<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 09:33:07 +0000</lastBuildDate>
    <item>
      <title>ALSA-2023:4706 — Important: subscription-manager security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2023:4706</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: dnf-plugin-subscription-manager, AlmaLinux:8: python3-cloud-what, AlmaLinux:8: python3-subscription-manager-rhsm, AlmaLinux:8: python3-syspurpose, AlmaLinux:8: subscription-manager, AlmaLinux:8: subscription-manager-migration, AlmaLinux:8: subscription-manager-plugin-ostree, AlmaLinux:8: subscription-manager-rhsm-certificates&lt;/p&gt;
&lt;p&gt;The subscription-manager packages provide programs and libraries to allow users to manage subscriptions and yum repositories from the AlmaLinux entitlement platform.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* subscription-manager: inadequate authorization of com.AlmaLinux.RHSM1 D-Bus interface allows local users to modify configuration (CVE-2023-3899)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: dnf-plugin-subscription-manager, AlmaLinux:8: python3-cloud-what, AlmaLinux:8: python3-subscription-manager-rhsm, AlmaLinux:8: python3-syspurpose, AlmaLinux:8: subscription-manager, AlmaLinux:8: subscription-manager-migration, AlmaLinux:8: subscription-manager-plugin-ostree, AlmaLinux:8: subscription-manager-rhsm-certificates&lt;/p&gt;
&lt;p&gt;The subscription-manager packages provide programs and libraries to allow users to manage subscriptions and yum repositories from the AlmaLinux entitlement platform.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* subscription-manager: inadequate authorization of com.AlmaLinux.RHSM1 D-Bus interface allows local users to modify configuration (CVE-2023-3899)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2023:4706</guid>
    </item>
    <item>
      <title>bdu:2023-04878</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-04878</link>
      <description>bdu:2023-04878</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-04878</guid>
    </item>
    <item>
      <title>certfr-2023-avi-0950 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;Juniper Secure Analytics&lt;/span&gt;. Certaines d'…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0950</link>
      <description>certfr-2023-avi-0950</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0950</guid>
    </item>
    <item>
      <title>EUVD-2026-261415</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-261415</link>
      <description>EUVD-2026-261415</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-261415</guid>
    </item>
    <item>
      <title>fkie_cve-2023-3899</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-3899</link>
      <description>&lt;p&gt;A vulnerability was found in subscription-manager that allows local privilege escalation due to inadequate authorization. The D-Bus interface com.redhat.RHSM1 exposes a significant number of methods to all users that could change the state of the registration. By using the com.redhat.RHSM1.Config.SetAll() method, a low-privileged local user could tamper with the state of the registration, by unregistering the system or by changing the current entitlements. This flaw allows an attacker to set arbitrary configuration directives for /etc/rhsm/rhsm.conf, which can be abused to cause a local privilege escalation to an unconfined root.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability was found in subscription-manager that allows local privilege escalation due to inadequate authorization. The D-Bus interface com.redhat.RHSM1 exposes a significant number of methods to all users that could change the state of the registration. By using the com.redhat.RHSM1.Config.SetAll() method, a low-privileged local user could tamper with the state of the registration, by unregistering the system or by changing the current entitlements. This flaw allows an attacker to set arbitrary configuration directives for /etc/rhsm/rhsm.conf, which can be abused to cause a local privilege escalation to an unconfined root.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-3899</guid>
    </item>
    <item>
      <title>GHSA-wp8h-m67c-cxpw</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-wp8h-m67c-cxpw</link>
      <description>&lt;p&gt;A vulnerability was found in subscription-manager that allows local privilege escalation due to inadequate authorization. The D-Bus interface com.redhat.RHSM1 exposes a significant number of methods to all users that could change the state of the registration. By using the com.redhat.RHSM1.Config.SetAll() method, a low-privileged local user could tamper with the state of the registration, by unregistering the system or by changing the current entitlements. This flaw allows an attacker to set arbitrary configuration directives for /etc/rhsm/rhsm.conf, which can be abused to cause a local privilege escalation to an unconfined root.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability was found in subscription-manager that allows local privilege escalation due to inadequate authorization. The D-Bus interface com.redhat.RHSM1 exposes a significant number of methods to all users that could change the state of the registration. By using the com.redhat.RHSM1.Config.SetAll() method, a low-privileged local user could tamper with the state of the registration, by unregistering the system or by changing the current entitlements. This flaw allows an attacker to set arbitrary configuration directives for /etc/rhsm/rhsm.conf, which can be abused to cause a local privilege escalation to an unconfined root.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-wp8h-m67c-cxpw</guid>
    </item>
    <item>
      <title>gsd-2023-3899</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-3899</link>
      <description>gsd-2023-3899</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-3899</guid>
    </item>
    <item>
      <title>RHSA-2023:4701 — Red Hat Security Advisory: subscription-manager security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2023:4701</link>
      <description>&lt;p&gt;subscription-manager: inadequate authorization of com.redhat.RHSM1 D-Bus interface allows local users to modify configuration&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;subscription-manager: inadequate authorization of com.redhat.RHSM1 D-Bus interface allows local users to modify configuration&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2023:4701</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-2118 — Red Hat Enterprise Linux (subscription-manager): Schwachstelle ermöglicht Privilegieneskalation</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2118</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um seine Privilegien zu erhöhen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um seine Privilegien zu erhöhen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2118</guid>
    </item>
  </channel>
</rss>
