<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 08:48:55 +0000</lastBuildDate>
    <item>
      <title>ALSA-2020:4436 — Low: gnome-software and fwupd security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2020:4436</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: appstream-data, AlmaLinux:8: libxmlb&lt;/p&gt;
&lt;p&gt;The gnome-software packages contain an application that makes it easy to add, remove, and update software in the GNOME desktop.&lt;/p&gt;
&lt;p&gt;The appstream-data package provides the distribution specific AppStream metadata required for the GNOME and KDE software centers.&lt;/p&gt;
&lt;p&gt;The fwupd packages provide a service that allows session software to update device firmware.&lt;/p&gt;
&lt;p&gt;The following packages have been upgraded to a later upstream version: gnome-software (3.36.1), fwupd (1.4.2).&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* fwupd: Possible bypass in signature verification (CVE-2020-10759)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: appstream-data, AlmaLinux:8: libxmlb&lt;/p&gt;
&lt;p&gt;The gnome-software packages contain an application that makes it easy to add, remove, and update software in the GNOME desktop.&lt;/p&gt;
&lt;p&gt;The appstream-data package provides the distribution specific AppStream metadata required for the GNOME and KDE software centers.&lt;/p&gt;
&lt;p&gt;The fwupd packages provide a service that allows session software to update device firmware.&lt;/p&gt;
&lt;p&gt;The following packages have been upgraded to a later upstream version: gnome-software (3.36.1), fwupd (1.4.2).&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* fwupd: Possible bypass in signature verification (CVE-2020-10759)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2020:4436</guid>
    </item>
    <item>
      <title>cnvd-2020-37942</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2020-37942</link>
      <description>cnvd-2020-37942</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2020-37942</guid>
    </item>
    <item>
      <title>EUVD-2026-40046</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-40046</link>
      <description>EUVD-2026-40046</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-40046</guid>
    </item>
    <item>
      <title>fkie_cve-2020-10759</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-10759</link>
      <description>&lt;p&gt;A PGP signature bypass flaw was found in fwupd (all versions), which could lead to the installation of unsigned firmware. As per upstream, a signature bypass is theoretically possible, but not practical because the Linux Vendor Firmware Service (LVFS) is either not implemented or enabled in versions of fwupd shipped with Red Hat Enterprise Linux 7 and 8. The highest threat from this vulnerability is to confidentiality and integrity.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A PGP signature bypass flaw was found in fwupd (all versions), which could lead to the installation of unsigned firmware. As per upstream, a signature bypass is theoretically possible, but not practical because the Linux Vendor Firmware Service (LVFS) is either not implemented or enabled in versions of fwupd shipped with Red Hat Enterprise Linux 7 and 8. The highest threat from this vulnerability is to confidentiality and integrity.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-10759</guid>
    </item>
    <item>
      <title>GHSA-phhj-vpf5-5666</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-phhj-vpf5-5666</link>
      <description>&lt;p&gt;A PGP signature bypass flaw was found in fwupd (all versions), which could lead to the installation of unsigned firmware. As per upstream, a signature bypass is theoretically possible, but not practical because the Linux Vendor Firmware Service (LVFS) is either not implemented or enabled in versions of fwupd shipped with Red Hat Enterprise Linux 7 and 8. The highest threat from this vulnerability is to confidentiality and integrity.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A PGP signature bypass flaw was found in fwupd (all versions), which could lead to the installation of unsigned firmware. As per upstream, a signature bypass is theoretically possible, but not practical because the Linux Vendor Firmware Service (LVFS) is either not implemented or enabled in versions of fwupd shipped with Red Hat Enterprise Linux 7 and 8. The highest threat from this vulnerability is to confidentiality and integrity.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-phhj-vpf5-5666</guid>
    </item>
    <item>
      <title>gsd-2020-10759</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-10759</link>
      <description>gsd-2020-10759</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-10759</guid>
    </item>
    <item>
      <title>OESA-2022-1801 — fwupd security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2022-1801</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: fwupd, openEuler:20.03-LTS-SP3: fwupd, openEuler:22.03-LTS: fwupd&lt;/p&gt;
&lt;p&gt;aims to make updating firmware on Linux automatic, safe and reliable.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A PGP signature bypass flaw was found in fwupd (all versions), which could lead to the installation of unsigned firmware. As per upstream, a signature bypass is theoretically possible, but not practical because the Linux Vendor Firmware Service (LVFS) is either not implemented or enabled in versions of fwupd shipped with Red Hat Enterprise Linux 7 and 8. The highest threat from this vulnerability is to confidentiality and integrity.(CVE-2020-10759)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: fwupd, openEuler:20.03-LTS-SP3: fwupd, openEuler:22.03-LTS: fwupd&lt;/p&gt;
&lt;p&gt;aims to make updating firmware on Linux automatic, safe and reliable.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A PGP signature bypass flaw was found in fwupd (all versions), which could lead to the installation of unsigned firmware. As per upstream, a signature bypass is theoretically possible, but not practical because the Linux Vendor Firmware Service (LVFS) is either not implemented or enabled in versions of fwupd shipped with Red Hat Enterprise Linux 7 and 8. The highest threat from this vulnerability is to confidentiality and integrity.(CVE-2020-10759)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2022-1801</guid>
    </item>
    <item>
      <title>openSUSE-SU-2020:0849-1 — Security update for fwupd</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2020:0849-1</link>
      <description>&lt;p&gt;Security update for fwupd&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for fwupd&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2020:0849-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2020:1681-1 — Security update for fwupd</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2020:1681-1</link>
      <description>&lt;p&gt;Security update for fwupd&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for fwupd&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2020:1681-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2020-10759</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-10759</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: fwupd, Ubuntu:18.04:LTS: fwupd, Ubuntu:20.04:LTS: fwupd&lt;/p&gt;
&lt;p&gt;A PGP signature bypass flaw was found in fwupd (all versions), which could lead to the installation of unsigned firmware. As per upstream, a signature bypass is theoretically possible, but not practical because the Linux Vendor Firmware Service (LVFS) is either not implemented or enabled in versions of fwupd shipped with Red Hat Enterprise Linux 7 and 8. The highest threat from this vulnerability is to confidentiality and integrity.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: fwupd, Ubuntu:18.04:LTS: fwupd, Ubuntu:20.04:LTS: fwupd&lt;/p&gt;
&lt;p&gt;A PGP signature bypass flaw was found in fwupd (all versions), which could lead to the installation of unsigned firmware. As per upstream, a signature bypass is theoretically possible, but not practical because the Linux Vendor Firmware Service (LVFS) is either not implemented or enabled in versions of fwupd shipped with Red Hat Enterprise Linux 7 and 8. The highest threat from this vulnerability is to confidentiality and integrity.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-10759</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-0193 — Red Hat Enterprise Linux: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0193</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um die Verfügbarkeit, Integrität und Vertraulichkeit zu gefährden.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um die Verfügbarkeit, Integrität und Vertraulichkeit zu gefährden.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0193</guid>
    </item>
  </channel>
</rss>
