<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 17:50:16 +0000</lastBuildDate>
    <item>
      <title>bdu:2022-05641</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-05641</link>
      <description>bdu:2022-05641</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-05641</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2022-36109 — CVE-2022-36109 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2022-36109</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2022-36109</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0622 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Certaines d'entre elles permettent à un attaq…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0622</link>
      <description>certfr-2025-avi-0622</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0622</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-MS11283 — Security fix for CVE-2022-36109 applied in: docker 20.10.18-r0, docker-fips 20.10.18-r0</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ms11283</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: docker, CleanStart: docker-fips&lt;/p&gt;
&lt;p&gt;CVE-2022-36109 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: docker, CleanStart: docker-fips&lt;/p&gt;
&lt;p&gt;CVE-2022-36109 affects multiple packages. This issue is resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ms11283</guid>
    </item>
    <item>
      <title>EUVD-2026-233733</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-233733</link>
      <description>EUVD-2026-233733</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-233733</guid>
    </item>
    <item>
      <title>fkie_cve-2022-36109</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-36109</link>
      <description>&lt;p&gt;Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where supplementary groups are not set up properly. If an attacker has direct access to a container and manipulates their supplementary group access, they may be able to use supplementary group access to bypass primary group restrictions in some cases, potentially gaining access to sensitive information or gaining the ability to execute code in that container.  This bug is fixed in Moby (Docker Engine) 20.10.18. Running containers should be stopped and restarted for the permissions to be fixed. For users unable to upgrade, this problem can be worked around by not using the `&amp;#34;USER $USERNAME&amp;#34;` Dockerfile instruction. Instead by calling `ENTRYPOINT [&amp;#34;su&amp;#34;, &amp;#34;-&amp;#34;, &amp;#34;user&amp;#34;]` the supplementary groups will be set up properly.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where supplementary groups are not set up properly. If an attacker has direct access to a container and manipulates their supplementary group access, they may be able to use supplementary group access to bypass primary group restrictions in some cases, potentially gaining access to sensitive information or gaining the ability to execute code in that container.  This bug is fixed in Moby (Docker Engine) 20.10.18. Running containers should be stopped and restarted for the permissions to be fixed. For users unable to upgrade, this problem can be worked around by not using the `&amp;#34;USER $USERNAME&amp;#34;` Dockerfile instruction. Instead by calling `ENTRYPOINT [&amp;#34;su&amp;#34;, &amp;#34;-&amp;#34;, &amp;#34;user&amp;#34;]` the supplementary groups will be set up properly.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-36109</guid>
    </item>
    <item>
      <title>GHSA-rc4r-wh2q-q6c4 — Docker supplementary group permissions not set up properly, allowing attackers to bypass primary group restrictions</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-rc4r-wh2q-q6c4</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/docker/docker&lt;/p&gt;
&lt;p&gt;Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where supplementary groups are not set up properly. If an attacker has direct access to a container and manipulates their supplementary group access, they may be able to use supplementary group access to bypass primary group restrictions in some cases, potentially gaining access to sensitive information or gaining the ability to execute code in that container.  This bug is fixed in Moby (Docker Engine) 20.10.18. Users should update to this version when it is available. Running containers should be stopped and restarted for the permissions to be fixed. For users unable to upgrade, this problem can be worked around by not using the `&amp;#34;USER $USERNAME&amp;#34;` Dockerfile instruction. Instead by calling `ENTRYPOINT [&amp;#34;su&amp;#34;, &amp;#34;-&amp;#34;, &amp;#34;user&amp;#34;]` the supplementary groups will be set up properly.&lt;/p&gt;
&lt;p&gt;Thanks to Steven Murdoch for reporting this issue.&lt;/p&gt;
&lt;p&gt;----&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;If an attacker has direct access to a container and manipulates their supplementary group access, they may be able to use supplementary group access to bypass primary group restrictions in some cases, potentially gaining access to sensitive information or gaining the ability to execute code in that container.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;This bug is fixed in Moby (Docker Engine) 20.10.18. Users should update to this version when it is available.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;This problem can be worked around by not using the `&amp;#34;USER $USERN…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/docker/docker&lt;/p&gt;
&lt;p&gt;Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where supplementary groups are not set up properly. If an attacker has direct access to a container and manipulates their supplementary group access, they may be able to use supplementary group access to bypass primary group restrictions in some cases, potentially gaining access to sensitive information or gaining the ability to execute code in that container.  This bug is fixed in Moby (Docker Engine) 20.10.18. Users should update to this version when it is available. Running containers should be stopped and restarted for the permissions to be fixed. For users unable to upgrade, this problem can be worked around by not using the `&amp;#34;USER $USERNAME&amp;#34;` Dockerfile instruction. Instead by calling `ENTRYPOINT [&amp;#34;su&amp;#34;, &amp;#34;-&amp;#34;, &amp;#34;user&amp;#34;]` the supplementary groups will be set up properly.&lt;/p&gt;
&lt;p&gt;Thanks to Steven Murdoch for reporting this issue.&lt;/p&gt;
&lt;p&gt;----&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;If an attacker has direct access to a container and manipulates their supplementary group access, they may be able to use supplementary group access to bypass primary group restrictions in some cases, potentially gaining access to sensitive information or gaining the ability to execute code in that container.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;This bug is fixed in Moby (Docker Engine) 20.10.18. Users should update to this version when it is available.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;This problem can be worked around by not using the `&amp;#34;USER $USERN…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-rc4r-wh2q-q6c4</guid>
    </item>
    <item>
      <title>gsd-2022-36109</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-36109</link>
      <description>gsd-2022-36109</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-36109</guid>
    </item>
    <item>
      <title>OESA-2022-1936 — docker security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2022-1936</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: docker, openEuler:20.03-LTS-SP3: docker, openEuler:22.03-LTS: docker&lt;/p&gt;
&lt;p&gt;Docker is an open source project to build, ship and run any application as a lightweight container.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where supplementary groups are not set up properly. If an attacker has direct access to a container and manipulates their supplementary group access, they may be able to use supplementary group access to bypass primary group restrictions in some cases, potentially gaining access to sensitive information or gaining the ability to execute code in that container. This bug is fixed in Moby (Docker Engine) 20.10.18. Running containers should be stopped and restarted for the permissions to be fixed. For users unable to upgrade, this problem can be worked around by not using the `&amp;amp;quot;USER $USERNAME&amp;amp;quot;` Dockerfile instruction. Instead by calling `ENTRYPOINT [&amp;amp;quot;su&amp;amp;quot;, &amp;amp;quot;-&amp;amp;quot;, &amp;amp;quot;user&amp;amp;quot;]` the supplementary groups will be set up properly.(CVE-2022-36109)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: docker, openEuler:20.03-LTS-SP3: docker, openEuler:22.03-LTS: docker&lt;/p&gt;
&lt;p&gt;Docker is an open source project to build, ship and run any application as a lightweight container.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where supplementary groups are not set up properly. If an attacker has direct access to a container and manipulates their supplementary group access, they may be able to use supplementary group access to bypass primary group restrictions in some cases, potentially gaining access to sensitive information or gaining the ability to execute code in that container. This bug is fixed in Moby (Docker Engine) 20.10.18. Running containers should be stopped and restarted for the permissions to be fixed. For users unable to upgrade, this problem can be worked around by not using the `&amp;amp;quot;USER $USERNAME&amp;amp;quot;` Dockerfile instruction. Instead by calling `ENTRYPOINT [&amp;amp;quot;su&amp;amp;quot;, &amp;amp;quot;-&amp;amp;quot;, &amp;amp;quot;user&amp;amp;quot;]` the supplementary groups will be set up properly.(CVE-2022-36109)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2022-1936</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:12790-1 — docker-20.10.23_ce-2.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12790-1</link>
      <description>&lt;p&gt;docker-20.10.23_ce-2.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;docker-20.10.23_ce-2.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:12790-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2023:0795-2 — Security update for docker</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2023:0795-2</link>
      <description>&lt;p&gt;Security update for docker&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for docker&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2023:0795-2</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-36109</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-36109</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: docker.io, Ubuntu:18.04:LTS: docker.io, Ubuntu:20.04:LTS: docker.io, Ubuntu:22.04:LTS: docker.io&lt;/p&gt;
&lt;p&gt;Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where supplementary groups are not set up properly. If an attacker has direct access to a container and manipulates their supplementary group access, they may be able to use supplementary group access to bypass primary group restrictions in some cases, potentially gaining access to sensitive information or gaining the ability to execute code in that container.  This bug is fixed in Moby (Docker Engine) 20.10.18. Running containers should be stopped and restarted for the permissions to be fixed. For users unable to upgrade, this problem can be worked around by not using the `&amp;#34;USER $USERNAME&amp;#34;` Dockerfile instruction. Instead by calling `ENTRYPOINT [&amp;#34;su&amp;#34;, &amp;#34;-&amp;#34;, &amp;#34;user&amp;#34;]` the supplementary groups will be set up properly.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: docker.io, Ubuntu:18.04:LTS: docker.io, Ubuntu:20.04:LTS: docker.io, Ubuntu:22.04:LTS: docker.io&lt;/p&gt;
&lt;p&gt;Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where supplementary groups are not set up properly. If an attacker has direct access to a container and manipulates their supplementary group access, they may be able to use supplementary group access to bypass primary group restrictions in some cases, potentially gaining access to sensitive information or gaining the ability to execute code in that container.  This bug is fixed in Moby (Docker Engine) 20.10.18. Running containers should be stopped and restarted for the permissions to be fixed. For users unable to upgrade, this problem can be worked around by not using the `&amp;#34;USER $USERNAME&amp;#34;` Dockerfile instruction. Instead by calling `ENTRYPOINT [&amp;#34;su&amp;#34;, &amp;#34;-&amp;#34;, &amp;#34;user&amp;#34;]` the supplementary groups will be set up properly.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-36109</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-1738 — IBM InfoSphere Information Server: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1738</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM InfoSphere Information Server ausnutzen, um seine Privilegien zu erweitern, beliebigen Programmcode auszuführen, einen Cross-Site-Scripting-Angriff durchzuführen, Informationen offenzulegen, einen Denial of Service Zustand herbeizuführen, Dateien zu manipulieren oder Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in IBM InfoSphere Information Server ausnutzen, um seine Privilegien zu erweitern, beliebigen Programmcode auszuführen, einen Cross-Site-Scripting-Angriff durchzuführen, Informationen offenzulegen, einen Denial of Service Zustand herbeizuführen, Dateien zu manipulieren oder Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1738</guid>
    </item>
  </channel>
</rss>
