<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 05:17:12 +0000</lastBuildDate>
    <item>
      <title>ALSA-2022:7822 — Low: container-tools:rhel8 security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2022:7822</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: aardvark-dns, AlmaLinux:8: buildah, AlmaLinux:8: buildah-tests, AlmaLinux:8: cockpit-podman, AlmaLinux:8: conmon, AlmaLinux:8: container-selinux, AlmaLinux:8: containernetworking-plugins, AlmaLinux:8: containers-common, AlmaLinux:8: crit, AlmaLinux:8: criu and 24 more&lt;/p&gt;
&lt;p&gt;The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* podman: possible information disclosure and modification (CVE-2022-2989)
* buildah: possible information disclosure and modification (CVE-2022-2990)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Bug Fix(es):&lt;/p&gt;
&lt;p&gt;* podman creates lock file in /etc/cni/net.d/cni.lock instead of /run/lock/ (BZ#2125644)
* (podman image trust) does not support the new trust type &amp;#34;sigstoreSigned &amp;#34; (BZ#2125645)
* podman kill may deadlock (BZ#2125647)
* Error: runc: exec failed: unable to start container process: open /dev/pts/0: operation not permitted: OCI permission denied [AlmaLinux 8.7] (BZ#2125648)
* containers-common-1-44 is missing RPM-GPG-KEY-AlmaLinux-beta [AlmaLinux 8.7] (BZ#2125686)
* ADD Dockerfile reference is not validating HTTP status code [rhel8-8.7.0] (BZ#2129767)
* Two aardvark-dns instances trying to use the same port on the same interface. [rhel-8.7.0.z] (netavark) (BZ#2130234)
* containers config.json gets empty after sudden power loss (BZ#2130236)
* PANIC podman API service endpoint handler panic (BZ#2132412)
* Podman container got global IPv6 address unexpectedly even when macvlan network is created for pure IPv4 network (BZ#2133390)
* Skopeo push image to AlmaLinux quay with sigstore was failed (BZ#213…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: aardvark-dns, AlmaLinux:8: buildah, AlmaLinux:8: buildah-tests, AlmaLinux:8: cockpit-podman, AlmaLinux:8: conmon, AlmaLinux:8: container-selinux, AlmaLinux:8: containernetworking-plugins, AlmaLinux:8: containers-common, AlmaLinux:8: crit, AlmaLinux:8: criu and 24 more&lt;/p&gt;
&lt;p&gt;The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* podman: possible information disclosure and modification (CVE-2022-2989)
* buildah: possible information disclosure and modification (CVE-2022-2990)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Bug Fix(es):&lt;/p&gt;
&lt;p&gt;* podman creates lock file in /etc/cni/net.d/cni.lock instead of /run/lock/ (BZ#2125644)
* (podman image trust) does not support the new trust type &amp;#34;sigstoreSigned &amp;#34; (BZ#2125645)
* podman kill may deadlock (BZ#2125647)
* Error: runc: exec failed: unable to start container process: open /dev/pts/0: operation not permitted: OCI permission denied [AlmaLinux 8.7] (BZ#2125648)
* containers-common-1-44 is missing RPM-GPG-KEY-AlmaLinux-beta [AlmaLinux 8.7] (BZ#2125686)
* ADD Dockerfile reference is not validating HTTP status code [rhel8-8.7.0] (BZ#2129767)
* Two aardvark-dns instances trying to use the same port on the same interface. [rhel-8.7.0.z] (netavark) (BZ#2130234)
* containers config.json gets empty after sudden power loss (BZ#2130236)
* PANIC podman API service endpoint handler panic (BZ#2132412)
* Podman container got global IPv6 address unexpectedly even when macvlan network is created for pure IPv4 network (BZ#2133390)
* Skopeo push image to AlmaLinux quay with sigstore was failed (BZ#213…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2022:7822</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2022-2990 — CVE-2022-2990 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2022-2990</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2022-2990</guid>
    </item>
    <item>
      <title>CLEANSTART-2024-MV49832 — incorrect handling of the supplementary groups in the Buildah container engine might lead to the sensitive information…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2024-mv49832</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: buildah&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the buildah package. An incorrect handling of the supplementary groups in the Buildah container engine might lead to the sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissions and is able t....&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: buildah&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the buildah package. An incorrect handling of the supplementary groups in the Buildah container engine might lead to the sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissions and is able t....&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2024-mv49832</guid>
    </item>
    <item>
      <title>EUVD-2026-12564</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-12564</link>
      <description>EUVD-2026-12564</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-12564</guid>
    </item>
    <item>
      <title>fkie_cve-2022-2990</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-2990</link>
      <description>&lt;p&gt;An incorrect handling of the supplementary groups in the Buildah container engine might lead to the sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissions and is able to execute a binary code in that container.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An incorrect handling of the supplementary groups in the Buildah container engine might lead to the sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissions and is able to execute a binary code in that container.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-2990</guid>
    </item>
    <item>
      <title>GHSA-fjm8-m7m6-2fjp — Buildah's incorrect handling of the supplementary groups may lead to data disclosure, modification</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-fjm8-m7m6-2fjp</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/containers/buildah&lt;/p&gt;
&lt;p&gt;An incorrect handling of the supplementary groups in the Buildah container engine might lead to the sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissions and is able to execute a binary code in that container.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/containers/buildah&lt;/p&gt;
&lt;p&gt;An incorrect handling of the supplementary groups in the Buildah container engine might lead to the sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissions and is able to execute a binary code in that container.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-fjm8-m7m6-2fjp</guid>
    </item>
    <item>
      <title>gsd-2022-2990</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-2990</link>
      <description>gsd-2022-2990</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-2990</guid>
    </item>
    <item>
      <title>msrc_CVE-2022-2990 — An incorrect handling of the supplementary groups in the Buildah container engine might lead to the sensitive informati…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2022-2990</link>
      <description>msrc_CVE-2022-2990</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2022-2990</guid>
    </item>
    <item>
      <title>OESA-2025-1059 — buildah security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-1059</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: buildah&lt;/p&gt;
&lt;p&gt;The  package provides a command line tool which can be used to * create a working container from scratch or * create a working container from an image as a starting point * mount/umount a working container&amp;amp;apos;s root file system for manipulation * save container&amp;amp;apos;s root file system layer to create a new image * delete a working container or an image&#13;
&#13;
Security Fix(es):&#13;
&#13;
The crypto/tls package of Go through 1.16.5 does not properly assert that the type of public key in an X.509 certificate matches the expected type when doing a RSA based key exchange, allowing a malicious TLS server to cause a TLS client to panic.(CVE-2021-34558)&#13;
&#13;
Uncontrolled recursion in the Parse functions in go/parser before Go 1.17.12 and Go 1.18.4 allow an attacker to cause a panic due to stack exhaustion via deeply nested types or declarations.(CVE-2022-1962)&#13;
&#13;
An incorrect handling of the supplementary groups in the Buildah container engine might lead to the sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissions and is able to execute a binary code in that container.(CVE-2022-2990)&#13;
&#13;
Programs which compile regular expressions from untrusted sources may be vulnerable to memory exhaustion or denial of service. The parsed regexp representation is linear in the size of the input, but in some cases the constant factor can be as high as 40,000, making relatively small…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: buildah&lt;/p&gt;
&lt;p&gt;The  package provides a command line tool which can be used to * create a working container from scratch or * create a working container from an image as a starting point * mount/umount a working container&amp;amp;apos;s root file system for manipulation * save container&amp;amp;apos;s root file system layer to create a new image * delete a working container or an image&#13;
&#13;
Security Fix(es):&#13;
&#13;
The crypto/tls package of Go through 1.16.5 does not properly assert that the type of public key in an X.509 certificate matches the expected type when doing a RSA based key exchange, allowing a malicious TLS server to cause a TLS client to panic.(CVE-2021-34558)&#13;
&#13;
Uncontrolled recursion in the Parse functions in go/parser before Go 1.17.12 and Go 1.18.4 allow an attacker to cause a panic due to stack exhaustion via deeply nested types or declarations.(CVE-2022-1962)&#13;
&#13;
An incorrect handling of the supplementary groups in the Buildah container engine might lead to the sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissions and is able to execute a binary code in that container.(CVE-2022-2990)&#13;
&#13;
Programs which compile regular expressions from untrusted sources may be vulnerable to memory exhaustion or denial of service. The parsed regexp representation is linear in the size of the input, but in some cases the constant factor can be as high as 40,000, making relatively small…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-1059</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:12289-1 — buildah-1.27.0-3.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12289-1</link>
      <description>&lt;p&gt;buildah-1.27.0-3.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;buildah-1.27.0-3.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:12289-1</guid>
    </item>
    <item>
      <title>RHSA-2023:1325 — Red Hat Security Advisory: OpenShift Container Platform 4.13.0 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2023:1325</link>
      <description>&lt;p&gt;buildah: possible information disclosure and modification OpenShift: Missing HTTP Strict Transport Security golang: crash in a golang.org/x/crypto/ssh server golang: net/http: excessive memory growth in a Go server accepting HTTP/2 requests golang: path/filepath: path-filepath filepath.Clean path traversal golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding golang: crypto/tls: large handshake records may cause panics golang: net/http, mime/multipart: denial of service from excessive resource consumption haproxy: segfault DoS openshift/apiserver-library-go: Bypass of SCC seccomp profile restrictions podman: symlink exchange attack in podman export volume python-werkzeug: high resource usage when parsing multipart form data with many fields haproxy: request smuggling attack in HTTP/1 header parsing&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;buildah: possible information disclosure and modification OpenShift: Missing HTTP Strict Transport Security golang: crash in a golang.org/x/crypto/ssh server golang: net/http: excessive memory growth in a Go server accepting HTTP/2 requests golang: path/filepath: path-filepath filepath.Clean path traversal golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding golang: crypto/tls: large handshake records may cause panics golang: net/http, mime/multipart: denial of service from excessive resource consumption haproxy: segfault DoS openshift/apiserver-library-go: Bypass of SCC seccomp profile restrictions podman: symlink exchange attack in podman export volume python-werkzeug: high resource usage when parsing multipart form data with many fields haproxy: request smuggling attack in HTTP/1 header parsing&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2023:1325</guid>
    </item>
    <item>
      <title>SUSE-SU-2022:3766-1 — Security update for buildah</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2022:3766-1</link>
      <description>&lt;p&gt;Security update for buildah&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for buildah&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2022:3766-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-2990</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-2990</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: golang-github-containers-buildah, Ubuntu:Pro:24.04:LTS: golang-github-containers-buildah, Ubuntu:25.10: golang-github-containers-buildah, Ubuntu:Pro:26.04:LTS: golang-github-containers-buildah&lt;/p&gt;
&lt;p&gt;An incorrect handling of the supplementary groups in the Buildah container engine might lead to the sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissions and is able to execute a binary code in that container.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: golang-github-containers-buildah, Ubuntu:Pro:24.04:LTS: golang-github-containers-buildah, Ubuntu:25.10: golang-github-containers-buildah, Ubuntu:Pro:26.04:LTS: golang-github-containers-buildah&lt;/p&gt;
&lt;p&gt;An incorrect handling of the supplementary groups in the Buildah container engine might lead to the sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissions and is able to execute a binary code in that container.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-2990</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-2044 — Red Hat Enterprise Linux: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2044</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um beliebigen Programmcode auszuführen, Dateien zu manipulieren, Informationen offenzulegen oder einen Denial of Service Zustand herbeizuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um beliebigen Programmcode auszuführen, Dateien zu manipulieren, Informationen offenzulegen oder einen Denial of Service Zustand herbeizuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2044</guid>
    </item>
  </channel>
</rss>
