<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 17:30:35 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-336206</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-336206</link>
      <description>EUVD-2026-336206</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-336206</guid>
    </item>
    <item>
      <title>fkie_cve-2026-53657</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-53657</link>
      <description>&lt;p&gt;Lima launches Linux virtual machines, typically on macOS, for running containerd. Prior to 2.1.3, on an instance of Lima running with the qemu driver, an arbitrary user in the VM could access /run/lima-guestagent.sock when the guest agent is enabled, which could result in running arbitrary commands with root privileges in the VM because the guest agent socket provides tunneling for arbitrary addresses, including Unix socket addresses for privileged daemons like D-Bus. This issue is fixed in version 2.1.3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Lima launches Linux virtual machines, typically on macOS, for running containerd. Prior to 2.1.3, on an instance of Lima running with the qemu driver, an arbitrary user in the VM could access /run/lima-guestagent.sock when the guest agent is enabled, which could result in running arbitrary commands with root privileges in the VM because the guest agent socket provides tunneling for arbitrary addresses, including Unix socket addresses for privileged daemons like D-Bus. This issue is fixed in version 2.1.3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-53657</guid>
    </item>
    <item>
      <title>GHSA-2j9v-p4xj-cjw2 — Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-2j9v-p4xj-cjw2</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/lima-vm/lima/v2&lt;/p&gt;
&lt;p&gt;### Impact
On an instance of Lima running with `qemu` driver, an arbitrary user in the VM could access `/run/lima-guestagent.sock` when the guest agent is enabled.&lt;/p&gt;
&lt;p&gt;This could result in running an arbitrary command with the root privileges in the VM (**not on the host**), as `lima-guestagent.sock` provides the tunneling service for an arbitrary address, including a Unix socket address for privileged daemons like D-Bus.&lt;/p&gt;
&lt;p&gt;This vulnerability is not exploitable on `vz` driver, as the guest agent uses vsocks instead of Unix sockets.&lt;/p&gt;
&lt;p&gt;### Patches
Patched in Lima v2.1.3 (8a45892378d22f40505c31a38f786a07701b6d50)&lt;/p&gt;
&lt;p&gt;&amp;gt; [!NOTE]
&amp;gt; The default user account in the VM can still run an arbitrary command as the root via the guest agent socket.
&amp;gt; This is not a vulnerability, as the user can already run an arbitrary command with `sudo` by design.&lt;/p&gt;
&lt;p&gt;### Workarounds
- On macOS hosts, use `vz` driver instead of `qemu` (`limactl create --vm-type=vz`. Default since v1.0.)
- Or, disable the guest agent (`limactl create --plain`)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/lima-vm/lima/v2&lt;/p&gt;
&lt;p&gt;### Impact
On an instance of Lima running with `qemu` driver, an arbitrary user in the VM could access `/run/lima-guestagent.sock` when the guest agent is enabled.&lt;/p&gt;
&lt;p&gt;This could result in running an arbitrary command with the root privileges in the VM (**not on the host**), as `lima-guestagent.sock` provides the tunneling service for an arbitrary address, including a Unix socket address for privileged daemons like D-Bus.&lt;/p&gt;
&lt;p&gt;This vulnerability is not exploitable on `vz` driver, as the guest agent uses vsocks instead of Unix sockets.&lt;/p&gt;
&lt;p&gt;### Patches
Patched in Lima v2.1.3 (8a45892378d22f40505c31a38f786a07701b6d50)&lt;/p&gt;
&lt;p&gt;&amp;gt; [!NOTE]
&amp;gt; The default user account in the VM can still run an arbitrary command as the root via the guest agent socket.
&amp;gt; This is not a vulnerability, as the user can already run an arbitrary command with `sudo` by design.&lt;/p&gt;
&lt;p&gt;### Workarounds
- On macOS hosts, use `vz` driver instead of `qemu` (`limactl create --vm-type=vz`. Default since v1.0.)
- Or, disable the guest agent (`limactl create --plain`)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-2j9v-p4xj-cjw2</guid>
    </item>
  </channel>
</rss>
