<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 02:25:15 +0000</lastBuildDate>
    <item>
      <title>ALSA-2020:5487 — Moderate: pacemaker security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2020:5487</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: pacemaker, AlmaLinux:8: pacemaker-cli, AlmaLinux:8: pacemaker-cts, AlmaLinux:8: pacemaker-doc, AlmaLinux:8: pacemaker-libs-devel, AlmaLinux:8: pacemaker-nagios-plugins-metadata, AlmaLinux:8: pacemaker-remote&lt;/p&gt;
&lt;p&gt;The Pacemaker cluster resource manager is a collection of technologies working together to maintain data integrity and application availability in the event of failures.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* pacemaker: ACL restrictions bypass (CVE-2020-25654)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: pacemaker, AlmaLinux:8: pacemaker-cli, AlmaLinux:8: pacemaker-cts, AlmaLinux:8: pacemaker-doc, AlmaLinux:8: pacemaker-libs-devel, AlmaLinux:8: pacemaker-nagios-plugins-metadata, AlmaLinux:8: pacemaker-remote&lt;/p&gt;
&lt;p&gt;The Pacemaker cluster resource manager is a collection of technologies working together to maintain data integrity and application availability in the event of failures.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* pacemaker: ACL restrictions bypass (CVE-2020-25654)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2020:5487</guid>
    </item>
    <item>
      <title>bdu:2021-03617</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2021-03617</link>
      <description>bdu:2021-03617</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2021-03617</guid>
    </item>
    <item>
      <title>EUVD-2026-45762</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-45762</link>
      <description>EUVD-2026-45762</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-45762</guid>
    </item>
    <item>
      <title>fkie_cve-2020-25654</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-25654</link>
      <description>&lt;p&gt;An ACL bypass flaw was found in pacemaker. An attacker having a local account on the cluster and in the haclient group could use IPC communication with various daemons directly to perform certain tasks that they would be prevented by ACLs from doing if they went through the configuration.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An ACL bypass flaw was found in pacemaker. An attacker having a local account on the cluster and in the haclient group could use IPC communication with various daemons directly to perform certain tasks that they would be prevented by ACLs from doing if they went through the configuration.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-25654</guid>
    </item>
    <item>
      <title>GHSA-3q2f-h5rm-7qv7</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3q2f-h5rm-7qv7</link>
      <description>&lt;p&gt;An ACL bypass flaw was found in pacemaker before 1.1.24-rc1 and 2.0.5-rc2. An attacker having a local account on the cluster and in the haclient group could use IPC communication with various daemons directly to perform certain tasks that they would be prevented by ACLs from doing if they went through the configuration.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An ACL bypass flaw was found in pacemaker before 1.1.24-rc1 and 2.0.5-rc2. An attacker having a local account on the cluster and in the haclient group could use IPC communication with various daemons directly to perform certain tasks that they would be prevented by ACLs from doing if they went through the configuration.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3q2f-h5rm-7qv7</guid>
    </item>
    <item>
      <title>gsd-2020-25654</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-25654</link>
      <description>gsd-2020-25654</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-25654</guid>
    </item>
    <item>
      <title>OESA-2022-1900 — pacemaker security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2022-1900</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP3: pacemaker&lt;/p&gt;
&lt;p&gt;Pacemaker is an advanced, scalable High-Availability cluster resource manager.&#13;
&#13;
Security Fix(es):&#13;
&#13;
An ACL bypass flaw was found in pacemaker. An attacker having a local account on the cluster and in the haclient group could use IPC communication with various daemons directly to perform certain tasks that they would be prevented by ACLs from doing if they went through the configuration.(CVE-2020-25654)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP3: pacemaker&lt;/p&gt;
&lt;p&gt;Pacemaker is an advanced, scalable High-Availability cluster resource manager.&#13;
&#13;
Security Fix(es):&#13;
&#13;
An ACL bypass flaw was found in pacemaker. An attacker having a local account on the cluster and in the haclient group could use IPC communication with various daemons directly to perform certain tasks that they would be prevented by ACLs from doing if they went through the configuration.(CVE-2020-25654)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2022-1900</guid>
    </item>
    <item>
      <title>RHSA-2020:5423 — Red Hat Security Advisory: pacemaker security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2020:5423</link>
      <description>&lt;p&gt;pacemaker: ACL restrictions bypass&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;pacemaker: ACL restrictions bypass&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2020:5423</guid>
    </item>
    <item>
      <title>RHSA-2020:5453 — Red Hat Security Advisory: pacemaker security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2020:5453</link>
      <description>&lt;p&gt;pacemaker: ACL restrictions bypass&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;pacemaker: ACL restrictions bypass&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2020:5453</guid>
    </item>
    <item>
      <title>SUSE-SU-2020:3094-1 — Security update for pacemaker</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2020:3094-1</link>
      <description>&lt;p&gt;Security update for pacemaker&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for pacemaker&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2020:3094-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2020-25654</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-25654</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: pacemaker, Ubuntu:18.04:LTS: pacemaker, Ubuntu:20.04:LTS: pacemaker&lt;/p&gt;
&lt;p&gt;An ACL bypass flaw was found in pacemaker. An attacker having a local account on the cluster and in the haclient group could use IPC communication with various daemons directly to perform certain tasks that they would be prevented by ACLs from doing if they went through the configuration.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: pacemaker, Ubuntu:18.04:LTS: pacemaker, Ubuntu:20.04:LTS: pacemaker&lt;/p&gt;
&lt;p&gt;An ACL bypass flaw was found in pacemaker. An attacker having a local account on the cluster and in the haclient group could use IPC communication with various daemons directly to perform certain tasks that they would be prevented by ACLs from doing if they went through the configuration.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-25654</guid>
    </item>
  </channel>
</rss>
