<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 03:37:12 +0000</lastBuildDate>
    <item>
      <title>ALSA-2023:5061 — Moderate: dmidecode security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2023:5061</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: dmidecode&lt;/p&gt;
&lt;p&gt;The dmidecode packages provide utilities for extracting Intel 64 and Intel Itanium hardware information from the system BIOS or Extensible Firmware Interface (EFI), depending on the SMBIOS/DMI standard. This information typically includes system manufacturer, model name, serial number, BIOS version, and asset tag, as well as other details, depending on the manufacturer.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* dmidecode: dump-bin to overwrite a local file (CVE-2023-30630)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: dmidecode&lt;/p&gt;
&lt;p&gt;The dmidecode packages provide utilities for extracting Intel 64 and Intel Itanium hardware information from the system BIOS or Extensible Firmware Interface (EFI), depending on the SMBIOS/DMI standard. This information typically includes system manufacturer, model name, serial number, BIOS version, and asset tag, as well as other details, depending on the manufacturer.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* dmidecode: dump-bin to overwrite a local file (CVE-2023-30630)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2023:5061</guid>
    </item>
    <item>
      <title>bdu:2023-07470</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-07470</link>
      <description>bdu:2023-07470</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-07470</guid>
    </item>
    <item>
      <title>BELL-CVE-2023-30630</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2023-30630</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: dmidecode&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: dmidecode&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2023-30630</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0575 — De multiples vulnérabilités ont été découvertes dans les produits Juniper Networks. Certaines d'entre elles permettent…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0575</link>
      <description>certfr-2024-avi-0575</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0575</guid>
    </item>
    <item>
      <title>EUVD-2026-220474</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-220474</link>
      <description>EUVD-2026-220474</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-220474</guid>
    </item>
    <item>
      <title>fkie_cve-2023-30630</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-30630</link>
      <description>&lt;p&gt;Dmidecode before 3.5 allows -dump-bin to overwrite a local file. This has security relevance because, for example, execution of Dmidecode via Sudo is plausible. NOTE: Some third parties have indicated the fix in 3.5 does not adequately address the vulnerability. The argument is that the proposed patch prevents dmidecode from writing to an existing file. However, there are multiple attack vectors that would not require overwriting an existing file that would provide the same level of unauthorized privilege escalation (e.g. creating a new file in /etc/cron.hourly).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Dmidecode before 3.5 allows -dump-bin to overwrite a local file. This has security relevance because, for example, execution of Dmidecode via Sudo is plausible. NOTE: Some third parties have indicated the fix in 3.5 does not adequately address the vulnerability. The argument is that the proposed patch prevents dmidecode from writing to an existing file. However, there are multiple attack vectors that would not require overwriting an existing file that would provide the same level of unauthorized privilege escalation (e.g. creating a new file in /etc/cron.hourly).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-30630</guid>
    </item>
    <item>
      <title>GHSA-9r2p-xmm5-5ppg</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9r2p-xmm5-5ppg</link>
      <description>&lt;p&gt;Dmidecode before 3.5 allows -dump-bin to overwrite a local file. This has security relevance because, for example, execution of Dmidecode via Sudo is plausible.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Dmidecode before 3.5 allows -dump-bin to overwrite a local file. This has security relevance because, for example, execution of Dmidecode via Sudo is plausible.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9r2p-xmm5-5ppg</guid>
    </item>
    <item>
      <title>gsd-2023-30630</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-30630</link>
      <description>gsd-2023-30630</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-30630</guid>
    </item>
    <item>
      <title>msrc_CVE-2023-30630 — Dmidecode before 3.5 allows -dump-bin to overwrite a local file. This has security relevance because for example execut…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2023-30630</link>
      <description>msrc_CVE-2023-30630</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2023-30630</guid>
    </item>
    <item>
      <title>OESA-2023-1264 — dmidecode security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2023-1264</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: dmidecode, openEuler:20.03-LTS-SP3: dmidecode, openEuler:22.03-LTS: dmidecode, openEuler:22.03-LTS-SP1: dmidecode&lt;/p&gt;
&lt;p&gt;Dmidecode reports information about your system&amp;#39;s hardware as described in your system BIOS according to the SMBIOS/DMI standard (see a sample output). This information typically includes system manufacturer, model name, serial number, BIOS version, asset tag as well as a lot of other details of varying level of interest and reliability depending on the manufacturer. This will often include usage status for the CPU sockets, expansion slots (e.g. AGP, PCI, ISA) and memory module slots, and the list of I/O ports (e.g. serial, parallel, USB).DMI data can be used to enable or disable specific portions of kernel code depending on the specific hardware. Thus, one use of dmidecode is for kernel developers to detect system &amp;#34;signatures&amp;#34; and add them to the kernel source code when needed.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Dmidecode before 3.5 allows -dump-bin to overwrite a local file. This has security relevance because, for example, execution of Dmidecode via Sudo is plausible.(CVE-2023-30630)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: dmidecode, openEuler:20.03-LTS-SP3: dmidecode, openEuler:22.03-LTS: dmidecode, openEuler:22.03-LTS-SP1: dmidecode&lt;/p&gt;
&lt;p&gt;Dmidecode reports information about your system&amp;#39;s hardware as described in your system BIOS according to the SMBIOS/DMI standard (see a sample output). This information typically includes system manufacturer, model name, serial number, BIOS version, asset tag as well as a lot of other details of varying level of interest and reliability depending on the manufacturer. This will often include usage status for the CPU sockets, expansion slots (e.g. AGP, PCI, ISA) and memory module slots, and the list of I/O ports (e.g. serial, parallel, USB).DMI data can be used to enable or disable specific portions of kernel code depending on the specific hardware. Thus, one use of dmidecode is for kernel developers to detect system &amp;#34;signatures&amp;#34; and add them to the kernel source code when needed.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Dmidecode before 3.5 allows -dump-bin to overwrite a local file. This has security relevance because, for example, execution of Dmidecode via Sudo is plausible.(CVE-2023-30630)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2023-1264</guid>
    </item>
    <item>
      <title>RHSA-2023:5061 — Red Hat Security Advisory: dmidecode security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2023:5061</link>
      <description>&lt;p&gt;dmidecode: dump-bin to overwrite a local file&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;dmidecode: dump-bin to overwrite a local file&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2023:5061</guid>
    </item>
    <item>
      <title>SUSE-SU-2023:2044-1 — Security update for dmidecode</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2023:2044-1</link>
      <description>&lt;p&gt;Security update for dmidecode&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for dmidecode&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2023:2044-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2023-30630</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-30630</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: dmidecode, Ubuntu:16.04:LTS: dmidecode, Ubuntu:18.04:LTS: dmidecode, Ubuntu:20.04:LTS: dmidecode, Ubuntu:20.04:LTS: cpu-x, Ubuntu:22.04:LTS: cpu-x, Ubuntu:22.04:LTS: dmidecode, Ubuntu:24.04:LTS: cpu-x, Ubuntu:25.10: cpu-x, Ubuntu:26.04:LTS: cpu-x&lt;/p&gt;
&lt;p&gt;Dmidecode before 3.5 allows -dump-bin to overwrite a local file. This has security relevance because, for example, execution of Dmidecode via Sudo is plausible. NOTE: Some third parties have indicated the fix in 3.5 does not adequately address the vulnerability. The argument is that the proposed patch prevents dmidecode from writing to an existing file. However, there are multiple attack vectors that would not require overwriting an existing file that would provide the same level of unauthorized privilege escalation (e.g. creating a new file in /etc/cron.hourly).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: dmidecode, Ubuntu:16.04:LTS: dmidecode, Ubuntu:18.04:LTS: dmidecode, Ubuntu:20.04:LTS: dmidecode, Ubuntu:20.04:LTS: cpu-x, Ubuntu:22.04:LTS: cpu-x, Ubuntu:22.04:LTS: dmidecode, Ubuntu:24.04:LTS: cpu-x, Ubuntu:25.10: cpu-x, Ubuntu:26.04:LTS: cpu-x&lt;/p&gt;
&lt;p&gt;Dmidecode before 3.5 allows -dump-bin to overwrite a local file. This has security relevance because, for example, execution of Dmidecode via Sudo is plausible. NOTE: Some third parties have indicated the fix in 3.5 does not adequately address the vulnerability. The argument is that the proposed patch prevents dmidecode from writing to an existing file. However, there are multiple attack vectors that would not require overwriting an existing file that would provide the same level of unauthorized privilege escalation (e.g. creating a new file in /etc/cron.hourly).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-30630</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-2320 — Red Hat Enterprise Linux(dmidecode): Schwachstelle ermöglicht Codeausführung</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2320</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um beliebigen Programmcode auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um beliebigen Programmcode auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2320</guid>
    </item>
  </channel>
</rss>
