<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 04:17:55 +0000</lastBuildDate>
    <item>
      <title>Withdrawn: BELL-CVE-2019-9946 — CVE-2019-9946 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2019-9946</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2019-9946</guid>
    </item>
    <item>
      <title>CLEANSTART-2025-IG62048 — Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2025-ig62048</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: containerd&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the containerd package. Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: containerd&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the containerd package. Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2025-ig62048</guid>
    </item>
    <item>
      <title>cnvd-2019-23129</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2019-23129</link>
      <description>cnvd-2019-23129</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2019-23129</guid>
    </item>
    <item>
      <title>EUVD-2026-53253</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-53253</link>
      <description>EUVD-2026-53253</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-53253</guid>
    </item>
    <item>
      <title>fkie_cve-2019-9946</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2019-9946</link>
      <description>&lt;p&gt;Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0.7.4 has a network firewall misconfiguration which affects Kubernetes. The CNI &amp;#39;portmap&amp;#39; plugin, used to setup HostPorts for CNI, inserts rules at the front of the iptables nat chains; which take precedence over the KUBE- SERVICES chain. Because of this, the HostPort/portmap rule could match incoming traffic even if there were better fitting, more specific service definition rules like NodePorts later in the chain. The issue is fixed in CNI 0.7.5 and Kubernetes 1.11.9, 1.12.7, 1.13.5, and 1.14.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0.7.4 has a network firewall misconfiguration which affects Kubernetes. The CNI &amp;#39;portmap&amp;#39; plugin, used to setup HostPorts for CNI, inserts rules at the front of the iptables nat chains; which take precedence over the KUBE- SERVICES chain. Because of this, the HostPort/portmap rule could match incoming traffic even if there were better fitting, more specific service definition rules like NodePorts later in the chain. The issue is fixed in CNI 0.7.5 and Kubernetes 1.11.9, 1.12.7, 1.13.5, and 1.14.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2019-9946</guid>
    </item>
    <item>
      <title>GHSA-6g96-g4m6-hw69</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6g96-g4m6-hw69</link>
      <description>&lt;p&gt;Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0.7.4 has a network firewall misconfiguration which affects Kubernetes. The CNI &amp;#39;portmap&amp;#39; plugin, used to setup HostPorts for CNI, inserts rules at the front of the iptables nat chains; which take precedence over the KUBE- SERVICES chain. Because of this, the HostPort/portmap rule could match incoming traffic even if there were better fitting, more specific service definition rules like NodePorts later in the chain. The issue is fixed in CNI 0.7.5 and Kubernetes 1.11.9, 1.12.7, 1.13.5, and 1.14.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0.7.4 has a network firewall misconfiguration which affects Kubernetes. The CNI &amp;#39;portmap&amp;#39; plugin, used to setup HostPorts for CNI, inserts rules at the front of the iptables nat chains; which take precedence over the KUBE- SERVICES chain. Because of this, the HostPort/portmap rule could match incoming traffic even if there were better fitting, more specific service definition rules like NodePorts later in the chain. The issue is fixed in CNI 0.7.5 and Kubernetes 1.11.9, 1.12.7, 1.13.5, and 1.14.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6g96-g4m6-hw69</guid>
    </item>
    <item>
      <title>gsd-2019-9946</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2019-9946</link>
      <description>gsd-2019-9946</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2019-9946</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:10884-1 — k3s-1.21.3+k3s1-1.2 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:10884-1</link>
      <description>&lt;p&gt;k3s-1.21.3+k3s1-1.2 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;k3s-1.21.3+k3s1-1.2 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:10884-1</guid>
    </item>
    <item>
      <title>RHBA-2019:0862 — Red Hat Bug Fix Advisory: containernetworking-plugins bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhba-2019:0862</link>
      <description>&lt;p&gt;kubernetes: Incorrect rule injection in CNI portmap plugin&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kubernetes: Incorrect rule injection in CNI portmap plugin&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhba-2019:0862</guid>
    </item>
    <item>
      <title>Withdrawn: UBUNTU-CVE-2019-9946</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-9946</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:20.04:LTS: kubernetes, Ubuntu:22.04:LTS: kubernetes, Ubuntu:24.04:LTS: kubernetes&lt;/p&gt;
&lt;p&gt;Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0.7.4 has a network firewall misconfiguration which affects Kubernetes. The CNI &amp;#39;portmap&amp;#39; plugin, used to setup HostPorts for CNI, inserts rules at the front of the iptables nat chains; which take precedence over the KUBE- SERVICES chain. Because of this, the HostPort/portmap rule could match incoming traffic even if there were better fitting, more specific service definition rules like NodePorts later in the chain. The issue is fixed in CNI 0.7.5 and Kubernetes 1.11.9, 1.12.7, 1.13.5, and 1.14.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:20.04:LTS: kubernetes, Ubuntu:22.04:LTS: kubernetes, Ubuntu:24.04:LTS: kubernetes&lt;/p&gt;
&lt;p&gt;Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0.7.4 has a network firewall misconfiguration which affects Kubernetes. The CNI &amp;#39;portmap&amp;#39; plugin, used to setup HostPorts for CNI, inserts rules at the front of the iptables nat chains; which take precedence over the KUBE- SERVICES chain. Because of this, the HostPort/portmap rule could match incoming traffic even if there were better fitting, more specific service definition rules like NodePorts later in the chain. The issue is fixed in CNI 0.7.5 and Kubernetes 1.11.9, 1.12.7, 1.13.5, and 1.14.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-9946</guid>
    </item>
  </channel>
</rss>
