<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 04:57:08 +0000</lastBuildDate>
    <item>
      <title>ALSA-2021:1796 — Moderate: container-tools:rhel8 security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2021:1796</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: cockpit-podman, AlmaLinux:8: conmon, AlmaLinux:8: containernetworking-plugins, AlmaLinux:8: crit, AlmaLinux:8: criu, AlmaLinux:8: fuse-overlayfs, AlmaLinux:8: libslirp, AlmaLinux:8: libslirp-devel, AlmaLinux:8: python3-criu, AlmaLinux:8: slirp4netns and 1 more&lt;/p&gt;
&lt;p&gt;The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* golang: crypto/ssh: crafted authentication request can lead to nil pointer dereference (CVE-2020-29652)&lt;/p&gt;
&lt;p&gt;* podman: Remote traffic to rootless containers is seen as orginating from localhost (CVE-2021-20199)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: cockpit-podman, AlmaLinux:8: conmon, AlmaLinux:8: containernetworking-plugins, AlmaLinux:8: crit, AlmaLinux:8: criu, AlmaLinux:8: fuse-overlayfs, AlmaLinux:8: libslirp, AlmaLinux:8: libslirp-devel, AlmaLinux:8: python3-criu, AlmaLinux:8: slirp4netns and 1 more&lt;/p&gt;
&lt;p&gt;The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* golang: crypto/ssh: crafted authentication request can lead to nil pointer dereference (CVE-2020-29652)&lt;/p&gt;
&lt;p&gt;* podman: Remote traffic to rootless containers is seen as orginating from localhost (CVE-2021-20199)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2021:1796</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2021-20199 — CVE-2021-20199 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2021-20199</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2021-20199</guid>
    </item>
    <item>
      <title>EUVD-2026-21513</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-21513</link>
      <description>EUVD-2026-21513</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-21513</guid>
    </item>
    <item>
      <title>fkie_cve-2021-20199</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-20199</link>
      <description>&lt;p&gt;Rootless containers run with Podman, receive all traffic with a source IP address of 127.0.0.1 (including from remote hosts). This impacts containerized applications that trust localhost (127.0.01) connections by default and do not require authentication. This issue affects Podman 1.8.0 onwards.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Rootless containers run with Podman, receive all traffic with a source IP address of 127.0.0.1 (including from remote hosts). This impacts containerized applications that trust localhost (127.0.01) connections by default and do not require authentication. This issue affects Podman 1.8.0 onwards.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-20199</guid>
    </item>
    <item>
      <title>GHSA-grh6-q6m2-rh72 — Podman Origin Validation Error</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-grh6-q6m2-rh72</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/containers/podman/v3&lt;/p&gt;
&lt;p&gt;Rootless containers run with Podman, receive all traffic with a source IP address of 127.0.0.1 (including from remote hosts). This impacts containerized applications that trust localhost (127.0.01) connections by default and do not require authentication. This issue affects Podman versions from 1.8.0 to 3.0.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/containers/podman/v3&lt;/p&gt;
&lt;p&gt;Rootless containers run with Podman, receive all traffic with a source IP address of 127.0.0.1 (including from remote hosts). This impacts containerized applications that trust localhost (127.0.01) connections by default and do not require authentication. This issue affects Podman versions from 1.8.0 to 3.0.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-grh6-q6m2-rh72</guid>
    </item>
    <item>
      <title>gsd-2021-20199</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-20199</link>
      <description>gsd-2021-20199</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-20199</guid>
    </item>
    <item>
      <title>msrc_CVE-2021-20199 — Rootless containers run with Podman receive all traffic with a source IP address of 127.0.0.1 (including from remote ho…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2021-20199</link>
      <description>msrc_CVE-2021-20199</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2021-20199</guid>
    </item>
    <item>
      <title>openSUSE-SU-2022:23018-1 — Security update for conmon, libcontainers-common, libseccomp, podman</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2022:23018-1</link>
      <description>&lt;p&gt;Security update for conmon, libcontainers-common, libseccomp, podman&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for conmon, libcontainers-common, libseccomp, podman&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2022:23018-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2022:23018-1 — Security update for conmon, libcontainers-common, libseccomp, podman</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2022:23018-1</link>
      <description>&lt;p&gt;Security update for conmon, libcontainers-common, libseccomp, podman&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for conmon, libcontainers-common, libseccomp, podman&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2022:23018-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-20199</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-20199</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:22.04:LTS: libpod, Ubuntu:Pro:24.04:LTS: libpod&lt;/p&gt;
&lt;p&gt;Rootless containers run with Podman, receive all traffic with a source IP address of 127.0.0.1 (including from remote hosts). This impacts containerized applications that trust localhost (127.0.01) connections by default and do not require authentication. This issue affects Podman 1.8.0 onwards.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:22.04:LTS: libpod, Ubuntu:Pro:24.04:LTS: libpod&lt;/p&gt;
&lt;p&gt;Rootless containers run with Podman, receive all traffic with a source IP address of 127.0.0.1 (including from remote hosts). This impacts containerized applications that trust localhost (127.0.01) connections by default and do not require authentication. This issue affects Podman 1.8.0 onwards.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-20199</guid>
    </item>
  </channel>
</rss>
