<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 02:38:28 +0000</lastBuildDate>
    <item>
      <title>ALSA-2024:2463 — Moderate: systemd security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2024:2463</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: rhel-net-naming-sysattrs, AlmaLinux:9: systemd, AlmaLinux:9: systemd-boot-unsigned, AlmaLinux:9: systemd-container, AlmaLinux:9: systemd-devel, AlmaLinux:9: systemd-journal-remote, AlmaLinux:9: systemd-libs, AlmaLinux:9: systemd-oomd, AlmaLinux:9: systemd-pam, AlmaLinux:9: systemd-resolved and 2 more&lt;/p&gt;
&lt;p&gt;The systemd packages contain systemd, a system and service manager for Linux, compatible with the SysV and LSB init scripts. It provides aggressive parallelism capabilities, uses socket and D-Bus activation for starting services, offers on-demand starting of daemons, and keeps track of processes using Linux cgroups. In addition, it supports snapshotting and restoring of the system state, maintains mount and automount points, and implements an elaborate transactional dependency-based service control logic. It can also work as a drop-in replacement for sysvinit.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* systemd-resolved: Unsigned name response in signed zone is not refused when DNSSEC=yes (CVE-2023-7008)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: rhel-net-naming-sysattrs, AlmaLinux:9: systemd, AlmaLinux:9: systemd-boot-unsigned, AlmaLinux:9: systemd-container, AlmaLinux:9: systemd-devel, AlmaLinux:9: systemd-journal-remote, AlmaLinux:9: systemd-libs, AlmaLinux:9: systemd-oomd, AlmaLinux:9: systemd-pam, AlmaLinux:9: systemd-resolved and 2 more&lt;/p&gt;
&lt;p&gt;The systemd packages contain systemd, a system and service manager for Linux, compatible with the SysV and LSB init scripts. It provides aggressive parallelism capabilities, uses socket and D-Bus activation for starting services, offers on-demand starting of daemons, and keeps track of processes using Linux cgroups. In addition, it supports snapshotting and restoring of the system state, maintains mount and automount points, and implements an elaborate transactional dependency-based service control logic. It can also work as a drop-in replacement for sysvinit.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* systemd-resolved: Unsigned name response in signed zone is not refused when DNSSEC=yes (CVE-2023-7008)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2024:2463</guid>
    </item>
    <item>
      <title>bdu:2024-00853</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-00853</link>
      <description>bdu:2024-00853</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-00853</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0720 — De multiples vulnérabilités ont été découvertes dans IBM QRadar SIEM. Certaines d'entre elles permettent à un attaquant…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0720</link>
      <description>certfr-2024-avi-0720</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0720</guid>
    </item>
    <item>
      <title>EUVD-2026-260282</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-260282</link>
      <description>EUVD-2026-260282</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-260282</guid>
    </item>
    <item>
      <title>fkie_cve-2023-7008</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-7008</link>
      <description>&lt;p&gt;A vulnerability was found in systemd-resolved. This issue may allow systemd-resolved to accept records of DNSSEC-signed domains even when they have no signature, allowing man-in-the-middles (or the upstream DNS resolver) to manipulate records.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability was found in systemd-resolved. This issue may allow systemd-resolved to accept records of DNSSEC-signed domains even when they have no signature, allowing man-in-the-middles (or the upstream DNS resolver) to manipulate records.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-7008</guid>
    </item>
    <item>
      <title>GHSA-hwxf-wjq7-j3hm</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hwxf-wjq7-j3hm</link>
      <description>&lt;p&gt;A vulnerability was found in systemd-resolved. This issue may allow systemd-resolved to accept records of DNSSEC-signed domains even when they have no signature, allowing man-in-the-middles (or the upstream DNS resolver) to manipulate records.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability was found in systemd-resolved. This issue may allow systemd-resolved to accept records of DNSSEC-signed domains even when they have no signature, allowing man-in-the-middles (or the upstream DNS resolver) to manipulate records.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hwxf-wjq7-j3hm</guid>
    </item>
    <item>
      <title>gsd-2023-7008</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-7008</link>
      <description>gsd-2023-7008</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-7008</guid>
    </item>
    <item>
      <title>ICSA-23-166-11 — Siemens SIMATIC S7-1500 TM MFP Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-23-166-11</link>
      <description>&lt;p&gt;json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend. A memory overflow vulnerability was found in the Linux kernel’s ipc functionality of the memcg subsystem, in the way a user calls the semget function multiple times, creating semaphores. This flaw allows a local user to starve the resources, causing a denial of service. The highest threat from this vulnerability is to system availability. A vulnerability was found in the fs/inode.c:inode_init_owner() function logic of the LInux kernel that allows local users to create files for the XFS file-system with an unintended group ownership and with group execution and SGID permission bits set, in a scenario where a directory is SGID and belongs to a certain group and is writable by a user who is not a member of this group. This can lead to excessive permissions granted in case when they should not. This vulnerability is similar to the previous CVE-2018-13405 and adds the missed fix for the XFS. When sending malicous data to kernel by ioctl cmd FBIOPUT_VSCREENINFO,kernel will write memory out of bounds. In gc_data_segment in fs/f2fs/gc.c in the Linux kernel before 5.16.3, special files are not considered, leading to a move_data_page NULL pointer dereference. A flaw was found in the Linux kernel. The existing KVM SEV API has a vulnerability that allows a non-root (host) user-level application to crash the host kernel by creating a confidential guest VM inst…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend. A memory overflow vulnerability was found in the Linux kernel’s ipc functionality of the memcg subsystem, in the way a user calls the semget function multiple times, creating semaphores. This flaw allows a local user to starve the resources, causing a denial of service. The highest threat from this vulnerability is to system availability. A vulnerability was found in the fs/inode.c:inode_init_owner() function logic of the LInux kernel that allows local users to create files for the XFS file-system with an unintended group ownership and with group execution and SGID permission bits set, in a scenario where a directory is SGID and belongs to a certain group and is writable by a user who is not a member of this group. This can lead to excessive permissions granted in case when they should not. This vulnerability is similar to the previous CVE-2018-13405 and adds the missed fix for the XFS. When sending malicous data to kernel by ioctl cmd FBIOPUT_VSCREENINFO,kernel will write memory out of bounds. In gc_data_segment in fs/f2fs/gc.c in the Linux kernel before 5.16.3, special files are not considered, leading to a move_data_page NULL pointer dereference. A flaw was found in the Linux kernel. The existing KVM SEV API has a vulnerability that allows a non-root (host) user-level application to crash the host kernel by creating a confidential guest VM inst…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-23-166-11</guid>
    </item>
    <item>
      <title>msrc_CVE-2023-7008 — Systemd-resolved: unsigned name response in signed zone is not refused when dnssec=yes</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2023-7008</link>
      <description>msrc_CVE-2023-7008</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2023-7008</guid>
    </item>
    <item>
      <title>OESA-2024-1020 — systemd security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-1020</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: systemd, openEuler:20.03-LTS-SP3: systemd, openEuler:20.03-LTS-SP4: systemd, openEuler:22.03-LTS: systemd, openEuler:22.03-LTS-SP1: systemd, openEuler:22.03-LTS-SP2: systemd&lt;/p&gt;
&lt;p&gt;systemd is a system and service manager that runs as PID 1 and starts the rest of the system.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A vulnerability was found in systemd-resolved. This issue may allow systemd-resolved to accept records of DNSSEC-signed domains even when they have no signature, allowing man-in-the-middles (or the upstream DNS resolver) to manipulate records.(CVE-2023-7008)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: systemd, openEuler:20.03-LTS-SP3: systemd, openEuler:20.03-LTS-SP4: systemd, openEuler:22.03-LTS: systemd, openEuler:22.03-LTS-SP1: systemd, openEuler:22.03-LTS-SP2: systemd&lt;/p&gt;
&lt;p&gt;systemd is a system and service manager that runs as PID 1 and starts the rest of the system.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A vulnerability was found in systemd-resolved. This issue may allow systemd-resolved to accept records of DNSSEC-signed domains even when they have no signature, allowing man-in-the-middles (or the upstream DNS resolver) to manipulate records.(CVE-2023-7008)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-1020</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:13665-1 — libsystemd0-254.8-4.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13665-1</link>
      <description>&lt;p&gt;libsystemd0-254.8-4.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libsystemd0-254.8-4.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:13665-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:3149-1 — Security update for systemd</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:3149-1</link>
      <description>&lt;p&gt;Security update for systemd&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for systemd&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:3149-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2023-7008</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-7008</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: systemd, Ubuntu:Pro:16.04:LTS: systemd, Ubuntu:Pro:18.04:LTS: systemd, Ubuntu:Pro:20.04:LTS: systemd, Ubuntu:22.04:LTS: systemd&lt;/p&gt;
&lt;p&gt;A vulnerability was found in systemd-resolved. This issue may allow systemd-resolved to accept records of DNSSEC-signed domains even when they have no signature, allowing man-in-the-middles (or the upstream DNS resolver) to manipulate records.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: systemd, Ubuntu:Pro:16.04:LTS: systemd, Ubuntu:Pro:18.04:LTS: systemd, Ubuntu:Pro:20.04:LTS: systemd, Ubuntu:22.04:LTS: systemd&lt;/p&gt;
&lt;p&gt;A vulnerability was found in systemd-resolved. This issue may allow systemd-resolved to accept records of DNSSEC-signed domains even when they have no signature, allowing man-in-the-middles (or the upstream DNS resolver) to manipulate records.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-7008</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-1751 — systemd: Schwachstelle ermöglicht Manipulation von Einträgen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1751</link>
      <description>&lt;p&gt;Ein entfernter Angreifer kann eine Schwachstelle in systemd ausnutzen, um Dateien zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter Angreifer kann eine Schwachstelle in systemd ausnutzen, um Dateien zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1751</guid>
    </item>
  </channel>
</rss>
