<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 08:54:34 +0000</lastBuildDate>
    <item>
      <title>ALSA-2023:6492 — Moderate: tang security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2023:6492</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: tang&lt;/p&gt;
&lt;p&gt;Tang is a server for binding data to network presence. It includes a daemon which provides cryptographic operations for binding to a remote service. The tang package provides the server side of the Network Bound Disk Encryption (NBDE) project.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* tang: Race condition exists in the key generation and rotation functionality (CVE-2023-1672)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: tang&lt;/p&gt;
&lt;p&gt;Tang is a server for binding data to network presence. It includes a daemon which provides cryptographic operations for binding to a remote service. The tang package provides the server side of the Network Bound Disk Encryption (NBDE) project.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* tang: Race condition exists in the key generation and rotation functionality (CVE-2023-1672)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2023:6492</guid>
    </item>
    <item>
      <title>bdu:2023-08353</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-08353</link>
      <description>bdu:2023-08353</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-08353</guid>
    </item>
    <item>
      <title>EUVD-2026-216162</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-216162</link>
      <description>EUVD-2026-216162</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-216162</guid>
    </item>
    <item>
      <title>fkie_cve-2023-1672</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-1672</link>
      <description>&lt;p&gt;A race condition exists in the Tang server functionality for key generation and key rotation. This flaw results in a small time window where Tang private keys become readable by other processes on the same host.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A race condition exists in the Tang server functionality for key generation and key rotation. This flaw results in a small time window where Tang private keys become readable by other processes on the same host.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-1672</guid>
    </item>
    <item>
      <title>GHSA-9wgp-4vcq-75qr</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9wgp-4vcq-75qr</link>
      <description>&lt;p&gt;A race condition exists in the Tang server functionality for key generation and key rotation. This flaw results in a small time window where Tang private keys become readable by other processes on the same host.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A race condition exists in the Tang server functionality for key generation and key rotation. This flaw results in a small time window where Tang private keys become readable by other processes on the same host.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9wgp-4vcq-75qr</guid>
    </item>
    <item>
      <title>gsd-2023-1672</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-1672</link>
      <description>gsd-2023-1672</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-1672</guid>
    </item>
    <item>
      <title>msrc_CVE-2023-1672 — Race condition exists in the key generation and rotation functionality</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2023-1672</link>
      <description>msrc_CVE-2023-1672</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2023-1672</guid>
    </item>
    <item>
      <title>OESA-2023-1403 — tang security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2023-1403</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: tang, openEuler:20.03-LTS-SP3: tang, openEuler:22.03-LTS: tang, openEuler:22.03-LTS-SP1: tang, openEuler:22.03-LTS-SP2: tang&lt;/p&gt;
&lt;p&gt;This package is a server for binding data to network presence. First, the client gets a list of the Tang server&amp;amp;apos;s advertised asymmetric keys. This can happen online by a simple HTTP GET. Alternatively, since the keys are asymmetric, the public key list can be distributed out of band. Second, the client uses one of these public keys to generate a unique, cryptographically strong encryption key. The data is then encrypted using this key. Once the data is encrypted, the key is discarded. Some small metadata is produced as part of this operation which the client should store in a convenient location. This process of encrypting data is the provisioning step. Third, when the client is ready to access its data, it simply loads the metadata produced in the provisioning step and performs an HTTP POST in order to recover the encryption key. This process is the recovery step.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;A race condition exists in the Tang server functionality for key generation and key rotation. This flaw results in a small time window where Tang private keys become readable by other processes on the same host.(CVE-2023-1672)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: tang, openEuler:20.03-LTS-SP3: tang, openEuler:22.03-LTS: tang, openEuler:22.03-LTS-SP1: tang, openEuler:22.03-LTS-SP2: tang&lt;/p&gt;
&lt;p&gt;This package is a server for binding data to network presence. First, the client gets a list of the Tang server&amp;amp;apos;s advertised asymmetric keys. This can happen online by a simple HTTP GET. Alternatively, since the keys are asymmetric, the public key list can be distributed out of band. Second, the client uses one of these public keys to generate a unique, cryptographically strong encryption key. The data is then encrypted using this key. Once the data is encrypted, the key is discarded. Some small metadata is produced as part of this operation which the client should store in a convenient location. This process of encrypting data is the provisioning step. Third, when the client is ready to access its data, it simply loads the metadata produced in the provisioning step and performs an HTTP POST in order to recover the encryption key. This process is the recovery step.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;A race condition exists in the Tang server functionality for key generation and key rotation. This flaw results in a small time window where Tang private keys become readable by other processes on the same host.(CVE-2023-1672)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2023-1403</guid>
    </item>
    <item>
      <title>RHSA-2023:6492 — Red Hat Security Advisory: tang security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2023:6492</link>
      <description>&lt;p&gt;tang: Race condition exists in the key generation and rotation functionality&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;tang: Race condition exists in the key generation and rotation functionality&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2023:6492</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2023-1672</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-1672</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:18.04:LTS: tang, Ubuntu:20.04:LTS: tang, Ubuntu:22.04:LTS: tang&lt;/p&gt;
&lt;p&gt;A race condition exists in the Tang server functionality for key generation and key rotation. This flaw results in a small time window where Tang private keys become readable by other processes on the same host.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:18.04:LTS: tang, Ubuntu:20.04:LTS: tang, Ubuntu:22.04:LTS: tang&lt;/p&gt;
&lt;p&gt;A race condition exists in the Tang server functionality for key generation and key rotation. This flaw results in a small time window where Tang private keys become readable by other processes on the same host.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-1672</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-2853 — Red Hat Enterprise Linux: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2853</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um einen Denial-of-Service-Zustand herbeizuführen, Sicherheitsmaßnahmen zu umgehen, seine Privilegien zu erweitern, vertrauliche Informationen offenzulegen oder beliebigen Code auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um einen Denial-of-Service-Zustand herbeizuführen, Sicherheitsmaßnahmen zu umgehen, seine Privilegien zu erweitern, vertrauliche Informationen offenzulegen oder beliebigen Code auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-2853</guid>
    </item>
  </channel>
</rss>
