<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 23:33:55 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-09312</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-09312</link>
      <description>bdu:2025-09312</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-09312</guid>
    </item>
    <item>
      <title>BELL-CVE-2025-54410</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-54410</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: docker&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: docker&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-54410</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0754 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0754</link>
      <description>certfr-2025-avi-0754</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0754</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-AX33738 — Security fixes for CVE-2025-54410, CVE-2026-32952, CVE-2026-33186, CVE-2026-40179, CVE-2026-42151, CVE-2026-42154, ghsa…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ax33738</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: elastic-beats&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the elastic-beats package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: elastic-beats&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the elastic-beats package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ax33738</guid>
    </item>
    <item>
      <title>EUVD-2026-248700</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-248700</link>
      <description>EUVD-2026-248700</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-248700</guid>
    </item>
    <item>
      <title>fkie_cve-2025-54410</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-54410</link>
      <description>&lt;p&gt;Moby is an open source container framework developed by Docker Inc. that is distributed as Docker Engine, Mirantis Container Runtime, and various other downstream projects/products. A firewalld vulnerability affects Moby releases before 28.0.0. When firewalld reloads, Docker fails to re-create iptables rules that isolate bridge networks, allowing any container to access all ports on any other container across different bridge networks on the same host. This breaks network segmentation between containers that should be isolated, creating significant risk in multi-tenant environments. Only containers in --internal networks remain protected.
Workarounds include reloading firewalld and either restarting the docker daemon, re-creating bridge networks, or using rootless mode. Maintainers anticipate a fix for this issue in version 25.0.13.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Moby is an open source container framework developed by Docker Inc. that is distributed as Docker Engine, Mirantis Container Runtime, and various other downstream projects/products. A firewalld vulnerability affects Moby releases before 28.0.0. When firewalld reloads, Docker fails to re-create iptables rules that isolate bridge networks, allowing any container to access all ports on any other container across different bridge networks on the same host. This breaks network segmentation between containers that should be isolated, creating significant risk in multi-tenant environments. Only containers in --internal networks remain protected.
Workarounds include reloading firewalld and either restarting the docker daemon, re-creating bridge networks, or using rootless mode. Maintainers anticipate a fix for this issue in version 25.0.13.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-54410</guid>
    </item>
    <item>
      <title>GHSA-4vq8-7jfc-9cvp — Moby firewalld reload removes bridge network isolation</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-4vq8-7jfc-9cvp</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/docker/docker&lt;/p&gt;
&lt;p&gt;Moby is an open source container framework developed by Docker Inc. that is distributed as Docker Engine, Mirantis Container Runtime, and various other downstream projects/products. The Moby daemon component (dockerd), which is developed as [moby/moby](https://github.com/moby/moby) is commonly referred to as Docker, or Docker Engine.&lt;/p&gt;
&lt;p&gt;Firewalld is a daemon used by some Linux distributions to provide a dynamically managed firewall. When Firewalld is running, Docker uses its iptables backend to create rules, including rules to isolate containers in one bridge network from containers in other bridge networks.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;The iptables rules created by Docker are removed when firewalld is reloaded using, for example &amp;#34;firewall-cmd --reload&amp;#34;, &amp;#34;killall -HUP firewalld&amp;#34;, or &amp;#34;systemctl reload firewalld&amp;#34;.&lt;/p&gt;
&lt;p&gt;When that happens, Docker must re-create the rules. However, in affected versions of Docker, the iptables rules that isolate containers in different bridge networks from each other are not re-created.&lt;/p&gt;
&lt;p&gt;Once these rules have been removed, containers have access to any port, on any container, in any non-internal bridge network, running on the Docker host.&lt;/p&gt;
&lt;p&gt;Containers running in networks created with `--internal` or equivalent have no access to other networks. Containers that are only connected to these networks remain isolated after a firewalld reload.&lt;/p&gt;
&lt;p&gt;Where Docker Engine is not running in the host&amp;#39;s network namespace, it is unaffected. Including, for example, Rootless Mode, and Docke…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/docker/docker&lt;/p&gt;
&lt;p&gt;Moby is an open source container framework developed by Docker Inc. that is distributed as Docker Engine, Mirantis Container Runtime, and various other downstream projects/products. The Moby daemon component (dockerd), which is developed as [moby/moby](https://github.com/moby/moby) is commonly referred to as Docker, or Docker Engine.&lt;/p&gt;
&lt;p&gt;Firewalld is a daemon used by some Linux distributions to provide a dynamically managed firewall. When Firewalld is running, Docker uses its iptables backend to create rules, including rules to isolate containers in one bridge network from containers in other bridge networks.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;The iptables rules created by Docker are removed when firewalld is reloaded using, for example &amp;#34;firewall-cmd --reload&amp;#34;, &amp;#34;killall -HUP firewalld&amp;#34;, or &amp;#34;systemctl reload firewalld&amp;#34;.&lt;/p&gt;
&lt;p&gt;When that happens, Docker must re-create the rules. However, in affected versions of Docker, the iptables rules that isolate containers in different bridge networks from each other are not re-created.&lt;/p&gt;
&lt;p&gt;Once these rules have been removed, containers have access to any port, on any container, in any non-internal bridge network, running on the Docker host.&lt;/p&gt;
&lt;p&gt;Containers running in networks created with `--internal` or equivalent have no access to other networks. Containers that are only connected to these networks remain isolated after a firewalld reload.&lt;/p&gt;
&lt;p&gt;Where Docker Engine is not running in the host&amp;#39;s network namespace, it is unaffected. Including, for example, Rootless Mode, and Docke…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-4vq8-7jfc-9cvp</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15434-1 — govulncheck-vulndb-0.0.20250811T192933-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15434-1</link>
      <description>&lt;p&gt;govulncheck-vulndb-0.0.20250811T192933-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;govulncheck-vulndb-0.0.20250811T192933-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15434-1</guid>
    </item>
    <item>
      <title>RHSA-2026:37387 — Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.22.0 security, enhancement &amp; bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:37387</link>
      <description>&lt;p&gt;github.com/containerd/containerd: containerd local privilege escalation containerd: containerd has an integer overflow in User ID handling runc: runc can be tricked into creating empty files/directories on host noobaa-core: Excessive permissions of /etc could lead to escalation of privilege in the noobaa-core container go-git: argument injection via the URL field go-git: go-git clients vulnerable to DoS via maliciously crafted Git server replies golang.org/x/net/proxy: golang.org/x/net/http/httpproxy: HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net golang.org/x/net/html: Quadratic parsing complexity in golang.org/x/net/html runc: opencontainers/selinux: container escape and denial of service due to arbitrary write gadgets and procfs write redirects github.com/moby/moby: Moby&amp;#39;s Firewalld reload removes bridge network isolation github.com/ulikunitz/xz: github.com/ulikunitz/xz leaks memory github.com/containerd/containerd: containerd: Memory exhaustion via CRI Attach implementation goroutine leaks github.com/sigstore/fulcio: Fulcio: Denial of Service via crafted OpenID Connect (OIDC) token fulcio: Fulcio: Server-Side Request Forgery (SSRF) via unanchored regex in MetaIssuer URL validation github.com/sigstore/rekor: Rekor denial of service github.com/sigstore/rekor: Rekor Server-Side Request Forgery (SSRF) golang.org/x/net/html: golang.org/x/net/html: Denial of Service due to excessive HTML parsing golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;github.com/containerd/containerd: containerd local privilege escalation containerd: containerd has an integer overflow in User ID handling runc: runc can be tricked into creating empty files/directories on host noobaa-core: Excessive permissions of /etc could lead to escalation of privilege in the noobaa-core container go-git: argument injection via the URL field go-git: go-git clients vulnerable to DoS via maliciously crafted Git server replies golang.org/x/net/proxy: golang.org/x/net/http/httpproxy: HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net golang.org/x/net/html: Quadratic parsing complexity in golang.org/x/net/html runc: opencontainers/selinux: container escape and denial of service due to arbitrary write gadgets and procfs write redirects github.com/moby/moby: Moby&amp;#39;s Firewalld reload removes bridge network isolation github.com/ulikunitz/xz: github.com/ulikunitz/xz leaks memory github.com/containerd/containerd: containerd: Memory exhaustion via CRI Attach implementation goroutine leaks github.com/sigstore/fulcio: Fulcio: Denial of Service via crafted OpenID Connect (OIDC) token fulcio: Fulcio: Server-Side Request Forgery (SSRF) via unanchored regex in MetaIssuer URL validation github.com/sigstore/rekor: Rekor denial of service github.com/sigstore/rekor: Rekor Server-Side Request Forgery (SSRF) golang.org/x/net/html: golang.org/x/net/html: Denial of Service due to excessive HTML parsing golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:37387</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-54410</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-54410</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: docker.io, Ubuntu:Pro:18.04:LTS: docker.io, Ubuntu:Pro:20.04:LTS: docker.io, Ubuntu:Pro:20.04:LTS: docker.io-app, Ubuntu:Pro:22.04:LTS: docker.io, Ubuntu:Pro:22.04:LTS: docker.io-app, Ubuntu:Pro:24.04:LTS: docker.io, Ubuntu:Pro:24.04:LTS: docker.io-app, Ubuntu:25.10: docker.io, Ubuntu:26.04:LTS: docker.io&lt;/p&gt;
&lt;p&gt;Moby is an open source container framework developed by Docker Inc. that is distributed as Docker Engine, Mirantis Container Runtime, and various other downstream projects/products. A firewalld vulnerability affects Moby releases before 28.0.0. When firewalld reloads, Docker fails to re-create iptables rules that isolate bridge networks, allowing any container to access all ports on any other container across different bridge networks on the same host. This breaks network segmentation between containers that should be isolated, creating significant risk in multi-tenant environments. Only containers in --internal networks remain protected. Workarounds include reloading firewalld and either restarting the docker daemon, re-creating bridge networks, or using rootless mode. Maintainers anticipate a fix for this issue in version 25.0.13.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: docker.io, Ubuntu:Pro:18.04:LTS: docker.io, Ubuntu:Pro:20.04:LTS: docker.io, Ubuntu:Pro:20.04:LTS: docker.io-app, Ubuntu:Pro:22.04:LTS: docker.io, Ubuntu:Pro:22.04:LTS: docker.io-app, Ubuntu:Pro:24.04:LTS: docker.io, Ubuntu:Pro:24.04:LTS: docker.io-app, Ubuntu:25.10: docker.io, Ubuntu:26.04:LTS: docker.io&lt;/p&gt;
&lt;p&gt;Moby is an open source container framework developed by Docker Inc. that is distributed as Docker Engine, Mirantis Container Runtime, and various other downstream projects/products. A firewalld vulnerability affects Moby releases before 28.0.0. When firewalld reloads, Docker fails to re-create iptables rules that isolate bridge networks, allowing any container to access all ports on any other container across different bridge networks on the same host. This breaks network segmentation between containers that should be isolated, creating significant risk in multi-tenant environments. Only containers in --internal networks remain protected. Workarounds include reloading firewalld and either restarting the docker daemon, re-creating bridge networks, or using rootless mode. Maintainers anticipate a fix for this issue in version 25.0.13.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-54410</guid>
    </item>
  </channel>
</rss>
