<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 04:56:52 +0000</lastBuildDate>
    <item>
      <title>ALSA-2022:8100 — Low: swtpm security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2022:8100</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: swtpm, AlmaLinux:9: swtpm-libs, AlmaLinux:9: swtpm-tools&lt;/p&gt;
&lt;p&gt;SWTPM is a TPM emulator built on libtpms providing TPM functionality for QEMU VMs.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* swtpm: Unchecked header size indicator against expected size (CVE-2022-23645)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: swtpm, AlmaLinux:9: swtpm-libs, AlmaLinux:9: swtpm-tools&lt;/p&gt;
&lt;p&gt;SWTPM is a TPM emulator built on libtpms providing TPM functionality for QEMU VMs.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* swtpm: Unchecked header size indicator against expected size (CVE-2022-23645)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2022:8100</guid>
    </item>
    <item>
      <title>bdu:2022-06088</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-06088</link>
      <description>bdu:2022-06088</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-06088</guid>
    </item>
    <item>
      <title>ESSA-2022:0193 — security update for</title>
      <link>https://cve.radiocsirt.org/vuln/essa-2022:0193</link>
      <description>&lt;p&gt;security update for&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;security update for&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/essa-2022:0193</guid>
    </item>
    <item>
      <title>EUVD-2026-234422</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-234422</link>
      <description>EUVD-2026-234422</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-234422</guid>
    </item>
    <item>
      <title>fkie_cve-2022-23645</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-23645</link>
      <description>&lt;p&gt;swtpm is a libtpms-based TPM emulator with socket, character device, and Linux CUSE interface. Versions prior to 0.5.3, 0.6.2, and 0.7.1 are vulnerable to out-of-bounds read. A specially crafted header of swtpm&amp;#39;s state, where the blobheader&amp;#39;s hdrsize indicator has an invalid value, may cause an out-of-bounds access when the byte array representing the state of the TPM is accessed. This will likely crash swtpm or prevent it from starting since the state cannot be understood. Users should upgrade to swtpm v0.5.3, v0.6.2, or v0.7.1 to receive a patch. There are currently no known workarounds.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;swtpm is a libtpms-based TPM emulator with socket, character device, and Linux CUSE interface. Versions prior to 0.5.3, 0.6.2, and 0.7.1 are vulnerable to out-of-bounds read. A specially crafted header of swtpm&amp;#39;s state, where the blobheader&amp;#39;s hdrsize indicator has an invalid value, may cause an out-of-bounds access when the byte array representing the state of the TPM is accessed. This will likely crash swtpm or prevent it from starting since the state cannot be understood. Users should upgrade to swtpm v0.5.3, v0.6.2, or v0.7.1 to receive a patch. There are currently no known workarounds.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-23645</guid>
    </item>
    <item>
      <title>gsd-2022-23645</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-23645</link>
      <description>gsd-2022-23645</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-23645</guid>
    </item>
    <item>
      <title>OESA-2022-1576 — swtpm security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2022-1576</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: swtpm, openEuler:20.03-LTS-SP2: swtpm, openEuler:20.03-LTS-SP3: swtpm&lt;/p&gt;
&lt;p&gt;TPM emulator built on libtpms providing TPM functionality for QEMU VMs&#13;
&#13;
Security Fix(es):&#13;
&#13;
swtpm is a libtpms-based TPM emulator with socket, character device, and Linux CUSE interface. Versions prior to 0.5.3, 0.6.2, and 0.7.1 are vulnerable to out-of-bounds read. A specially crafted header of swtpm&amp;amp;apos;s state, where the blobheader&amp;amp;apos;s hdrsize indicator has an invalid value, may cause an out-of-bounds access when the byte array representing the state of the TPM is accessed. This will likely crash swtpm or prevent it from starting since the state cannot be understood. Users should upgrade to swtpm v0.5.3, v0.6.2, or v0.7.1 to receive a patch. There are currently no known workarounds.(CVE-2022-23645)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: swtpm, openEuler:20.03-LTS-SP2: swtpm, openEuler:20.03-LTS-SP3: swtpm&lt;/p&gt;
&lt;p&gt;TPM emulator built on libtpms providing TPM functionality for QEMU VMs&#13;
&#13;
Security Fix(es):&#13;
&#13;
swtpm is a libtpms-based TPM emulator with socket, character device, and Linux CUSE interface. Versions prior to 0.5.3, 0.6.2, and 0.7.1 are vulnerable to out-of-bounds read. A specially crafted header of swtpm&amp;amp;apos;s state, where the blobheader&amp;amp;apos;s hdrsize indicator has an invalid value, may cause an out-of-bounds access when the byte array representing the state of the TPM is accessed. This will likely crash swtpm or prevent it from starting since the state cannot be understood. Users should upgrade to swtpm v0.5.3, v0.6.2, or v0.7.1 to receive a patch. There are currently no known workarounds.(CVE-2022-23645)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2022-1576</guid>
    </item>
    <item>
      <title>RHSA-2022:7472 — Red Hat Security Advisory: virt:rhel and virt-devel:rhel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2022:7472</link>
      <description>&lt;p&gt;QEMU: fdc: heap buffer overflow in DMA read data transfers libvirt: missing locking in nwfilterConnectNumOfNWFilters can lead to denial of service libguestfs: Buffer overflow in get_keys leads to DoS swtpm: Unchecked header size indicator against expected size&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;QEMU: fdc: heap buffer overflow in DMA read data transfers libvirt: missing locking in nwfilterConnectNumOfNWFilters can lead to denial of service libguestfs: Buffer overflow in get_keys leads to DoS swtpm: Unchecked header size indicator against expected size&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2022:7472</guid>
    </item>
    <item>
      <title>SUSE-SU-2022:1297-1 — Security update for swtpm</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2022:1297-1</link>
      <description>&lt;p&gt;Security update for swtpm&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for swtpm&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2022:1297-1</guid>
    </item>
    <item>
      <title>Withdrawn: UBUNTU-CVE-2022-23645</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-23645</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: swtpm&lt;/p&gt;
&lt;p&gt;swtpm is a libtpms-based TPM emulator with socket, character device, and Linux CUSE interface. Versions prior to 0.5.3, 0.6.2, and 0.7.1 are vulnerable to out-of-bounds read. A specially crafted header of swtpm&amp;#39;s state, where the blobheader&amp;#39;s hdrsize indicator has an invalid value, may cause an out-of-bounds access when the byte array representing the state of the TPM is accessed. This will likely crash swtpm or prevent it from starting since the state cannot be understood. Users should upgrade to swtpm v0.5.3, v0.6.2, or v0.7.1 to receive a patch. There are currently no known workarounds.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: swtpm&lt;/p&gt;
&lt;p&gt;swtpm is a libtpms-based TPM emulator with socket, character device, and Linux CUSE interface. Versions prior to 0.5.3, 0.6.2, and 0.7.1 are vulnerable to out-of-bounds read. A specially crafted header of swtpm&amp;#39;s state, where the blobheader&amp;#39;s hdrsize indicator has an invalid value, may cause an out-of-bounds access when the byte array representing the state of the TPM is accessed. This will likely crash swtpm or prevent it from starting since the state cannot be understood. Users should upgrade to swtpm v0.5.3, v0.6.2, or v0.7.1 to receive a patch. There are currently no known workarounds.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-23645</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-2052 — Mehrere Red Hat Enterprise Linux Pakete: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2052</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um einen Denial of Service Angriff durchzuführen, Sicherheitsvorkehrungen zu umgehen oder sonstige Auswirkungen zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um einen Denial of Service Angriff durchzuführen, Sicherheitsvorkehrungen zu umgehen oder sonstige Auswirkungen zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2052</guid>
    </item>
  </channel>
</rss>
