<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 17:11:19 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-248149</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-248149</link>
      <description>EUVD-2026-248149</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-248149</guid>
    </item>
    <item>
      <title>fkie_cve-2025-53945</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-53945</link>
      <description>&lt;p&gt;apko allows users to build and publish OCI container images built from apk packages. Starting in version 0.27.0 and prior to version 0.29.5, critical files were inadvertently set to 0666, which could likely be abused for root escalation. Version 0.29.5 contains a fix for the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;apko allows users to build and publish OCI container images built from apk packages. Starting in version 0.27.0 and prior to version 0.29.5, critical files were inadvertently set to 0666, which could likely be abused for root escalation. Version 0.29.5 contains a fix for the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-53945</guid>
    </item>
    <item>
      <title>GHSA-x6ph-r535-3vjw — apko is vulnerable to attack through incorrect permissions in /etc/ld.so.cache and other files</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-x6ph-r535-3vjw</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: chainguard.dev/apko&lt;/p&gt;
&lt;p&gt;It was discovered that the ld.so.cache in images generated by apko had file system permissions mode `0666`:
```
bash-5.3# find / -type f -perm -o+w
/etc/ld.so.cache
```&lt;/p&gt;
&lt;p&gt;This issue was introduced in commit [04f37e2 (&amp;#34;generate /etc/ld.so.cache (#1629)&amp;#34;)](https://github.com/chainguard-dev/apko/commit/04f37e2d50d5a502e155788561fb7d40de705bd9)([v0.27.0](https://github.com/chainguard-dev/apko/releases/tag/v0.27.0)).&lt;/p&gt;
&lt;p&gt;###  Impact
This potentially allows a local unprivileged user to add additional additional directories including dynamic libraries to the dynamic loader path. A user could exploit this by placing a malicious library in a directory they control.&lt;/p&gt;
&lt;p&gt;### Patches
This issue was addressed in apko in [aedb077 (&amp;#34;fix: /etc/ld.so.cache file permissions (#1758)&amp;#34;)](https://github.com/chainguard-dev/apko/commit/aedb0772d6bf6e74d8f17690946dbc791d0f6af3) ([v0.29.5](https://github.com/chainguard-dev/apko/releases/tag/v0.29.5)).&lt;/p&gt;
&lt;p&gt;### Acknowledgements&lt;/p&gt;
&lt;p&gt;Many thanks to Cody Harris from [H2O.ai](http://h2o.ai/) for reporting this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: chainguard.dev/apko&lt;/p&gt;
&lt;p&gt;It was discovered that the ld.so.cache in images generated by apko had file system permissions mode `0666`:
```
bash-5.3# find / -type f -perm -o+w
/etc/ld.so.cache
```&lt;/p&gt;
&lt;p&gt;This issue was introduced in commit [04f37e2 (&amp;#34;generate /etc/ld.so.cache (#1629)&amp;#34;)](https://github.com/chainguard-dev/apko/commit/04f37e2d50d5a502e155788561fb7d40de705bd9)([v0.27.0](https://github.com/chainguard-dev/apko/releases/tag/v0.27.0)).&lt;/p&gt;
&lt;p&gt;###  Impact
This potentially allows a local unprivileged user to add additional additional directories including dynamic libraries to the dynamic loader path. A user could exploit this by placing a malicious library in a directory they control.&lt;/p&gt;
&lt;p&gt;### Patches
This issue was addressed in apko in [aedb077 (&amp;#34;fix: /etc/ld.so.cache file permissions (#1758)&amp;#34;)](https://github.com/chainguard-dev/apko/commit/aedb0772d6bf6e74d8f17690946dbc791d0f6af3) ([v0.29.5](https://github.com/chainguard-dev/apko/releases/tag/v0.29.5)).&lt;/p&gt;
&lt;p&gt;### Acknowledgements&lt;/p&gt;
&lt;p&gt;Many thanks to Cody Harris from [H2O.ai](http://h2o.ai/) for reporting this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-x6ph-r535-3vjw</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15405-1 — govulncheck-vulndb-0.0.20250730T213748-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15405-1</link>
      <description>&lt;p&gt;govulncheck-vulndb-0.0.20250730T213748-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;govulncheck-vulndb-0.0.20250730T213748-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15405-1</guid>
    </item>
  </channel>
</rss>
