<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 06:20:53 +0000</lastBuildDate>
    <item>
      <title>ALSA-2020:4676 — Moderate: virt:rhel and virt-devel:rhel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2020:4676</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: hivex, AlmaLinux:8: hivex-devel, AlmaLinux:8: libguestfs-winsupport, AlmaLinux:8: libiscsi, AlmaLinux:8: libiscsi-devel, AlmaLinux:8: libiscsi-utils, AlmaLinux:8: libnbd, AlmaLinux:8: libnbd-devel, AlmaLinux:8: libvirt, AlmaLinux:8: libvirt-admin and 61 more&lt;/p&gt;
&lt;p&gt;Kernel-based Virtual Machine (KVM) offers a full virtualization solution for Linux on numerous hardware platforms. The virt:rhel module contains packages which provide user-space components used to run virtual machines using KVM. The packages also provide APIs for managing and interacting with the virtualized systems.&lt;/p&gt;
&lt;p&gt;The following packages have been upgraded to a later upstream version: hivex (1.3.18), libguestfs (1.40.2), libguestfs-winsupport (8.2), libvirt (6.0.0), libvirt-dbus (1.3.0), libvirt-python (6.0.0), nbdkit (1.16.2), perl-Sys-Virt (6.0.0), qemu-kvm (4.2.0), seabios (1.13.0), SLOF (20191022). (BZ#1810193, BZ#1844296)&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libvirt: leak of /dev/mapper/control into QEMU guests (CVE-2020-14339)&lt;/p&gt;
&lt;p&gt;* QEMU: Slirp: use-after-free during packet reassembly (CVE-2019-15890)&lt;/p&gt;
&lt;p&gt;* libvirt: Potential DoS by holding a monitor job while querying QEMU guest-agent (CVE-2019-20485)&lt;/p&gt;
&lt;p&gt;* QEMU: slirp: use-after-free in ip_reass() function in ip_input.c (CVE-2020-1983)&lt;/p&gt;
&lt;p&gt;* libvirt: Potential denial of service via active pool without target path (CVE-2020-10703)&lt;/p&gt;
&lt;p&gt;* libvirt: leak of sensitive cookie information via dumpxml (CVE-2020-14301)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: hivex, AlmaLinux:8: hivex-devel, AlmaLinux:8: libguestfs-winsupport, AlmaLinux:8: libiscsi, AlmaLinux:8: libiscsi-devel, AlmaLinux:8: libiscsi-utils, AlmaLinux:8: libnbd, AlmaLinux:8: libnbd-devel, AlmaLinux:8: libvirt, AlmaLinux:8: libvirt-admin and 61 more&lt;/p&gt;
&lt;p&gt;Kernel-based Virtual Machine (KVM) offers a full virtualization solution for Linux on numerous hardware platforms. The virt:rhel module contains packages which provide user-space components used to run virtual machines using KVM. The packages also provide APIs for managing and interacting with the virtualized systems.&lt;/p&gt;
&lt;p&gt;The following packages have been upgraded to a later upstream version: hivex (1.3.18), libguestfs (1.40.2), libguestfs-winsupport (8.2), libvirt (6.0.0), libvirt-dbus (1.3.0), libvirt-python (6.0.0), nbdkit (1.16.2), perl-Sys-Virt (6.0.0), qemu-kvm (4.2.0), seabios (1.13.0), SLOF (20191022). (BZ#1810193, BZ#1844296)&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libvirt: leak of /dev/mapper/control into QEMU guests (CVE-2020-14339)&lt;/p&gt;
&lt;p&gt;* QEMU: Slirp: use-after-free during packet reassembly (CVE-2019-15890)&lt;/p&gt;
&lt;p&gt;* libvirt: Potential DoS by holding a monitor job while querying QEMU guest-agent (CVE-2019-20485)&lt;/p&gt;
&lt;p&gt;* QEMU: slirp: use-after-free in ip_reass() function in ip_input.c (CVE-2020-1983)&lt;/p&gt;
&lt;p&gt;* libvirt: Potential denial of service via active pool without target path (CVE-2020-10703)&lt;/p&gt;
&lt;p&gt;* libvirt: leak of sensitive cookie information via dumpxml (CVE-2020-14301)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2020:4676</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2020-14339 — CVE-2020-14339 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2020-14339</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2020-14339</guid>
    </item>
    <item>
      <title>cnvd-2020-47042</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2020-47042</link>
      <description>cnvd-2020-47042</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2020-47042</guid>
    </item>
    <item>
      <title>EUVD-2026-42373</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-42373</link>
      <description>EUVD-2026-42373</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-42373</guid>
    </item>
    <item>
      <title>fkie_cve-2020-14339</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-14339</link>
      <description>&lt;p&gt;A flaw was found in libvirt, where it leaked a file descriptor for `/dev/mapper/control` into the QEMU process. This file descriptor allows for privileged operations to happen against the device-mapper on the host. This flaw allows a malicious guest user or process to perform operations outside of their standard permissions, potentially causing serious damage to the host operating system. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in libvirt, where it leaked a file descriptor for `/dev/mapper/control` into the QEMU process. This file descriptor allows for privileged operations to happen against the device-mapper on the host. This flaw allows a malicious guest user or process to perform operations outside of their standard permissions, potentially causing serious damage to the host operating system. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-14339</guid>
    </item>
    <item>
      <title>GHSA-c772-g5j9-w9w8</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-c772-g5j9-w9w8</link>
      <description>&lt;p&gt;A flaw was found in libvirt, where it leaked a file descriptor for `/dev/mapper/control` into the QEMU process. This file descriptor allows for privileged operations to happen against the device-mapper on the host. This flaw allows a malicious guest user or process to perform operations outside of their standard permissions, potentially causing serious damage to the host operating system. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in libvirt, where it leaked a file descriptor for `/dev/mapper/control` into the QEMU process. This file descriptor allows for privileged operations to happen against the device-mapper on the host. This flaw allows a malicious guest user or process to perform operations outside of their standard permissions, potentially causing serious damage to the host operating system. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-c772-g5j9-w9w8</guid>
    </item>
    <item>
      <title>gsd-2020-14339</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-14339</link>
      <description>gsd-2020-14339</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-14339</guid>
    </item>
    <item>
      <title>OESA-2021-1010 — libvirt security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2021-1010</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS: libvirt, openEuler:20.03-LTS-SP1: libvirt&lt;/p&gt;
&lt;p&gt;Libvirt is a C toolkit to interact with the virtualization capabilities of recent versions of Linux (and other OSes). The main package includes the libvirtd server exporting the virtualization support.\r\n\r\n&#13;
Security Fix(es):\r\n\r\n&#13;
A flaw was found in libvirt, where it leaked a file descriptor for `/dev/mapper/control` into the QEMU process. This file descriptor allows for privileged operations to happen against the device-mapper on the host. This flaw allows a malicious guest user or process to perform operations outside of their standard permissions, potentially causing serious damage to the host operating system. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.(CVE-2020-14339)\r\n\r\n&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS: libvirt, openEuler:20.03-LTS-SP1: libvirt&lt;/p&gt;
&lt;p&gt;Libvirt is a C toolkit to interact with the virtualization capabilities of recent versions of Linux (and other OSes). The main package includes the libvirtd server exporting the virtualization support.\r\n\r\n&#13;
Security Fix(es):\r\n\r\n&#13;
A flaw was found in libvirt, where it leaked a file descriptor for `/dev/mapper/control` into the QEMU process. This file descriptor allows for privileged operations to happen against the device-mapper on the host. This flaw allows a malicious guest user or process to perform operations outside of their standard permissions, potentially causing serious damage to the host operating system. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.(CVE-2020-14339)\r\n\r\n&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2021-1010</guid>
    </item>
    <item>
      <title>openSUSE-SU-2020:1455-1 — Security update for libvirt</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2020:1455-1</link>
      <description>&lt;p&gt;Security update for libvirt&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for libvirt&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2020:1455-1</guid>
    </item>
    <item>
      <title>RHSA-2020:3586 — Red Hat Security Advisory: virt:8.2 and virt-devel:8.2 security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2020:3586</link>
      <description>&lt;p&gt;QEMU: slirp: networking out-of-bounds read information disclosure vulnerability libvirt: leak of /dev/mapper/control into QEMU guests&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;QEMU: slirp: networking out-of-bounds read information disclosure vulnerability libvirt: leak of /dev/mapper/control into QEMU guests&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2020:3586</guid>
    </item>
    <item>
      <title>SUSE-SU-2020:2233-1 — Security update for libvirt</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2020:2233-1</link>
      <description>&lt;p&gt;Security update for libvirt&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for libvirt&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2020:2233-1</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-1722 — QEMU und libvirt: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1722</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in QEMU und libvirt ausnutzen, um Informationen offenzulegen und um Sicherheitsmechanismen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in QEMU und libvirt ausnutzen, um Informationen offenzulegen und um Sicherheitsmechanismen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1722</guid>
    </item>
  </channel>
</rss>
