<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 09:58:05 +0000</lastBuildDate>
    <item>
      <title>ALSA-2024:2679 — Moderate: libxml2 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2024:2679</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: libxml2, AlmaLinux:9: libxml2-devel, AlmaLinux:9: python3-libxml2&lt;/p&gt;
&lt;p&gt;The libxml2 library is a development toolbox providing the implementation of various XML standards.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libxml2: use-after-free in XMLReader (CVE-2024-25062)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: libxml2, AlmaLinux:9: libxml2-devel, AlmaLinux:9: python3-libxml2&lt;/p&gt;
&lt;p&gt;The libxml2 library is a development toolbox providing the implementation of various XML standards.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libxml2: use-after-free in XMLReader (CVE-2024-25062)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2024:2679</guid>
    </item>
    <item>
      <title>bdu:2024-01415</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-01415</link>
      <description>bdu:2024-01415</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-01415</guid>
    </item>
    <item>
      <title>BELL-CVE-2024-25062</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2024-25062</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: libxml2, Alpaquita:stream: libxml2, BellSoft Hardened Containers:23: libxml2, BellSoft Hardened Containers:stream: libxml2&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: libxml2, Alpaquita:stream: libxml2, BellSoft Hardened Containers:23: libxml2, BellSoft Hardened Containers:stream: libxml2&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2024-25062</guid>
    </item>
    <item>
      <title>BIT-java-2024-25062</title>
      <link>https://cve.radiocsirt.org/vuln/bit-java-2024-25062</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: java&lt;/p&gt;
&lt;p&gt;An issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing crafted XML documents can lead to an xmlValidatePopElement use-after-free.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: java&lt;/p&gt;
&lt;p&gt;An issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing crafted XML documents can lead to an xmlValidatePopElement use-after-free.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-java-2024-25062</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0579 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0579</link>
      <description>certfr-2024-avi-0579</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0579</guid>
    </item>
    <item>
      <title>EUVD-2026-258572</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-258572</link>
      <description>EUVD-2026-258572</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-258572</guid>
    </item>
    <item>
      <title>fkie_cve-2024-25062</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-25062</link>
      <description>&lt;p&gt;An issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing crafted XML documents can lead to an xmlValidatePopElement use-after-free.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing crafted XML documents can lead to an xmlValidatePopElement use-after-free.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-25062</guid>
    </item>
    <item>
      <title>GHSA-x77r-6xxm-wjmx</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-x77r-6xxm-wjmx</link>
      <description>&lt;p&gt;An issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing crafted XML documents can lead to an xmlValidatePopElement use-after-free.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing crafted XML documents can lead to an xmlValidatePopElement use-after-free.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-x77r-6xxm-wjmx</guid>
    </item>
    <item>
      <title>gsd-2024-25062</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-25062</link>
      <description>gsd-2024-25062</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-25062</guid>
    </item>
    <item>
      <title>ICSA-23-166-11 — Siemens SIMATIC S7-1500 TM MFP Linux Kernel</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-23-166-11</link>
      <description>&lt;p&gt;json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend. A memory overflow vulnerability was found in the Linux kernel’s ipc functionality of the memcg subsystem, in the way a user calls the semget function multiple times, creating semaphores. This flaw allows a local user to starve the resources, causing a denial of service. The highest threat from this vulnerability is to system availability. A vulnerability was found in the fs/inode.c:inode_init_owner() function logic of the LInux kernel that allows local users to create files for the XFS file-system with an unintended group ownership and with group execution and SGID permission bits set, in a scenario where a directory is SGID and belongs to a certain group and is writable by a user who is not a member of this group. This can lead to excessive permissions granted in case when they should not. This vulnerability is similar to the previous CVE-2018-13405 and adds the missed fix for the XFS. When sending malicous data to kernel by ioctl cmd FBIOPUT_VSCREENINFO,kernel will write memory out of bounds. In gc_data_segment in fs/f2fs/gc.c in the Linux kernel before 5.16.3, special files are not considered, leading to a move_data_page NULL pointer dereference. A flaw was found in the Linux kernel. The existing KVM SEV API has a vulnerability that allows a non-root (host) user-level application to crash the host kernel by creating a confidential guest VM inst…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend. A memory overflow vulnerability was found in the Linux kernel’s ipc functionality of the memcg subsystem, in the way a user calls the semget function multiple times, creating semaphores. This flaw allows a local user to starve the resources, causing a denial of service. The highest threat from this vulnerability is to system availability. A vulnerability was found in the fs/inode.c:inode_init_owner() function logic of the LInux kernel that allows local users to create files for the XFS file-system with an unintended group ownership and with group execution and SGID permission bits set, in a scenario where a directory is SGID and belongs to a certain group and is writable by a user who is not a member of this group. This can lead to excessive permissions granted in case when they should not. This vulnerability is similar to the previous CVE-2018-13405 and adds the missed fix for the XFS. When sending malicous data to kernel by ioctl cmd FBIOPUT_VSCREENINFO,kernel will write memory out of bounds. In gc_data_segment in fs/f2fs/gc.c in the Linux kernel before 5.16.3, special files are not considered, leading to a move_data_page NULL pointer dereference. A flaw was found in the Linux kernel. The existing KVM SEV API has a vulnerability that allows a non-root (host) user-level application to crash the host kernel by creating a confidential guest VM inst…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-23-166-11</guid>
    </item>
    <item>
      <title>msrc_CVE-2024-25062 — An issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5. When using the XML Reader interface with DTD…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2024-25062</link>
      <description>msrc_CVE-2024-25062</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2024-25062</guid>
    </item>
    <item>
      <title>OESA-2024-1183 — libxml2 security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-1183</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: libxml2, openEuler:20.03-LTS-SP4: libxml2, openEuler:22.03-LTS: libxml2, openEuler:22.03-LTS-SP1: libxml2, openEuler:22.03-LTS-SP2: libxml2, openEuler:22.03-LTS-SP3: libxml2&lt;/p&gt;
&lt;p&gt;Library providing XML and HTML support.&#13;
&#13;
Security Fix(es):&#13;
&#13;
An issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing crafted XML documents can lead to an xmlValidatePopElement use-after-free.(CVE-2024-25062)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: libxml2, openEuler:20.03-LTS-SP4: libxml2, openEuler:22.03-LTS: libxml2, openEuler:22.03-LTS-SP1: libxml2, openEuler:22.03-LTS-SP2: libxml2, openEuler:22.03-LTS-SP3: libxml2&lt;/p&gt;
&lt;p&gt;Library providing XML and HTML support.&#13;
&#13;
Security Fix(es):&#13;
&#13;
An issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing crafted XML documents can lead to an xmlValidatePopElement use-after-free.(CVE-2024-25062)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-1183</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:13676-1 — libxml2-2-2.11.6-2.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13676-1</link>
      <description>&lt;p&gt;libxml2-2-2.11.6-2.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libxml2-2-2.11.6-2.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:13676-1</guid>
    </item>
    <item>
      <title>RHSA-2024:3299 — Red Hat Security Advisory: libxml2 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:3299</link>
      <description>&lt;p&gt;libxml2: use-after-free in XMLReader&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libxml2: use-after-free in XMLReader&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:3299</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:0461-1 — Security update for libxml2</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:0461-1</link>
      <description>&lt;p&gt;Security update for libxml2&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for libxml2&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:0461-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-25062</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-25062</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: libxml2, Ubuntu:Pro:16.04:LTS: libxml2, Ubuntu:Pro:18.04:LTS: libxml2, Ubuntu:20.04:LTS: libxml2, Ubuntu:22.04:LTS: libxml2&lt;/p&gt;
&lt;p&gt;An issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing crafted XML documents can lead to an xmlValidatePopElement use-after-free.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: libxml2, Ubuntu:Pro:16.04:LTS: libxml2, Ubuntu:Pro:18.04:LTS: libxml2, Ubuntu:20.04:LTS: libxml2, Ubuntu:22.04:LTS: libxml2&lt;/p&gt;
&lt;p&gt;An issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing crafted XML documents can lead to an xmlValidatePopElement use-after-free.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-25062</guid>
    </item>
    <item>
      <title>VDE-2025-053 — Phoenix Contact: Multiple Vulnerabilities in PLCnext Firmware</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2025-053</link>
      <description>&lt;p&gt;Coreutils: heap overflow in split --line-bytes with very long lines Unprivileged overlay + shiftfs read access Nano: running `chmod` and `chown` on the filename allows malicious user to replace the emergency file with a malicious symlink to a root-owned file SSL_select_next_proto buffer overread Remote Code Execution in pypa/setuptools&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Coreutils: heap overflow in split --line-bytes with very long lines Unprivileged overlay + shiftfs read access Nano: running `chmod` and `chown` on the filename allows malicious user to replace the emergency file with a malicious symlink to a root-owned file SSL_select_next_proto buffer overread Remote Code Execution in pypa/setuptools&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2025-053</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-0280 — libxml2: Schwachstelle ermöglicht Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0280</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in libxml2 ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in libxml2 ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0280</guid>
    </item>
  </channel>
</rss>
