<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 11:31:30 +0000</lastBuildDate>
    <item>
      <title>ALSA-2023:6473 — Moderate: buildah security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2023:6473</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: buildah, AlmaLinux:9: buildah-tests&lt;/p&gt;
&lt;p&gt;The buildah package provides a tool for facilitating building OCI container images. Among other things, buildah enables you to: Create a working container, either from scratch or using an image as a starting point; Create an image, either from a working container or using the instructions in a Dockerfile; Build both Docker and OCI images.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* golang: html/template: improper handling of JavaScript whitespace (CVE-2023-24540)
* net/http, golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding (CVE-2022-41723)
* golang: crypto/tls: large handshake records may cause panics (CVE-2022-41724)
* golang: net/http, mime/multipart: denial of service from excessive resource consumption (CVE-2022-41725)
* golang: net/http, net/textproto: denial of service from excessive memory allocation (CVE-2023-24534)
* golang: net/http, net/textproto, mime/multipart: denial of service from excessive resource consumption (CVE-2023-24536)
* golang: html/template: backticks not treated as string delimiters (CVE-2023-24538)
* golang: html/template: improper sanitization of CSS values (CVE-2023-24539)
* containerd: Supplementary groups are not set up properly (CVE-2023-25173)
* golang: html/template: improper handling of empty HTML attributes (CVE-2023-29400)
* golang: net/http: insufficient sanitization of Host header (CVE-2023-29406)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: buildah, AlmaLinux:9: buildah-tests&lt;/p&gt;
&lt;p&gt;The buildah package provides a tool for facilitating building OCI container images. Among other things, buildah enables you to: Create a working container, either from scratch or using an image as a starting point; Create an image, either from a working container or using the instructions in a Dockerfile; Build both Docker and OCI images.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* golang: html/template: improper handling of JavaScript whitespace (CVE-2023-24540)
* net/http, golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding (CVE-2022-41723)
* golang: crypto/tls: large handshake records may cause panics (CVE-2022-41724)
* golang: net/http, mime/multipart: denial of service from excessive resource consumption (CVE-2022-41725)
* golang: net/http, net/textproto: denial of service from excessive memory allocation (CVE-2023-24534)
* golang: net/http, net/textproto, mime/multipart: denial of service from excessive resource consumption (CVE-2023-24536)
* golang: html/template: backticks not treated as string delimiters (CVE-2023-24538)
* golang: html/template: improper sanitization of CSS values (CVE-2023-24539)
* containerd: Supplementary groups are not set up properly (CVE-2023-25173)
* golang: html/template: improper handling of empty HTML attributes (CVE-2023-29400)
* golang: net/http: insufficient sanitization of Host header (CVE-2023-29406)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2023:6473</guid>
    </item>
    <item>
      <title>bdu:2023-01488</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-01488</link>
      <description>bdu:2023-01488</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-01488</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2023-25173 — CVE-2023-25173 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2023-25173</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2023-25173</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0199 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;les produits IBM&lt;/span&gt;. Certaines d'entre el…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0199</link>
      <description>certfr-2024-avi-0199</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0199</guid>
    </item>
    <item>
      <title>CLEANSTART-2025-PN33710 — containerd is an open source container runtime</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2025-pn33710</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: containerd&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the containerd package. containerd is an open source container runtime.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: containerd&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the containerd package. containerd is an open source container runtime.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2025-pn33710</guid>
    </item>
    <item>
      <title>EUVD-2026-221558</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-221558</link>
      <description>EUVD-2026-221558</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-221558</guid>
    </item>
    <item>
      <title>fkie_cve-2023-25173</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-25173</link>
      <description>&lt;p&gt;containerd is an open source container runtime. A bug was found in containerd prior to versions 1.6.18 and 1.5.18 where supplementary groups are not set up properly inside a container. If an attacker has direct access to a container and manipulates their supplementary group access, they may be able to use supplementary group access to bypass primary group restrictions in some cases, potentially gaining access to sensitive information or gaining the ability to execute code in that container. Downstream applications that use the containerd client library may be affected as well.&lt;/p&gt;
&lt;p&gt;This bug has been fixed in containerd v1.6.18 and v.1.5.18. Users should update to these versions and recreate containers to resolve this issue. Users who rely on a downstream application that uses containerd&amp;#39;s client library should check that application for a separate advisory and instructions. As a workaround, ensure that the `&amp;#34;USER $USERNAME&amp;#34;` Dockerfile instruction is not used. Instead, set the container entrypoint to a value similar to `ENTRYPOINT [&amp;#34;su&amp;#34;, &amp;#34;-&amp;#34;, &amp;#34;user&amp;#34;]` to allow `su` to properly set up supplementary groups.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;containerd is an open source container runtime. A bug was found in containerd prior to versions 1.6.18 and 1.5.18 where supplementary groups are not set up properly inside a container. If an attacker has direct access to a container and manipulates their supplementary group access, they may be able to use supplementary group access to bypass primary group restrictions in some cases, potentially gaining access to sensitive information or gaining the ability to execute code in that container. Downstream applications that use the containerd client library may be affected as well.&lt;/p&gt;
&lt;p&gt;This bug has been fixed in containerd v1.6.18 and v.1.5.18. Users should update to these versions and recreate containers to resolve this issue. Users who rely on a downstream application that uses containerd&amp;#39;s client library should check that application for a separate advisory and instructions. As a workaround, ensure that the `&amp;#34;USER $USERNAME&amp;#34;` Dockerfile instruction is not used. Instead, set the container entrypoint to a value similar to `ENTRYPOINT [&amp;#34;su&amp;#34;, &amp;#34;-&amp;#34;, &amp;#34;user&amp;#34;]` to allow `su` to properly set up supplementary groups.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-25173</guid>
    </item>
    <item>
      <title>GHSA-hmfx-3pcx-653p — Supplementary groups are not set up properly in github.com/containerd/containerd</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hmfx-3pcx-653p</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/containerd/containerd&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;A bug was found in containerd where supplementary groups are not set up properly inside a container.  If an attacker has direct access to a container and manipulates their supplementary group access, they may be able to use supplementary group access to bypass primary group restrictions in some cases, potentially gaining access to sensitive information or gaining the ability to execute code in that container.&lt;/p&gt;
&lt;p&gt;Downstream applications that use the containerd client library may be affected as well.&lt;/p&gt;
&lt;p&gt;### Patches
This bug has been fixed in containerd v1.6.18 and v.1.5.18.  Users should update to these versions and recreate containers to resolve this issue.  Users who rely on a downstream application that uses containerd&amp;#39;s client library should check that application for a separate advisory and instructions.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Ensure that the `&amp;#34;USER $USERNAME&amp;#34;` Dockerfile instruction is not used.  Instead, set the container entrypoint to a value similar to `ENTRYPOINT [&amp;#34;su&amp;#34;, &amp;#34;-&amp;#34;, &amp;#34;user&amp;#34;]` to allow `su` to properly set up supplementary groups.&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;- https://www.benthamsgaze.org/2022/08/22/vulnerability-in-linux-containers-investigation-and-mitigation/
- Docker/Moby: CVE-2022-36109, fixed in Docker 20.10.18
- CRI-O: CVE-2022-2995, fixed in CRI-O 1.25.0
- Podman: CVE-2022-2989, fixed in Podman 3.0.1 and 4.2.0
- Buildah: CVE-2022-2990, fixed in Buildah 1.27.1&lt;/p&gt;
&lt;p&gt;Note that CVE IDs apply to a particular implementation, even if an issue is common.&lt;/p&gt;
&lt;p&gt;### For more inf…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/containerd/containerd&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;A bug was found in containerd where supplementary groups are not set up properly inside a container.  If an attacker has direct access to a container and manipulates their supplementary group access, they may be able to use supplementary group access to bypass primary group restrictions in some cases, potentially gaining access to sensitive information or gaining the ability to execute code in that container.&lt;/p&gt;
&lt;p&gt;Downstream applications that use the containerd client library may be affected as well.&lt;/p&gt;
&lt;p&gt;### Patches
This bug has been fixed in containerd v1.6.18 and v.1.5.18.  Users should update to these versions and recreate containers to resolve this issue.  Users who rely on a downstream application that uses containerd&amp;#39;s client library should check that application for a separate advisory and instructions.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Ensure that the `&amp;#34;USER $USERNAME&amp;#34;` Dockerfile instruction is not used.  Instead, set the container entrypoint to a value similar to `ENTRYPOINT [&amp;#34;su&amp;#34;, &amp;#34;-&amp;#34;, &amp;#34;user&amp;#34;]` to allow `su` to properly set up supplementary groups.&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;- https://www.benthamsgaze.org/2022/08/22/vulnerability-in-linux-containers-investigation-and-mitigation/
- Docker/Moby: CVE-2022-36109, fixed in Docker 20.10.18
- CRI-O: CVE-2022-2995, fixed in CRI-O 1.25.0
- Podman: CVE-2022-2989, fixed in Podman 3.0.1 and 4.2.0
- Buildah: CVE-2022-2990, fixed in Buildah 1.27.1&lt;/p&gt;
&lt;p&gt;Note that CVE IDs apply to a particular implementation, even if an issue is common.&lt;/p&gt;
&lt;p&gt;### For more inf…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hmfx-3pcx-653p</guid>
    </item>
    <item>
      <title>gsd-2023-25173</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-25173</link>
      <description>gsd-2023-25173</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-25173</guid>
    </item>
    <item>
      <title>msrc_CVE-2023-25173 — containerd supplementary groups are not set up properly</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2023-25173</link>
      <description>msrc_CVE-2023-25173</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2023-25173</guid>
    </item>
    <item>
      <title>OESA-2023-1147 — containerd security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2023-1147</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: containerd, openEuler:20.03-LTS-SP3: containerd, openEuler:22.03-LTS: containerd, openEuler:22.03-LTS-SP1: containerd&lt;/p&gt;
&lt;p&gt;containerd is an industry-standard container runtime with an emphasis on simplicity, robustness and portability.  It is available as a daemon for Linux and Windows, which can manage the complete container lifecycle of its host system: image transfer and storage, container execution and supervision, low-level storage and network attachments, etc.&#13;
&#13;
Security Fix(es):&#13;
&#13;
containerd is an open source container runtime. Before versions 1.6.18 and 1.5.18, when importing an OCI image, there was no limit on the number of bytes read for certain files. A maliciously crafted image with a large file where a limit was not applied could cause a denial of service. This bug has been fixed in containerd 1.6.18 and 1.5.18. Users should update to these versions to resolve the issue. As a workaround, ensure that only trusted images are used and that only trusted users have permissions to import images.(CVE-2023-25153)&#13;
&#13;
containerd is an open source container runtime. A bug was found in containerd prior to versions 1.6.18 and 1.5.18 where supplementary groups are not set up properly inside a container. If an attacker has direct access to a container and manipulates their supplementary group access, they may be able to use supplementary group access to bypass primary group restrictions in some cases, potentially gaining access to sensitive information or gaining the ability to execute code in that container. Downstream applications that use the containerd client library may be affected as well.…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: containerd, openEuler:20.03-LTS-SP3: containerd, openEuler:22.03-LTS: containerd, openEuler:22.03-LTS-SP1: containerd&lt;/p&gt;
&lt;p&gt;containerd is an industry-standard container runtime with an emphasis on simplicity, robustness and portability.  It is available as a daemon for Linux and Windows, which can manage the complete container lifecycle of its host system: image transfer and storage, container execution and supervision, low-level storage and network attachments, etc.&#13;
&#13;
Security Fix(es):&#13;
&#13;
containerd is an open source container runtime. Before versions 1.6.18 and 1.5.18, when importing an OCI image, there was no limit on the number of bytes read for certain files. A maliciously crafted image with a large file where a limit was not applied could cause a denial of service. This bug has been fixed in containerd 1.6.18 and 1.5.18. Users should update to these versions to resolve the issue. As a workaround, ensure that only trusted images are used and that only trusted users have permissions to import images.(CVE-2023-25153)&#13;
&#13;
containerd is an open source container runtime. A bug was found in containerd prior to versions 1.6.18 and 1.5.18 where supplementary groups are not set up properly inside a container. If an attacker has direct access to a container and manipulates their supplementary group access, they may be able to use supplementary group access to bypass primary group restrictions in some cases, potentially gaining access to sensitive information or gaining the ability to execute code in that container. Downstream applications that use the containerd client library may be affected as well.…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2023-1147</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:12822-1 — containerd-1.6.19-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12822-1</link>
      <description>&lt;p&gt;containerd-1.6.19-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;containerd-1.6.19-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:12822-1</guid>
    </item>
    <item>
      <title>RHEA-2023:7493 — Red Hat Enhancement Advisory: OpenShift sandboxed containers 1.5.0 update</title>
      <link>https://cve.radiocsirt.org/vuln/rhea-2023:7493</link>
      <description>&lt;p&gt;containerd: Supplementary groups are not set up properly&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;containerd: Supplementary groups are not set up properly&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhea-2023:7493</guid>
    </item>
    <item>
      <title>SUSE-SU-2023:1826-1 — Security update for containerd</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2023:1826-1</link>
      <description>&lt;p&gt;Security update for containerd&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for containerd&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2023:1826-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2023-25173</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-25173</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: containerd, Ubuntu:Pro:18.04:LTS: containerd, Ubuntu:20.04:LTS: containerd, Ubuntu:22.04:LTS: containerd&lt;/p&gt;
&lt;p&gt;containerd is an open source container runtime. A bug was found in containerd prior to versions 1.6.18 and 1.5.18 where supplementary groups are not set up properly inside a container. If an attacker has direct access to a container and manipulates their supplementary group access, they may be able to use supplementary group access to bypass primary group restrictions in some cases, potentially gaining access to sensitive information or gaining the ability to execute code in that container. Downstream applications that use the containerd client library may be affected as well. This bug has been fixed in containerd v1.6.18 and v.1.5.18. Users should update to these versions and recreate containers to resolve this issue. Users who rely on a downstream application that uses containerd&amp;#39;s client library should check that application for a separate advisory and instructions. As a workaround, ensure that the `&amp;#34;USER $USERNAME&amp;#34;` Dockerfile instruction is not used. Instead, set the container entrypoint to a value similar to `ENTRYPOINT [&amp;#34;su&amp;#34;, &amp;#34;-&amp;#34;, &amp;#34;user&amp;#34;]` to allow `su` to properly set up supplementary groups.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: containerd, Ubuntu:Pro:18.04:LTS: containerd, Ubuntu:20.04:LTS: containerd, Ubuntu:22.04:LTS: containerd&lt;/p&gt;
&lt;p&gt;containerd is an open source container runtime. A bug was found in containerd prior to versions 1.6.18 and 1.5.18 where supplementary groups are not set up properly inside a container. If an attacker has direct access to a container and manipulates their supplementary group access, they may be able to use supplementary group access to bypass primary group restrictions in some cases, potentially gaining access to sensitive information or gaining the ability to execute code in that container. Downstream applications that use the containerd client library may be affected as well. This bug has been fixed in containerd v1.6.18 and v.1.5.18. Users should update to these versions and recreate containers to resolve this issue. Users who rely on a downstream application that uses containerd&amp;#39;s client library should check that application for a separate advisory and instructions. As a workaround, ensure that the `&amp;#34;USER $USERNAME&amp;#34;` Dockerfile instruction is not used. Instead, set the container entrypoint to a value similar to `ENTRYPOINT [&amp;#34;su&amp;#34;, &amp;#34;-&amp;#34;, &amp;#34;user&amp;#34;]` to allow `su` to properly set up supplementary groups.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-25173</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-1141 — Red Hat Enterprise Linux Migration Toolkit for Containers: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1141</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen im Red Hat Enterprise Linux Migration Toolkit for Containers ausnutzen, um beliebigen Programmcode auszuführen oder einen Denial of Service Zustand herbeizuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen im Red Hat Enterprise Linux Migration Toolkit for Containers ausnutzen, um beliebigen Programmcode auszuführen oder einen Denial of Service Zustand herbeizuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1141</guid>
    </item>
  </channel>
</rss>
