<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/osv_almalinux/10</id>
  <title>Most recent entries from osv_almalinux</title>
  <updated>2026-10-06T08:20:07.365930+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:74464</id>
    <title>ALSA-2026:74464 — Moderate: ghostscript security update</title>
    <updated>2026-10-02T09:46:54+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:10: ghostscript, AlmaLinux:10: ghostscript-doc, AlmaLinux:10: ghostscript-tools-dvipdf, AlmaLinux:10: ghostscript-tools-fonts, AlmaLinux:10: ghostscript-tools-printing, AlmaLinux:10: libgs, AlmaLinux:10: libgs-devel</p>
<p>The Ghostscript suite contains utilities for rendering PostScript and PDF documents. Ghostscript translates PostScript code to common bitmap formats so that the code can be displayed or printed.</p>
<p>Security Fix(es):</p>
<p>* ghostscript: ghostscript: Heap buffer overflow via JPEG 2000 output adapter (CVE-2026-39919)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:74464"/>
    <published>2026-10-01T00:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:74457</id>
    <title>ALSA-2026:74457 — Moderate: ghostscript security update</title>
    <updated>2026-10-05T10:39:56+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: ghostscript, AlmaLinux:9: ghostscript-doc, AlmaLinux:9: ghostscript-tools-dvipdf, AlmaLinux:9: ghostscript-tools-fonts, AlmaLinux:9: ghostscript-tools-printing, AlmaLinux:9: ghostscript-x11, AlmaLinux:9: libgs, AlmaLinux:9: libgs-devel</p>
<p>The Ghostscript suite contains utilities for rendering PostScript and PDF documents. Ghostscript translates PostScript code to common bitmap formats so that the code can be displayed or printed.</p>
<p>Security Fix(es):</p>
<p>* ghostscript: ghostscript: Heap buffer overflow via JPEG 2000 output adapter (CVE-2026-39919)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:74457"/>
    <published>2026-10-01T00:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:74442</id>
    <title>ALSA-2026:74442 — Important: libpcap security update</title>
    <updated>2026-10-01T13:43:26+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:10: libpcap, AlmaLinux:10: libpcap-devel</p>
<p>The libpcap packages provide a portable framework for low-level network monitoring. The libpcap library provides network statistics collection, security monitoring, and network debugging.</p>
<p>Security Fix(es):</p>
<p>* libpcap: libpcap: Out-of-bounds read and write vulnerability allows arbitrary memory access (CVE-2026-0799)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:74442"/>
    <published>2026-10-01T00:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:74441</id>
    <title>ALSA-2026:74441 — Important: libpcap security update</title>
    <updated>2026-10-02T12:38:51+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: libpcap, AlmaLinux:9: libpcap-devel</p>
<p>The libpcap packages provide a portable framework for low-level network monitoring. The libpcap library provides network statistics collection, security monitoring, and network debugging.</p>
<p>Security Fix(es):</p>
<p>* libpcap: libpcap: Out-of-bounds read and write vulnerability allows arbitrary memory access (CVE-2026-0799)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:74441"/>
    <published>2026-10-01T00:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:74424</id>
    <title>ALSA-2026:74424 — Important: libvirt security, bug fix, and enhancement update</title>
    <updated>2026-10-05T10:42:25+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: libvirt, AlmaLinux:9: libvirt-client, AlmaLinux:9: libvirt-client-qemu, AlmaLinux:9: libvirt-daemon, AlmaLinux:9: libvirt-daemon-common, AlmaLinux:9: libvirt-daemon-config-network, AlmaLinux:9: libvirt-daemon-config-nwfilter, AlmaLinux:9: libvirt-daemon-driver-interface, AlmaLinux:9: libvirt-daemon-driver-network, AlmaLinux:9: libvirt-daemon-driver-nodedev and 22 more</p>
<p>The libvirt library contains a C API for managing and interacting with the virtualization capabilities of Linux and other operating systems. In addition, libvirt provides tools for remote management of virtualized systems.</p>
<p>Security Fix(es):</p>
<p>* libvirt: swtpm privilege escalation via symlink following (CVE-2026-63622)
  * libvirt: Integer overflow in NodeGetFreePages RPC handler leading to heap buffer overflow (CVE-2026-18917)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* Live migration fails when virtio-vga becomes available, video device switches from virtio-gpu-pci to virtio-vga on target [almalinux-9.8.z] (JIRA:AlmaLinux-186018)
  * libvirt-guests does not work together with virtlockd on shutdown [almalinux-9.8.z] (JIRA:AlmaLinux-224986)
  * Expose guest-get-devices in libvirt-api [almalinux-9.8.z] (JIRA:AlmaLinux-243306)
  * allow hyperv pvpanic "device" to process Windows crash dump [almalinux-9.8.z] (JIRA:AlmaLinux-242549)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:74424"/>
    <published>2026-10-01T00:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:74370</id>
    <title>ALSA-2026:74370 — Important: gvfs security update</title>
    <updated>2026-10-01T13:44:02+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: gvfs, AlmaLinux:9: gvfs-client, AlmaLinux:9: gvfs-devel, AlmaLinux:9: gvfs-fuse, AlmaLinux:9: gvfs-goa, AlmaLinux:9: gvfs-gphoto2, AlmaLinux:9: gvfs-mtp, AlmaLinux:9: gvfs-smb</p>
<p>GVFS is the GNOME Desktop Virtual File System layer that allows users to easily access local and remote data using File Transfer Protocol (FTP), Secure Shell File Transfer Protocol (SFTP), Web Distributed Authoring and Versioning (WebDAV), Common Internet File System (CIFS), Server Message Block (SMB), and other protocols. GVFS integrates with the GNOME I/O (GIO) abstraction layer.</p>
<p>Security Fix(es):</p>
<p>* gvfs: SFTP: heap-based buffer overflow in read_reply() (CVE-2026-84268)
  * gvfs: gvfs-admin socket ownership race permits local root (CVE-2026-88924)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:74370"/>
    <published>2026-10-01T00:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:74133</id>
    <title>ALSA-2026:74133 — Moderate: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-01T09:21:58+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: bpftool, AlmaLinux:8: kernel, AlmaLinux:8: kernel-abi-stablelists, AlmaLinux:8: kernel-core, AlmaLinux:8: kernel-cross-headers, AlmaLinux:8: kernel-debug, AlmaLinux:8: kernel-debug-core, AlmaLinux:8: kernel-debug-devel, AlmaLinux:8: kernel-debug-modules, AlmaLinux:8: kernel-debug-modules-extra and 15 more</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: RDMA/siw: Reject MPA FPDU length underflow before signed receive math (CVE-2026-64102)
  * kernel: vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets (CVE-2026-68299)
  * kernel: net/liquidio: drop cached VF pci_dev LUT (CVE-2026-72329)
  * kernel: dm-integrity: don't increment hash_offset twice (CVE-2026-72099)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* [AlmaLinux 8.10] "kernel BUG at lib/list_debug.c:28!": list_add corruption in register_trace_event AlmaLinux 8.10 (JIRA:AlmaLinux-214136)
  * request_key_auth use-after-free on every request-key upcall since 4.18.0-553.165.1 (regression from CVE-2026-63823 backport) (JIRA:AlmaLinux-270349)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:74133"/>
    <published>2026-09-30T00:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:74132</id>
    <title>ALSA-2026:74132 — Moderate: kernel-rt security, bug fix, and enhancement update</title>
    <updated>2026-10-01T09:24:16+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: kernel-rt, AlmaLinux:8: kernel-rt-core, AlmaLinux:8: kernel-rt-debug, AlmaLinux:8: kernel-rt-debug-core, AlmaLinux:8: kernel-rt-debug-devel, AlmaLinux:8: kernel-rt-debug-modules, AlmaLinux:8: kernel-rt-debug-modules-extra, AlmaLinux:8: kernel-rt-devel, AlmaLinux:8: kernel-rt-modules, AlmaLinux:8: kernel-rt-modules-extra</p>
<p>The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.</p>
<p>Security Fix(es):</p>
<p>* kernel: RDMA/siw: Reject MPA FPDU length underflow before signed receive math (CVE-2026-64102)
  * kernel: vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets (CVE-2026-68299)
  * kernel: net/liquidio: drop cached VF pci_dev LUT (CVE-2026-72329)
  * kernel: dm-integrity: don't increment hash_offset twice (CVE-2026-72099)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* [AlmaLinux 8.10] "kernel BUG at lib/list_debug.c:28!": list_add corruption in register_trace_event AlmaLinux 8.10 (JIRA:AlmaLinux-214136)
  * request_key_auth use-after-free on every request-key upcall since 4.18.0-553.165.1 (regression from CVE-2026-63823 backport) (JIRA:AlmaLinux-270349)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:74132"/>
    <published>2026-09-30T00:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:74095</id>
    <title>ALSA-2026:74095 — Important: rsync security, bug fix, and enhancement update</title>
    <updated>2026-10-01T09:24:21+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: rsync, AlmaLinux:8: rsync-daemon</p>
<p>The rsync utility enables the users to copy and synchronize files locally or across a network. Synchronization with rsync is fast because rsync only sends the differences in files over the network instead of sending whole files. The rsync utility is also used as a mirroring tool.</p>
<p>Security Fix(es):</p>
<p>* rsync: rsync 2.3.3 &lt; 3.5.0 Path Traversal via --partial-dir/--backup-dir Symlink (CVE-2026-70460)
  * rsync: rsync: Arbitrary file deletion via malicious file list (CVE-2026-53789)
  * rsync: rsync &lt; 3.5.0 Command Injection via Multiple Code Paths (CVE-2026-53790)
  * rsync: rsync: Memory corruption via crafted file entries (CVE-2026-70458)
  * rsync: rsync: Denial of Service via handshake stall (CVE-2026-70464)
  * rsync: rsync: Local Privilege Escalation via Symlink Following (CVE-2026-53803)
  * rsync: rsync: Unauthorized File Access via Symlink Module Root (CVE-2026-53784)
  * rsync: rsync: Authorization bypass via `auth users` directive parsing (CVE-2026-70463)
  * rsync: rsync 3.1.0 &lt; 3.5.0 Access Control Bypass via DNS Resolution Failure (CVE-2026-70452)
  * rsync: rsync: Arbitrary file write via --temp-dir or --link-dest options (CVE-2026-53795)
  * rsync: rsync: Heap Out-of-Bounds Write via crafted argument list (CVE-2026-70456)
  * rsync: rsync &lt; 3.5.0 Path Confinement Bypass via /./ Boundary Marker in Chroot Mode (CVE-2026-53793)
  * rsync: rsync: Denial of Service via Algorithmic Complexity (CVE-2026-70453)
  * rsync: rsync: Information disclosure and denial o…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:74095"/>
    <published>2026-09-30T00:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:74084</id>
    <title>ALSA-2026:74084 — Critical: webkit2gtk3 security update</title>
    <updated>2026-10-01T09:25:52+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: webkit2gtk3, AlmaLinux:8: webkit2gtk3-devel, AlmaLinux:8: webkit2gtk3-jsc, AlmaLinux:8: webkit2gtk3-jsc-devel</p>
<p>WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform.</p>
<p>Security Fix(es):</p>
<p>* chromium-browser: skia: chromium-browser: skia: Inappropriate implementation in Skia (CVE-2023-4860)
  * chromium-browser: angle: Out of bounds memory access in ANGLE (CVE-2024-7532)
  * chromium-browser: skia: chromium-browser: skia: Out of bounds memory access in Skia in Google Chrome allows a remote attacker who had compromised the renderer process to perform out of bounds memory access via a crafted HTML page (CVE-2024-7966)
  * chromium: skia: chromium: skia: Heap buffer overflow in Skia (CVE-2024-8193)
  * chromium: skia: chromium: skia: Heap buffer overflow in Skia (CVE-2024-8198)
  * chromium: skia: chromium: skia: Heap buffer overflow in Skia (CVE-2024-8636)
  * chromium-browser: skia: chromium-browser: skia: Integer overflow in Skia in Google Chrome (CVE-2024-9123)
  * chromium-browser: skia: chromium-browser: skia: Integer overflow in Skia (CVE-2025-0436)
  * chromium-browser: skia: chromium-browser: skia: Use after free in Skia (CVE-2025-0444)
  * chromium-browser: angle: ANGLE Out-of-Bounds Write Vulnerability (CVE-2025-8901)
  * chromium-browser: angle: Use after free in ANGLE (CVE-2025-9478)
  * chromium-browser: angle: Heap buffer overflow in ANGLE (CVE-2025-10502)
  * chromium-browser: angle: Use after free in ANGLE (CVE-2026-0908)
  * chromium-browser: angle: Integer overflow in ANGLE (CVE-2026-3536)
  * chromium-browser: skia: chromium-browser…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:74084"/>
    <published>2026-09-30T00:00:00+00:00</published>
  </entry>
</feed>
