<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 01:25:03 +0000</lastBuildDate>
    <item>
      <title>bdu:2024-06891</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-06891</link>
      <description>bdu:2024-06891</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-06891</guid>
    </item>
    <item>
      <title>BELL-CVE-2024-45310</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2024-45310</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: runc, Alpaquita:stream: runc&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: runc, Alpaquita:stream: runc&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2024-45310</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0641 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0641</link>
      <description>certfr-2026-avi-0641</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0641</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-CX82241 — Security fixes in runc 1.1.14-r0</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-cx82241</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: runc&lt;/p&gt;
&lt;p&gt;Package runc version 1.1.14-r0 fixes 40 vulnerabilities: ghsa-vvgc-356p-c3xw, CVE-2026-25679, CVE-2025-22873, CVE-2025-22872, CVE-2025-22871...&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: runc&lt;/p&gt;
&lt;p&gt;Package runc version 1.1.14-r0 fixes 40 vulnerabilities: ghsa-vvgc-356p-c3xw, CVE-2026-25679, CVE-2025-22873, CVE-2025-22872, CVE-2025-22871...&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-cx82241</guid>
    </item>
    <item>
      <title>EUVD-2026-218589</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-218589</link>
      <description>EUVD-2026-218589</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-218589</guid>
    </item>
    <item>
      <title>fkie_cve-2024-45310</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-45310</link>
      <description>&lt;p&gt;runc is a CLI tool for spawning and running containers according to the OCI specification. runc 1.1.13 and earlier, as well as 1.2.0-rc2 and earlier, can be tricked into creating empty files or directories in arbitrary locations in the host filesystem by sharing a volume between two containers and exploiting a race with `os.MkdirAll`. While this could be used to create empty files, existing files would not be truncated. An attacker must have the ability to start containers using some kind of custom volume configuration. Containers using user namespaces are still affected, but the scope of places an attacker can create inodes can be significantly reduced. Sufficiently strict LSM policies (SELinux/Apparmor) can also in principle block this attack -- we suspect the industry standard SELinux policy may restrict this attack&amp;#39;s scope but the exact scope of protection hasn&amp;#39;t been analysed. This is exploitable using runc directly as well as through Docker and Kubernetes. The issue is fixed in runc v1.1.14 and v1.2.0-rc3.&lt;/p&gt;
&lt;p&gt;Some workarounds are available. Using user namespaces restricts this attack fairly significantly such that the attacker can only create inodes in directories that the remapped root user/group has write access to. Unless the root user is remapped to an actual
user on the host (such as with rootless containers that don&amp;#39;t use `/etc/sub[ug]id`), this in practice means that an attacker would only be able to create inodes in world-writable directories. A strict enough SEL…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;runc is a CLI tool for spawning and running containers according to the OCI specification. runc 1.1.13 and earlier, as well as 1.2.0-rc2 and earlier, can be tricked into creating empty files or directories in arbitrary locations in the host filesystem by sharing a volume between two containers and exploiting a race with `os.MkdirAll`. While this could be used to create empty files, existing files would not be truncated. An attacker must have the ability to start containers using some kind of custom volume configuration. Containers using user namespaces are still affected, but the scope of places an attacker can create inodes can be significantly reduced. Sufficiently strict LSM policies (SELinux/Apparmor) can also in principle block this attack -- we suspect the industry standard SELinux policy may restrict this attack&amp;#39;s scope but the exact scope of protection hasn&amp;#39;t been analysed. This is exploitable using runc directly as well as through Docker and Kubernetes. The issue is fixed in runc v1.1.14 and v1.2.0-rc3.&lt;/p&gt;
&lt;p&gt;Some workarounds are available. Using user namespaces restricts this attack fairly significantly such that the attacker can only create inodes in directories that the remapped root user/group has write access to. Unless the root user is remapped to an actual
user on the host (such as with rootless containers that don&amp;#39;t use `/etc/sub[ug]id`), this in practice means that an attacker would only be able to create inodes in world-writable directories. A strict enough SEL…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-45310</guid>
    </item>
    <item>
      <title>GHSA-jfvp-7x6p-h2pv — runc can be confused to create empty files/directories on the host</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jfvp-7x6p-h2pv</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/opencontainers/runc&lt;/p&gt;
&lt;p&gt;### Impact
runc 1.1.13 and earlier as well as 1.2.0-rc2 and earlier can be tricked into
creating empty files or directories in arbitrary locations in the host
filesystem by sharing a volume between two containers and exploiting a race
with os.MkdirAll. While this can be used to create empty files, existing
files **will not** be truncated.&lt;/p&gt;
&lt;p&gt;An attacker must have the ability to start containers using some kind of custom
volume configuration. Containers using user namespaces are still affected, but
the scope of places an attacker can create inodes can be significantly reduced.
Sufficiently strict LSM policies (SELinux/Apparmor) can also in principle block
this attack -- we suspect the industry standard SELinux policy may restrict
this attack&amp;#39;s scope but the exact scope of protection hasn&amp;#39;t been analysed.&lt;/p&gt;
&lt;p&gt;This is exploitable using runc directly as well as through Docker and
Kubernetes.&lt;/p&gt;
&lt;p&gt;The CVSS score for this vulnerability is
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N (Low severity, 3.6).&lt;/p&gt;
&lt;p&gt;### Workarounds
Using user namespaces restricts this attack fairly significantly such that the
attacker can only create inodes in directories that the remapped root
user/group has write access to. Unless the root user is remapped to an actual
user on the host (such as with rootless containers that don&amp;#39;t use
/etc/sub[ug]id), this in practice means that an attacker would only be able to
create inodes in world-writable directories.&lt;/p&gt;
&lt;p&gt;A strict enough SELinux or AppArmor policy could in principl…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/opencontainers/runc&lt;/p&gt;
&lt;p&gt;### Impact
runc 1.1.13 and earlier as well as 1.2.0-rc2 and earlier can be tricked into
creating empty files or directories in arbitrary locations in the host
filesystem by sharing a volume between two containers and exploiting a race
with os.MkdirAll. While this can be used to create empty files, existing
files **will not** be truncated.&lt;/p&gt;
&lt;p&gt;An attacker must have the ability to start containers using some kind of custom
volume configuration. Containers using user namespaces are still affected, but
the scope of places an attacker can create inodes can be significantly reduced.
Sufficiently strict LSM policies (SELinux/Apparmor) can also in principle block
this attack -- we suspect the industry standard SELinux policy may restrict
this attack&amp;#39;s scope but the exact scope of protection hasn&amp;#39;t been analysed.&lt;/p&gt;
&lt;p&gt;This is exploitable using runc directly as well as through Docker and
Kubernetes.&lt;/p&gt;
&lt;p&gt;The CVSS score for this vulnerability is
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N (Low severity, 3.6).&lt;/p&gt;
&lt;p&gt;### Workarounds
Using user namespaces restricts this attack fairly significantly such that the
attacker can only create inodes in directories that the remapped root
user/group has write access to. Unless the root user is remapped to an actual
user on the host (such as with rootless containers that don&amp;#39;t use
/etc/sub[ug]id), this in practice means that an attacker would only be able to
create inodes in world-writable directories.&lt;/p&gt;
&lt;p&gt;A strict enough SELinux or AppArmor policy could in principl…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jfvp-7x6p-h2pv</guid>
    </item>
    <item>
      <title>msrc_CVE-2024-45310 — runc can be confused to create empty files/directories on the host</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2024-45310</link>
      <description>msrc_CVE-2024-45310</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2024-45310</guid>
    </item>
    <item>
      <title>OESA-2024-2134 — runc security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-2134</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: runc&lt;/p&gt;
&lt;p&gt;runc is a CLI tool for spawning and running containers according to the OCI specification.&#13;
&#13;
Security Fix(es):&#13;
&#13;
runc is a CLI tool for spawning and running containers according to the OCI specification. runc 1.1.13 and earlier, as well as 1.2.0-rc2 and earlier, can be tricked into creating empty files or directories in arbitrary locations in the host filesystem by sharing a volume between two containers and exploiting a race with `os.MkdirAll`. While this could be used to create empty files, existing files would not be truncated. An attacker must have the ability to start containers using some kind of custom volume configuration. Containers using user namespaces are still affected, but the scope of places an attacker can create inodes can be significantly reduced. Sufficiently strict LSM policies (SELinux/Apparmor) can also in principle block this attack -- we suspect the industry standard SELinux policy may restrict this attack&amp;amp;apos;s scope but the exact scope of protection hasn&amp;amp;apos;t been analysed. This is exploitable using runc directly as well as through Docker and Kubernetes. The issue is fixed in runc v1.1.14 and v1.2.0-rc3.&#13;
&#13;
Some workarounds are available. Using user namespaces restricts this attack fairly significantly such that the attacker can only create inodes in directories that the remapped root user/group has write access to. Unless the root user is remapped to an actual
user on the host (such as with rootless containers that don&amp;amp;apos;t use `/etc/sub[ug]…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: runc&lt;/p&gt;
&lt;p&gt;runc is a CLI tool for spawning and running containers according to the OCI specification.&#13;
&#13;
Security Fix(es):&#13;
&#13;
runc is a CLI tool for spawning and running containers according to the OCI specification. runc 1.1.13 and earlier, as well as 1.2.0-rc2 and earlier, can be tricked into creating empty files or directories in arbitrary locations in the host filesystem by sharing a volume between two containers and exploiting a race with `os.MkdirAll`. While this could be used to create empty files, existing files would not be truncated. An attacker must have the ability to start containers using some kind of custom volume configuration. Containers using user namespaces are still affected, but the scope of places an attacker can create inodes can be significantly reduced. Sufficiently strict LSM policies (SELinux/Apparmor) can also in principle block this attack -- we suspect the industry standard SELinux policy may restrict this attack&amp;amp;apos;s scope but the exact scope of protection hasn&amp;amp;apos;t been analysed. This is exploitable using runc directly as well as through Docker and Kubernetes. The issue is fixed in runc v1.1.14 and v1.2.0-rc3.&#13;
&#13;
Some workarounds are available. Using user namespaces restricts this attack fairly significantly such that the attacker can only create inodes in directories that the remapped root user/group has write access to. Unless the root user is remapped to an actual
user on the host (such as with rootless containers that don&amp;amp;apos;t use `/etc/sub[ug]…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-2134</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15424-1 — govulncheck-vulndb-0.0.20250807T150727-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15424-1</link>
      <description>&lt;p&gt;govulncheck-vulndb-0.0.20250807T150727-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;govulncheck-vulndb-0.0.20250807T150727-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15424-1</guid>
    </item>
    <item>
      <title>RHSA-2026:3406 — Red Hat Security Advisory: New container image: rhceph-9.0</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:3406</link>
      <description>&lt;p&gt;nodejs-underscore: Arbitrary code execution via the template function runc: runc can be tricked into creating empty files/directories on host golang-jwt: Bad documentation of error handling in ParseWithClaims can lead to potentially dangerous situations in golang-jwt nanoid: nanoid mishandles non-integer values Scrapy: python-scrapy: brotli: Python brotli decompression bomb DoS form-data: Unsafe random function in form-data util-linux: util-linux: Heap buffer overread in setpwnam() when processing 256-byte usernames golang.org/x/oauth2/jws: Unexpected memory consumption during token parsing in golang.org/x/oauth2/jws dompurify: Mutation XSS in DOMPurify Due to Improper Template Literal Handling urllib3: urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation urllib3: urllib3 does not control redirects in browsers and Node.js urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion urllib3: urllib3 Streaming API improperly handles highly compressed data urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;nodejs-underscore: Arbitrary code execution via the template function runc: runc can be tricked into creating empty files/directories on host golang-jwt: Bad documentation of error handling in ParseWithClaims can lead to potentially dangerous situations in golang-jwt nanoid: nanoid mishandles non-integer values Scrapy: python-scrapy: brotli: Python brotli decompression bomb DoS form-data: Unsafe random function in form-data util-linux: util-linux: Heap buffer overread in setpwnam() when processing 256-byte usernames golang.org/x/oauth2/jws: Unexpected memory consumption during token parsing in golang.org/x/oauth2/jws dompurify: Mutation XSS in DOMPurify Due to Improper Template Literal Handling urllib3: urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation urllib3: urllib3 does not control redirects in browsers and Node.js urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion urllib3: urllib3 Streaming API improperly handles highly compressed data urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:3406</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:3324-1 — Security update for runc</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:3324-1</link>
      <description>&lt;p&gt;Security update for runc&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for runc&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:3324-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-45310</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-45310</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: runc, Ubuntu:Pro:18.04:LTS: runc, Ubuntu:20.04:LTS: runc, Ubuntu:20.04:LTS: runc-app, Ubuntu:22.04:LTS: runc, Ubuntu:22.04:LTS: runc-app, Ubuntu:24.04:LTS: runc, Ubuntu:24.04:LTS: runc-app&lt;/p&gt;
&lt;p&gt;runc is a CLI tool for spawning and running containers according to the OCI specification. runc 1.1.13 and earlier, as well as 1.2.0-rc2 and earlier, can be tricked into creating empty files or directories in arbitrary locations in the host filesystem by sharing a volume between two containers and exploiting a race with `os.MkdirAll`. While this could be used to create empty files, existing files would not be truncated. An attacker must have the ability to start containers using some kind of custom volume configuration. Containers using user namespaces are still affected, but the scope of places an attacker can create inodes can be significantly reduced. Sufficiently strict LSM policies (SELinux/Apparmor) can also in principle block this attack -- we suspect the industry standard SELinux policy may restrict this attack&amp;#39;s scope but the exact scope of protection hasn&amp;#39;t been analysed. This is exploitable using runc directly as well as through Docker and Kubernetes. The issue is fixed in runc v1.1.14 and v1.2.0-rc3. Some workarounds are available. Using user namespaces restricts this attack fairly significantly such that the attacker can only create inodes in directories that the remapped root user/group has write access to. Unless the root user is remapped to an actual user on the host (such as with rootless containers that don&amp;#39;t use `/etc/sub[ug]id`), this in practice means that an attacker would only be able to create inodes in world-writable directories. A strict enough SELi…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: runc, Ubuntu:Pro:18.04:LTS: runc, Ubuntu:20.04:LTS: runc, Ubuntu:20.04:LTS: runc-app, Ubuntu:22.04:LTS: runc, Ubuntu:22.04:LTS: runc-app, Ubuntu:24.04:LTS: runc, Ubuntu:24.04:LTS: runc-app&lt;/p&gt;
&lt;p&gt;runc is a CLI tool for spawning and running containers according to the OCI specification. runc 1.1.13 and earlier, as well as 1.2.0-rc2 and earlier, can be tricked into creating empty files or directories in arbitrary locations in the host filesystem by sharing a volume between two containers and exploiting a race with `os.MkdirAll`. While this could be used to create empty files, existing files would not be truncated. An attacker must have the ability to start containers using some kind of custom volume configuration. Containers using user namespaces are still affected, but the scope of places an attacker can create inodes can be significantly reduced. Sufficiently strict LSM policies (SELinux/Apparmor) can also in principle block this attack -- we suspect the industry standard SELinux policy may restrict this attack&amp;#39;s scope but the exact scope of protection hasn&amp;#39;t been analysed. This is exploitable using runc directly as well as through Docker and Kubernetes. The issue is fixed in runc v1.1.14 and v1.2.0-rc3. Some workarounds are available. Using user namespaces restricts this attack fairly significantly such that the attacker can only create inodes in directories that the remapped root user/group has write access to. Unless the root user is remapped to an actual user on the host (such as with rootless containers that don&amp;#39;t use `/etc/sub[ug]id`), this in practice means that an attacker would only be able to create inodes in world-writable directories. A strict enough SELi…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-45310</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-0632 — IBM MQ: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0632</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM MQ ausnutzen, um Dateien zu manipulieren und Sicherheitsmaßnahmen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM MQ ausnutzen, um Dateien zu manipulieren und Sicherheitsmaßnahmen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0632</guid>
    </item>
  </channel>
</rss>
