<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 22:26:11 +0000</lastBuildDate>
    <item>
      <title>2NGA002579 — ABB Arctic communication solution ARM600 Vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/2nga002579</link>
      <description>&lt;p&gt;ABB is aware of public reports of a vulnerabilities in product versions listed as affected in this advisory. An attacker who successfully exploited these vulnerabilities could cause the product to stop, make the product inacces-sible, take remote control of the product or insert and run arbitrary code.
As part of ABB product lifecycle policy, once a product transitions to end-of-life, we discontinue maintenance, security patches, and technical support to focus on current and future technologies. While the product will continue to function, we strongly recommend implementing mitigations defined in this document, such as using a private APN cellular network between Arctic wireless gateways and ARM600 for establishing VPN tunnels, to mitigate security risks and avoid potential vulnerabilities.
As part of ABB product lifecycle policy, once a product transitions to Limited state, we discontinue maintenance, security patches, and technical support to focus on current and future technologies. While the product will continue to function, we strongly recommend implementing mitigations defined in this document to mitigate security risks.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ABB is aware of public reports of a vulnerabilities in product versions listed as affected in this advisory. An attacker who successfully exploited these vulnerabilities could cause the product to stop, make the product inacces-sible, take remote control of the product or insert and run arbitrary code.
As part of ABB product lifecycle policy, once a product transitions to end-of-life, we discontinue maintenance, security patches, and technical support to focus on current and future technologies. While the product will continue to function, we strongly recommend implementing mitigations defined in this document, such as using a private APN cellular network between Arctic wireless gateways and ARM600 for establishing VPN tunnels, to mitigate security risks and avoid potential vulnerabilities.
As part of ABB product lifecycle policy, once a product transitions to Limited state, we discontinue maintenance, security patches, and technical support to focus on current and future technologies. While the product will continue to function, we strongly recommend implementing mitigations defined in this document to mitigate security risks.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/2nga002579</guid>
    </item>
    <item>
      <title>ALSA-2022:7185 — Important: device-mapper-multipath security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2022:7185</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: device-mapper-multipath, AlmaLinux:9: device-mapper-multipath-devel, AlmaLinux:9: device-mapper-multipath-libs, AlmaLinux:9: kpartx&lt;/p&gt;
&lt;p&gt;The device-mapper-multipath packages provide tools that use the device-mapper multipath kernel module to manage multipath devices.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* device-mapper-multipath: Authorization bypass, multipathd daemon listens for client connections on an abstract Unix socket (CVE-2022-41974)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: device-mapper-multipath, AlmaLinux:9: device-mapper-multipath-devel, AlmaLinux:9: device-mapper-multipath-libs, AlmaLinux:9: kpartx&lt;/p&gt;
&lt;p&gt;The device-mapper-multipath packages provide tools that use the device-mapper multipath kernel module to manage multipath devices.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* device-mapper-multipath: Authorization bypass, multipathd daemon listens for client connections on an abstract Unix socket (CVE-2022-41974)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2022:7185</guid>
    </item>
    <item>
      <title>bdu:2022-06669</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-06669</link>
      <description>bdu:2022-06669</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-06669</guid>
    </item>
    <item>
      <title>certfr-2023-avi-0120 — De multiples vulnérabilités ont été corrigées dans les produits &lt;span
class="textit"&gt;IBM&lt;/span&gt;. Elles permettent à un…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0120</link>
      <description>certfr-2023-avi-0120</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0120</guid>
    </item>
    <item>
      <title>EUVD-2026-19560</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-19560</link>
      <description>EUVD-2026-19560</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-19560</guid>
    </item>
    <item>
      <title>fkie_cve-2022-41974</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-41974</link>
      <description>&lt;p&gt;multipath-tools 0.7.0 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited alone or in conjunction with CVE-2022-41973. Local users able to write to UNIX domain sockets can bypass access controls and manipulate the multipath setup. This can lead to local privilege escalation to root. This occurs because an attacker can repeat a keyword, which is mishandled because arithmetic ADD is used instead of bitwise OR.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;multipath-tools 0.7.0 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited alone or in conjunction with CVE-2022-41973. Local users able to write to UNIX domain sockets can bypass access controls and manipulate the multipath setup. This can lead to local privilege escalation to root. This occurs because an attacker can repeat a keyword, which is mishandled because arithmetic ADD is used instead of bitwise OR.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-41974</guid>
    </item>
    <item>
      <title>GHSA-46cw-54vx-86g5</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-46cw-54vx-86g5</link>
      <description>&lt;p&gt;multipath-tools 0.7.0 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited alone or in conjunction with CVE-2022-41973. Local users able to write to UNIX domain sockets can bypass access controls and manipulate the multipath setup. This can lead to local privilege escalation to root. This occurs because an attacker can repeat a keyword, which is mishandled because arithmetic ADD is used instead of bitwise OR.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;multipath-tools 0.7.0 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited alone or in conjunction with CVE-2022-41973. Local users able to write to UNIX domain sockets can bypass access controls and manipulate the multipath setup. This can lead to local privilege escalation to root. This occurs because an attacker can repeat a keyword, which is mishandled because arithmetic ADD is used instead of bitwise OR.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-46cw-54vx-86g5</guid>
    </item>
    <item>
      <title>gsd-2022-41974</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-41974</link>
      <description>gsd-2022-41974</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-41974</guid>
    </item>
    <item>
      <title>ICSA-25-105-08 — ABB M2M Gateway</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-25-105-08</link>
      <description>&lt;p&gt;ABB is aware of public reports of a vulnerabilities in product versions listed as affected in this advisory. An attacker who successfully exploited these vulnerabilities could cause the product to stop, make the product inacces-sible, take remote control of the product or insert and run arbitrary code.
As part of ABB product lifecycle policy, once a product transitions to end-of-life, we discontinue maintenance, security patches, and technical support to focus on current and future technologies. While the product will continue to function, we strongly recommend implementing mitigations defined in this document, such as using a private APN cellular network between Arctic wireless gateways and ARM600 for establishing VPN tunnels, to mitigate security risks and avoid potential vulnerabilities.
As part of ABB product lifecycle policy, once a product transitions to Limited state, we discontinue maintenance, security patches, and technical support to focus on current and future technologies. While the product will continue to function, we strongly recommend implementing mitigations defined in this document to mitigate security risks.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ABB is aware of public reports of a vulnerabilities in product versions listed as affected in this advisory. An attacker who successfully exploited these vulnerabilities could cause the product to stop, make the product inacces-sible, take remote control of the product or insert and run arbitrary code.
As part of ABB product lifecycle policy, once a product transitions to end-of-life, we discontinue maintenance, security patches, and technical support to focus on current and future technologies. While the product will continue to function, we strongly recommend implementing mitigations defined in this document, such as using a private APN cellular network between Arctic wireless gateways and ARM600 for establishing VPN tunnels, to mitigate security risks and avoid potential vulnerabilities.
As part of ABB product lifecycle policy, once a product transitions to Limited state, we discontinue maintenance, security patches, and technical support to focus on current and future technologies. While the product will continue to function, we strongly recommend implementing mitigations defined in this document to mitigate security risks.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-25-105-08</guid>
    </item>
    <item>
      <title>msrc_CVE-2022-41974 — multipath-tools 0.7.0 through 0.9.x before 0.9.2 allows local users to obtain root access as exploited alone or in conj…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2022-41974</link>
      <description>msrc_CVE-2022-41974</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2022-41974</guid>
    </item>
    <item>
      <title>OESA-2022-2050 — multipath-tools security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2022-2050</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: multipath-tools, openEuler:20.03-LTS-SP3: multipath-tools, openEuler:22.03-LTS: multipath-tools&lt;/p&gt;
&lt;p&gt;This package provides the multipath tool and the multipathd daemon to manage dm-multipath devices. multipath can detect and set up multipath maps. multipathd sets up multipath maps automatically, monitors path devices for failure, removal, or addition, and applies the necessary changes to the multipath maps to ensure continuous availability of the map devices.&#13;
&#13;
Security Fix(es):&#13;
&#13;
multipath-tools 0.7.0 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited alone or in conjunction with CVE-2022-41973. Local users able to write to UNIX domain sockets can bypass access controls and manipulate the multipath setup. This can lead to local privilege escalation to root. This occurs because an attacker can repeat a keyword, which is mishandled because arithmetic ADD is used instead of bitwise OR.(CVE-2022-41974)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: multipath-tools, openEuler:20.03-LTS-SP3: multipath-tools, openEuler:22.03-LTS: multipath-tools&lt;/p&gt;
&lt;p&gt;This package provides the multipath tool and the multipathd daemon to manage dm-multipath devices. multipath can detect and set up multipath maps. multipathd sets up multipath maps automatically, monitors path devices for failure, removal, or addition, and applies the necessary changes to the multipath maps to ensure continuous availability of the map devices.&#13;
&#13;
Security Fix(es):&#13;
&#13;
multipath-tools 0.7.0 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited alone or in conjunction with CVE-2022-41973. Local users able to write to UNIX domain sockets can bypass access controls and manipulate the multipath setup. This can lead to local privilege escalation to root. This occurs because an attacker can repeat a keyword, which is mishandled because arithmetic ADD is used instead of bitwise OR.(CVE-2022-41974)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2022-2050</guid>
    </item>
    <item>
      <title>RHSA-2022:7185 — Red Hat Security Advisory: device-mapper-multipath security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2022:7185</link>
      <description>&lt;p&gt;device-mapper-multipath: Authorization bypass, multipathd daemon listens for client connections on an abstract Unix socket&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;device-mapper-multipath: Authorization bypass, multipathd daemon listens for client connections on an abstract Unix socket&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2022:7185</guid>
    </item>
    <item>
      <title>RHSA-2022:7187 — Red Hat Security Advisory: device-mapper-multipath security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2022:7187</link>
      <description>&lt;p&gt;device-mapper-multipath: Authorization bypass, multipathd daemon listens for client connections on an abstract Unix socket&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;device-mapper-multipath: Authorization bypass, multipathd daemon listens for client connections on an abstract Unix socket&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2022:7187</guid>
    </item>
    <item>
      <title>SUSE-SU-2022:3707-1 — Security update for multipath-tools</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2022:3707-1</link>
      <description>&lt;p&gt;Security update for multipath-tools&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for multipath-tools&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2022:3707-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-41974</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-41974</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: multipath-tools, Ubuntu:16.04:LTS: multipath-tools, Ubuntu:18.04:LTS: multipath-tools, Ubuntu:20.04:LTS: multipath-tools, Ubuntu:22.04:LTS: multipath-tools&lt;/p&gt;
&lt;p&gt;multipath-tools 0.7.0 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited alone or in conjunction with CVE-2022-41973. Local users able to write to UNIX domain sockets can bypass access controls and manipulate the multipath setup. This can lead to local privilege escalation to root. This occurs because an attacker can repeat a keyword, which is mishandled because arithmetic ADD is used instead of bitwise OR.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: multipath-tools, Ubuntu:16.04:LTS: multipath-tools, Ubuntu:18.04:LTS: multipath-tools, Ubuntu:20.04:LTS: multipath-tools, Ubuntu:22.04:LTS: multipath-tools&lt;/p&gt;
&lt;p&gt;multipath-tools 0.7.0 through 0.9.x before 0.9.2 allows local users to obtain root access, as exploited alone or in conjunction with CVE-2022-41973. Local users able to write to UNIX domain sockets can bypass access controls and manipulate the multipath setup. This can lead to local privilege escalation to root. This occurs because an attacker can repeat a keyword, which is mishandled because arithmetic ADD is used instead of bitwise OR.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-41974</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-1864 — Red Hat Enterprise Linux (multipathd): Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1864</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1864</guid>
    </item>
  </channel>
</rss>
