<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 19:53:26 +0000</lastBuildDate>
    <item>
      <title>ALSA-2022:1759 — Moderate: virt:rhel and virt-devel:rhel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2022:1759</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: SLOF, AlmaLinux:8: hivex, AlmaLinux:8: hivex-devel, AlmaLinux:8: libguestfs, AlmaLinux:8: libguestfs-appliance, AlmaLinux:8: libguestfs-bash-completion, AlmaLinux:8: libguestfs-devel, AlmaLinux:8: libguestfs-gfs2, AlmaLinux:8: libguestfs-gobject, AlmaLinux:8: libguestfs-gobject-devel and 120 more&lt;/p&gt;
&lt;p&gt;Kernel-based Virtual Machine (KVM) offers a full virtualization solution for Linux on numerous hardware platforms. The virt:rhel module contains packages which provide user-space components used to run virtual machines using KVM. The packages also provide APIs for managing and interacting with the virtualized systems.&lt;/p&gt;
&lt;p&gt;The following packages have been upgraded to a later upstream version: qemu-kvm (6.2.0), libvirt (8.0.0), libvirt-python (8.0.0), perl-Sys-Virt (8.0.0), seabios (1.15.0), libtpms (0.9.1). (BZ#1997410, BZ#2012802, BZ#2012806, BZ#2012813, BZ#2018392, BZ#2027716, BZ#2029355)&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* QEMU: virtio-net: heap use-after-free in virtio_net_receive_rcu (CVE-2021-3748)&lt;/p&gt;
&lt;p&gt;* ntfs-3g: Out-of-bounds heap buffer access in ntfs_get_attribute_value() due to incorrect check of bytes_in_use value in MFT records (CVE-2021-33285)&lt;/p&gt;
&lt;p&gt;* ntfs-3g: Heap buffer overflow triggered by a specially crafted Unicode string (CVE-2021-33286)&lt;/p&gt;
&lt;p&gt;* ntfs-3g: Heap buffer overflow in ntfs_attr_pread_i() triggered by specially crafted NTFS attributes (CVE-2021-33287)&lt;/p&gt;
&lt;p&gt;* ntfs-3g: Heap buffer overflow triggered by a specially crafted MFT section (CVE-2021-33289)&lt;/p&gt;
&lt;p&gt;* ntfs-3g: Heap buffer overflow triggered by a specially crafted NTFS inode pathname (CVE-2021-35266)&lt;/p&gt;
&lt;p&gt;* ntfs-3g: Stack buffer overflow triggered when correcting differences between MFT and MFTMirror sections (CVE-2021-35267)&lt;/p&gt;
&lt;p&gt;* ntfs-3g: Heap buffer overflow in ntfs_inode_real_open() triggered by a specially crafted NTFS inode (CVE-202…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: SLOF, AlmaLinux:8: hivex, AlmaLinux:8: hivex-devel, AlmaLinux:8: libguestfs, AlmaLinux:8: libguestfs-appliance, AlmaLinux:8: libguestfs-bash-completion, AlmaLinux:8: libguestfs-devel, AlmaLinux:8: libguestfs-gfs2, AlmaLinux:8: libguestfs-gobject, AlmaLinux:8: libguestfs-gobject-devel and 120 more&lt;/p&gt;
&lt;p&gt;Kernel-based Virtual Machine (KVM) offers a full virtualization solution for Linux on numerous hardware platforms. The virt:rhel module contains packages which provide user-space components used to run virtual machines using KVM. The packages also provide APIs for managing and interacting with the virtualized systems.&lt;/p&gt;
&lt;p&gt;The following packages have been upgraded to a later upstream version: qemu-kvm (6.2.0), libvirt (8.0.0), libvirt-python (8.0.0), perl-Sys-Virt (8.0.0), seabios (1.15.0), libtpms (0.9.1). (BZ#1997410, BZ#2012802, BZ#2012806, BZ#2012813, BZ#2018392, BZ#2027716, BZ#2029355)&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* QEMU: virtio-net: heap use-after-free in virtio_net_receive_rcu (CVE-2021-3748)&lt;/p&gt;
&lt;p&gt;* ntfs-3g: Out-of-bounds heap buffer access in ntfs_get_attribute_value() due to incorrect check of bytes_in_use value in MFT records (CVE-2021-33285)&lt;/p&gt;
&lt;p&gt;* ntfs-3g: Heap buffer overflow triggered by a specially crafted Unicode string (CVE-2021-33286)&lt;/p&gt;
&lt;p&gt;* ntfs-3g: Heap buffer overflow in ntfs_attr_pread_i() triggered by specially crafted NTFS attributes (CVE-2021-33287)&lt;/p&gt;
&lt;p&gt;* ntfs-3g: Heap buffer overflow triggered by a specially crafted MFT section (CVE-2021-33289)&lt;/p&gt;
&lt;p&gt;* ntfs-3g: Heap buffer overflow triggered by a specially crafted NTFS inode pathname (CVE-2021-35266)&lt;/p&gt;
&lt;p&gt;* ntfs-3g: Stack buffer overflow triggered when correcting differences between MFT and MFTMirror sections (CVE-2021-35267)&lt;/p&gt;
&lt;p&gt;* ntfs-3g: Heap buffer overflow in ntfs_inode_real_open() triggered by a specially crafted NTFS inode (CVE-202…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2022:1759</guid>
    </item>
    <item>
      <title>bdu:2022-00753</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-00753</link>
      <description>bdu:2022-00753</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-00753</guid>
    </item>
    <item>
      <title>EUVD-2026-21065</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-21065</link>
      <description>EUVD-2026-21065</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-21065</guid>
    </item>
    <item>
      <title>fkie_cve-2021-3748</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-3748</link>
      <description>&lt;p&gt;A use-after-free vulnerability was found in the virtio-net device of QEMU. It could occur when the descriptor&amp;#39;s address belongs to the non direct access region, due to num_buffers being set after the virtqueue elem has been unmapped. A malicious guest could use this flaw to crash QEMU, resulting in a denial of service condition, or potentially execute code on the host with the privileges of the QEMU process.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A use-after-free vulnerability was found in the virtio-net device of QEMU. It could occur when the descriptor&amp;#39;s address belongs to the non direct access region, due to num_buffers being set after the virtqueue elem has been unmapped. A malicious guest could use this flaw to crash QEMU, resulting in a denial of service condition, or potentially execute code on the host with the privileges of the QEMU process.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-3748</guid>
    </item>
    <item>
      <title>GHSA-4f87-mww8-gm8x</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-4f87-mww8-gm8x</link>
      <description>&lt;p&gt;A use-after-free vulnerability was found in the virtio-net device of QEMU. It could occur when the descriptor&amp;#39;s address belongs to the non direct access region, due to num_buffers being set after the virtqueue elem has been unmapped. A malicious guest could use this flaw to crash QEMU, resulting in a denial of service condition, or potentially execute code on the host with the privileges of the QEMU process.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A use-after-free vulnerability was found in the virtio-net device of QEMU. It could occur when the descriptor&amp;#39;s address belongs to the non direct access region, due to num_buffers being set after the virtqueue elem has been unmapped. A malicious guest could use this flaw to crash QEMU, resulting in a denial of service condition, or potentially execute code on the host with the privileges of the QEMU process.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-4f87-mww8-gm8x</guid>
    </item>
    <item>
      <title>gsd-2021-3748</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-3748</link>
      <description>gsd-2021-3748</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-3748</guid>
    </item>
    <item>
      <title>msrc_CVE-2021-3748 — A use-after-free vulnerability was found in the virtio-net device of QEMU. It could occur when the descriptor's address…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2021-3748</link>
      <description>msrc_CVE-2021-3748</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2021-3748</guid>
    </item>
    <item>
      <title>OESA-2021-1371 — qemu security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2021-1371</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: qemu, openEuler:20.03-LTS-SP2: qemu&lt;/p&gt;
&lt;p&gt;QEMU is a FAST! processor emulator using dynamic translation to achieve good emulation speed.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A use-after-free vulnerability was found in the virtio-net device of QEMU. It could occur when the descriptor&amp;amp;apos;s address belongs to the non direct access region, due to num_buffers being set after the virtqueue elem has been unmapped. A malicious guest could use this flaw to crash QEMU, resulting in a denial of service condition, or potentially execute code on the host with the privileges of the QEMU process. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.(CVE-2021-3748)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: qemu, openEuler:20.03-LTS-SP2: qemu&lt;/p&gt;
&lt;p&gt;QEMU is a FAST! processor emulator using dynamic translation to achieve good emulation speed.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A use-after-free vulnerability was found in the virtio-net device of QEMU. It could occur when the descriptor&amp;amp;apos;s address belongs to the non direct access region, due to num_buffers being set after the virtqueue elem has been unmapped. A malicious guest could use this flaw to crash QEMU, resulting in a denial of service condition, or potentially execute code on the host with the privileges of the QEMU process. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.(CVE-2021-3748)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2021-1371</guid>
    </item>
    <item>
      <title>openSUSE-SU-2021:3604-1 — Security update for qemu</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2021:3604-1</link>
      <description>&lt;p&gt;Security update for qemu&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for qemu&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2021:3604-1</guid>
    </item>
    <item>
      <title>RHSA-2021:4112 — Red Hat Security Advisory: virt:av and virt-devel:av security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:4112</link>
      <description>&lt;p&gt;QEMU: virtio-net: heap use-after-free in virtio_net_receive_rcu&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;QEMU: virtio-net: heap use-after-free in virtio_net_receive_rcu&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:4112</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-3748</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-3748</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: qemu, Ubuntu:20.04:LTS: qemu, Ubuntu:22.04:LTS: qemu&lt;/p&gt;
&lt;p&gt;A use-after-free vulnerability was found in the virtio-net device of QEMU. It could occur when the descriptor&amp;#39;s address belongs to the non direct access region, due to num_buffers being set after the virtqueue elem has been unmapped. A malicious guest could use this flaw to crash QEMU, resulting in a denial of service condition, or potentially execute code on the host with the privileges of the QEMU process.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: qemu, Ubuntu:20.04:LTS: qemu, Ubuntu:22.04:LTS: qemu&lt;/p&gt;
&lt;p&gt;A use-after-free vulnerability was found in the virtio-net device of QEMU. It could occur when the descriptor&amp;#39;s address belongs to the non direct access region, due to num_buffers being set after the virtqueue elem has been unmapped. A malicious guest could use this flaw to crash QEMU, resulting in a denial of service condition, or potentially execute code on the host with the privileges of the QEMU process.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-3748</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-0096 — Red Hat Enterprise Linux: Schwachstelle ermöglicht Ausführen von beliebigem Programmcode mit den Rechten des Dienstes</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0096</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um beliebigen Programmcode mit den Rechten des Dienstes auszuführen oder einen Denial of Service Zustand herbeizuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um beliebigen Programmcode mit den Rechten des Dienstes auszuführen oder einen Denial of Service Zustand herbeizuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0096</guid>
    </item>
  </channel>
</rss>
