<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 06:04:42 +0000</lastBuildDate>
    <item>
      <title>cnvd-2020-52439</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2020-52439</link>
      <description>cnvd-2020-52439</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2020-52439</guid>
    </item>
    <item>
      <title>EUVD-2026-42036</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-42036</link>
      <description>EUVD-2026-42036</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-42036</guid>
    </item>
    <item>
      <title>fkie_cve-2020-13846</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-13846</link>
      <description>&lt;p&gt;Sylabs Singularity 3.5.0 through 3.5.3 fails to report an error in a Status Code.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Sylabs Singularity 3.5.0 through 3.5.3 fails to report an error in a Status Code.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-13846</guid>
    </item>
    <item>
      <title>GHSA-6w7g-p4jh-rf92 — "Verify All" Returns Success Despite Validation Failures in Singularity</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6w7g-p4jh-rf92</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/sylabs/singularity&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;The `--all / -a` option to `singularity verify` returns success even when some objects in a SIF container are not signed, or cannot be verified.&lt;/p&gt;
&lt;p&gt;The SIF objects that are not verified are reported in `WARNING` log messages, but a `Container Verified` message and exit code of `0`  are returned.&lt;/p&gt;
&lt;p&gt;Workflows that verify a container using `--all / -a` and use the exit code as an indicator of success are vulnerable to running SIF containers that have unsigned, or modified, objects that may be exploited to introduce malicious behavior.&lt;/p&gt;
&lt;p&gt;```
$ singularity verify -a image.sif 
WARNING: Missing signature for SIF descriptor 2 (JSON.Generic)
WARNING: Missing signature for SIF descriptor 3 (FS)
Container is signed by 1 key(s):&lt;/p&gt;
&lt;p&gt;Verifying partition: Def.FILE:
12045C8C0B1004D058DE4BEDA20C27EE7FF7BA84
[LOCAL]   Unit Test &amp;lt;unit@test.com&amp;gt;
[OK]      Data integrity verified&lt;/p&gt;
&lt;p&gt;INFO:    Container verified: image.sif&lt;/p&gt;
&lt;p&gt;$ echo $?
0
```&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;Singularity 3.6.0 has a new implementation of sign/verify that fixes this issue.&lt;/p&gt;
&lt;p&gt;All users are advised to upgrade to 3.6.0. Note that Singularity 3.6.0 uses a new signature format that is necessarily incompatible with Singularity &amp;lt; 3.6.0 - e.g. Singularity 3.5.3 cannot verify containers signed by 3.6.0.&lt;/p&gt;
&lt;p&gt;Version 3.6.0 includes a `--legacy-insecure` flag for the `singularity verify` command, that will perform verification of the older, and insecure, legacy signatures for compatibility with existing containers. This does not guarantee that con…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/sylabs/singularity&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;The `--all / -a` option to `singularity verify` returns success even when some objects in a SIF container are not signed, or cannot be verified.&lt;/p&gt;
&lt;p&gt;The SIF objects that are not verified are reported in `WARNING` log messages, but a `Container Verified` message and exit code of `0`  are returned.&lt;/p&gt;
&lt;p&gt;Workflows that verify a container using `--all / -a` and use the exit code as an indicator of success are vulnerable to running SIF containers that have unsigned, or modified, objects that may be exploited to introduce malicious behavior.&lt;/p&gt;
&lt;p&gt;```
$ singularity verify -a image.sif 
WARNING: Missing signature for SIF descriptor 2 (JSON.Generic)
WARNING: Missing signature for SIF descriptor 3 (FS)
Container is signed by 1 key(s):&lt;/p&gt;
&lt;p&gt;Verifying partition: Def.FILE:
12045C8C0B1004D058DE4BEDA20C27EE7FF7BA84
[LOCAL]   Unit Test &amp;lt;unit@test.com&amp;gt;
[OK]      Data integrity verified&lt;/p&gt;
&lt;p&gt;INFO:    Container verified: image.sif&lt;/p&gt;
&lt;p&gt;$ echo $?
0
```&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;Singularity 3.6.0 has a new implementation of sign/verify that fixes this issue.&lt;/p&gt;
&lt;p&gt;All users are advised to upgrade to 3.6.0. Note that Singularity 3.6.0 uses a new signature format that is necessarily incompatible with Singularity &amp;lt; 3.6.0 - e.g. Singularity 3.5.3 cannot verify containers signed by 3.6.0.&lt;/p&gt;
&lt;p&gt;Version 3.6.0 includes a `--legacy-insecure` flag for the `singularity verify` command, that will perform verification of the older, and insecure, legacy signatures for compatibility with existing containers. This does not guarantee that con…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6w7g-p4jh-rf92</guid>
    </item>
    <item>
      <title>gsd-2020-13846</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-13846</link>
      <description>gsd-2020-13846</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-13846</guid>
    </item>
    <item>
      <title>openSUSE-SU-2020:1011-1 — Security update for singularity</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2020:1011-1</link>
      <description>&lt;p&gt;Security update for singularity&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for singularity&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2020:1011-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2020-13846</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-13846</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:18.04:LTS: singularity-container, Ubuntu:Pro:24.04:LTS: singularity-container, Ubuntu:25.10: singularity-container, Ubuntu:26.04:LTS: singularity-container&lt;/p&gt;
&lt;p&gt;Sylabs Singularity 3.5.0 through 3.5.3 fails to report an error in a Status Code.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:18.04:LTS: singularity-container, Ubuntu:Pro:24.04:LTS: singularity-container, Ubuntu:25.10: singularity-container, Ubuntu:26.04:LTS: singularity-container&lt;/p&gt;
&lt;p&gt;Sylabs Singularity 3.5.0 through 3.5.3 fails to report an error in a Status Code.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-13846</guid>
    </item>
  </channel>
</rss>
