<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 10:28:04 +0000</lastBuildDate>
    <item>
      <title>ALSA-2021:4191 — Moderate: virt:rhel and virt-devel:rhel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2021:4191</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: hivex, AlmaLinux:8: hivex-devel, AlmaLinux:8: libguestfs, AlmaLinux:8: libguestfs-bash-completion, AlmaLinux:8: libguestfs-benchmarking, AlmaLinux:8: libguestfs-devel, AlmaLinux:8: libguestfs-gfs2, AlmaLinux:8: libguestfs-gobject, AlmaLinux:8: libguestfs-gobject-devel, AlmaLinux:8: libguestfs-inspect-icons and 83 more&lt;/p&gt;
&lt;p&gt;Kernel-based Virtual Machine (KVM) offers a full virtualization solution for Linux on numerous hardware platforms. The virt:rhel module contains packages which provide user-space components used to run virtual machines using KVM. The packages also provide APIs for managing and interacting with the virtualized systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* QEMU: net: e1000e: use-after-free while sending packets (CVE-2020-15859)&lt;/p&gt;
&lt;p&gt;* QEMU: slirp: invalid pointer initialization may lead to information disclosure (bootp) (CVE-2021-3592)&lt;/p&gt;
&lt;p&gt;* QEMU: slirp: invalid pointer initialization may lead to information disclosure (udp6) (CVE-2021-3593)&lt;/p&gt;
&lt;p&gt;* QEMU: slirp: invalid pointer initialization may lead to information disclosure (udp) (CVE-2021-3594)&lt;/p&gt;
&lt;p&gt;* QEMU: slirp: invalid pointer initialization may lead to information disclosure (tftp) (CVE-2021-3595)&lt;/p&gt;
&lt;p&gt;* libvirt: Insecure sVirt label generation (CVE-2021-3631)&lt;/p&gt;
&lt;p&gt;* libvirt: Improper locking on ACL failure in virStoragePoolLookupByTargetPath API (CVE-2021-3667)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: hivex, AlmaLinux:8: hivex-devel, AlmaLinux:8: libguestfs, AlmaLinux:8: libguestfs-bash-completion, AlmaLinux:8: libguestfs-benchmarking, AlmaLinux:8: libguestfs-devel, AlmaLinux:8: libguestfs-gfs2, AlmaLinux:8: libguestfs-gobject, AlmaLinux:8: libguestfs-gobject-devel, AlmaLinux:8: libguestfs-inspect-icons and 83 more&lt;/p&gt;
&lt;p&gt;Kernel-based Virtual Machine (KVM) offers a full virtualization solution for Linux on numerous hardware platforms. The virt:rhel module contains packages which provide user-space components used to run virtual machines using KVM. The packages also provide APIs for managing and interacting with the virtualized systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* QEMU: net: e1000e: use-after-free while sending packets (CVE-2020-15859)&lt;/p&gt;
&lt;p&gt;* QEMU: slirp: invalid pointer initialization may lead to information disclosure (bootp) (CVE-2021-3592)&lt;/p&gt;
&lt;p&gt;* QEMU: slirp: invalid pointer initialization may lead to information disclosure (udp6) (CVE-2021-3593)&lt;/p&gt;
&lt;p&gt;* QEMU: slirp: invalid pointer initialization may lead to information disclosure (udp) (CVE-2021-3594)&lt;/p&gt;
&lt;p&gt;* QEMU: slirp: invalid pointer initialization may lead to information disclosure (tftp) (CVE-2021-3595)&lt;/p&gt;
&lt;p&gt;* libvirt: Insecure sVirt label generation (CVE-2021-3631)&lt;/p&gt;
&lt;p&gt;* libvirt: Improper locking on ACL failure in virStoragePoolLookupByTargetPath API (CVE-2021-3667)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2021:4191</guid>
    </item>
    <item>
      <title>bdu:2024-01495</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-01495</link>
      <description>bdu:2024-01495</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-01495</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2021-3592 — CVE-2021-3592 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2021-3592</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2021-3592</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0997 — De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Certaines d'entre elles permettent à un a…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0997</link>
      <description>certfr-2024-avi-0997</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0997</guid>
    </item>
    <item>
      <title>cnvd-2021-45152</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2021-45152</link>
      <description>cnvd-2021-45152</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2021-45152</guid>
    </item>
    <item>
      <title>EUVD-2026-20907</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-20907</link>
      <description>EUVD-2026-20907</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-20907</guid>
    </item>
    <item>
      <title>fkie_cve-2021-3592</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-3592</link>
      <description>&lt;p&gt;An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the bootp_input() function and could occur while processing a udp packet that is smaller than the size of the &amp;#39;bootp_t&amp;#39; structure. A malicious guest could use this flaw to leak 10 bytes of uninitialized heap memory from the host. The highest threat from this vulnerability is to data confidentiality. This flaw affects libslirp versions prior to 4.6.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the bootp_input() function and could occur while processing a udp packet that is smaller than the size of the &amp;#39;bootp_t&amp;#39; structure. A malicious guest could use this flaw to leak 10 bytes of uninitialized heap memory from the host. The highest threat from this vulnerability is to data confidentiality. This flaw affects libslirp versions prior to 4.6.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-3592</guid>
    </item>
    <item>
      <title>GHSA-xrpp-vwp4-q9hp</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xrpp-vwp4-q9hp</link>
      <description>&lt;p&gt;An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the bootp_input() function and could occur while processing a udp packet that is smaller than the size of the &amp;#39;bootp_t&amp;#39; structure. A malicious guest could use this flaw to leak 10 bytes of uninitialized heap memory from the host. The highest threat from this vulnerability is to data confidentiality. This flaw affects libslirp versions prior to 4.6.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the bootp_input() function and could occur while processing a udp packet that is smaller than the size of the &amp;#39;bootp_t&amp;#39; structure. A malicious guest could use this flaw to leak 10 bytes of uninitialized heap memory from the host. The highest threat from this vulnerability is to data confidentiality. This flaw affects libslirp versions prior to 4.6.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xrpp-vwp4-q9hp</guid>
    </item>
    <item>
      <title>gsd-2021-3592</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-3592</link>
      <description>gsd-2021-3592</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-3592</guid>
    </item>
    <item>
      <title>OESA-2021-1411 — qemu security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2021-1411</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: qemu, openEuler:20.03-LTS-SP2: qemu&lt;/p&gt;
&lt;p&gt;QEMU is a FAST! processor emulator using dynamic translation to achieve good emulation speed.&#13;
&#13;
Security Fix(es):&#13;
&#13;
An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the udp6_input() function and could occur while processing a udp packet that is smaller than the size of the &amp;amp;apos;udphdr&amp;amp;apos; structure. This issue may lead to out-of-bounds read access or indirect host memory disclosure to the guest. The highest threat from this vulnerability is to data confidentiality.(CVE-2021-3593)&#13;
&#13;
An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the bootp_input() function and could occur while processing a udp packet that is smaller than the size of the &amp;amp;apos;bootp_t&amp;amp;apos; structure. A malicious guest could use this flaw to leak 10 bytes of uninitialized heap memory from the host. The highest threat from this vulnerability is to data confidentiality.(CVE-2021-3592)&#13;
&#13;
An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the tftp_input() function and could occur while processing a udp packet that is smaller than the size of the &amp;amp;apos;tftp_t&amp;amp;apos; structure. This issue may lead to out-of-bounds read access or indirect host memory disclosure to the guest. The highest threat from this vulnerability is to data confidentiality.(CVE-2021-3595)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: qemu, openEuler:20.03-LTS-SP2: qemu&lt;/p&gt;
&lt;p&gt;QEMU is a FAST! processor emulator using dynamic translation to achieve good emulation speed.&#13;
&#13;
Security Fix(es):&#13;
&#13;
An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the udp6_input() function and could occur while processing a udp packet that is smaller than the size of the &amp;amp;apos;udphdr&amp;amp;apos; structure. This issue may lead to out-of-bounds read access or indirect host memory disclosure to the guest. The highest threat from this vulnerability is to data confidentiality.(CVE-2021-3593)&#13;
&#13;
An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the bootp_input() function and could occur while processing a udp packet that is smaller than the size of the &amp;amp;apos;bootp_t&amp;amp;apos; structure. A malicious guest could use this flaw to leak 10 bytes of uninitialized heap memory from the host. The highest threat from this vulnerability is to data confidentiality.(CVE-2021-3592)&#13;
&#13;
An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the tftp_input() function and could occur while processing a udp packet that is smaller than the size of the &amp;amp;apos;tftp_t&amp;amp;apos; structure. This issue may lead to out-of-bounds read access or indirect host memory disclosure to the guest. The highest threat from this vulnerability is to data confidentiality.(CVE-2021-3595)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2021-1411</guid>
    </item>
    <item>
      <title>openSUSE-SU-2021:2474-1 — Security update for qemu</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2021:2474-1</link>
      <description>&lt;p&gt;Security update for qemu&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for qemu&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2021:2474-1</guid>
    </item>
    <item>
      <title>RHSA-2021:4191 — Red Hat Security Advisory: virt:rhel and virt-devel:rhel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:4191</link>
      <description>&lt;p&gt;QEMU: net: e1000e: use-after-free while sending packets QEMU: slirp: invalid pointer initialization may lead to information disclosure (bootp) QEMU: slirp: invalid pointer initialization may lead to information disclosure (udp6) QEMU: slirp: invalid pointer initialization may lead to information disclosure (udp) QEMU: slirp: invalid pointer initialization may lead to information disclosure (tftp) libvirt: Insecure sVirt label generation libvirt: Improper locking on ACL failure in virStoragePoolLookupByTargetPath API&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;QEMU: net: e1000e: use-after-free while sending packets QEMU: slirp: invalid pointer initialization may lead to information disclosure (bootp) QEMU: slirp: invalid pointer initialization may lead to information disclosure (udp6) QEMU: slirp: invalid pointer initialization may lead to information disclosure (udp) QEMU: slirp: invalid pointer initialization may lead to information disclosure (tftp) libvirt: Insecure sVirt label generation libvirt: Improper locking on ACL failure in virStoragePoolLookupByTargetPath API&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:4191</guid>
    </item>
    <item>
      <title>SUSE-SU-2021:14772-1 — Security update for kvm</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2021:14772-1</link>
      <description>&lt;p&gt;Security update for kvm&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for kvm&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2021:14772-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-3592</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-3592</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: qemu, Ubuntu:Pro:16.04:LTS: qemu, Ubuntu:18.04:LTS: qemu, Ubuntu:20.04:LTS: libslirp, Ubuntu:22.04:LTS: libslirp&lt;/p&gt;
&lt;p&gt;An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the bootp_input() function and could occur while processing a udp packet that is smaller than the size of the &amp;#39;bootp_t&amp;#39; structure. A malicious guest could use this flaw to leak 10 bytes of uninitialized heap memory from the host. The highest threat from this vulnerability is to data confidentiality. This flaw affects libslirp versions prior to 4.6.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: qemu, Ubuntu:Pro:16.04:LTS: qemu, Ubuntu:18.04:LTS: qemu, Ubuntu:20.04:LTS: libslirp, Ubuntu:22.04:LTS: libslirp&lt;/p&gt;
&lt;p&gt;An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the bootp_input() function and could occur while processing a udp packet that is smaller than the size of the &amp;#39;bootp_t&amp;#39; structure. A malicious guest could use this flaw to leak 10 bytes of uninitialized heap memory from the host. The highest threat from this vulnerability is to data confidentiality. This flaw affects libslirp versions prior to 4.6.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-3592</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-1219 — QEMU: Mehrere Schwachstellen ermöglichen Offenlegung von Informationen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1219</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in QEMU ausnutzen, um Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in QEMU ausnutzen, um Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1219</guid>
    </item>
  </channel>
</rss>
