<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 19:51:41 +0000</lastBuildDate>
    <item>
      <title>2NGA002579 — ABB Arctic communication solution ARM600 Vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/2nga002579</link>
      <description>&lt;p&gt;ABB is aware of public reports of a vulnerabilities in product versions listed as affected in this advisory. An attacker who successfully exploited these vulnerabilities could cause the product to stop, make the product inacces-sible, take remote control of the product or insert and run arbitrary code.
As part of ABB product lifecycle policy, once a product transitions to end-of-life, we discontinue maintenance, security patches, and technical support to focus on current and future technologies. While the product will continue to function, we strongly recommend implementing mitigations defined in this document, such as using a private APN cellular network between Arctic wireless gateways and ARM600 for establishing VPN tunnels, to mitigate security risks and avoid potential vulnerabilities.
As part of ABB product lifecycle policy, once a product transitions to Limited state, we discontinue maintenance, security patches, and technical support to focus on current and future technologies. While the product will continue to function, we strongly recommend implementing mitigations defined in this document to mitigate security risks.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ABB is aware of public reports of a vulnerabilities in product versions listed as affected in this advisory. An attacker who successfully exploited these vulnerabilities could cause the product to stop, make the product inacces-sible, take remote control of the product or insert and run arbitrary code.
As part of ABB product lifecycle policy, once a product transitions to end-of-life, we discontinue maintenance, security patches, and technical support to focus on current and future technologies. While the product will continue to function, we strongly recommend implementing mitigations defined in this document, such as using a private APN cellular network between Arctic wireless gateways and ARM600 for establishing VPN tunnels, to mitigate security risks and avoid potential vulnerabilities.
As part of ABB product lifecycle policy, once a product transitions to Limited state, we discontinue maintenance, security patches, and technical support to focus on current and future technologies. While the product will continue to function, we strongly recommend implementing mitigations defined in this document to mitigate security risks.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/2nga002579</guid>
    </item>
    <item>
      <title>ALSA-2022:6206 — Important: systemd security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2022:6206</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: systemd, AlmaLinux:8: systemd-container, AlmaLinux:8: systemd-devel, AlmaLinux:8: systemd-journal-remote, AlmaLinux:8: systemd-libs, AlmaLinux:8: systemd-pam, AlmaLinux:8: systemd-tests, AlmaLinux:8: systemd-udev&lt;/p&gt;
&lt;p&gt;The systemd packages contain systemd, a system and service manager for Linux, compatible with the SysV and LSB init scripts. It provides aggressive parallelism capabilities, uses socket and D-Bus activation for starting services, offers on-demand starting of daemons, and keeps track of processes using Linux cgroups. In addition, it supports snapshotting and restoring of the system state, maintains mount and automount points, and implements an elaborate transactional dependency-based service control logic. It can also work as a drop-in replacement for sysvinit.
Security Fix(es):
* systemd-resolved: use-after-free when dealing with DnsStream in resolved-dns-stream.c (CVE-2022-2526)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: systemd, AlmaLinux:8: systemd-container, AlmaLinux:8: systemd-devel, AlmaLinux:8: systemd-journal-remote, AlmaLinux:8: systemd-libs, AlmaLinux:8: systemd-pam, AlmaLinux:8: systemd-tests, AlmaLinux:8: systemd-udev&lt;/p&gt;
&lt;p&gt;The systemd packages contain systemd, a system and service manager for Linux, compatible with the SysV and LSB init scripts. It provides aggressive parallelism capabilities, uses socket and D-Bus activation for starting services, offers on-demand starting of daemons, and keeps track of processes using Linux cgroups. In addition, it supports snapshotting and restoring of the system state, maintains mount and automount points, and implements an elaborate transactional dependency-based service control logic. It can also work as a drop-in replacement for sysvinit.
Security Fix(es):
* systemd-resolved: use-after-free when dealing with DnsStream in resolved-dns-stream.c (CVE-2022-2526)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2022:6206</guid>
    </item>
    <item>
      <title>bdu:2022-05168</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-05168</link>
      <description>bdu:2022-05168</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-05168</guid>
    </item>
    <item>
      <title>certfr-2022-avi-1025 — De multiples vulnérabilités ont été découvertes dans IBM QRadar.
Certaines d'entre elles permettent à un attaquant de p…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-1025</link>
      <description>certfr-2022-avi-1025</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-1025</guid>
    </item>
    <item>
      <title>EUVD-2026-12404</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-12404</link>
      <description>EUVD-2026-12404</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-12404</guid>
    </item>
    <item>
      <title>fkie_cve-2022-2526</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-2526</link>
      <description>&lt;p&gt;A use-after-free vulnerability was found in systemd. This issue occurs due to the on_stream_io() function and dns_stream_complete() function in &amp;#39;resolved-dns-stream.c&amp;#39; not incrementing the reference counting for the DnsStream object. Therefore, other functions and callbacks called can dereference the DNSStream object, causing the use-after-free when the reference is still used later.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A use-after-free vulnerability was found in systemd. This issue occurs due to the on_stream_io() function and dns_stream_complete() function in &amp;#39;resolved-dns-stream.c&amp;#39; not incrementing the reference counting for the DnsStream object. Therefore, other functions and callbacks called can dereference the DNSStream object, causing the use-after-free when the reference is still used later.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-2526</guid>
    </item>
    <item>
      <title>GHSA-f4r4-2gxf-88xj</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-f4r4-2gxf-88xj</link>
      <description>&lt;p&gt;A use-after-free vulnerability was found in systemd. This issue occurs due to the on_stream_io() function and dns_stream_complete() function in &amp;#39;resolved-dns-stream.c&amp;#39; not incrementing the reference counting for the DnsStream object. Therefore, other functions and callbacks called can dereference the DNSStream object, causing the use-after-free when the reference is still used later.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A use-after-free vulnerability was found in systemd. This issue occurs due to the on_stream_io() function and dns_stream_complete() function in &amp;#39;resolved-dns-stream.c&amp;#39; not incrementing the reference counting for the DnsStream object. Therefore, other functions and callbacks called can dereference the DNSStream object, causing the use-after-free when the reference is still used later.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-f4r4-2gxf-88xj</guid>
    </item>
    <item>
      <title>gsd-2022-2526</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-2526</link>
      <description>gsd-2022-2526</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-2526</guid>
    </item>
    <item>
      <title>ICSA-25-105-08 — ABB M2M Gateway</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-25-105-08</link>
      <description>&lt;p&gt;ABB is aware of public reports of a vulnerabilities in product versions listed as affected in this advisory. An attacker who successfully exploited these vulnerabilities could cause the product to stop, make the product inacces-sible, take remote control of the product or insert and run arbitrary code.
As part of ABB product lifecycle policy, once a product transitions to end-of-life, we discontinue maintenance, security patches, and technical support to focus on current and future technologies. While the product will continue to function, we strongly recommend implementing mitigations defined in this document, such as using a private APN cellular network between Arctic wireless gateways and ARM600 for establishing VPN tunnels, to mitigate security risks and avoid potential vulnerabilities.
As part of ABB product lifecycle policy, once a product transitions to Limited state, we discontinue maintenance, security patches, and technical support to focus on current and future technologies. While the product will continue to function, we strongly recommend implementing mitigations defined in this document to mitigate security risks.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ABB is aware of public reports of a vulnerabilities in product versions listed as affected in this advisory. An attacker who successfully exploited these vulnerabilities could cause the product to stop, make the product inacces-sible, take remote control of the product or insert and run arbitrary code.
As part of ABB product lifecycle policy, once a product transitions to end-of-life, we discontinue maintenance, security patches, and technical support to focus on current and future technologies. While the product will continue to function, we strongly recommend implementing mitigations defined in this document, such as using a private APN cellular network between Arctic wireless gateways and ARM600 for establishing VPN tunnels, to mitigate security risks and avoid potential vulnerabilities.
As part of ABB product lifecycle policy, once a product transitions to Limited state, we discontinue maintenance, security patches, and technical support to focus on current and future technologies. While the product will continue to function, we strongly recommend implementing mitigations defined in this document to mitigate security risks.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-25-105-08</guid>
    </item>
    <item>
      <title>RHSA-2022:6160 — Red Hat Security Advisory: systemd security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2022:6160</link>
      <description>&lt;p&gt;systemd-resolved: use-after-free when dealing with DnsStream in resolved-dns-stream.c&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;systemd-resolved: use-after-free when dealing with DnsStream in resolved-dns-stream.c&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2022:6160</guid>
    </item>
    <item>
      <title>RHSA-2022:6161 — Red Hat Security Advisory: systemd security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2022:6161</link>
      <description>&lt;p&gt;systemd-resolved: use-after-free when dealing with DnsStream in resolved-dns-stream.c&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;systemd-resolved: use-after-free when dealing with DnsStream in resolved-dns-stream.c&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2022:6161</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-2526</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-2526</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: systemd&lt;/p&gt;
&lt;p&gt;A use-after-free vulnerability was found in systemd. This issue occurs due to the on_stream_io() function and dns_stream_complete() function in &amp;#39;resolved-dns-stream.c&amp;#39; not incrementing the reference counting for the DnsStream object. Therefore, other functions and callbacks called can dereference the DNSStream object, causing the use-after-free when the reference is still used later.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: systemd&lt;/p&gt;
&lt;p&gt;A use-after-free vulnerability was found in systemd. This issue occurs due to the on_stream_io() function and dns_stream_complete() function in &amp;#39;resolved-dns-stream.c&amp;#39; not incrementing the reference counting for the DnsStream object. Therefore, other functions and callbacks called can dereference the DNSStream object, causing the use-after-free when the reference is still used later.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-2526</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-1177 — systemd: Schwachstelle ermöglicht nicht spezifizierten Angriff</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1177</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in systemd ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in systemd ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1177</guid>
    </item>
  </channel>
</rss>
