<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 19:00:48 +0000</lastBuildDate>
    <item>
      <title>ALSA-2022:1991 — Moderate: cpio security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2022:1991</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: cpio&lt;/p&gt;
&lt;p&gt;The cpio packages provide the GNU cpio utility for creating and extracting archives, or copying files from one place to another.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* cpio: integer overflow in ds_fgetstr() in dstring.c can lead to an out-of-bounds write via a crafted pattern file (CVE-2021-38185)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: cpio&lt;/p&gt;
&lt;p&gt;The cpio packages provide the GNU cpio utility for creating and extracting archives, or copying files from one place to another.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* cpio: integer overflow in ds_fgetstr() in dstring.c can lead to an out-of-bounds write via a crafted pattern file (CVE-2021-38185)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2022:1991</guid>
    </item>
    <item>
      <title>bdu:2021-05090</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2021-05090</link>
      <description>bdu:2021-05090</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2021-05090</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2021-38185 — CVE-2021-38185 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2021-38185</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2021-38185</guid>
    </item>
    <item>
      <title>certfr-2022-avi-952 — De multiples vulnérabilités ont été découvertes dans IBM QRadar.
Certaines d'entre elles permettent à un attaquant de p…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-952</link>
      <description>certfr-2022-avi-952</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-952</guid>
    </item>
    <item>
      <title>CLEANSTART-2024-HF57565 — GNU cpio through 2</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2024-hf57565</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: cpio&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the cpio package. GNU cpio through 2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: cpio&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the cpio package. GNU cpio through 2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2024-hf57565</guid>
    </item>
    <item>
      <title>EUVD-2026-243458</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-243458</link>
      <description>EUVD-2026-243458</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-243458</guid>
    </item>
    <item>
      <title>fkie_cve-2021-38185</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-38185</link>
      <description>&lt;p&gt;GNU cpio through 2.13 allows attackers to execute arbitrary code via a crafted pattern file, because of a dstring.c ds_fgetstr integer overflow that triggers an out-of-bounds heap write. NOTE: it is unclear whether there are common cases where the pattern file, associated with the -E option, is untrusted data.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;GNU cpio through 2.13 allows attackers to execute arbitrary code via a crafted pattern file, because of a dstring.c ds_fgetstr integer overflow that triggers an out-of-bounds heap write. NOTE: it is unclear whether there are common cases where the pattern file, associated with the -E option, is untrusted data.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-38185</guid>
    </item>
    <item>
      <title>GHSA-pp74-ghrg-jwfh</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-pp74-ghrg-jwfh</link>
      <description>&lt;p&gt;GNU cpio through 2.13 allows attackers to execute arbitrary code via a crafted pattern file, because of a dstring.c ds_fgetstr integer overflow that triggers an out-of-bounds heap write. NOTE: it is unclear whether there are common cases where the pattern file, associated with the -E option, is untrusted data.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;GNU cpio through 2.13 allows attackers to execute arbitrary code via a crafted pattern file, because of a dstring.c ds_fgetstr integer overflow that triggers an out-of-bounds heap write. NOTE: it is unclear whether there are common cases where the pattern file, associated with the -E option, is untrusted data.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-pp74-ghrg-jwfh</guid>
    </item>
    <item>
      <title>gsd-2021-38185</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-38185</link>
      <description>gsd-2021-38185</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-38185</guid>
    </item>
    <item>
      <title>msrc_CVE-2021-38185 — GNU cpio through 2.13 allows attackers to execute arbitrary code via a crafted pattern file because of a dstring.c ds_f…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2021-38185</link>
      <description>msrc_CVE-2021-38185</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2021-38185</guid>
    </item>
    <item>
      <title>OESA-2021-1325 — cpio security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2021-1325</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: cpio, openEuler:20.03-LTS-SP2: cpio&lt;/p&gt;
&lt;p&gt;GNU cpio copies files into or out of a cpio or tar archive. The archive can be another file on the disk, a magnetic tape, or a pipe.&#13;
&#13;
Security Fix(es):&#13;
&#13;
GNU cpio through 2.13 allows attackers to execute arbitrary code via a crafted pattern file, because of a dstring.c ds_fgetstr integer overflow that triggers an out-of-bounds heap write. NOTE: it is unclear whether there are common cases where the pattern file, associated with the -E option, is untrusted data.(CVE-2021-38185)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: cpio, openEuler:20.03-LTS-SP2: cpio&lt;/p&gt;
&lt;p&gt;GNU cpio copies files into or out of a cpio or tar archive. The archive can be another file on the disk, a magnetic tape, or a pipe.&#13;
&#13;
Security Fix(es):&#13;
&#13;
GNU cpio through 2.13 allows attackers to execute arbitrary code via a crafted pattern file, because of a dstring.c ds_fgetstr integer overflow that triggers an out-of-bounds heap write. NOTE: it is unclear whether there are common cases where the pattern file, associated with the -E option, is untrusted data.(CVE-2021-38185)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2021-1325</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:10697-1 — cpio-2.13-3.3 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:10697-1</link>
      <description>&lt;p&gt;cpio-2.13-3.3 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;cpio-2.13-3.3 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:10697-1</guid>
    </item>
    <item>
      <title>SSA-202008 — SSA-202008: Multiple Vulnerabilities in Ruggedcom Rox Before V2.17.0</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-202008</link>
      <description>&lt;p&gt;An issue was discovered in shadow 4.5. newgidmap (in shadow-utils) is setuid and allows an unprivileged user to be placed in a user namespace where setgroups(2) is permitted. This allows an attacker to remove themselves from a supplementary group, which may allow access to certain filesystem paths if the administrator has used &amp;#34;group blacklisting&amp;#34; (e.g., chmod g-rwx) to restrict access to paths. This flaw effectively reverts a security feature in the kernel (in particular, the /proc/self/setgroups knob) to prevent this sort of privilege escalation. GnuPG 2.2.4 and 2.2.5 does not enforce a configuration in which key certification requires an offline master Certify key, which results in apparently valid certifications that occurred only with access to a signing subkey. remember_Ktype in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30, allows attackers to trigger excessive memory consumption (aka OOM). This can occur during execution of cxxfilt. binutils version 2.32 and earlier contains a Integer Overflow vulnerability in objdump, bfd_get_dynamic_reloc_upper_bound,bfd_canonicalize_dynamic_reloc that can result in Integer overflow trigger heap overflow. Successful exploitation allows execution of arbitrary code.. This attack appear to be exploitable via Local. This vulnerability appears to have been fixed in after commit 3a551c7a1b80fca579461774860574eabfd7f18f. libseccomp before 2.4.0 did not correctly generate 64-bit syscall argument comparisons using the ar…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An issue was discovered in shadow 4.5. newgidmap (in shadow-utils) is setuid and allows an unprivileged user to be placed in a user namespace where setgroups(2) is permitted. This allows an attacker to remove themselves from a supplementary group, which may allow access to certain filesystem paths if the administrator has used &amp;#34;group blacklisting&amp;#34; (e.g., chmod g-rwx) to restrict access to paths. This flaw effectively reverts a security feature in the kernel (in particular, the /proc/self/setgroups knob) to prevent this sort of privilege escalation. GnuPG 2.2.4 and 2.2.5 does not enforce a configuration in which key certification requires an offline master Certify key, which results in apparently valid certifications that occurred only with access to a signing subkey. remember_Ktype in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30, allows attackers to trigger excessive memory consumption (aka OOM). This can occur during execution of cxxfilt. binutils version 2.32 and earlier contains a Integer Overflow vulnerability in objdump, bfd_get_dynamic_reloc_upper_bound,bfd_canonicalize_dynamic_reloc that can result in Integer overflow trigger heap overflow. Successful exploitation allows execution of arbitrary code.. This attack appear to be exploitable via Local. This vulnerability appears to have been fixed in after commit 3a551c7a1b80fca579461774860574eabfd7f18f. libseccomp before 2.4.0 did not correctly generate 64-bit syscall argument comparisons using the ar…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-202008</guid>
    </item>
    <item>
      <title>SUSE-RU-2021:2779-1 — Recommended update for cpio</title>
      <link>https://cve.radiocsirt.org/vuln/suse-ru-2021:2779-1</link>
      <description>&lt;p&gt;Recommended update for cpio&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Recommended update for cpio&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-ru-2021:2779-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-38185</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-38185</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: cpio, Ubuntu:Pro:16.04:LTS: cpio, Ubuntu:18.04:LTS: cpio, Ubuntu:20.04:LTS: cpio, Ubuntu:22.04:LTS: cpio&lt;/p&gt;
&lt;p&gt;GNU cpio through 2.13 allows attackers to execute arbitrary code via a crafted pattern file, because of a dstring.c ds_fgetstr integer overflow that triggers an out-of-bounds heap write. NOTE: it is unclear whether there are common cases where the pattern file, associated with the -E option, is untrusted data.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: cpio, Ubuntu:Pro:16.04:LTS: cpio, Ubuntu:18.04:LTS: cpio, Ubuntu:20.04:LTS: cpio, Ubuntu:22.04:LTS: cpio&lt;/p&gt;
&lt;p&gt;GNU cpio through 2.13 allows attackers to execute arbitrary code via a crafted pattern file, because of a dstring.c ds_fgetstr integer overflow that triggers an out-of-bounds heap write. NOTE: it is unclear whether there are common cases where the pattern file, associated with the -E option, is untrusted data.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-38185</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-1852 — cpio: Schwachstelle ermöglicht Codeausführung</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1852</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in cpio ausnutzen, um beliebigen Programmcode auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in cpio ausnutzen, um beliebigen Programmcode auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1852</guid>
    </item>
  </channel>
</rss>
