<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 07:57:07 +0000</lastBuildDate>
    <item>
      <title>bdu:2023-01662</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-01662</link>
      <description>bdu:2023-01662</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-01662</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2020-14382 — CVE-2020-14382 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2020-14382</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2020-14382</guid>
    </item>
    <item>
      <title>EUVD-2026-42431</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-42431</link>
      <description>EUVD-2026-42431</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-42431</guid>
    </item>
    <item>
      <title>fkie_cve-2020-14382</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-14382</link>
      <description>&lt;p&gt;A vulnerability was found in upstream release cryptsetup-2.2.0 where, there&amp;#39;s a bug in LUKS2 format validation code, that is effectively invoked on every device/image presenting itself as LUKS2 container. The bug is in segments validation code in file &amp;#39;lib/luks2/luks2_json_metadata.c&amp;#39; in function hdr_validate_segments(struct crypt_device *cd, json_object *hdr_jobj) where the code does not check for possible overflow on memory allocation used for intervals array (see statement &amp;#34;intervals = malloc(first_backup * sizeof(*intervals));&amp;#34;). Due to the bug, library can be *tricked* to expect such allocation was successful but for far less memory then originally expected. Later it may read data FROM image crafted by an attacker and actually write such data BEYOND allocated memory.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability was found in upstream release cryptsetup-2.2.0 where, there&amp;#39;s a bug in LUKS2 format validation code, that is effectively invoked on every device/image presenting itself as LUKS2 container. The bug is in segments validation code in file &amp;#39;lib/luks2/luks2_json_metadata.c&amp;#39; in function hdr_validate_segments(struct crypt_device *cd, json_object *hdr_jobj) where the code does not check for possible overflow on memory allocation used for intervals array (see statement &amp;#34;intervals = malloc(first_backup * sizeof(*intervals));&amp;#34;). Due to the bug, library can be *tricked* to expect such allocation was successful but for far less memory then originally expected. Later it may read data FROM image crafted by an attacker and actually write such data BEYOND allocated memory.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-14382</guid>
    </item>
    <item>
      <title>GHSA-v8mw-xqhr-2vqp</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-v8mw-xqhr-2vqp</link>
      <description>&lt;p&gt;A vulnerability was found in upstream release cryptsetup-2.2.0 where, there&amp;#39;s a bug in LUKS2 format validation code, that is effectively invoked on every device/image presenting itself as LUKS2 container. The bug is in segments validation code in file &amp;#39;lib/luks2/luks2_json_metadata.c&amp;#39; in function hdr_validate_segments(struct crypt_device *cd, json_object *hdr_jobj) where the code does not check for possible overflow on memory allocation used for intervals array (see statement &amp;#34;intervals = malloc(first_backup * sizeof(*intervals));&amp;#34;). Due to the bug, library can be *tricked* to expect such allocation was successful but for far less memory then originally expected. Later it may read data FROM image crafted by an attacker and actually write such data BEYOND allocated memory.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability was found in upstream release cryptsetup-2.2.0 where, there&amp;#39;s a bug in LUKS2 format validation code, that is effectively invoked on every device/image presenting itself as LUKS2 container. The bug is in segments validation code in file &amp;#39;lib/luks2/luks2_json_metadata.c&amp;#39; in function hdr_validate_segments(struct crypt_device *cd, json_object *hdr_jobj) where the code does not check for possible overflow on memory allocation used for intervals array (see statement &amp;#34;intervals = malloc(first_backup * sizeof(*intervals));&amp;#34;). Due to the bug, library can be *tricked* to expect such allocation was successful but for far less memory then originally expected. Later it may read data FROM image crafted by an attacker and actually write such data BEYOND allocated memory.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-v8mw-xqhr-2vqp</guid>
    </item>
    <item>
      <title>gsd-2020-14382</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-14382</link>
      <description>gsd-2020-14382</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-14382</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:10704-1 — cryptsetup-2.4.1-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:10704-1</link>
      <description>&lt;p&gt;cryptsetup-2.4.1-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;cryptsetup-2.4.1-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:10704-1</guid>
    </item>
    <item>
      <title>RHSA-2020:4900 — Red Hat Security Advisory: cryptsetup security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2020:4900</link>
      <description>&lt;p&gt;cryptsetup: Out-of-bounds write when validating segments&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;cryptsetup: Out-of-bounds write when validating segments&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2020:4900</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2020-14382</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-14382</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: cryptsetup&lt;/p&gt;
&lt;p&gt;A vulnerability was found in upstream release cryptsetup-2.2.0 where, there&amp;#39;s a bug in LUKS2 format validation code, that is effectively invoked on every device/image presenting itself as LUKS2 container. The bug is in segments validation code in file &amp;#39;lib/luks2/luks2_json_metadata.c&amp;#39; in function hdr_validate_segments(struct crypt_device *cd, json_object *hdr_jobj) where the code does not check for possible overflow on memory allocation used for intervals array (see statement &amp;#34;intervals = malloc(first_backup * sizeof(*intervals));&amp;#34;). Due to the bug, library can be *tricked* to expect such allocation was successful but for far less memory then originally expected. Later it may read data FROM image crafted by an attacker and actually write such data BEYOND allocated memory.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: cryptsetup&lt;/p&gt;
&lt;p&gt;A vulnerability was found in upstream release cryptsetup-2.2.0 where, there&amp;#39;s a bug in LUKS2 format validation code, that is effectively invoked on every device/image presenting itself as LUKS2 container. The bug is in segments validation code in file &amp;#39;lib/luks2/luks2_json_metadata.c&amp;#39; in function hdr_validate_segments(struct crypt_device *cd, json_object *hdr_jobj) where the code does not check for possible overflow on memory allocation used for intervals array (see statement &amp;#34;intervals = malloc(first_backup * sizeof(*intervals));&amp;#34;). Due to the bug, library can be *tricked* to expect such allocation was successful but for far less memory then originally expected. Later it may read data FROM image crafted by an attacker and actually write such data BEYOND allocated memory.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-14382</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-0193 — Red Hat Enterprise Linux: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0193</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um die Verfügbarkeit, Integrität und Vertraulichkeit zu gefährden.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um die Verfügbarkeit, Integrität und Vertraulichkeit zu gefährden.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0193</guid>
    </item>
  </channel>
</rss>
