<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 10:16:13 +0000</lastBuildDate>
    <item>
      <title>ALSA-2023:2165 — Important: edk2 security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2023:2165</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: edk2-aarch64, AlmaLinux:9: edk2-ovmf, AlmaLinux:9: edk2-tools, AlmaLinux:9: edk2-tools-doc&lt;/p&gt;
&lt;p&gt;EDK (Embedded Development Kit) is a project to enable UEFI support for Virtual Machines. This package contains a sample 64-bit UEFI firmware for QEMU and KVM.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* openssl: X.400 address type confusion in X.509 GeneralName (CVE-2023-0286)
* edk2: integer underflow in SmmEntryPoint function leads to potential SMM privilege escalation (CVE-2021-38578)
* openssl: timing attack in RSA Decryption implementation (CVE-2022-4304)
* openssl: double free after calling PEM_read_bio_ex (CVE-2022-4450)
* openssl: use-after-free following BIO_new_NDEF (CVE-2023-0215)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: edk2-aarch64, AlmaLinux:9: edk2-ovmf, AlmaLinux:9: edk2-tools, AlmaLinux:9: edk2-tools-doc&lt;/p&gt;
&lt;p&gt;EDK (Embedded Development Kit) is a project to enable UEFI support for Virtual Machines. This package contains a sample 64-bit UEFI firmware for QEMU and KVM.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* openssl: X.400 address type confusion in X.509 GeneralName (CVE-2023-0286)
* edk2: integer underflow in SmmEntryPoint function leads to potential SMM privilege escalation (CVE-2021-38578)
* openssl: timing attack in RSA Decryption implementation (CVE-2022-4304)
* openssl: double free after calling PEM_read_bio_ex (CVE-2022-4450)
* openssl: use-after-free following BIO_new_NDEF (CVE-2023-0215)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2023:2165</guid>
    </item>
    <item>
      <title>bdu:2023-03835</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-03835</link>
      <description>bdu:2023-03835</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-03835</guid>
    </item>
    <item>
      <title>certfr-2023-avi-0733 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;les produits Siemens&lt;/span&gt;. Certaines d'entr…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0733</link>
      <description>certfr-2023-avi-0733</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0733</guid>
    </item>
    <item>
      <title>cnvd-2022-23460</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2022-23460</link>
      <description>cnvd-2022-23460</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2022-23460</guid>
    </item>
    <item>
      <title>EUVD-2026-257644</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-257644</link>
      <description>EUVD-2026-257644</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-257644</guid>
    </item>
    <item>
      <title>fkie_cve-2021-38578</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-38578</link>
      <description>&lt;p&gt;Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-38578</guid>
    </item>
    <item>
      <title>GHSA-grqq-3jqg-g95p</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-grqq-3jqg-g95p</link>
      <description>&lt;p&gt;Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-grqq-3jqg-g95p</guid>
    </item>
    <item>
      <title>gsd-2021-38578</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-38578</link>
      <description>gsd-2021-38578</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-38578</guid>
    </item>
    <item>
      <title>ICSA-23-257-04 — Siemens RUGGEDCOM APE1808 Products</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-23-257-04</link>
      <description>&lt;p&gt;An attacker with local access to the system could potentially disclose information&#13;
from protected memory areas via a side-channel attack on the processor cache. Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize. An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. IHISI function 0x17 verifies that the output buffer lies within the command buffer but does not verify that output data does not go beyond the end of the command buffer. In particular, the GetFlashTable function is called directly on the Command Buffer before the DataSize is check, leading to possible circumstances where the data immediately following the command buffer could be destroyed before returning a buffer size error. Using SPI injection, it is possible to modify the FDM contents after it has been measured. This TOCTOU attack could be used to alter data and code used by the remainder of the boot process. Some versions of InsydeH2O use the FreeType tools to embed fonts into the BIOS. InsydeH2O does not use the FreeType API at runtime and usage during build time does not produce a vulnerability in the BIOS. The CVSS reflects this limited usage. In UsbCoreDxe, untrusted input may allow SMRAM or OS memory tampering Use of untrusted pointers could allow OS or SMRAM memory tampering leading to escalation of privileges. This issue was discovered by Insyde during security review. https://www.insyde.com/security-pledge/SA-2022058 In UsbCor…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An attacker with local access to the system could potentially disclose information&#13;
from protected memory areas via a side-channel attack on the processor cache. Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize. An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. IHISI function 0x17 verifies that the output buffer lies within the command buffer but does not verify that output data does not go beyond the end of the command buffer. In particular, the GetFlashTable function is called directly on the Command Buffer before the DataSize is check, leading to possible circumstances where the data immediately following the command buffer could be destroyed before returning a buffer size error. Using SPI injection, it is possible to modify the FDM contents after it has been measured. This TOCTOU attack could be used to alter data and code used by the remainder of the boot process. Some versions of InsydeH2O use the FreeType tools to embed fonts into the BIOS. InsydeH2O does not use the FreeType API at runtime and usage during build time does not produce a vulnerability in the BIOS. The CVSS reflects this limited usage. In UsbCoreDxe, untrusted input may allow SMRAM or OS memory tampering Use of untrusted pointers could allow OS or SMRAM memory tampering leading to escalation of privileges. This issue was discovered by Insyde during security review. https://www.insyde.com/security-pledge/SA-2022058 In UsbCor…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-23-257-04</guid>
    </item>
    <item>
      <title>msrc_CVE-2021-38578 — Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize.</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2021-38578</link>
      <description>msrc_CVE-2021-38578</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2021-38578</guid>
    </item>
    <item>
      <title>OESA-2022-2122 — edk2 security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2022-2122</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: edk2, openEuler:20.03-LTS-SP3: edk2, openEuler:22.03-LTS: edk2&lt;/p&gt;
&lt;p&gt;EDK II is a modern, feature-rich, cross-platform firmware development environment for the UEFI and PI specifications. &#13;
&#13;
Security Fix(es):&#13;
&#13;
Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize.(CVE-2021-38578)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: edk2, openEuler:20.03-LTS-SP3: edk2, openEuler:22.03-LTS: edk2&lt;/p&gt;
&lt;p&gt;EDK II is a modern, feature-rich, cross-platform firmware development environment for the UEFI and PI specifications. &#13;
&#13;
Security Fix(es):&#13;
&#13;
Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize.(CVE-2021-38578)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2022-2122</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:12542-1 — ovmf-202211-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12542-1</link>
      <description>&lt;p&gt;ovmf-202211-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ovmf-202211-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:12542-1</guid>
    </item>
    <item>
      <title>SUSE-SU-2023:1921-1 — Security update for ovmf</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2023:1921-1</link>
      <description>&lt;p&gt;Security update for ovmf&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for ovmf&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2023:1921-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-38578</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-38578</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: edk2, Ubuntu:Pro:18.04:LTS: edk2, Ubuntu:20.04:LTS: edk2, Ubuntu:22.04:LTS: edk2&lt;/p&gt;
&lt;p&gt;Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: edk2, Ubuntu:Pro:18.04:LTS: edk2, Ubuntu:20.04:LTS: edk2, Ubuntu:22.04:LTS: edk2&lt;/p&gt;
&lt;p&gt;Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-38578</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-1315 — Dell PowerEdge: Schwachstelle ermöglicht Erlangen von Administratorrechten</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1315</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Dell PowerEdge ausnutzen, um Administratorrechte zu erlangen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Dell PowerEdge ausnutzen, um Administratorrechte zu erlangen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1315</guid>
    </item>
  </channel>
</rss>
