<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 13:25:35 +0000</lastBuildDate>
    <item>
      <title>ALSA-2022:7954 — Moderate: podman security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2022:7954</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: podman, AlmaLinux:9: podman-docker, AlmaLinux:9: podman-gvproxy, AlmaLinux:9: podman-plugins, AlmaLinux:9: podman-remote, AlmaLinux:9: podman-tests&lt;/p&gt;
&lt;p&gt;The podman tool manages pods, container images, and containers. It is part of the libpod library, which is for applications that use container pods. Container pods is a concept in Kubernetes.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* golang.org/x/text: Panic in language.ParseAcceptLanguage while parsing -u- extension (CVE-2020-28851)
* golang.org/x/text: Panic in language.ParseAcceptLanguage while processing bcp47 tag (CVE-2020-28852)
* podman: podman machine spawns gvproxy with port bound to all IPs (CVE-2021-4024)
* podman: Remote traffic to rootless containers is seen as orginating from localhost (CVE-2021-20199)
* containers/storage: DoS via malicious image (CVE-2021-20291)
* golang: net/http/httputil: ReverseProxy forwards connection headers if first one is empty (CVE-2021-33197)
* golang: crypto/tls: certificate of wrong type is causing TLS client to panic (CVE-2021-34558)
* golang: crash in a golang.org/x/crypto/ssh server (CVE-2022-27191)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: podman, AlmaLinux:9: podman-docker, AlmaLinux:9: podman-gvproxy, AlmaLinux:9: podman-plugins, AlmaLinux:9: podman-remote, AlmaLinux:9: podman-tests&lt;/p&gt;
&lt;p&gt;The podman tool manages pods, container images, and containers. It is part of the libpod library, which is for applications that use container pods. Container pods is a concept in Kubernetes.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* golang.org/x/text: Panic in language.ParseAcceptLanguage while parsing -u- extension (CVE-2020-28851)
* golang.org/x/text: Panic in language.ParseAcceptLanguage while processing bcp47 tag (CVE-2020-28852)
* podman: podman machine spawns gvproxy with port bound to all IPs (CVE-2021-4024)
* podman: Remote traffic to rootless containers is seen as orginating from localhost (CVE-2021-20199)
* containers/storage: DoS via malicious image (CVE-2021-20291)
* golang: net/http/httputil: ReverseProxy forwards connection headers if first one is empty (CVE-2021-33197)
* golang: crypto/tls: certificate of wrong type is causing TLS client to panic (CVE-2021-34558)
* golang: crash in a golang.org/x/crypto/ssh server (CVE-2022-27191)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2022:7954</guid>
    </item>
    <item>
      <title>bdu:2023-03676</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-03676</link>
      <description>bdu:2023-03676</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-03676</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2021-4024 — CVE-2021-4024 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2021-4024</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2021-4024</guid>
    </item>
    <item>
      <title>EUVD-2026-21241</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-21241</link>
      <description>EUVD-2026-21241</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-21241</guid>
    </item>
    <item>
      <title>fkie_cve-2021-4024</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-4024</link>
      <description>&lt;p&gt;A flaw was found in podman. The `podman machine` function (used to create and manage Podman virtual machine containing a Podman process) spawns a `gvproxy` process on the host system. The `gvproxy` API is accessible on port 7777 on all IP addresses on the host. If that port is open on the host&amp;#39;s firewall, an attacker can potentially use the `gvproxy` API to forward ports on the host to ports in the VM, making private services on the VM accessible to the network. This issue could be also used to interrupt the host&amp;#39;s services by forwarding all ports to the VM.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in podman. The `podman machine` function (used to create and manage Podman virtual machine containing a Podman process) spawns a `gvproxy` process on the host system. The `gvproxy` API is accessible on port 7777 on all IP addresses on the host. If that port is open on the host&amp;#39;s firewall, an attacker can potentially use the `gvproxy` API to forward ports on the host to ports in the VM, making private services on the VM accessible to the network. This issue could be also used to interrupt the host&amp;#39;s services by forwarding all ports to the VM.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-4024</guid>
    </item>
    <item>
      <title>GHSA-3cf2-x423-x582 — Exposure of Sensitive Information to an Unauthorized Actor and Origin Validation Error in podman</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3cf2-x423-x582</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/containers/podman/v3&lt;/p&gt;
&lt;p&gt;A flaw was found in podman. The `podman machine` function (used to create and manage Podman virtual machine containing a Podman process) spawns a `gvproxy` process on the host system. The `gvproxy` API is accessible on port 7777 on all IP addresses on the host. If that port is open on the host&amp;#39;s firewall, an attacker can potentially use the `gvproxy` API to forward ports on the host to ports in the VM, making private services on the VM accessible to the network. This issue could be also used to interrupt the host&amp;#39;s services by forwarding all ports to the VM.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/containers/podman/v3&lt;/p&gt;
&lt;p&gt;A flaw was found in podman. The `podman machine` function (used to create and manage Podman virtual machine containing a Podman process) spawns a `gvproxy` process on the host system. The `gvproxy` API is accessible on port 7777 on all IP addresses on the host. If that port is open on the host&amp;#39;s firewall, an attacker can potentially use the `gvproxy` API to forward ports on the host to ports in the VM, making private services on the VM accessible to the network. This issue could be also used to interrupt the host&amp;#39;s services by forwarding all ports to the VM.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3cf2-x423-x582</guid>
    </item>
    <item>
      <title>gsd-2021-4024</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-4024</link>
      <description>gsd-2021-4024</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-4024</guid>
    </item>
    <item>
      <title>openSUSE-SU-2022:23018-1 — Security update for conmon, libcontainers-common, libseccomp, podman</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2022:23018-1</link>
      <description>&lt;p&gt;Security update for conmon, libcontainers-common, libseccomp, podman&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for conmon, libcontainers-common, libseccomp, podman&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2022:23018-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2022:23018-1 — Security update for conmon, libcontainers-common, libseccomp, podman</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2022:23018-1</link>
      <description>&lt;p&gt;Security update for conmon, libcontainers-common, libseccomp, podman&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for conmon, libcontainers-common, libseccomp, podman&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2022:23018-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-4024</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-4024</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:22.04:LTS: libpod, Ubuntu:Pro:24.04:LTS: libpod&lt;/p&gt;
&lt;p&gt;A flaw was found in podman. The `podman machine` function (used to create and manage Podman virtual machine containing a Podman process) spawns a `gvproxy` process on the host system. The `gvproxy` API is accessible on port 7777 on all IP addresses on the host. If that port is open on the host&amp;#39;s firewall, an attacker can potentially use the `gvproxy` API to forward ports on the host to ports in the VM, making private services on the VM accessible to the network. This issue could be also used to interrupt the host&amp;#39;s services by forwarding all ports to the VM.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:22.04:LTS: libpod, Ubuntu:Pro:24.04:LTS: libpod&lt;/p&gt;
&lt;p&gt;A flaw was found in podman. The `podman machine` function (used to create and manage Podman virtual machine containing a Podman process) spawns a `gvproxy` process on the host system. The `gvproxy` API is accessible on port 7777 on all IP addresses on the host. If that port is open on the host&amp;#39;s firewall, an attacker can potentially use the `gvproxy` API to forward ports on the host to ports in the VM, making private services on the VM accessible to the network. This issue could be also used to interrupt the host&amp;#39;s services by forwarding all ports to the VM.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-4024</guid>
    </item>
  </channel>
</rss>
