<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 08:02:20 +0000</lastBuildDate>
    <item>
      <title>ALSA-2021:4191 — Moderate: virt:rhel and virt-devel:rhel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2021:4191</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: hivex, AlmaLinux:8: hivex-devel, AlmaLinux:8: libguestfs, AlmaLinux:8: libguestfs-bash-completion, AlmaLinux:8: libguestfs-benchmarking, AlmaLinux:8: libguestfs-devel, AlmaLinux:8: libguestfs-gfs2, AlmaLinux:8: libguestfs-gobject, AlmaLinux:8: libguestfs-gobject-devel, AlmaLinux:8: libguestfs-inspect-icons and 83 more&lt;/p&gt;
&lt;p&gt;Kernel-based Virtual Machine (KVM) offers a full virtualization solution for Linux on numerous hardware platforms. The virt:rhel module contains packages which provide user-space components used to run virtual machines using KVM. The packages also provide APIs for managing and interacting with the virtualized systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* QEMU: net: e1000e: use-after-free while sending packets (CVE-2020-15859)&lt;/p&gt;
&lt;p&gt;* QEMU: slirp: invalid pointer initialization may lead to information disclosure (bootp) (CVE-2021-3592)&lt;/p&gt;
&lt;p&gt;* QEMU: slirp: invalid pointer initialization may lead to information disclosure (udp6) (CVE-2021-3593)&lt;/p&gt;
&lt;p&gt;* QEMU: slirp: invalid pointer initialization may lead to information disclosure (udp) (CVE-2021-3594)&lt;/p&gt;
&lt;p&gt;* QEMU: slirp: invalid pointer initialization may lead to information disclosure (tftp) (CVE-2021-3595)&lt;/p&gt;
&lt;p&gt;* libvirt: Insecure sVirt label generation (CVE-2021-3631)&lt;/p&gt;
&lt;p&gt;* libvirt: Improper locking on ACL failure in virStoragePoolLookupByTargetPath API (CVE-2021-3667)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: hivex, AlmaLinux:8: hivex-devel, AlmaLinux:8: libguestfs, AlmaLinux:8: libguestfs-bash-completion, AlmaLinux:8: libguestfs-benchmarking, AlmaLinux:8: libguestfs-devel, AlmaLinux:8: libguestfs-gfs2, AlmaLinux:8: libguestfs-gobject, AlmaLinux:8: libguestfs-gobject-devel, AlmaLinux:8: libguestfs-inspect-icons and 83 more&lt;/p&gt;
&lt;p&gt;Kernel-based Virtual Machine (KVM) offers a full virtualization solution for Linux on numerous hardware platforms. The virt:rhel module contains packages which provide user-space components used to run virtual machines using KVM. The packages also provide APIs for managing and interacting with the virtualized systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* QEMU: net: e1000e: use-after-free while sending packets (CVE-2020-15859)&lt;/p&gt;
&lt;p&gt;* QEMU: slirp: invalid pointer initialization may lead to information disclosure (bootp) (CVE-2021-3592)&lt;/p&gt;
&lt;p&gt;* QEMU: slirp: invalid pointer initialization may lead to information disclosure (udp6) (CVE-2021-3593)&lt;/p&gt;
&lt;p&gt;* QEMU: slirp: invalid pointer initialization may lead to information disclosure (udp) (CVE-2021-3594)&lt;/p&gt;
&lt;p&gt;* QEMU: slirp: invalid pointer initialization may lead to information disclosure (tftp) (CVE-2021-3595)&lt;/p&gt;
&lt;p&gt;* libvirt: Insecure sVirt label generation (CVE-2021-3631)&lt;/p&gt;
&lt;p&gt;* libvirt: Improper locking on ACL failure in virStoragePoolLookupByTargetPath API (CVE-2021-3667)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2021:4191</guid>
    </item>
    <item>
      <title>bdu:2022-05841</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-05841</link>
      <description>bdu:2022-05841</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-05841</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0380 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;les produits NetApp&lt;/span&gt;. Elles permettent…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0380</link>
      <description>certfr-2024-avi-0380</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0380</guid>
    </item>
    <item>
      <title>EUVD-2026-215975</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-215975</link>
      <description>EUVD-2026-215975</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-215975</guid>
    </item>
    <item>
      <title>fkie_cve-2021-3667</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-3667</link>
      <description>&lt;p&gt;An improper locking issue was found in the virStoragePoolLookupByTargetPath API of libvirt. It occurs in the storagePoolLookupByTargetPath function where a locked virStoragePoolObj object is not properly released on ACL permission failure. Clients connecting to the read-write socket with limited ACL permissions could use this flaw to acquire the lock and prevent other users from accessing storage pool/volume APIs, resulting in a denial of service condition. The highest threat from this vulnerability is to system availability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An improper locking issue was found in the virStoragePoolLookupByTargetPath API of libvirt. It occurs in the storagePoolLookupByTargetPath function where a locked virStoragePoolObj object is not properly released on ACL permission failure. Clients connecting to the read-write socket with limited ACL permissions could use this flaw to acquire the lock and prevent other users from accessing storage pool/volume APIs, resulting in a denial of service condition. The highest threat from this vulnerability is to system availability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-3667</guid>
    </item>
    <item>
      <title>GHSA-q27q-h2jw-qq6c</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-q27q-h2jw-qq6c</link>
      <description>&lt;p&gt;An improper locking issue was found in the virStoragePoolLookupByTargetPath API of libvirt. It occurs in the storagePoolLookupByTargetPath function where a locked virStoragePoolObj object is not properly released on ACL permission failure. Clients connecting to the read-write socket with limited ACL permissions could use this flaw to acquire the lock and prevent other users from accessing storage pool/volume APIs, resulting in a denial of service condition. The highest threat from this vulnerability is to system availability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An improper locking issue was found in the virStoragePoolLookupByTargetPath API of libvirt. It occurs in the storagePoolLookupByTargetPath function where a locked virStoragePoolObj object is not properly released on ACL permission failure. Clients connecting to the read-write socket with limited ACL permissions could use this flaw to acquire the lock and prevent other users from accessing storage pool/volume APIs, resulting in a denial of service condition. The highest threat from this vulnerability is to system availability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-q27q-h2jw-qq6c</guid>
    </item>
    <item>
      <title>gsd-2021-3667</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-3667</link>
      <description>gsd-2021-3667</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-3667</guid>
    </item>
    <item>
      <title>msrc_CVE-2021-3667 — An improper locking issue was found in the virStoragePoolLookupByTargetPath API of libvirt. It occurs in the storagePoo…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2021-3667</link>
      <description>msrc_CVE-2021-3667</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2021-3667</guid>
    </item>
    <item>
      <title>OESA-2021-1385 — libvirt security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2021-1385</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: libvirt, openEuler:20.03-LTS-SP2: libvirt&lt;/p&gt;
&lt;p&gt;Libvirt is a C toolkit to interact with the virtualization capabilities of recent versions of Linux (and other OSes). The main package includes the libvirtd server exporting the virtualization support.&#13;
&#13;
Security Fix(es):&#13;
&#13;
An improper locking issue was found in the virStoragePoolLookupByTargetPath API of libvirt. It occurs in the storagePoolLookupByTargetPath function where a locked virStoragePoolObj object is not properly released on ACL permission failure. Clients connecting to the read-write socket with limited ACL permissions could use this flaw to acquire the lock and prevent other users from accessing storage pool/volume APIs, resulting in a denial of service condition. The highest threat from this vulnerability is to system availability.(CVE-2021-3667)&#13;
&#13;
A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs&amp;amp;apos; dynamic labels. This flaw allows one exploited guest to access files labeled for another guest, resulting in the breaking out of sVirt confinement. The highest threat from this vulnerability is to confidentiality and integrity.(CVE-2021-3631)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: libvirt, openEuler:20.03-LTS-SP2: libvirt&lt;/p&gt;
&lt;p&gt;Libvirt is a C toolkit to interact with the virtualization capabilities of recent versions of Linux (and other OSes). The main package includes the libvirtd server exporting the virtualization support.&#13;
&#13;
Security Fix(es):&#13;
&#13;
An improper locking issue was found in the virStoragePoolLookupByTargetPath API of libvirt. It occurs in the storagePoolLookupByTargetPath function where a locked virStoragePoolObj object is not properly released on ACL permission failure. Clients connecting to the read-write socket with limited ACL permissions could use this flaw to acquire the lock and prevent other users from accessing storage pool/volume APIs, resulting in a denial of service condition. The highest threat from this vulnerability is to system availability.(CVE-2021-3667)&#13;
&#13;
A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs&amp;amp;apos; dynamic labels. This flaw allows one exploited guest to access files labeled for another guest, resulting in the breaking out of sVirt confinement. The highest threat from this vulnerability is to confidentiality and integrity.(CVE-2021-3631)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2021-1385</guid>
    </item>
    <item>
      <title>openSUSE-SU-2021:1451-1 — Security update for libvirt</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2021:1451-1</link>
      <description>&lt;p&gt;Security update for libvirt&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for libvirt&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2021:1451-1</guid>
    </item>
    <item>
      <title>RHSA-2021:3703 — Red Hat Security Advisory: virt:av and virt-devel:av security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:3703</link>
      <description>&lt;p&gt;QEMU: net: Infinite loop in loopback mode may lead to stack overflow libvirt: Insecure sVirt label generation libvirt: Improper locking on ACL failure in virStoragePoolLookupByTargetPath API QEMU: usbredir: free() call on invalid pointer in bufp_alloc() ntfs-3g: Out-of-bounds heap buffer access in ntfs_get_attribute_value() due to incorrect check of bytes_in_use value in MFT records ntfs-3g: Heap buffer overflow triggered by a specially crafted Unicode string ntfs-3g: Heap buffer overflow in ntfs_attr_pread_i() triggered by specially crafted NTFS attributes ntfs-3g: Heap buffer overflow triggered by a specially crafted MFT section ntfs-3g: Heap buffer overflow triggered by a specially crafted NTFS inode pathname ntfs-3g: Stack buffer overflow triggered when correcting differences between MFT and MFTMirror sections ntfs-3g: Heap buffer overflow in ntfs_inode_real_open() triggered by a specially crafted NTFS inode ntfs-3g: Heap buffer overflow in ntfs_attr_setup_flag() triggered by a specially crafted NTFS attribute from MFT ntfs-3g: NULL pointer dereference in ntfs_extent_inode_open() ntfs-3g: Out-of-bounds read in ntfs_ie_lookup() ntfs-3g: Out-of-bounds read in ntfs_runlists_merge_i() ntfs-3g: Integer overflow in memmove() leading to heap buffer overflow in ntfs_attr_record_resize() ntfs-3g: Out-of-bounds read ntfs_attr_find_in_attrdef() triggered by an invalid attribute ntfs-3g: Heap buffer overflow in ntfs_inode_lookup_by_name() ntfs-3g: Endless recursion from ntfs_attr_pw…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;QEMU: net: Infinite loop in loopback mode may lead to stack overflow libvirt: Insecure sVirt label generation libvirt: Improper locking on ACL failure in virStoragePoolLookupByTargetPath API QEMU: usbredir: free() call on invalid pointer in bufp_alloc() ntfs-3g: Out-of-bounds heap buffer access in ntfs_get_attribute_value() due to incorrect check of bytes_in_use value in MFT records ntfs-3g: Heap buffer overflow triggered by a specially crafted Unicode string ntfs-3g: Heap buffer overflow in ntfs_attr_pread_i() triggered by specially crafted NTFS attributes ntfs-3g: Heap buffer overflow triggered by a specially crafted MFT section ntfs-3g: Heap buffer overflow triggered by a specially crafted NTFS inode pathname ntfs-3g: Stack buffer overflow triggered when correcting differences between MFT and MFTMirror sections ntfs-3g: Heap buffer overflow in ntfs_inode_real_open() triggered by a specially crafted NTFS inode ntfs-3g: Heap buffer overflow in ntfs_attr_setup_flag() triggered by a specially crafted NTFS attribute from MFT ntfs-3g: NULL pointer dereference in ntfs_extent_inode_open() ntfs-3g: Out-of-bounds read in ntfs_ie_lookup() ntfs-3g: Out-of-bounds read in ntfs_runlists_merge_i() ntfs-3g: Integer overflow in memmove() leading to heap buffer overflow in ntfs_attr_record_resize() ntfs-3g: Out-of-bounds read ntfs_attr_find_in_attrdef() triggered by an invalid attribute ntfs-3g: Heap buffer overflow in ntfs_inode_lookup_by_name() ntfs-3g: Endless recursion from ntfs_attr_pw…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:3703</guid>
    </item>
    <item>
      <title>SUSE-SU-2021:2812-1 — Security update for libvirt</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2021:2812-1</link>
      <description>&lt;p&gt;Security update for libvirt&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for libvirt&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2021:2812-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-3667</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-3667</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: libvirt, Ubuntu:22.04:LTS: libvirt&lt;/p&gt;
&lt;p&gt;An improper locking issue was found in the virStoragePoolLookupByTargetPath API of libvirt. It occurs in the storagePoolLookupByTargetPath function where a locked virStoragePoolObj object is not properly released on ACL permission failure. Clients connecting to the read-write socket with limited ACL permissions could use this flaw to acquire the lock and prevent other users from accessing storage pool/volume APIs, resulting in a denial of service condition. The highest threat from this vulnerability is to system availability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: libvirt, Ubuntu:22.04:LTS: libvirt&lt;/p&gt;
&lt;p&gt;An improper locking issue was found in the virStoragePoolLookupByTargetPath API of libvirt. It occurs in the storagePoolLookupByTargetPath function where a locked virStoragePoolObj object is not properly released on ACL permission failure. Clients connecting to the read-write socket with limited ACL permissions could use this flaw to acquire the lock and prevent other users from accessing storage pool/volume APIs, resulting in a denial of service condition. The highest threat from this vulnerability is to system availability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-3667</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-1728 — Red Enterprise Linux Advanced Virtualization: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1728</link>
      <description>&lt;p&gt;Ein entfernter oder lokaler, authentisierter Angreifer kann mehrere Schwachstellen in Red Enterprise Linux Advanced Virtualization ausnutzen, um einen Denial of Service zu verursachen, Sicherheitsvorkehrungen zu umgehen, beliebigen Code auszuführen und Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter oder lokaler, authentisierter Angreifer kann mehrere Schwachstellen in Red Enterprise Linux Advanced Virtualization ausnutzen, um einen Denial of Service zu verursachen, Sicherheitsvorkehrungen zu umgehen, beliebigen Code auszuführen und Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1728</guid>
    </item>
  </channel>
</rss>
