<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 01:56:17 +0000</lastBuildDate>
    <item>
      <title>ALSA-2022:6463 — Moderate: gnupg2 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2022:6463</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: gnupg2, AlmaLinux:8: gnupg2-smime&lt;/p&gt;
&lt;p&gt;The GNU Privacy Guard (GnuPG or GPG) is a tool for encrypting data and creating digital signatures, compliant with OpenPGP and S/MIME standards.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* gpg: Signature spoofing via status line injection (CVE-2022-34903)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: gnupg2, AlmaLinux:8: gnupg2-smime&lt;/p&gt;
&lt;p&gt;The GNU Privacy Guard (GnuPG or GPG) is a tool for encrypting data and creating digital signatures, compliant with OpenPGP and S/MIME standards.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* gpg: Signature spoofing via status line injection (CVE-2022-34903)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2022:6463</guid>
    </item>
    <item>
      <title>bdu:2023-03850</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-03850</link>
      <description>bdu:2023-03850</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-03850</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2022-34903 — CVE-2022-34903 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2022-34903</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2022-34903</guid>
    </item>
    <item>
      <title>certfr-2022-avi-1069 — De multiples vulnérabilités ont été découvertes dans les produits IBM.
Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-1069</link>
      <description>certfr-2022-avi-1069</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-1069</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-KS26224 — Security fixes in gnupg 2.2.35-r4</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ks26224</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: gnupg&lt;/p&gt;
&lt;p&gt;Package gnupg version 2.2.35-r4 fixes 1 vulnerabilities: CVE-2022-34903&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: gnupg&lt;/p&gt;
&lt;p&gt;Package gnupg version 2.2.35-r4 fixes 1 vulnerabilities: CVE-2022-34903&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ks26224</guid>
    </item>
    <item>
      <title>EUVD-2026-18011</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-18011</link>
      <description>EUVD-2026-18011</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-18011</guid>
    </item>
    <item>
      <title>fkie_cve-2022-34903</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-34903</link>
      <description>&lt;p&gt;GnuPG through 2.3.6, in unusual situations where an attacker possesses any secret-key information from a victim&amp;#39;s keyring and other constraints (e.g., use of GPGME) are met, allows signature forgery via injection into the status line.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;GnuPG through 2.3.6, in unusual situations where an attacker possesses any secret-key information from a victim&amp;#39;s keyring and other constraints (e.g., use of GPGME) are met, allows signature forgery via injection into the status line.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-34903</guid>
    </item>
    <item>
      <title>GHSA-356p-pg27-x2cf</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-356p-pg27-x2cf</link>
      <description>&lt;p&gt;GnuPG through 2.3.6, in unusual situations where an attacker possesses any secret-key information from a victim&amp;#39;s keyring and other constraints (e.g., use of GPGME) are met, allows signature forgery via injection into the status line.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;GnuPG through 2.3.6, in unusual situations where an attacker possesses any secret-key information from a victim&amp;#39;s keyring and other constraints (e.g., use of GPGME) are met, allows signature forgery via injection into the status line.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-356p-pg27-x2cf</guid>
    </item>
    <item>
      <title>gsd-2022-34903</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-34903</link>
      <description>gsd-2022-34903</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-34903</guid>
    </item>
    <item>
      <title>ICSA-24-046-11 — Siemens SCALANCE XCM-/XRM-300</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-24-046-11</link>
      <description>&lt;p&gt;A carefully crafted If: request header can cause a memory read, or write of a single zero byte, in a pool (heap) memory location beyond the header value sent. This could cause the process to crash.&lt;/p&gt;
&lt;p&gt;This issue affects Apache HTTP Server 2.4.54 and earlier. A flaw was found in python. In algorithms with quadratic time complexity using non-binary bases, when using int(&amp;#34;text&amp;#34;), a system could take 50ms to parse an int string with 100,000 digits and 5s for 1,000,000 digits (float, decimal, int.from_bytes(), and int() for binary bases 2, 4, 8, 16, and 32 are not affected). The highest threat from this vulnerability is to system availability. A flaw was found in libdnf&amp;#39;s signature verification functionality in versions before 0.60.1. This flaw allows an attacker to achieve code execution if they can alter the header information of an RPM package and then trick a user or system into installing it. The highest risk of this vulnerability is to confidentiality, integrity, as well as system availability. An out-of-bounds memory access flaw was found in the ATI VGA device emulation of QEMU. This flaw occurs in the ati_2d_blt() routine while handling MMIO write operations when the guest provides invalid values for the destination display parameters. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service. A vulnerability was found in the fs/inode.c:inode_init_owner() function logic of the LInux kernel that allows local users to create…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A carefully crafted If: request header can cause a memory read, or write of a single zero byte, in a pool (heap) memory location beyond the header value sent. This could cause the process to crash.&lt;/p&gt;
&lt;p&gt;This issue affects Apache HTTP Server 2.4.54 and earlier. A flaw was found in python. In algorithms with quadratic time complexity using non-binary bases, when using int(&amp;#34;text&amp;#34;), a system could take 50ms to parse an int string with 100,000 digits and 5s for 1,000,000 digits (float, decimal, int.from_bytes(), and int() for binary bases 2, 4, 8, 16, and 32 are not affected). The highest threat from this vulnerability is to system availability. A flaw was found in libdnf&amp;#39;s signature verification functionality in versions before 0.60.1. This flaw allows an attacker to achieve code execution if they can alter the header information of an RPM package and then trick a user or system into installing it. The highest risk of this vulnerability is to confidentiality, integrity, as well as system availability. An out-of-bounds memory access flaw was found in the ATI VGA device emulation of QEMU. This flaw occurs in the ati_2d_blt() routine while handling MMIO write operations when the guest provides invalid values for the destination display parameters. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service. A vulnerability was found in the fs/inode.c:inode_init_owner() function logic of the LInux kernel that allows local users to create…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-24-046-11</guid>
    </item>
    <item>
      <title>msrc_CVE-2022-34903 — GnuPG through 2.3.6 in unusual situations where an attacker possesses any secret-key information from a victim's keyrin…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2022-34903</link>
      <description>msrc_CVE-2022-34903</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2022-34903</guid>
    </item>
    <item>
      <title>OESA-2022-1847 — gnupg2 security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2022-1847</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: gnupg2, openEuler:20.03-LTS-SP3: gnupg2, openEuler:22.03-LTS: gnupg2&lt;/p&gt;
&lt;p&gt;GnuPG is a complete and free implementation of the OpenPGP standard as defined by RFC4880 (also known as PGP).  GnuPG enables encryption and signing of data and communication, and features a versatile key management system as well as access modules for public key directories.&#13;
&#13;
Security Fix(es):&#13;
&#13;
GnuPG through 2.3.6, in unusual situations where an attacker possesses any secret-key information from a victim&amp;amp;apos;s keyring and other constraints (e.g., use of GPGME) are met, allows signature forgery via injection into the status line.(CVE-2022-34903)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: gnupg2, openEuler:20.03-LTS-SP3: gnupg2, openEuler:22.03-LTS: gnupg2&lt;/p&gt;
&lt;p&gt;GnuPG is a complete and free implementation of the OpenPGP standard as defined by RFC4880 (also known as PGP).  GnuPG enables encryption and signing of data and communication, and features a versatile key management system as well as access modules for public key directories.&#13;
&#13;
Security Fix(es):&#13;
&#13;
GnuPG through 2.3.6, in unusual situations where an attacker possesses any secret-key information from a victim&amp;amp;apos;s keyring and other constraints (e.g., use of GPGME) are met, allows signature forgery via injection into the status line.(CVE-2022-34903)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2022-1847</guid>
    </item>
    <item>
      <title>openSUSE-SU-2022:2546-1 — Security update for gpg2</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2022:2546-1</link>
      <description>&lt;p&gt;Security update for gpg2&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for gpg2&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2022:2546-1</guid>
    </item>
    <item>
      <title>SSA-202008 — SSA-202008: Multiple Vulnerabilities in Ruggedcom Rox Before V2.17.0</title>
      <link>https://cve.radiocsirt.org/vuln/ssa-202008</link>
      <description>&lt;p&gt;An issue was discovered in shadow 4.5. newgidmap (in shadow-utils) is setuid and allows an unprivileged user to be placed in a user namespace where setgroups(2) is permitted. This allows an attacker to remove themselves from a supplementary group, which may allow access to certain filesystem paths if the administrator has used &amp;#34;group blacklisting&amp;#34; (e.g., chmod g-rwx) to restrict access to paths. This flaw effectively reverts a security feature in the kernel (in particular, the /proc/self/setgroups knob) to prevent this sort of privilege escalation. GnuPG 2.2.4 and 2.2.5 does not enforce a configuration in which key certification requires an offline master Certify key, which results in apparently valid certifications that occurred only with access to a signing subkey. remember_Ktype in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30, allows attackers to trigger excessive memory consumption (aka OOM). This can occur during execution of cxxfilt. binutils version 2.32 and earlier contains a Integer Overflow vulnerability in objdump, bfd_get_dynamic_reloc_upper_bound,bfd_canonicalize_dynamic_reloc that can result in Integer overflow trigger heap overflow. Successful exploitation allows execution of arbitrary code.. This attack appear to be exploitable via Local. This vulnerability appears to have been fixed in after commit 3a551c7a1b80fca579461774860574eabfd7f18f. libseccomp before 2.4.0 did not correctly generate 64-bit syscall argument comparisons using the ar…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An issue was discovered in shadow 4.5. newgidmap (in shadow-utils) is setuid and allows an unprivileged user to be placed in a user namespace where setgroups(2) is permitted. This allows an attacker to remove themselves from a supplementary group, which may allow access to certain filesystem paths if the administrator has used &amp;#34;group blacklisting&amp;#34; (e.g., chmod g-rwx) to restrict access to paths. This flaw effectively reverts a security feature in the kernel (in particular, the /proc/self/setgroups knob) to prevent this sort of privilege escalation. GnuPG 2.2.4 and 2.2.5 does not enforce a configuration in which key certification requires an offline master Certify key, which results in apparently valid certifications that occurred only with access to a signing subkey. remember_Ktype in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30, allows attackers to trigger excessive memory consumption (aka OOM). This can occur during execution of cxxfilt. binutils version 2.32 and earlier contains a Integer Overflow vulnerability in objdump, bfd_get_dynamic_reloc_upper_bound,bfd_canonicalize_dynamic_reloc that can result in Integer overflow trigger heap overflow. Successful exploitation allows execution of arbitrary code.. This attack appear to be exploitable via Local. This vulnerability appears to have been fixed in after commit 3a551c7a1b80fca579461774860574eabfd7f18f. libseccomp before 2.4.0 did not correctly generate 64-bit syscall argument comparisons using the ar…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ssa-202008</guid>
    </item>
    <item>
      <title>SUSE-SU-2022:2529-1 — Security update for gpg2</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2022:2529-1</link>
      <description>&lt;p&gt;Security update for gpg2&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for gpg2&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2022:2529-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-34903</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-34903</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: gnupg, Ubuntu:Pro:16.04:LTS: gnupg, Ubuntu:Pro:16.04:LTS: gnupg2, Ubuntu:18.04:LTS: gnupg2, Ubuntu:20.04:LTS: gnupg2, Ubuntu:22.04:LTS: gnupg2&lt;/p&gt;
&lt;p&gt;GnuPG through 2.3.6, in unusual situations where an attacker possesses any secret-key information from a victim&amp;#39;s keyring and other constraints (e.g., use of GPGME) are met, allows signature forgery via injection into the status line.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: gnupg, Ubuntu:Pro:16.04:LTS: gnupg, Ubuntu:Pro:16.04:LTS: gnupg2, Ubuntu:18.04:LTS: gnupg2, Ubuntu:20.04:LTS: gnupg2, Ubuntu:22.04:LTS: gnupg2&lt;/p&gt;
&lt;p&gt;GnuPG through 2.3.6, in unusual situations where an attacker possesses any secret-key information from a victim&amp;#39;s keyring and other constraints (e.g., use of GPGME) are met, allows signature forgery via injection into the status line.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-34903</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-0511 — GnuPGP: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0511</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in GnuPGP ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in GnuPGP ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0511</guid>
    </item>
  </channel>
</rss>
