<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 12:02:16 +0000</lastBuildDate>
    <item>
      <title>ALSA-2023:0837 — Moderate: systemd security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2023:0837</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: systemd, AlmaLinux:8: systemd-container, AlmaLinux:8: systemd-devel, AlmaLinux:8: systemd-journal-remote, AlmaLinux:8: systemd-libs, AlmaLinux:8: systemd-pam, AlmaLinux:8: systemd-tests, AlmaLinux:8: systemd-udev&lt;/p&gt;
&lt;p&gt;The systemd packages contain systemd, a system and service manager for Linux, compatible with the SysV and LSB init scripts. It provides aggressive parallelism capabilities, uses socket and D-Bus activation for starting services, offers on-demand starting of daemons, and keeps track of processes using Linux cgroups. In addition, it supports snapshotting and restoring of the system state, maintains mount and automount points, and implements an elaborate transactional dependency-based service control logic. It can also work as a drop-in replacement for sysvinit.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* systemd: local information leak due to systemd-coredump not respecting fs.suid_dumpable kernel setting (CVE-2022-4415)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Bug Fix(es):&lt;/p&gt;
&lt;p&gt;* systemd doesn&amp;#39;t record messages to the journal during boot (BZ#2164049)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: systemd, AlmaLinux:8: systemd-container, AlmaLinux:8: systemd-devel, AlmaLinux:8: systemd-journal-remote, AlmaLinux:8: systemd-libs, AlmaLinux:8: systemd-pam, AlmaLinux:8: systemd-tests, AlmaLinux:8: systemd-udev&lt;/p&gt;
&lt;p&gt;The systemd packages contain systemd, a system and service manager for Linux, compatible with the SysV and LSB init scripts. It provides aggressive parallelism capabilities, uses socket and D-Bus activation for starting services, offers on-demand starting of daemons, and keeps track of processes using Linux cgroups. In addition, it supports snapshotting and restoring of the system state, maintains mount and automount points, and implements an elaborate transactional dependency-based service control logic. It can also work as a drop-in replacement for sysvinit.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* systemd: local information leak due to systemd-coredump not respecting fs.suid_dumpable kernel setting (CVE-2022-4415)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Bug Fix(es):&lt;/p&gt;
&lt;p&gt;* systemd doesn&amp;#39;t record messages to the journal during boot (BZ#2164049)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2023:0837</guid>
    </item>
    <item>
      <title>bdu:2023-07591</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-07591</link>
      <description>bdu:2023-07591</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-07591</guid>
    </item>
    <item>
      <title>certfr-2023-avi-0210 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;le noyau Linux d'Ubuntu&lt;/span&gt;. Elles permett…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0210</link>
      <description>certfr-2023-avi-0210</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0210</guid>
    </item>
    <item>
      <title>EUVD-2026-257692</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-257692</link>
      <description>EUVD-2026-257692</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-257692</guid>
    </item>
    <item>
      <title>fkie_cve-2022-4415</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-4415</link>
      <description>&lt;p&gt;A vulnerability was found in systemd. This security flaw can cause a local information leak due to systemd-coredump not respecting the fs.suid_dumpable kernel setting.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability was found in systemd. This security flaw can cause a local information leak due to systemd-coredump not respecting the fs.suid_dumpable kernel setting.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-4415</guid>
    </item>
    <item>
      <title>GHSA-x49m-v7mv-3wvx</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-x49m-v7mv-3wvx</link>
      <description>&lt;p&gt;A vulnerability was found in systemd. This security flaw can cause a local information leak due to systemd-coredump not respecting the fs.suid_dumpable kernel setting.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability was found in systemd. This security flaw can cause a local information leak due to systemd-coredump not respecting the fs.suid_dumpable kernel setting.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-x49m-v7mv-3wvx</guid>
    </item>
    <item>
      <title>gsd-2022-4415</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-4415</link>
      <description>gsd-2022-4415</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-4415</guid>
    </item>
    <item>
      <title>ICSA-24-046-11 — Siemens SCALANCE XCM-/XRM-300</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-24-046-11</link>
      <description>&lt;p&gt;A carefully crafted If: request header can cause a memory read, or write of a single zero byte, in a pool (heap) memory location beyond the header value sent. This could cause the process to crash.&lt;/p&gt;
&lt;p&gt;This issue affects Apache HTTP Server 2.4.54 and earlier. A flaw was found in python. In algorithms with quadratic time complexity using non-binary bases, when using int(&amp;#34;text&amp;#34;), a system could take 50ms to parse an int string with 100,000 digits and 5s for 1,000,000 digits (float, decimal, int.from_bytes(), and int() for binary bases 2, 4, 8, 16, and 32 are not affected). The highest threat from this vulnerability is to system availability. A flaw was found in libdnf&amp;#39;s signature verification functionality in versions before 0.60.1. This flaw allows an attacker to achieve code execution if they can alter the header information of an RPM package and then trick a user or system into installing it. The highest risk of this vulnerability is to confidentiality, integrity, as well as system availability. An out-of-bounds memory access flaw was found in the ATI VGA device emulation of QEMU. This flaw occurs in the ati_2d_blt() routine while handling MMIO write operations when the guest provides invalid values for the destination display parameters. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service. A vulnerability was found in the fs/inode.c:inode_init_owner() function logic of the LInux kernel that allows local users to create…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A carefully crafted If: request header can cause a memory read, or write of a single zero byte, in a pool (heap) memory location beyond the header value sent. This could cause the process to crash.&lt;/p&gt;
&lt;p&gt;This issue affects Apache HTTP Server 2.4.54 and earlier. A flaw was found in python. In algorithms with quadratic time complexity using non-binary bases, when using int(&amp;#34;text&amp;#34;), a system could take 50ms to parse an int string with 100,000 digits and 5s for 1,000,000 digits (float, decimal, int.from_bytes(), and int() for binary bases 2, 4, 8, 16, and 32 are not affected). The highest threat from this vulnerability is to system availability. A flaw was found in libdnf&amp;#39;s signature verification functionality in versions before 0.60.1. This flaw allows an attacker to achieve code execution if they can alter the header information of an RPM package and then trick a user or system into installing it. The highest risk of this vulnerability is to confidentiality, integrity, as well as system availability. An out-of-bounds memory access flaw was found in the ATI VGA device emulation of QEMU. This flaw occurs in the ati_2d_blt() routine while handling MMIO write operations when the guest provides invalid values for the destination display parameters. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service. A vulnerability was found in the fs/inode.c:inode_init_owner() function logic of the LInux kernel that allows local users to create…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-24-046-11</guid>
    </item>
    <item>
      <title>msrc_CVE-2022-4415 — A vulnerability was found in systemd. This security flaw can cause a local information leak due to systemd-coredump not…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2022-4415</link>
      <description>msrc_CVE-2022-4415</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2022-4415</guid>
    </item>
    <item>
      <title>OESA-2023-1027 — systemd security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2023-1027</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP1: systemd&lt;/p&gt;
&lt;p&gt;systemd is a system and service manager that runs as PID 1 and starts the rest of the system. &#13;
&#13;
Security Fix(es):&#13;
&#13;
A vulnerability was found in systemd. This security flaw can cause a local information leak due to systemd-coredump not respecting the fs.suid_dumpable kernel setting.(CVE-2022-4415)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP1: systemd&lt;/p&gt;
&lt;p&gt;systemd is a system and service manager that runs as PID 1 and starts the rest of the system. &#13;
&#13;
Security Fix(es):&#13;
&#13;
A vulnerability was found in systemd. This security flaw can cause a local information leak due to systemd-coredump not respecting the fs.suid_dumpable kernel setting.(CVE-2022-4415)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2023-1027</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:12576-1 — libsystemd0-252.3-2.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12576-1</link>
      <description>&lt;p&gt;libsystemd0-252.3-2.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libsystemd0-252.3-2.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:12576-1</guid>
    </item>
    <item>
      <title>RHSA-2024:1105 — Red Hat Security Advisory: systemd security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:1105</link>
      <description>&lt;p&gt;systemd: buffer overrun in format_timespan() function systemd: local information leak due to systemd-coredump not respecting fs.suid_dumpable kernel setting systemd: privilege escalation via the less pager&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;systemd: buffer overrun in format_timespan() function systemd: local information leak due to systemd-coredump not respecting fs.suid_dumpable kernel setting systemd: privilege escalation via the less pager&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:1105</guid>
    </item>
    <item>
      <title>SUSE-SU-2022:4627-1 — Security update for systemd</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2022:4627-1</link>
      <description>&lt;p&gt;Security update for systemd&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for systemd&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2022:4627-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-4415</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-4415</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: systemd, Ubuntu:Pro:18.04:LTS: systemd, Ubuntu:20.04:LTS: systemd, Ubuntu:22.04:LTS: systemd&lt;/p&gt;
&lt;p&gt;A vulnerability was found in systemd. This security flaw can cause a local information leak due to systemd-coredump not respecting the fs.suid_dumpable kernel setting.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: systemd, Ubuntu:Pro:18.04:LTS: systemd, Ubuntu:20.04:LTS: systemd, Ubuntu:22.04:LTS: systemd&lt;/p&gt;
&lt;p&gt;A vulnerability was found in systemd. This security flaw can cause a local information leak due to systemd-coredump not respecting the fs.suid_dumpable kernel setting.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-4415</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-2384 — systemd: Schwachstelle ermöglicht Offenlegung von Informationen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2384</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in systemd und Red Hat Enterprise Linux ausnutzen, um Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in systemd und Red Hat Enterprise Linux ausnutzen, um Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2384</guid>
    </item>
  </channel>
</rss>
