<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 06:12:14 +0000</lastBuildDate>
    <item>
      <title>ALSA-2023:5094 — Important: qemu-kvm security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2023:5094</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: qemu-guest-agent, AlmaLinux:9: qemu-img, AlmaLinux:9: qemu-kvm, AlmaLinux:9: qemu-kvm-audio-pa, AlmaLinux:9: qemu-kvm-block-curl, AlmaLinux:9: qemu-kvm-block-rbd, AlmaLinux:9: qemu-kvm-common, AlmaLinux:9: qemu-kvm-core, AlmaLinux:9: qemu-kvm-device-display-virtio-gpu, AlmaLinux:9: qemu-kvm-device-display-virtio-gpu-ccw and 9 more&lt;/p&gt;
&lt;p&gt;Kernel-based Virtual Machine (KVM) is a full virtualization solution for Linux on a variety of architectures. The qemu-kvm packages provide the user-space component for running virtual machines that use KVM.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* QEMU: VNC: improper I/O watch removal in TLS handshake can lead to remote unauthenticated denial of service (CVE-2023-3354)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Bug Fix(es):&lt;/p&gt;
&lt;p&gt;* [qemu-kvm] rhel guest failed boot with multi disks on error Failed to start udev Wait for Complete Device Initialization (BZ#2211923)
* [almalinux9.2] hotplug/hotunplug mlx vdpa device to the occupied addr port, then qemu core dump occurs after shutdown guest (BZ#2227721)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: qemu-guest-agent, AlmaLinux:9: qemu-img, AlmaLinux:9: qemu-kvm, AlmaLinux:9: qemu-kvm-audio-pa, AlmaLinux:9: qemu-kvm-block-curl, AlmaLinux:9: qemu-kvm-block-rbd, AlmaLinux:9: qemu-kvm-common, AlmaLinux:9: qemu-kvm-core, AlmaLinux:9: qemu-kvm-device-display-virtio-gpu, AlmaLinux:9: qemu-kvm-device-display-virtio-gpu-ccw and 9 more&lt;/p&gt;
&lt;p&gt;Kernel-based Virtual Machine (KVM) is a full virtualization solution for Linux on a variety of architectures. The qemu-kvm packages provide the user-space component for running virtual machines that use KVM.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* QEMU: VNC: improper I/O watch removal in TLS handshake can lead to remote unauthenticated denial of service (CVE-2023-3354)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Bug Fix(es):&lt;/p&gt;
&lt;p&gt;* [qemu-kvm] rhel guest failed boot with multi disks on error Failed to start udev Wait for Complete Device Initialization (BZ#2211923)
* [almalinux9.2] hotplug/hotunplug mlx vdpa device to the occupied addr port, then qemu core dump occurs after shutdown guest (BZ#2227721)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2023:5094</guid>
    </item>
    <item>
      <title>bdu:2023-05003</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-05003</link>
      <description>bdu:2023-05003</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-05003</guid>
    </item>
    <item>
      <title>BELL-CVE-2023-3354</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2023-3354</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: qemu, Alpaquita:stream: qemu&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: qemu, Alpaquita:stream: qemu&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2023-3354</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0619 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Certaines d'entre elles permettent à un attaq…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0619</link>
      <description>certfr-2024-avi-0619</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0619</guid>
    </item>
    <item>
      <title>ESSA-2023:0374 — security update for virt:rhel module</title>
      <link>https://cve.radiocsirt.org/vuln/essa-2023:0374</link>
      <description>&lt;p&gt;security update for virt:rhel module&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;security update for virt:rhel module&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/essa-2023:0374</guid>
    </item>
    <item>
      <title>EUVD-2026-216524</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-216524</link>
      <description>EUVD-2026-216524</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-216524</guid>
    </item>
    <item>
      <title>fkie_cve-2023-3354</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-3354</link>
      <description>&lt;p&gt;A flaw was found in the QEMU built-in VNC server. When a client connects to the VNC server, QEMU checks whether the current number of connections crosses a certain threshold and if so, cleans up the previous connection. If the previous connection happens to be in the handshake phase and fails, QEMU cleans up the connection again, resulting in a NULL pointer dereference issue. This could allow a remote unauthenticated client to cause a denial of service.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in the QEMU built-in VNC server. When a client connects to the VNC server, QEMU checks whether the current number of connections crosses a certain threshold and if so, cleans up the previous connection. If the previous connection happens to be in the handshake phase and fails, QEMU cleans up the connection again, resulting in a NULL pointer dereference issue. This could allow a remote unauthenticated client to cause a denial of service.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-3354</guid>
    </item>
    <item>
      <title>GHSA-vhf9-5f69-9hjm</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-vhf9-5f69-9hjm</link>
      <description>&lt;p&gt;A flaw was found in the QEMU built-in VNC server. When a client connects to the VNC server, QEMU checks whether the current number of connections crosses a certain threshold and if so, cleans up the previous connection. If the previous connection happens to be in the handshake phase and fails, QEMU cleans up the connection again, resulting in a NULL pointer dereference issue. This could allow a remote unauthenticated client to cause a denial of service.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in the QEMU built-in VNC server. When a client connects to the VNC server, QEMU checks whether the current number of connections crosses a certain threshold and if so, cleans up the previous connection. If the previous connection happens to be in the handshake phase and fails, QEMU cleans up the connection again, resulting in a NULL pointer dereference issue. This could allow a remote unauthenticated client to cause a denial of service.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-vhf9-5f69-9hjm</guid>
    </item>
    <item>
      <title>gsd-2023-3354</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-3354</link>
      <description>gsd-2023-3354</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-3354</guid>
    </item>
    <item>
      <title>msrc_CVE-2023-3354 — Improper i/o watch removal in tls handshake can lead to remote unauthenticated denial of service</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2023-3354</link>
      <description>msrc_CVE-2023-3354</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2023-3354</guid>
    </item>
    <item>
      <title>OESA-2023-1657 — qemu security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2023-1657</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: qemu, openEuler:20.03-LTS-SP3: qemu, openEuler:22.03-LTS-SP1: qemu, openEuler:22.03-LTS-SP2: qemu&lt;/p&gt;
&lt;p&gt;QEMU is a FAST! processor emulator using dynamic translation to achieve good emulation speed.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A flaw was found in the QEMU built-in VNC server. When a client connects to the VNC server, QEMU checks whether the current number of connections crosses a certain threshold and if so, cleans up the previous connection. If the previous connection happens to be in the handshake phase and fails, QEMU cleans up the connection again, resulting in a NULL pointer dereference issue. This could allow a remote unauthenticated client to cause a denial of service.(CVE-2023-3354)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: qemu, openEuler:20.03-LTS-SP3: qemu, openEuler:22.03-LTS-SP1: qemu, openEuler:22.03-LTS-SP2: qemu&lt;/p&gt;
&lt;p&gt;QEMU is a FAST! processor emulator using dynamic translation to achieve good emulation speed.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A flaw was found in the QEMU built-in VNC server. When a client connects to the VNC server, QEMU checks whether the current number of connections crosses a certain threshold and if so, cleans up the previous connection. If the previous connection happens to be in the handshake phase and fails, QEMU cleans up the connection again, resulting in a NULL pointer dereference issue. This could allow a remote unauthenticated client to cause a denial of service.(CVE-2023-3354)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2023-1657</guid>
    </item>
    <item>
      <title>RHSA-2023:5239 — Red Hat Security Advisory: virt:rhel and virt-devel:rhel security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2023:5239</link>
      <description>&lt;p&gt;NTFS-3G: buffer overflow issue in NTFS-3G can cause code execution via crafted metadata in an NTFS image QEMU: VNC: improper I/O watch removal in TLS handshake can lead to remote unauthenticated denial of service&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;NTFS-3G: buffer overflow issue in NTFS-3G can cause code execution via crafted metadata in an NTFS image QEMU: VNC: improper I/O watch removal in TLS handshake can lead to remote unauthenticated denial of service&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2023:5239</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:0589-1 — Security update for qemu</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:0589-1</link>
      <description>&lt;p&gt;Security update for qemu&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for qemu&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:0589-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2023-3354</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-3354</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:18.04:LTS: qemu, Ubuntu:20.04:LTS: qemu, Ubuntu:22.04:LTS: qemu&lt;/p&gt;
&lt;p&gt;A flaw was found in the QEMU built-in VNC server. When a client connects to the VNC server, QEMU checks whether the current number of connections crosses a certain threshold and if so, cleans up the previous connection. If the previous connection happens to be in the handshake phase and fails, QEMU cleans up the connection again, resulting in a NULL pointer dereference issue. This could allow a remote unauthenticated client to cause a denial of service.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:18.04:LTS: qemu, Ubuntu:20.04:LTS: qemu, Ubuntu:22.04:LTS: qemu&lt;/p&gt;
&lt;p&gt;A flaw was found in the QEMU built-in VNC server. When a client connects to the VNC server, QEMU checks whether the current number of connections crosses a certain threshold and if so, cleans up the previous connection. If the previous connection happens to be in the handshake phase and fails, QEMU cleans up the connection again, resulting in a NULL pointer dereference issue. This could allow a remote unauthenticated client to cause a denial of service.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-3354</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-1709 — QEMU: Schwachstelle ermöglicht Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1709</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in QEMU ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in QEMU ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1709</guid>
    </item>
  </channel>
</rss>
