<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 12:12:10 +0000</lastBuildDate>
    <item>
      <title>ALSA-2021:1734 — Moderate: shim security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2021:1734</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: shim-aa64, AlmaLinux:8: shim-ia32, AlmaLinux:8: shim-unsigned-aarch64, AlmaLinux:8: shim-unsigned-x64, AlmaLinux:8: shim-x64&lt;/p&gt;
&lt;p&gt;The shim package contains a first-stage UEFI boot loader that handles chaining to a trusted full boot loader under secure boot environments.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* grub2: acpi command allows privileged user to load crafted ACPI tables when Secure Boot is enabled (CVE-2020-14372)&lt;/p&gt;
&lt;p&gt;* grub2: Use-after-free in rmmod command (CVE-2020-25632)&lt;/p&gt;
&lt;p&gt;* grub2: Out-of-bounds write in grub_usb_device_initialize() (CVE-2020-25647)&lt;/p&gt;
&lt;p&gt;* grub2: Stack buffer overflow in grub_parser_split_cmdline() (CVE-2020-27749)&lt;/p&gt;
&lt;p&gt;* grub2: cutmem command allows privileged user to remove memory regions when Secure Boot is enabled (CVE-2020-27779)&lt;/p&gt;
&lt;p&gt;* grub2: Heap out-of-bounds write in short form option parser (CVE-2021-20225)&lt;/p&gt;
&lt;p&gt;* grub2: Heap out-of-bounds write due to miscalculation of space required for quoting (CVE-2021-20233)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: shim-aa64, AlmaLinux:8: shim-ia32, AlmaLinux:8: shim-unsigned-aarch64, AlmaLinux:8: shim-unsigned-x64, AlmaLinux:8: shim-x64&lt;/p&gt;
&lt;p&gt;The shim package contains a first-stage UEFI boot loader that handles chaining to a trusted full boot loader under secure boot environments.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* grub2: acpi command allows privileged user to load crafted ACPI tables when Secure Boot is enabled (CVE-2020-14372)&lt;/p&gt;
&lt;p&gt;* grub2: Use-after-free in rmmod command (CVE-2020-25632)&lt;/p&gt;
&lt;p&gt;* grub2: Out-of-bounds write in grub_usb_device_initialize() (CVE-2020-25647)&lt;/p&gt;
&lt;p&gt;* grub2: Stack buffer overflow in grub_parser_split_cmdline() (CVE-2020-27749)&lt;/p&gt;
&lt;p&gt;* grub2: cutmem command allows privileged user to remove memory regions when Secure Boot is enabled (CVE-2020-27779)&lt;/p&gt;
&lt;p&gt;* grub2: Heap out-of-bounds write in short form option parser (CVE-2021-20225)&lt;/p&gt;
&lt;p&gt;* grub2: Heap out-of-bounds write due to miscalculation of space required for quoting (CVE-2021-20233)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2021:1734</guid>
    </item>
    <item>
      <title>bdu:2022-00304</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-00304</link>
      <description>bdu:2022-00304</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-00304</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2021-20233 — CVE-2021-20233 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2021-20233</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2021-20233</guid>
    </item>
    <item>
      <title>certfr-2021-avi-172 — GRUB2 est le bootloader le plus couramment utilisé par les distributions
Linux pour démarrer le système d'exploitation.…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2021-avi-172</link>
      <description>certfr-2021-avi-172</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2021-avi-172</guid>
    </item>
    <item>
      <title>cnvd-2021-16935</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2021-16935</link>
      <description>cnvd-2021-16935</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2021-16935</guid>
    </item>
    <item>
      <title>EUVD-2026-21574</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-21574</link>
      <description>EUVD-2026-21574</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-21574</guid>
    </item>
    <item>
      <title>fkie_cve-2021-20233</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-20233</link>
      <description>&lt;p&gt;A flaw was found in grub2 in versions prior to 2.06. Setparam_prefix() in the menu rendering code performs a length calculation on the assumption that expressing a quoted single quote will require 3 characters, while it actually requires 4 characters which allows an attacker to corrupt memory by one byte for each quote in the input. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in grub2 in versions prior to 2.06. Setparam_prefix() in the menu rendering code performs a length calculation on the assumption that expressing a quoted single quote will require 3 characters, while it actually requires 4 characters which allows an attacker to corrupt memory by one byte for each quote in the input. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-20233</guid>
    </item>
    <item>
      <title>GHSA-257g-8w4g-3cc3</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-257g-8w4g-3cc3</link>
      <description>&lt;p&gt;A flaw was found in grub2 in versions prior to 2.06. Setparam_prefix() in the menu rendering code performs a length calculation on the assumption that expressing a quoted single quote will require 3 characters, while it actually requires 4 characters which allows an attacker to corrupt memory by one byte for each quote in the input. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in grub2 in versions prior to 2.06. Setparam_prefix() in the menu rendering code performs a length calculation on the assumption that expressing a quoted single quote will require 3 characters, while it actually requires 4 characters which allows an attacker to corrupt memory by one byte for each quote in the input. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-257g-8w4g-3cc3</guid>
    </item>
    <item>
      <title>gsd-2021-20233</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-20233</link>
      <description>gsd-2021-20233</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-20233</guid>
    </item>
    <item>
      <title>ICSA-21-336-06 — Hitachi Energy APM Edge</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-21-336-06</link>
      <description>&lt;p&gt;An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer dereference will result, leading to a crash and a denial of service attack. A server is only vulnerable if it has TLSv1.2 and renegotiation enabled (which is the default configuration). OpenSSL TLS clients are not impacted by this issue. All OpenSSL 1.1.1 versions are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1k. OpenSSL 1.0.2 is not impacted by this issue. Fixed in OpenSSL 1.1.1k (Affected 1.1.1-1.1.1j). Hitachi Energy is aware of public reports of this vulnerability in the following open-source software components: OpenSSL, LibSSL, libxml2 and GRUB2 bootloader. The vulnerability also affects some APM Edge products. An attacker who successfully exploits this vulnerability could cause the product to become inaccessible. SEE NVD for full Description. In situations where an attacker receives automated notification of the success or failure of a decryption attempt an attacker, after sending a very large number of messages to be decrypted, can recover a CMS/PKCS7 transported encryption key or decrypt any RSA encrypted message that was encrypted with the public RSA key, using a Bleichenbacher padding oracle attack. Applications are not a…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer dereference will result, leading to a crash and a denial of service attack. A server is only vulnerable if it has TLSv1.2 and renegotiation enabled (which is the default configuration). OpenSSL TLS clients are not impacted by this issue. All OpenSSL 1.1.1 versions are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1k. OpenSSL 1.0.2 is not impacted by this issue. Fixed in OpenSSL 1.1.1k (Affected 1.1.1-1.1.1j). Hitachi Energy is aware of public reports of this vulnerability in the following open-source software components: OpenSSL, LibSSL, libxml2 and GRUB2 bootloader. The vulnerability also affects some APM Edge products. An attacker who successfully exploits this vulnerability could cause the product to become inaccessible. SEE NVD for full Description. In situations where an attacker receives automated notification of the success or failure of a decryption attempt an attacker, after sending a very large number of messages to be decrypted, can recover a CMS/PKCS7 transported encryption key or decrypt any RSA encrypted message that was encrypted with the public RSA key, using a Bleichenbacher padding oracle attack. Applications are not a…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-21-336-06</guid>
    </item>
    <item>
      <title>msrc_CVE-2021-20233 — A flaw was found in grub2 in versions prior to 2.06. Setparam_prefix() in the menu rendering code performs a length cal…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2021-20233</link>
      <description>msrc_CVE-2021-20233</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2021-20233</guid>
    </item>
    <item>
      <title>OESA-2021-1095 — grub2 security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2021-1095</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS: grub2, openEuler:20.03-LTS-SP1: grub2&lt;/p&gt;
&lt;p&gt;GNU GRUB is a Multiboot boot loader. It was derived from GRUB, the GRand Unified Bootloader, which was originally designed and implemented by Erich Stefan Boleyn. Briefly, a boot loader is the first software program that runs when a computer starts. It is responsible for loading and transferring control to the operating system kernel software (such as the Hurd or Linux). The kernel, in turn, initializes the rest of the operating system (e.g. GNU).&#13;
&#13;
Security Fix(es):&#13;
&#13;
A flaw was found in grub2 in versions prior to 2.06. The rmmod implementation allows the unloading of a module used as a dependency without checking if any other dependent module is still loaded leading to a use-after-free scenario. This could allow arbitrary code to be executed or a bypass of Secure Boot protections. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.(CVE-2020-25632)&#13;
&#13;
A flaw was found in grub2 in versions prior to 2.06. During USB device initialization, descriptors are read with very little bounds checking and assumes the USB device is providing sane values. If properly exploited, an attacker could trigger memory corruption leading to arbitrary code execution allowing a bypass of the Secure Boot mechanism. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.(CVE-2020-25647)&#13;
&#13;
A flaw was found in grub2 in versions prior to 2.06. Variable names present are expanded…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS: grub2, openEuler:20.03-LTS-SP1: grub2&lt;/p&gt;
&lt;p&gt;GNU GRUB is a Multiboot boot loader. It was derived from GRUB, the GRand Unified Bootloader, which was originally designed and implemented by Erich Stefan Boleyn. Briefly, a boot loader is the first software program that runs when a computer starts. It is responsible for loading and transferring control to the operating system kernel software (such as the Hurd or Linux). The kernel, in turn, initializes the rest of the operating system (e.g. GNU).&#13;
&#13;
Security Fix(es):&#13;
&#13;
A flaw was found in grub2 in versions prior to 2.06. The rmmod implementation allows the unloading of a module used as a dependency without checking if any other dependent module is still loaded leading to a use-after-free scenario. This could allow arbitrary code to be executed or a bypass of Secure Boot protections. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.(CVE-2020-25632)&#13;
&#13;
A flaw was found in grub2 in versions prior to 2.06. During USB device initialization, descriptors are read with very little bounds checking and assumes the USB device is providing sane values. If properly exploited, an attacker could trigger memory corruption leading to arbitrary code execution allowing a bypass of the Secure Boot mechanism. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.(CVE-2020-25647)&#13;
&#13;
A flaw was found in grub2 in versions prior to 2.06. Variable names present are expanded…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2021-1095</guid>
    </item>
    <item>
      <title>openSUSE-SU-2021:0462-1 — Security update for grub2</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2021:0462-1</link>
      <description>&lt;p&gt;Security update for grub2&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for grub2&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2021:0462-1</guid>
    </item>
    <item>
      <title>RHSA-2021:0697 — Red Hat Security Advisory: grub2 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:0697</link>
      <description>&lt;p&gt;grub2: acpi command allows privileged user to load crafted ACPI tables when Secure Boot is enabled grub2: Use-after-free in rmmod command grub2: Out-of-bounds write in grub_usb_device_initialize() grub2: Stack buffer overflow in grub_parser_split_cmdline() grub2: cutmem command allows privileged user to remove memory regions when Secure Boot is enabled grub2: Heap out-of-bounds write in short form option parser grub2: Heap out-of-bounds write due to miscalculation of space required for quoting&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;grub2: acpi command allows privileged user to load crafted ACPI tables when Secure Boot is enabled grub2: Use-after-free in rmmod command grub2: Out-of-bounds write in grub_usb_device_initialize() grub2: Stack buffer overflow in grub_parser_split_cmdline() grub2: cutmem command allows privileged user to remove memory regions when Secure Boot is enabled grub2: Heap out-of-bounds write in short form option parser grub2: Heap out-of-bounds write due to miscalculation of space required for quoting&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:0697</guid>
    </item>
    <item>
      <title>SUSE-SU-2021:0679-1 — Security update for grub2</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2021:0679-1</link>
      <description>&lt;p&gt;Security update for grub2&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for grub2&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2021:0679-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-20233</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-20233</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: grub2-signed, Ubuntu:18.04:LTS: grub2-signed, Ubuntu:18.04:LTS: grub2-unsigned, Ubuntu:20.04:LTS: grub2-signed, Ubuntu:20.04:LTS: grub2-unsigned&lt;/p&gt;
&lt;p&gt;A flaw was found in grub2 in versions prior to 2.06. Setparam_prefix() in the menu rendering code performs a length calculation on the assumption that expressing a quoted single quote will require 3 characters, while it actually requires 4 characters which allows an attacker to corrupt memory by one byte for each quote in the input. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: grub2-signed, Ubuntu:18.04:LTS: grub2-signed, Ubuntu:18.04:LTS: grub2-unsigned, Ubuntu:20.04:LTS: grub2-signed, Ubuntu:20.04:LTS: grub2-unsigned&lt;/p&gt;
&lt;p&gt;A flaw was found in grub2 in versions prior to 2.06. Setparam_prefix() in the menu rendering code performs a length calculation on the assumption that expressing a quoted single quote will require 3 characters, while it actually requires 4 characters which allows an attacker to corrupt memory by one byte for each quote in the input. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-20233</guid>
    </item>
  </channel>
</rss>
