<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 03:49:17 +0000</lastBuildDate>
    <item>
      <title>ALSA-2024:10978 — Important: python3.12 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2024:10978</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: python3.12, AlmaLinux:9: python3.12-debug, AlmaLinux:9: python3.12-devel, AlmaLinux:9: python3.12-idle, AlmaLinux:9: python3.12-libs, AlmaLinux:9: python3.12-test, AlmaLinux:9: python3.12-tkinter&lt;/p&gt;
&lt;p&gt;Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* python: Virtual environment (venv) activation scripts don&amp;#39;t quote paths (CVE-2024-9287)
  * python: Unbounded memory buffering in SelectorSocketTransport.writelines() (CVE-2024-12254)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: python3.12, AlmaLinux:9: python3.12-debug, AlmaLinux:9: python3.12-devel, AlmaLinux:9: python3.12-idle, AlmaLinux:9: python3.12-libs, AlmaLinux:9: python3.12-test, AlmaLinux:9: python3.12-tkinter&lt;/p&gt;
&lt;p&gt;Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* python: Virtual environment (venv) activation scripts don&amp;#39;t quote paths (CVE-2024-9287)
  * python: Unbounded memory buffering in SelectorSocketTransport.writelines() (CVE-2024-12254)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2024:10978</guid>
    </item>
    <item>
      <title>bdu:2025-00345</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-00345</link>
      <description>bdu:2025-00345</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-00345</guid>
    </item>
    <item>
      <title>BELL-CVE-2024-12254</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2024-12254</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:stream: python3, BellSoft Hardened Containers:stream: python3&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:stream: python3, BellSoft Hardened Containers:stream: python3&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2024-12254</guid>
    </item>
    <item>
      <title>BIT-libpython-2024-12254 — Unbounded memory buffering in SelectorSocketTransport.writelines()</title>
      <link>https://cve.radiocsirt.org/vuln/bit-libpython-2024-12254</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: libpython&lt;/p&gt;
&lt;p&gt;Starting in Python 3.12.0, the asyncio._SelectorSocketTransport.writelines()
 method would not &amp;#34;pause&amp;#34; writing and signal to the Protocol to drain 
the buffer to the wire once the write buffer reached the &amp;#34;high-water 
mark&amp;#34;. Because of this, Protocols would not periodically drain the write
 buffer potentially leading to memory exhaustion.&lt;/p&gt;
&lt;p&gt;This
 vulnerability likely impacts a small number of users, you must be using
 Python 3.12.0 or later, on macOS or Linux, using the asyncio module 
with protocols, and using .writelines() method which had new 
zero-copy-on-write behavior in Python 3.12.0 and later. If not all of 
these factors are true then your usage of Python is unaffected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: libpython&lt;/p&gt;
&lt;p&gt;Starting in Python 3.12.0, the asyncio._SelectorSocketTransport.writelines()
 method would not &amp;#34;pause&amp;#34; writing and signal to the Protocol to drain 
the buffer to the wire once the write buffer reached the &amp;#34;high-water 
mark&amp;#34;. Because of this, Protocols would not periodically drain the write
 buffer potentially leading to memory exhaustion.&lt;/p&gt;
&lt;p&gt;This
 vulnerability likely impacts a small number of users, you must be using
 Python 3.12.0 or later, on macOS or Linux, using the asyncio module 
with protocols, and using .writelines() method which had new 
zero-copy-on-write behavior in Python 3.12.0 and later. If not all of 
these factors are true then your usage of Python is unaffected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-libpython-2024-12254</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0641 — De multiples vulnérabilités ont été découvertes dans les produits Splunk. Elles permettent à un attaquant de provoquer…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0641</link>
      <description>certfr-2025-avi-0641</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0641</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-CI66802 — Security fixes for CVE-2015-2104, CVE-2020-8908, CVE-2021-21295, CVE-2021-21409, CVE-2021-37136, CVE-2022-1471, CVE-202…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ci66802</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: cassandra-fips&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the cassandra-fips package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: cassandra-fips&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the cassandra-fips package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ci66802</guid>
    </item>
    <item>
      <title>EUVD-2026-343285</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-343285</link>
      <description>EUVD-2026-343285</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-343285</guid>
    </item>
    <item>
      <title>fkie_cve-2024-12254</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-12254</link>
      <description>&lt;p&gt;Starting in Python 3.12.0, the asyncio._SelectorSocketTransport.writelines()
 method would not &amp;#34;pause&amp;#34; writing and signal to the Protocol to drain 
the buffer to the wire once the write buffer reached the &amp;#34;high-water 
mark&amp;#34;. Because of this, Protocols would not periodically drain the write
 buffer potentially leading to memory exhaustion.&lt;/p&gt;
&lt;p&gt;This
 vulnerability likely impacts a small number of users, you must be using
 Python 3.12.0 or later, on macOS or Linux, using the asyncio module 
with protocols, and using .writelines() method which had new 
zero-copy-on-write behavior in Python 3.12.0 and later. If not all of 
these factors are true then your usage of Python is unaffected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Starting in Python 3.12.0, the asyncio._SelectorSocketTransport.writelines()
 method would not &amp;#34;pause&amp;#34; writing and signal to the Protocol to drain 
the buffer to the wire once the write buffer reached the &amp;#34;high-water 
mark&amp;#34;. Because of this, Protocols would not periodically drain the write
 buffer potentially leading to memory exhaustion.&lt;/p&gt;
&lt;p&gt;This
 vulnerability likely impacts a small number of users, you must be using
 Python 3.12.0 or later, on macOS or Linux, using the asyncio module 
with protocols, and using .writelines() method which had new 
zero-copy-on-write behavior in Python 3.12.0 and later. If not all of 
these factors are true then your usage of Python is unaffected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-12254</guid>
    </item>
    <item>
      <title>GHSA-ph84-rcj2-fxxm</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-ph84-rcj2-fxxm</link>
      <description>&lt;p&gt;Starting in Python 3.12.0, the asyncio._SelectorSocketTransport.writelines()
 method would not &amp;#34;pause&amp;#34; writing and signal to the Protocol to drain 
the buffer to the wire once the write buffer reached the &amp;#34;high-water 
mark&amp;#34;. Because of this, Protocols would not periodically drain the write
 buffer potentially leading to memory exhaustion.&lt;/p&gt;
&lt;p&gt;This
 vulnerability likely impacts a small number of users, you must be using
 Python 3.12.0 or later, on macOS or Linux, using the asyncio module 
with protocols, and using .writelines() method which had new 
zero-copy-on-write behavior in Python 3.12.0 and later. If not all of 
these factors are true then your usage of Python is unaffected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Starting in Python 3.12.0, the asyncio._SelectorSocketTransport.writelines()
 method would not &amp;#34;pause&amp;#34; writing and signal to the Protocol to drain 
the buffer to the wire once the write buffer reached the &amp;#34;high-water 
mark&amp;#34;. Because of this, Protocols would not periodically drain the write
 buffer potentially leading to memory exhaustion.&lt;/p&gt;
&lt;p&gt;This
 vulnerability likely impacts a small number of users, you must be using
 Python 3.12.0 or later, on macOS or Linux, using the asyncio module 
with protocols, and using .writelines() method which had new 
zero-copy-on-write behavior in Python 3.12.0 and later. If not all of 
these factors are true then your usage of Python is unaffected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-ph84-rcj2-fxxm</guid>
    </item>
    <item>
      <title>msrc_CVE-2024-12254 — Unbounded memory buffering in SelectorSocketTransport.writelines()</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2024-12254</link>
      <description>msrc_CVE-2024-12254</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2024-12254</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:14581-1 — python312-3.12.8-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:14581-1</link>
      <description>&lt;p&gt;python312-3.12.8-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python312-3.12.8-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:14581-1</guid>
    </item>
    <item>
      <title>RHBA-2025:6294 — Red Hat Bug Fix Advisory: python3.12 bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhba-2025:6294</link>
      <description>&lt;p&gt;python: cpython: tarfile: ReDos via excessive backtracking while parsing header values python: Virtual environment (venv) activation scripts don&amp;#39;t quote paths python: Unbounded memory buffering in SelectorSocketTransport.writelines() python: cpython: URL parser allowed square brackets in domain names&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python: cpython: tarfile: ReDos via excessive backtracking while parsing header values python: Virtual environment (venv) activation scripts don&amp;#39;t quote paths python: Unbounded memory buffering in SelectorSocketTransport.writelines() python: cpython: URL parser allowed square brackets in domain names&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhba-2025:6294</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:4291-1 — Security update for python312</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:4291-1</link>
      <description>&lt;p&gt;Security update for python312&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for python312&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:4291-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-12254</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-12254</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: python3.12&lt;/p&gt;
&lt;p&gt;Starting in Python 3.12.0, the asyncio._SelectorSocketTransport.writelines()  method would not &amp;#34;pause&amp;#34; writing and signal to the Protocol to drain the buffer to the wire once the write buffer reached the &amp;#34;high-water mark&amp;#34;. Because of this, Protocols would not periodically drain the write  buffer potentially leading to memory exhaustion. This  vulnerability likely impacts a small number of users, you must be using  Python 3.12.0 or later, on macOS or Linux, using the asyncio module with protocols, and using .writelines() method which had new zero-copy-on-write behavior in Python 3.12.0 and later. If not all of these factors are true then your usage of Python is unaffected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: python3.12&lt;/p&gt;
&lt;p&gt;Starting in Python 3.12.0, the asyncio._SelectorSocketTransport.writelines()  method would not &amp;#34;pause&amp;#34; writing and signal to the Protocol to drain the buffer to the wire once the write buffer reached the &amp;#34;high-water mark&amp;#34;. Because of this, Protocols would not periodically drain the write  buffer potentially leading to memory exhaustion. This  vulnerability likely impacts a small number of users, you must be using  Python 3.12.0 or later, on macOS or Linux, using the asyncio module with protocols, and using .writelines() method which had new zero-copy-on-write behavior in Python 3.12.0 and later. If not all of these factors are true then your usage of Python is unaffected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-12254</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-3630 — Python: Schwachstelle ermöglicht Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3630</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Python ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Python ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3630</guid>
    </item>
  </channel>
</rss>
