<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 23:34:18 +0000</lastBuildDate>
    <item>
      <title>bdu:2024-02406</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-02406</link>
      <description>bdu:2024-02406</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-02406</guid>
    </item>
    <item>
      <title>BELL-CVE-2024-3094</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2024-3094</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: xz, BellSoft Hardened Containers:23: xz&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: xz, BellSoft Hardened Containers:23: xz&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2024-3094</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0500 — De multiples vulnérabilités ont été découvertes dans Elastic Kibana. Certaines d'entre elles permettent à un attaquant…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0500</link>
      <description>certfr-2024-avi-0500</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0500</guid>
    </item>
    <item>
      <title>CLEANSTART-2025-NL28578 — Malicious code was discovered in the upstream tarballs of xz, starting with version 5</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2025-nl28578</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: xz&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the xz package. Malicious code was discovered in the upstream tarballs of xz, starting with version 5.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: xz&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the xz package. Malicious code was discovered in the upstream tarballs of xz, starting with version 5.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2025-nl28578</guid>
    </item>
    <item>
      <title>EUVD-2026-344020</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-344020</link>
      <description>EUVD-2026-344020</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-344020</guid>
    </item>
    <item>
      <title>fkie_cve-2024-3094</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-3094</link>
      <description>&lt;p&gt;Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. &#13;
Through a series of complex obfuscations, the liblzma build process extracts a prebuilt object file from a disguised test file existing in the source code, which is then used to modify specific functions in the liblzma code. This results in a modified liblzma library that can be used by any software linked against this library, intercepting and modifying the data interaction with this library.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. &#13;
Through a series of complex obfuscations, the liblzma build process extracts a prebuilt object file from a disguised test file existing in the source code, which is then used to modify specific functions in the liblzma code. This results in a modified liblzma library that can be used by any software linked against this library, intercepting and modifying the data interaction with this library.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-3094</guid>
    </item>
    <item>
      <title>GHSA-rxwq-x6h5-x525</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-rxwq-x6h5-x525</link>
      <description>&lt;p&gt;Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. The tarballs included extra .m4 files, which contained instructions for building with automake that did not exist in the repository. These instructions, through a series of complex obfuscations, extract a prebuilt object file from one of the test archives, which is then used to modify specific functions in the code while building the liblzma package. This issue results in liblzma being used by additional software, like sshd, to provide functionality that will be interpreted by the modified functions.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. The tarballs included extra .m4 files, which contained instructions for building with automake that did not exist in the repository. These instructions, through a series of complex obfuscations, extract a prebuilt object file from one of the test archives, which is then used to modify specific functions in the code while building the liblzma package. This issue results in liblzma being used by additional software, like sshd, to provide functionality that will be interpreted by the modified functions.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-rxwq-x6h5-x525</guid>
    </item>
    <item>
      <title>gsd-2024-3094</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-3094</link>
      <description>gsd-2024-3094</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-3094</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:14017-1 — liblzma5-32bit-5.6.2-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:14017-1</link>
      <description>&lt;p&gt;liblzma5-32bit-5.6.2-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;liblzma5-32bit-5.6.2-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:14017-1</guid>
    </item>
    <item>
      <title>Withdrawn: UBUNTU-CVE-2024-3094</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-3094</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: xz-utils, Ubuntu:22.04:LTS: xz-utils, Ubuntu:24.04:LTS: xz-utils&lt;/p&gt;
&lt;p&gt;Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of complex obfuscations, the liblzma build process extracts a prebuilt object file from a disguised test file existing in the source code, which is then used to modify specific functions in the liblzma code. This results in a modified liblzma library that can be used by any software linked against this library, intercepting and modifying the data interaction with this library.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: xz-utils, Ubuntu:22.04:LTS: xz-utils, Ubuntu:24.04:LTS: xz-utils&lt;/p&gt;
&lt;p&gt;Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of complex obfuscations, the liblzma build process extracts a prebuilt object file from a disguised test file existing in the source code, which is then used to modify specific functions in the liblzma code. This results in a modified liblzma library that can be used by any software linked against this library, intercepting and modifying the data interaction with this library.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-3094</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-0762 — xz: Schwachstelle ermöglicht Ausführen von beliebigem Programmcode</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0762</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Debian Linux, SUSE Linux, Arch Linux, Fedora Linux, xz und Gentoo Linux ausnutzen, um beliebigen Programmcode auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Debian Linux, SUSE Linux, Arch Linux, Fedora Linux, xz und Gentoo Linux ausnutzen, um beliebigen Programmcode auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0762</guid>
    </item>
  </channel>
</rss>
