<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 07:19:26 +0000</lastBuildDate>
    <item>
      <title>ALSA-2022:0368 — Moderate: rpm security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2022:0368</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: rpm-build, AlmaLinux:8: rpm-plugin-fapolicyd&lt;/p&gt;
&lt;p&gt;The RPM Package Manager (RPM) is a command-line driven package management system capable of installing, uninstalling, verifying, querying, and updating software packages.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* rpm: RPM does not require subkeys to have a valid binding signature (CVE-2021-3521)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: rpm-build, AlmaLinux:8: rpm-plugin-fapolicyd&lt;/p&gt;
&lt;p&gt;The RPM Package Manager (RPM) is a command-line driven package management system capable of installing, uninstalling, verifying, querying, and updating software packages.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* rpm: RPM does not require subkeys to have a valid binding signature (CVE-2021-3521)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2022:0368</guid>
    </item>
    <item>
      <title>bdu:2024-04926</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-04926</link>
      <description>bdu:2024-04926</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-04926</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2021-3521 — CVE-2021-3521 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2021-3521</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2021-3521</guid>
    </item>
    <item>
      <title>certfr-2022-avi-544 — De multiples vulnérabilités ont été découvertes dans IBM Netcool
Operations Insight. Certaines d'entre elles permettent…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-544</link>
      <description>certfr-2022-avi-544</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-544</guid>
    </item>
    <item>
      <title>EUVD-2026-20999</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-20999</link>
      <description>EUVD-2026-20999</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-20999</guid>
    </item>
    <item>
      <title>fkie_cve-2021-3521</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-3521</link>
      <description>&lt;p&gt;There is a flaw in RPM&amp;#39;s signature functionality. OpenPGP subkeys are associated with a primary key via a &amp;#34;binding signature.&amp;#34; RPM does not check the binding signature of subkeys prior to importing them. If an attacker is able to add or socially engineer another party to add a malicious subkey to a legitimate public key, RPM could wrongly trust a malicious signature. The greatest impact of this flaw is to data integrity. To exploit this flaw, an attacker must either compromise an RPM repository or convince an administrator to install an untrusted RPM or public key. It is strongly recommended to only use RPMs and public keys from trusted sources.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;There is a flaw in RPM&amp;#39;s signature functionality. OpenPGP subkeys are associated with a primary key via a &amp;#34;binding signature.&amp;#34; RPM does not check the binding signature of subkeys prior to importing them. If an attacker is able to add or socially engineer another party to add a malicious subkey to a legitimate public key, RPM could wrongly trust a malicious signature. The greatest impact of this flaw is to data integrity. To exploit this flaw, an attacker must either compromise an RPM repository or convince an administrator to install an untrusted RPM or public key. It is strongly recommended to only use RPMs and public keys from trusted sources.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-3521</guid>
    </item>
    <item>
      <title>GHSA-pr6x-p264-jrpq</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-pr6x-p264-jrpq</link>
      <description>&lt;p&gt;There is a flaw in RPM&amp;#39;s signature functionality. OpenPGP subkeys are associated with a primary key via a &amp;#34;binding signature.&amp;#34; RPM does not check the binding signature of subkeys prior to importing them. If an attacker is able to add or socially engineer another party to add a malicious subkey to a legitimate public key, RPM could wrongly trust a malicious signature. The greatest impact of this flaw is to data integrity. To exploit this flaw, an attacker must either compromise an RPM repository or convince an administrator to install an untrusted RPM or public key. It is strongly recommended to only use RPMs and public keys from trusted sources.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;There is a flaw in RPM&amp;#39;s signature functionality. OpenPGP subkeys are associated with a primary key via a &amp;#34;binding signature.&amp;#34; RPM does not check the binding signature of subkeys prior to importing them. If an attacker is able to add or socially engineer another party to add a malicious subkey to a legitimate public key, RPM could wrongly trust a malicious signature. The greatest impact of this flaw is to data integrity. To exploit this flaw, an attacker must either compromise an RPM repository or convince an administrator to install an untrusted RPM or public key. It is strongly recommended to only use RPMs and public keys from trusted sources.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-pr6x-p264-jrpq</guid>
    </item>
    <item>
      <title>gsd-2021-3521</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-3521</link>
      <description>gsd-2021-3521</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-3521</guid>
    </item>
    <item>
      <title>msrc_CVE-2021-3521 — There is a flaw in RPM's signature functionality. OpenPGP subkeys are associated with a primary key via a "binding sign…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2021-3521</link>
      <description>msrc_CVE-2021-3521</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2021-3521</guid>
    </item>
    <item>
      <title>OESA-2021-1431 — rpm security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2021-1431</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: rpm, openEuler:20.03-LTS-SP2: rpm&lt;/p&gt;
&lt;p&gt;The RPM Package Manager (RPM) is a powerful package management system capability as below&#13;
&#13;
Security Fix(es):&#13;
&#13;
The OpenPGP subkey is associated with the master key through a binding signature. RPM will not check their binding signature before importing the subkey; if the attacker can add it or the other party of social engineering adds the malicious subkey to the legal public Key, RPM may mistakenly trust malicious signatures.(CVE-2021-3521)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: rpm, openEuler:20.03-LTS-SP2: rpm&lt;/p&gt;
&lt;p&gt;The RPM Package Manager (RPM) is a powerful package management system capability as below&#13;
&#13;
Security Fix(es):&#13;
&#13;
The OpenPGP subkey is associated with the master key through a binding signature. RPM will not check their binding signature before importing the subkey; if the attacker can add it or the other party of social engineering adds the malicious subkey to the legal public Key, RPM may mistakenly trust malicious signatures.(CVE-2021-3521)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2021-1431</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:12245-1 — librpmbuild9-4.17.1-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12245-1</link>
      <description>&lt;p&gt;librpmbuild9-4.17.1-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;librpmbuild9-4.17.1-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:12245-1</guid>
    </item>
    <item>
      <title>RHSA-2022:0254 — Red Hat Security Advisory: rpm security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2022:0254</link>
      <description>&lt;p&gt;rpm: RPM does not require subkeys to have a valid binding signature&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;rpm: RPM does not require subkeys to have a valid binding signature&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2022:0254</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:1557-2 — Security update for rpm</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:1557-2</link>
      <description>&lt;p&gt;Security update for rpm&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for rpm&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:1557-2</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-3521</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-3521</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: rpm, Ubuntu:Pro:16.04:LTS: rpm, Ubuntu:Pro:18.04:LTS: rpm, Ubuntu:Pro:20.04:LTS: rpm, Ubuntu:22.04:LTS: rpm, Ubuntu:24.04:LTS: rpm, Ubuntu:25.10: rpm, Ubuntu:26.04:LTS: rpm&lt;/p&gt;
&lt;p&gt;There is a flaw in RPM&amp;#39;s signature functionality. OpenPGP subkeys are associated with a primary key via a &amp;#34;binding signature.&amp;#34; RPM does not check the binding signature of subkeys prior to importing them. If an attacker is able to add or socially engineer another party to add a malicious subkey to a legitimate public key, RPM could wrongly trust a malicious signature. The greatest impact of this flaw is to data integrity. To exploit this flaw, an attacker must either compromise an RPM repository or convince an administrator to install an untrusted RPM or public key. It is strongly recommended to only use RPMs and public keys from trusted sources.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: rpm, Ubuntu:Pro:16.04:LTS: rpm, Ubuntu:Pro:18.04:LTS: rpm, Ubuntu:Pro:20.04:LTS: rpm, Ubuntu:22.04:LTS: rpm, Ubuntu:24.04:LTS: rpm, Ubuntu:25.10: rpm, Ubuntu:26.04:LTS: rpm&lt;/p&gt;
&lt;p&gt;There is a flaw in RPM&amp;#39;s signature functionality. OpenPGP subkeys are associated with a primary key via a &amp;#34;binding signature.&amp;#34; RPM does not check the binding signature of subkeys prior to importing them. If an attacker is able to add or socially engineer another party to add a malicious subkey to a legitimate public key, RPM could wrongly trust a malicious signature. The greatest impact of this flaw is to data integrity. To exploit this flaw, an attacker must either compromise an RPM repository or convince an administrator to install an untrusted RPM or public key. It is strongly recommended to only use RPMs and public keys from trusted sources.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-3521</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-1243 — RPM: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1243</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in RPM ausnutzen, um Sicherheitsvorkehrungen zu umgehen, Dateien zu manipulieren oder sonstige Auswirkungen zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in RPM ausnutzen, um Sicherheitsvorkehrungen zu umgehen, Dateien zu manipulieren oder sonstige Auswirkungen zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1243</guid>
    </item>
  </channel>
</rss>
