<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 16:19:37 +0000</lastBuildDate>
    <item>
      <title>ALSA-2021:1762 — Moderate: virt:rhel and virt-devel:rhel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2021:1762</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: hivex, AlmaLinux:8: hivex-devel, AlmaLinux:8: libguestfs-winsupport, AlmaLinux:8: libiscsi, AlmaLinux:8: libiscsi-devel, AlmaLinux:8: libiscsi-utils, AlmaLinux:8: libnbd, AlmaLinux:8: libnbd-devel, AlmaLinux:8: libvirt-dbus, AlmaLinux:8: nbdfuse and 36 more&lt;/p&gt;
&lt;p&gt;Kernel-based Virtual Machine (KVM) offers a full virtualization solution for Linux on numerous hardware platforms. The virt:rhel module contains packages which provide user-space components used to run virtual machines using KVM. The packages also provide APIs for managing and interacting with the virtualized systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libvirt: double free in qemuAgentGetInterfaces() in qemu_agent.c (CVE-2020-25637)&lt;/p&gt;
&lt;p&gt;* QEMU: heap buffer overflow in msix_table_mmio_write() in hw/pci/msix.c (CVE-2020-27821)&lt;/p&gt;
&lt;p&gt;* QEMU: ide: atapi: OOB access while processing read commands (CVE-2020-29443)&lt;/p&gt;
&lt;p&gt;* QEMU: heap buffer overflow in iscsi_aio_ioctl_cb() in block/iscsi.c may lead to information disclosure (CVE-2020-11947)&lt;/p&gt;
&lt;p&gt;* QEMU: reachable assertion failure in net_tx_pkt_add_raw_fragment() in hw/net/net_tx_pkt.c (CVE-2020-16092)&lt;/p&gt;
&lt;p&gt;* QEMU: infinite loop in e1000e_write_packet_to_guest() in hw/net/e1000e_core.c (CVE-2020-25707)&lt;/p&gt;
&lt;p&gt;* QEMU: assertion failure through usb_packet_unmap() in hw/usb/hcd-ehci.c (CVE-2020-25723)&lt;/p&gt;
&lt;p&gt;* QEMU: e1000e: infinite loop scenario in case of null packet descriptor (CVE-2020-28916)&lt;/p&gt;
&lt;p&gt;* QEMU: slirp: out-of-bounds access while processing ARP/NCSI packets (CVE-2020-29129, CVE-2020-29130)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Rel…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: hivex, AlmaLinux:8: hivex-devel, AlmaLinux:8: libguestfs-winsupport, AlmaLinux:8: libiscsi, AlmaLinux:8: libiscsi-devel, AlmaLinux:8: libiscsi-utils, AlmaLinux:8: libnbd, AlmaLinux:8: libnbd-devel, AlmaLinux:8: libvirt-dbus, AlmaLinux:8: nbdfuse and 36 more&lt;/p&gt;
&lt;p&gt;Kernel-based Virtual Machine (KVM) offers a full virtualization solution for Linux on numerous hardware platforms. The virt:rhel module contains packages which provide user-space components used to run virtual machines using KVM. The packages also provide APIs for managing and interacting with the virtualized systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libvirt: double free in qemuAgentGetInterfaces() in qemu_agent.c (CVE-2020-25637)&lt;/p&gt;
&lt;p&gt;* QEMU: heap buffer overflow in msix_table_mmio_write() in hw/pci/msix.c (CVE-2020-27821)&lt;/p&gt;
&lt;p&gt;* QEMU: ide: atapi: OOB access while processing read commands (CVE-2020-29443)&lt;/p&gt;
&lt;p&gt;* QEMU: heap buffer overflow in iscsi_aio_ioctl_cb() in block/iscsi.c may lead to information disclosure (CVE-2020-11947)&lt;/p&gt;
&lt;p&gt;* QEMU: reachable assertion failure in net_tx_pkt_add_raw_fragment() in hw/net/net_tx_pkt.c (CVE-2020-16092)&lt;/p&gt;
&lt;p&gt;* QEMU: infinite loop in e1000e_write_packet_to_guest() in hw/net/e1000e_core.c (CVE-2020-25707)&lt;/p&gt;
&lt;p&gt;* QEMU: assertion failure through usb_packet_unmap() in hw/usb/hcd-ehci.c (CVE-2020-25723)&lt;/p&gt;
&lt;p&gt;* QEMU: e1000e: infinite loop scenario in case of null packet descriptor (CVE-2020-28916)&lt;/p&gt;
&lt;p&gt;* QEMU: slirp: out-of-bounds access while processing ARP/NCSI packets (CVE-2020-29129, CVE-2020-29130)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Rel…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2021:1762</guid>
    </item>
    <item>
      <title>bdu:2021-05249</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2021-05249</link>
      <description>bdu:2021-05249</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2021-05249</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2020-29443 — CVE-2020-29443 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2020-29443</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2020-29443</guid>
    </item>
    <item>
      <title>cnvd-2021-06865</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2021-06865</link>
      <description>cnvd-2021-06865</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2021-06865</guid>
    </item>
    <item>
      <title>EUVD-2026-47323</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-47323</link>
      <description>EUVD-2026-47323</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-47323</guid>
    </item>
    <item>
      <title>fkie_cve-2020-29443</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-29443</link>
      <description>&lt;p&gt;ide_atapi_cmd_reply_end in hw/ide/atapi.c in QEMU 5.1.0 allows out-of-bounds read access because a buffer index is not validated.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ide_atapi_cmd_reply_end in hw/ide/atapi.c in QEMU 5.1.0 allows out-of-bounds read access because a buffer index is not validated.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-29443</guid>
    </item>
    <item>
      <title>GHSA-3q92-j8r6-g6h8</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3q92-j8r6-g6h8</link>
      <description>&lt;p&gt;ide_atapi_cmd_reply_end in hw/ide/atapi.c in QEMU 5.1.0 allows out-of-bounds read access because a buffer index is not validated.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ide_atapi_cmd_reply_end in hw/ide/atapi.c in QEMU 5.1.0 allows out-of-bounds read access because a buffer index is not validated.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3q92-j8r6-g6h8</guid>
    </item>
    <item>
      <title>gsd-2020-29443</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-29443</link>
      <description>gsd-2020-29443</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-29443</guid>
    </item>
    <item>
      <title>OESA-2021-1128 — qemu security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2021-1128</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS: qemu, openEuler:20.03-LTS-SP1: qemu&lt;/p&gt;
&lt;p&gt;QEMU is a FAST! processor emulator using dynamic translation to achieve good emulation speed.  QEMU has two operating modes:     Full system emulation. In this mode, QEMU emulates a full system (for example a PC),    including one or several processors and various peripherals. It can be used to launch    different Operating Systems without rebooting the PC or to debug system code.     User mode emulation. In this mode, QEMU can launch processes compiled for one CPU on another CPU.    It can be used to launch the Wine Windows API emulator (https://www.winehq.org) or to ease    cross-compilation and cross-debugging. You can refer to https://www.qemu.org for more infortmation.&#13;
&#13;
Security Fix(es):&#13;
&#13;
ide_atapi_cmd_reply_end in hw/ide/atapi.c in QEMU 5.1.0 allows out-of-bounds read access because a buffer index is not validated.(CVE-2020-29443)&#13;
&#13;
An integer overflow issue was found in the vmxnet3 NIC emulator of the QEMU for versions up to v5.2.0. It may occur if a guest was to supply invalid values for rx/tx queue size or other NIC parameters. A privileged guest user may use this flaw to crash the QEMU process on the host resulting in DoS scenario.(CVE-2021-20203)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS: qemu, openEuler:20.03-LTS-SP1: qemu&lt;/p&gt;
&lt;p&gt;QEMU is a FAST! processor emulator using dynamic translation to achieve good emulation speed.  QEMU has two operating modes:     Full system emulation. In this mode, QEMU emulates a full system (for example a PC),    including one or several processors and various peripherals. It can be used to launch    different Operating Systems without rebooting the PC or to debug system code.     User mode emulation. In this mode, QEMU can launch processes compiled for one CPU on another CPU.    It can be used to launch the Wine Windows API emulator (https://www.winehq.org) or to ease    cross-compilation and cross-debugging. You can refer to https://www.qemu.org for more infortmation.&#13;
&#13;
Security Fix(es):&#13;
&#13;
ide_atapi_cmd_reply_end in hw/ide/atapi.c in QEMU 5.1.0 allows out-of-bounds read access because a buffer index is not validated.(CVE-2020-29443)&#13;
&#13;
An integer overflow issue was found in the vmxnet3 NIC emulator of the QEMU for versions up to v5.2.0. It may occur if a guest was to supply invalid values for rx/tx queue size or other NIC parameters. A privileged guest user may use this flaw to crash the QEMU process on the host resulting in DoS scenario.(CVE-2021-20203)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2021-1128</guid>
    </item>
    <item>
      <title>RHBA-2021:0639 — Red Hat Bug Fix Advisory: virt:8.3 bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhba-2021:0639</link>
      <description>&lt;p&gt;QEMU: infinite loop in e1000e_write_packet_to_guest() in hw/net/e1000e_core.c QEMU: assertion failure through usb_packet_unmap() in hw/usb/hcd-ehci.c QEMU: net: an assert failure via eth_get_gso_type QEMU: heap buffer overflow in msix_table_mmio_write() in hw/pci/msix.c QEMU: ide: atapi: OOB access while processing read commands QEMU: virtiofsd: potential privileged host device access from guest&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;QEMU: infinite loop in e1000e_write_packet_to_guest() in hw/net/e1000e_core.c QEMU: assertion failure through usb_packet_unmap() in hw/usb/hcd-ehci.c QEMU: net: an assert failure via eth_get_gso_type QEMU: heap buffer overflow in msix_table_mmio_write() in hw/pci/msix.c QEMU: ide: atapi: OOB access while processing read commands QEMU: virtiofsd: potential privileged host device access from guest&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhba-2021:0639</guid>
    </item>
    <item>
      <title>RHSA-2021:2322 — Red Hat Security Advisory: qemu-kvm security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:2322</link>
      <description>&lt;p&gt;QEMU: ide: atapi: OOB access while processing read commands&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;QEMU: ide: atapi: OOB access while processing read commands&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:2322</guid>
    </item>
    <item>
      <title>SUSE-SU-2021:1305-1 — Security update for qemu</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2021:1305-1</link>
      <description>&lt;p&gt;Security update for qemu&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for qemu&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2021:1305-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2020-29443</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-29443</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: qemu, Ubuntu:16.04:LTS: qemu, Ubuntu:18.04:LTS: qemu, Ubuntu:20.04:LTS: qemu&lt;/p&gt;
&lt;p&gt;ide_atapi_cmd_reply_end in hw/ide/atapi.c in QEMU 5.1.0 allows out-of-bounds read access because a buffer index is not validated.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: qemu, Ubuntu:16.04:LTS: qemu, Ubuntu:18.04:LTS: qemu, Ubuntu:20.04:LTS: qemu&lt;/p&gt;
&lt;p&gt;ide_atapi_cmd_reply_end in hw/ide/atapi.c in QEMU 5.1.0 allows out-of-bounds read access because a buffer index is not validated.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-29443</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-1275 — QEMU: Schwachstelle ermöglicht Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1275</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in QEMU ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in QEMU ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1275</guid>
    </item>
  </channel>
</rss>
