<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 19:50:27 +0000</lastBuildDate>
    <item>
      <title>bdu:2024-01031</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-01031</link>
      <description>bdu:2024-01031</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-01031</guid>
    </item>
    <item>
      <title>BELL-CVE-2024-23651</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2024-23651</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: podman, Alpaquita:stream: docker, Alpaquita:stream: podman&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: podman, Alpaquita:stream: docker, Alpaquita:stream: podman&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2024-23651</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0841 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0841</link>
      <description>certfr-2024-avi-0841</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0841</guid>
    </item>
    <item>
      <title>CLEANSTART-2025-MU54155 — BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2025-mu54155</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: buildkit, CleanStart: buildkitd&lt;/p&gt;
&lt;p&gt;CVE-2024-23651 affects multiple packages. BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: buildkit, CleanStart: buildkitd&lt;/p&gt;
&lt;p&gt;CVE-2024-23651 affects multiple packages. BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2025-mu54155</guid>
    </item>
    <item>
      <title>EUVD-2026-241769</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-241769</link>
      <description>EUVD-2026-241769</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-241769</guid>
    </item>
    <item>
      <title>fkie_cve-2024-23651</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-23651</link>
      <description>&lt;p&gt;BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Two malicious build steps running in parallel sharing the same cache mounts with subpaths could cause a race condition that can lead to files from the host system being accessible to the build container. The issue has been fixed in v0.12.5. Workarounds include, avoiding using BuildKit frontend from an untrusted source or building an untrusted Dockerfile containing cache mounts with --mount=type=cache,source=... options.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Two malicious build steps running in parallel sharing the same cache mounts with subpaths could cause a race condition that can lead to files from the host system being accessible to the build container. The issue has been fixed in v0.12.5. Workarounds include, avoiding using BuildKit frontend from an untrusted source or building an untrusted Dockerfile containing cache mounts with --mount=type=cache,source=... options.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-23651</guid>
    </item>
    <item>
      <title>GHSA-m3r6-h7wv-7xxv — BuildKit vulnerable to possible race condition with accessing subpaths from cache mounts</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-m3r6-h7wv-7xxv</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/moby/buildkit&lt;/p&gt;
&lt;p&gt;### Impact
Two malicious build steps running in parallel sharing the same cache mounts with subpaths could cause a race condition that can lead to files from the host system being accessible to the build container.&lt;/p&gt;
&lt;p&gt;### Patches
The issue has been fixed in v0.12.5&lt;/p&gt;
&lt;p&gt;### Workarounds
Avoid using BuildKit frontend from an untrusted source or building an untrusted Dockerfile containing cache mounts with `--mount=type=cache,source=...` options.&lt;/p&gt;
&lt;p&gt;### References
https://www.openwall.com/lists/oss-security/2019/05/28/1&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/moby/buildkit&lt;/p&gt;
&lt;p&gt;### Impact
Two malicious build steps running in parallel sharing the same cache mounts with subpaths could cause a race condition that can lead to files from the host system being accessible to the build container.&lt;/p&gt;
&lt;p&gt;### Patches
The issue has been fixed in v0.12.5&lt;/p&gt;
&lt;p&gt;### Workarounds
Avoid using BuildKit frontend from an untrusted source or building an untrusted Dockerfile containing cache mounts with `--mount=type=cache,source=...` options.&lt;/p&gt;
&lt;p&gt;### References
https://www.openwall.com/lists/oss-security/2019/05/28/1&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-m3r6-h7wv-7xxv</guid>
    </item>
    <item>
      <title>gsd-2024-23651</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-23651</link>
      <description>gsd-2024-23651</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-23651</guid>
    </item>
    <item>
      <title>msrc_CVE-2024-23651 — BuildKit possible race condition with accessing subpaths from cache mounts</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2024-23651</link>
      <description>msrc_CVE-2024-23651</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2024-23651</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:13651-1 — buildkit-0.12.5-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13651-1</link>
      <description>&lt;p&gt;buildkit-0.12.5-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;buildkit-0.12.5-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:13651-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:0587-1 — Security update for docker</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:0587-1</link>
      <description>&lt;p&gt;Security update for docker&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for docker&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:0587-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-23651</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-23651</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:18.04:LTS: docker.io, Ubuntu:Pro:20.04:LTS: docker.io, Ubuntu:Pro:20.04:LTS: docker.io-app, Ubuntu:22.04:LTS: docker.io-app, Ubuntu:Pro:22.04:LTS: docker.io, Ubuntu:24.04:LTS: docker.io-app, Ubuntu:Pro:24.04:LTS: docker.io&lt;/p&gt;
&lt;p&gt;BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Two malicious build steps running in parallel sharing the same cache mounts with subpaths could cause a race condition that can lead to files from the host system being accessible to the build container. The issue has been fixed in v0.12.5. Workarounds include, avoiding using BuildKit frontend from an untrusted source or building an untrusted Dockerfile containing cache mounts with --mount=type=cache,source=... options.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:18.04:LTS: docker.io, Ubuntu:Pro:20.04:LTS: docker.io, Ubuntu:Pro:20.04:LTS: docker.io-app, Ubuntu:22.04:LTS: docker.io-app, Ubuntu:Pro:22.04:LTS: docker.io, Ubuntu:24.04:LTS: docker.io-app, Ubuntu:Pro:24.04:LTS: docker.io&lt;/p&gt;
&lt;p&gt;BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Two malicious build steps running in parallel sharing the same cache mounts with subpaths could cause a race condition that can lead to files from the host system being accessible to the build container. The issue has been fixed in v0.12.5. Workarounds include, avoiding using BuildKit frontend from an untrusted source or building an untrusted Dockerfile containing cache mounts with --mount=type=cache,source=... options.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-23651</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-0272 — docker: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0272</link>
      <description>&lt;p&gt;Ein entfernter Angreifer kann mehrere Schwachstellen in Docker ausnutzen, um seine Privilegien zu erhöhen, einen Denial-of-Service-Zustand zu verursachen, vertrauliche Informationen offenzulegen, Sicherheitsmaßnahmen zu umgehen oder Dateien zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter Angreifer kann mehrere Schwachstellen in Docker ausnutzen, um seine Privilegien zu erhöhen, einen Denial-of-Service-Zustand zu verursachen, vertrauliche Informationen offenzulegen, Sicherheitsmaßnahmen zu umgehen oder Dateien zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0272</guid>
    </item>
  </channel>
</rss>
