of access without further restrictions.&lt;/p&gt;
&lt;p&gt;### Specific Go Package Affected
github.com/opencontainers/runc/libcontainer&lt;/p&gt;
&lt;p&gt;### Patches
This vulnerability has been fixed in `1.0.0-rc10`. It should be noted that the current fix is effectively a hot-fix, and there are known ways for it to be worked around (such as making the entire root filesystem a shared volume controlled by another container). We recommend that users review their access policies to ensure that untrusted users do not have such high levels of controls over container mount configuration.&lt;/p&gt;
&lt;p&gt;### Workarounds
If you are not providing the ability for untrusted users to configure mountpoints for `runc` (or through a higher-level t…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/opencontainers/runc&lt;/p&gt;
&lt;p&gt;### Impact
By crafting a malicious root filesystem (with `/proc` being a symlink to a directory which was inside a volume shared with another running container), an attacker in control of both containers can trick `runc` into not correctly configuring the container&amp;#39;s security labels and not correctly masking paths inside `/proc` which contain potentially-sensitive information about the host (or even allow for direct attacks against the host).&lt;/p&gt;
&lt;p&gt;In order to exploit this bug, an untrusted user must be able to spawn custom containers with custom mount configurations (such that a volume is shared between two containers). It should be noted that we consider this to be a fairly high level of access for an untrusted user -- and we do not recommend allowing completely untrusted users to have such degrees of access without further restrictions.&lt;/p&gt;
&lt;p&gt;### Specific Go Package Affected
github.com/opencontainers/runc/libcontainer&lt;/p&gt;
&lt;p&gt;### Patches
This vulnerability has been fixed in `1.0.0-rc10`. It should be noted that the current fix is effectively a hot-fix, and there are known ways for it to be worked around (such as making the entire root filesystem a shared volume controlled by another container). We recommend that users review their access policies to ensure that untrusted users do not have such high levels of controls over container mount configuration.&lt;/p&gt;
&lt;p&gt;### Workarounds
If you are not providing the ability for untrusted users to configure mountpoints for `runc` (or through a higher-level t…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-fh74-hm69-rqjw</guid>
    </item>
    <item>
      <title>gsd-2019-19921</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2019-19921</link>
      <description>gsd-2019-19921</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2019-19921</guid>
    </item>
    <item>
      <title>openSUSE-SU-2020:0219-1 — Security update for docker-runc</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2020:0219-1</link>
      <description>&lt;p&gt;Security update for docker-runc&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for docker-runc&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2020:0219-1</guid>
    </item>
    <item>
      <title>RHSA-2020:0688 — Red Hat Security Advisory: OpenShift Container Platform 4.2.22 runc security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2020:0688</link>
      <description>&lt;p&gt;runc: volume mount race condition with shared mounts leads to information leak/integrity manipulation&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;runc: volume mount race condition with shared mounts leads to information leak/integrity manipulation&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2020:0688</guid>
    </item>
    <item>
      <title>SUSE-SU-2020:0375-1 — Security update for docker-runc</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2020:0375-1</link>
      <description>&lt;p&gt;Security update for docker-runc&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for docker-runc&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2020:0375-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2019-19921</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-19921</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: runc, Ubuntu:18.04:LTS: runc, Ubuntu:20.04:LTS: runc&lt;/p&gt;
&lt;p&gt;runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. (This vulnerability does not affect Docker due to an implementation detail that happens to block the attack.)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: runc, Ubuntu:18.04:LTS: runc, Ubuntu:20.04:LTS: runc&lt;/p&gt;
&lt;p&gt;runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. (This vulnerability does not affect Docker due to an implementation detail that happens to block the attack.)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-19921</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-1089 — Red Hat OpenShift Container Platform: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1089</link>
      <description>&lt;p&gt;Ein lokaler oder entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat OpenShift Container Platform ausnutzen, um seine Privilegien zu erhöhen, Code zur Ausführung zu bringen oder Dateien zu manipulieren&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler oder entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat OpenShift Container Platform ausnutzen, um seine Privilegien zu erhöhen, Code zur Ausführung zu bringen oder Dateien zu manipulieren&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1089</guid>
    </item>
  </channel>
</rss>
