<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from osv_almalinux</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 07:10:23 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:74370 — Important: gvfs security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:74370</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: gvfs, AlmaLinux:9: gvfs-client, AlmaLinux:9: gvfs-devel, AlmaLinux:9: gvfs-fuse, AlmaLinux:9: gvfs-goa, AlmaLinux:9: gvfs-gphoto2, AlmaLinux:9: gvfs-mtp, AlmaLinux:9: gvfs-smb&lt;/p&gt;
&lt;p&gt;GVFS is the GNOME Desktop Virtual File System layer that allows users to easily access local and remote data using File Transfer Protocol (FTP), Secure Shell File Transfer Protocol (SFTP), Web Distributed Authoring and Versioning (WebDAV), Common Internet File System (CIFS), Server Message Block (SMB), and other protocols. GVFS integrates with the GNOME I/O (GIO) abstraction layer.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* gvfs: SFTP: heap-based buffer overflow in read_reply() (CVE-2026-84268)
  * gvfs: gvfs-admin socket ownership race permits local root (CVE-2026-88924)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: gvfs, AlmaLinux:9: gvfs-client, AlmaLinux:9: gvfs-devel, AlmaLinux:9: gvfs-fuse, AlmaLinux:9: gvfs-goa, AlmaLinux:9: gvfs-gphoto2, AlmaLinux:9: gvfs-mtp, AlmaLinux:9: gvfs-smb&lt;/p&gt;
&lt;p&gt;GVFS is the GNOME Desktop Virtual File System layer that allows users to easily access local and remote data using File Transfer Protocol (FTP), Secure Shell File Transfer Protocol (SFTP), Web Distributed Authoring and Versioning (WebDAV), Common Internet File System (CIFS), Server Message Block (SMB), and other protocols. GVFS integrates with the GNOME I/O (GIO) abstraction layer.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* gvfs: SFTP: heap-based buffer overflow in read_reply() (CVE-2026-84268)
  * gvfs: gvfs-admin socket ownership race permits local root (CVE-2026-88924)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:74370</guid>
      <pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>ALSA-2026:74442 — Important: libpcap security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:74442</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: libpcap, AlmaLinux:10: libpcap-devel&lt;/p&gt;
&lt;p&gt;The libpcap packages provide a portable framework for low-level network monitoring. The libpcap library provides network statistics collection, security monitoring, and network debugging.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libpcap: libpcap: Out-of-bounds read and write vulnerability allows arbitrary memory access (CVE-2026-0799)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: libpcap, AlmaLinux:10: libpcap-devel&lt;/p&gt;
&lt;p&gt;The libpcap packages provide a portable framework for low-level network monitoring. The libpcap library provides network statistics collection, security monitoring, and network debugging.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libpcap: libpcap: Out-of-bounds read and write vulnerability allows arbitrary memory access (CVE-2026-0799)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:74442</guid>
      <pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>ALSA-2026:73954 — Moderate: openssh security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:73954</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: openssh, AlmaLinux:10: openssh-askpass, AlmaLinux:10: openssh-clients, AlmaLinux:10: openssh-keycat, AlmaLinux:10: openssh-keysign, AlmaLinux:10: openssh-server&lt;/p&gt;
&lt;p&gt;OpenSSH is an SSH protocol implementation supported by a number of Linux, UNIX, and similar operating systems. It includes the core files necessary for both the OpenSSH client and server.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* openssh: OpenSSH: Brute-force attacks facilitated due to insufficient authentication delay (CVE-2026-60001)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: openssh, AlmaLinux:10: openssh-askpass, AlmaLinux:10: openssh-clients, AlmaLinux:10: openssh-keycat, AlmaLinux:10: openssh-keysign, AlmaLinux:10: openssh-server&lt;/p&gt;
&lt;p&gt;OpenSSH is an SSH protocol implementation supported by a number of Linux, UNIX, and similar operating systems. It includes the core files necessary for both the OpenSSH client and server.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* openssh: OpenSSH: Brute-force attacks facilitated due to insufficient authentication delay (CVE-2026-60001)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:73954</guid>
      <pubDate>Wed, 30 Sep 2026 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>ALSA-2026:73979 — Critical: freerdp security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:73979</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: freerdp, AlmaLinux:10: freerdp-devel, AlmaLinux:10: freerdp-libs, AlmaLinux:10: freerdp-server, AlmaLinux:10: libwinpr, AlmaLinux:10: libwinpr-devel&lt;/p&gt;
&lt;p&gt;FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. The xfreerdp client can connect to RDP servers such as Microsoft Windows machines, xrdp, and VirtualBox.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* freerdp: FreeRDP 3.0.0 through 3.30.0 Protocol Negotiation Bypass (CVE-2026-91949)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: freerdp, AlmaLinux:10: freerdp-devel, AlmaLinux:10: freerdp-libs, AlmaLinux:10: freerdp-server, AlmaLinux:10: libwinpr, AlmaLinux:10: libwinpr-devel&lt;/p&gt;
&lt;p&gt;FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. The xfreerdp client can connect to RDP servers such as Microsoft Windows machines, xrdp, and VirtualBox.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* freerdp: FreeRDP 3.0.0 through 3.30.0 Protocol Negotiation Bypass (CVE-2026-91949)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:73979</guid>
      <pubDate>Wed, 30 Sep 2026 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>ALSA-2026:73765 — Important: dogtag-pki security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:73765</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: idm-pki-acme, AlmaLinux:10: idm-pki-base, AlmaLinux:10: idm-pki-ca, AlmaLinux:10: idm-pki-java, AlmaLinux:10: idm-pki-kra, AlmaLinux:10: idm-pki-server, AlmaLinux:10: idm-pki-tools, AlmaLinux:10: python3-idm-pki&lt;/p&gt;
&lt;p&gt;IdM PKI is an enterprise software system designed to manage enterprise Public Key Infrastructure deployments. IdM PKI consists of the following components:&lt;/p&gt;
&lt;p&gt;* Certificate Authority (CA)
  * Key Recovery Authority (KRA)
  * Online Certificate Status Protocol (OCSP) Manager
  * Token Key Service (TKS)
  * Token Processing Service (TPS)
  * Automatic Certificate Management Environment (ACME) Responder
  * Enrollment over Secure Transport (EST) Responder&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* pki-core: Dogtag/PKI: certprofile-import allows code execution via unsanitized profile content (ExternalProcessConstraint) (CVE-2026-76561)
  * pki-core: Dogtag PKI v2 REST ACL filter&amp;#39;s reverse-lexicographic tie-break lets a CA Agent invoke the admin-only raw profile creation endpoint (CVE-2026-80110)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: idm-pki-acme, AlmaLinux:10: idm-pki-base, AlmaLinux:10: idm-pki-ca, AlmaLinux:10: idm-pki-java, AlmaLinux:10: idm-pki-kra, AlmaLinux:10: idm-pki-server, AlmaLinux:10: idm-pki-tools, AlmaLinux:10: python3-idm-pki&lt;/p&gt;
&lt;p&gt;IdM PKI is an enterprise software system designed to manage enterprise Public Key Infrastructure deployments. IdM PKI consists of the following components:&lt;/p&gt;
&lt;p&gt;* Certificate Authority (CA)
  * Key Recovery Authority (KRA)
  * Online Certificate Status Protocol (OCSP) Manager
  * Token Key Service (TKS)
  * Token Processing Service (TPS)
  * Automatic Certificate Management Environment (ACME) Responder
  * Enrollment over Secure Transport (EST) Responder&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* pki-core: Dogtag/PKI: certprofile-import allows code execution via unsanitized profile content (ExternalProcessConstraint) (CVE-2026-76561)
  * pki-core: Dogtag PKI v2 REST ACL filter&amp;#39;s reverse-lexicographic tie-break lets a CA Agent invoke the admin-only raw profile creation endpoint (CVE-2026-80110)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:73765</guid>
      <pubDate>Wed, 30 Sep 2026 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>ALSA-2026:73766 — Important: pki-core security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:73766</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: idm-pki-acme, AlmaLinux:9: idm-pki-base, AlmaLinux:9: idm-pki-ca, AlmaLinux:9: idm-pki-java, AlmaLinux:9: idm-pki-kra, AlmaLinux:9: idm-pki-server, AlmaLinux:9: idm-pki-tools, AlmaLinux:9: python3-idm-pki&lt;/p&gt;
&lt;p&gt;The Public Key Infrastructure (PKI) Core contains fundamental packages required by AlmaLinux Certificate System.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* pki-core: Dogtag/PKI: certprofile-import allows code execution via unsanitized profile content (ExternalProcessConstraint) (CVE-2026-76561)
  * pki-core: Dogtag PKI v2 REST ACL filter&amp;#39;s reverse-lexicographic tie-break lets a CA Agent invoke the admin-only raw profile creation endpoint (CVE-2026-80110)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: idm-pki-acme, AlmaLinux:9: idm-pki-base, AlmaLinux:9: idm-pki-ca, AlmaLinux:9: idm-pki-java, AlmaLinux:9: idm-pki-kra, AlmaLinux:9: idm-pki-server, AlmaLinux:9: idm-pki-tools, AlmaLinux:9: python3-idm-pki&lt;/p&gt;
&lt;p&gt;The Public Key Infrastructure (PKI) Core contains fundamental packages required by AlmaLinux Certificate System.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* pki-core: Dogtag/PKI: certprofile-import allows code execution via unsanitized profile content (ExternalProcessConstraint) (CVE-2026-76561)
  * pki-core: Dogtag PKI v2 REST ACL filter&amp;#39;s reverse-lexicographic tie-break lets a CA Agent invoke the admin-only raw profile creation endpoint (CVE-2026-80110)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:73766</guid>
      <pubDate>Wed, 30 Sep 2026 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>ALSA-2026:72623 — Important: kernel security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:72623</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core, AlmaLinux:9: kernel-64k-debug-modules-extra and 64 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: ext4: fix e4b bitmap inconsistency reports (CVE-2026-45942)
  * kernel: RDMA/rxe: Fix iova-to-va conversion for MR page sizes != PAGE_SIZE (CVE-2026-46325)
  * kernel: crypto: af_alg - Cap AEAD AD length to 0x80000000 (CVE-2026-52972)
  * kernel: fhandle: fix UAF due to unlocked -&amp;gt;mnt_ns read in may_decode_fh() (CVE-2026-53341)
  * kernel: arm64: tlb: Flush walk cache when unsharing PMD tables (CVE-2026-63875)
  * kernel: RDMA/siw: Reject MPA FPDU length underflow before signed receive math (CVE-2026-64102)
  * kernel: perf/core: Detach event groups during remove_on_exec (CVE-2026-64556)
  * kernel: crypto: tegra - fix rctx-&amp;gt;cryptlen calculation in tegra_gcm_do_one_req() (CVE-2026-80522)
  * kernel: perf: Reject exited events as group leaders (CVE-2026-74753)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* KVM: s390: Limit adapter indicator access to mapped page [almalinux-9.8.z] (JIRA:AlmaLinux-188656)
  * crypto: xxhash64 should not be fips approved [almalinux-9.8.z] (JIRA:AlmaLinux-256437)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core, AlmaLinux:9: kernel-64k-debug-modules-extra and 64 more&lt;/p&gt;
&lt;p&gt;The kernel packages contain the Linux kernel, the core of any Linux operating system.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* kernel: ext4: fix e4b bitmap inconsistency reports (CVE-2026-45942)
  * kernel: RDMA/rxe: Fix iova-to-va conversion for MR page sizes != PAGE_SIZE (CVE-2026-46325)
  * kernel: crypto: af_alg - Cap AEAD AD length to 0x80000000 (CVE-2026-52972)
  * kernel: fhandle: fix UAF due to unlocked -&amp;gt;mnt_ns read in may_decode_fh() (CVE-2026-53341)
  * kernel: arm64: tlb: Flush walk cache when unsharing PMD tables (CVE-2026-63875)
  * kernel: RDMA/siw: Reject MPA FPDU length underflow before signed receive math (CVE-2026-64102)
  * kernel: perf/core: Detach event groups during remove_on_exec (CVE-2026-64556)
  * kernel: crypto: tegra - fix rctx-&amp;gt;cryptlen calculation in tegra_gcm_do_one_req() (CVE-2026-80522)
  * kernel: perf: Reject exited events as group leaders (CVE-2026-74753)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* KVM: s390: Limit adapter indicator access to mapped page [almalinux-9.8.z] (JIRA:AlmaLinux-188656)
  * crypto: xxhash64 should not be fips approved [almalinux-9.8.z] (JIRA:AlmaLinux-256437)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:72623</guid>
      <pubDate>Mon, 28 Sep 2026 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>ALSA-2026:73998 — Important: gvfs security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:73998</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: gvfs, AlmaLinux:10: gvfs-client, AlmaLinux:10: gvfs-fuse, AlmaLinux:10: gvfs-goa, AlmaLinux:10: gvfs-gphoto2, AlmaLinux:10: gvfs-mtp, AlmaLinux:10: gvfs-smb&lt;/p&gt;
&lt;p&gt;GVFS is the GNOME Desktop Virtual File System layer that allows users to easily access local and remote data using File Transfer Protocol (FTP), Secure Shell File Transfer Protocol (SFTP), Web Distributed Authoring and Versioning (WebDAV), Common Internet File System (CIFS), Server Message Block (SMB), and other protocols. GVFS integrates with the GNOME I/O (GIO) abstraction layer.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* gvfs: SFTP: heap-based buffer overflow in read_reply() (CVE-2026-84268)
  * gvfs: gvfs-admin socket ownership race permits local root (CVE-2026-88924)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: gvfs, AlmaLinux:10: gvfs-client, AlmaLinux:10: gvfs-fuse, AlmaLinux:10: gvfs-goa, AlmaLinux:10: gvfs-gphoto2, AlmaLinux:10: gvfs-mtp, AlmaLinux:10: gvfs-smb&lt;/p&gt;
&lt;p&gt;GVFS is the GNOME Desktop Virtual File System layer that allows users to easily access local and remote data using File Transfer Protocol (FTP), Secure Shell File Transfer Protocol (SFTP), Web Distributed Authoring and Versioning (WebDAV), Common Internet File System (CIFS), Server Message Block (SMB), and other protocols. GVFS integrates with the GNOME I/O (GIO) abstraction layer.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* gvfs: SFTP: heap-based buffer overflow in read_reply() (CVE-2026-84268)
  * gvfs: gvfs-admin socket ownership race permits local root (CVE-2026-88924)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:73998</guid>
      <pubDate>Wed, 30 Sep 2026 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>ALSA-2026:74084 — Critical: webkit2gtk3 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:74084</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: webkit2gtk3, AlmaLinux:8: webkit2gtk3-devel, AlmaLinux:8: webkit2gtk3-jsc, AlmaLinux:8: webkit2gtk3-jsc-devel&lt;/p&gt;
&lt;p&gt;WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* chromium-browser: skia: chromium-browser: skia: Inappropriate implementation in Skia (CVE-2023-4860)
  * chromium-browser: angle: Out of bounds memory access in ANGLE (CVE-2024-7532)
  * chromium-browser: skia: chromium-browser: skia: Out of bounds memory access in Skia in Google Chrome allows a remote attacker who had compromised the renderer process to perform out of bounds memory access via a crafted HTML page (CVE-2024-7966)
  * chromium: skia: chromium: skia: Heap buffer overflow in Skia (CVE-2024-8193)
  * chromium: skia: chromium: skia: Heap buffer overflow in Skia (CVE-2024-8198)
  * chromium: skia: chromium: skia: Heap buffer overflow in Skia (CVE-2024-8636)
  * chromium-browser: skia: chromium-browser: skia: Integer overflow in Skia in Google Chrome (CVE-2024-9123)
  * chromium-browser: skia: chromium-browser: skia: Integer overflow in Skia (CVE-2025-0436)
  * chromium-browser: skia: chromium-browser: skia: Use after free in Skia (CVE-2025-0444)
  * chromium-browser: angle: ANGLE Out-of-Bounds Write Vulnerability (CVE-2025-8901)
  * chromium-browser: angle: Use after free in ANGLE (CVE-2025-9478)
  * chromium-browser: angle: Heap buffer overflow in ANGLE (CVE-2025-10502)
  * chromium-browser: angle: Use after free in ANGLE (CVE-2026-0908)
  * chromium-browser: angle: Integer overflow in ANGLE (CVE-2026-3536)
  * chromium-browser: skia: chromium-browser…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: webkit2gtk3, AlmaLinux:8: webkit2gtk3-devel, AlmaLinux:8: webkit2gtk3-jsc, AlmaLinux:8: webkit2gtk3-jsc-devel&lt;/p&gt;
&lt;p&gt;WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* chromium-browser: skia: chromium-browser: skia: Inappropriate implementation in Skia (CVE-2023-4860)
  * chromium-browser: angle: Out of bounds memory access in ANGLE (CVE-2024-7532)
  * chromium-browser: skia: chromium-browser: skia: Out of bounds memory access in Skia in Google Chrome allows a remote attacker who had compromised the renderer process to perform out of bounds memory access via a crafted HTML page (CVE-2024-7966)
  * chromium: skia: chromium: skia: Heap buffer overflow in Skia (CVE-2024-8193)
  * chromium: skia: chromium: skia: Heap buffer overflow in Skia (CVE-2024-8198)
  * chromium: skia: chromium: skia: Heap buffer overflow in Skia (CVE-2024-8636)
  * chromium-browser: skia: chromium-browser: skia: Integer overflow in Skia in Google Chrome (CVE-2024-9123)
  * chromium-browser: skia: chromium-browser: skia: Integer overflow in Skia (CVE-2025-0436)
  * chromium-browser: skia: chromium-browser: skia: Use after free in Skia (CVE-2025-0444)
  * chromium-browser: angle: ANGLE Out-of-Bounds Write Vulnerability (CVE-2025-8901)
  * chromium-browser: angle: Use after free in ANGLE (CVE-2025-9478)
  * chromium-browser: angle: Heap buffer overflow in ANGLE (CVE-2025-10502)
  * chromium-browser: angle: Use after free in ANGLE (CVE-2026-0908)
  * chromium-browser: angle: Integer overflow in ANGLE (CVE-2026-3536)
  * chromium-browser: skia: chromium-browser…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:74084</guid>
      <pubDate>Wed, 30 Sep 2026 00:00:00 +0000</pubDate>
    </item>
    <item>
      <title>ALSA-2026:74095 — Important: rsync security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:74095</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: rsync, AlmaLinux:8: rsync-daemon&lt;/p&gt;
&lt;p&gt;The rsync utility enables the users to copy and synchronize files locally or across a network. Synchronization with rsync is fast because rsync only sends the differences in files over the network instead of sending whole files. The rsync utility is also used as a mirroring tool.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* rsync: rsync 2.3.3 &amp;lt; 3.5.0 Path Traversal via --partial-dir/--backup-dir Symlink (CVE-2026-70460)
  * rsync: rsync: Arbitrary file deletion via malicious file list (CVE-2026-53789)
  * rsync: rsync &amp;lt; 3.5.0 Command Injection via Multiple Code Paths (CVE-2026-53790)
  * rsync: rsync: Memory corruption via crafted file entries (CVE-2026-70458)
  * rsync: rsync: Denial of Service via handshake stall (CVE-2026-70464)
  * rsync: rsync: Local Privilege Escalation via Symlink Following (CVE-2026-53803)
  * rsync: rsync: Unauthorized File Access via Symlink Module Root (CVE-2026-53784)
  * rsync: rsync: Authorization bypass via `auth users` directive parsing (CVE-2026-70463)
  * rsync: rsync 3.1.0 &amp;lt; 3.5.0 Access Control Bypass via DNS Resolution Failure (CVE-2026-70452)
  * rsync: rsync: Arbitrary file write via --temp-dir or --link-dest options (CVE-2026-53795)
  * rsync: rsync: Heap Out-of-Bounds Write via crafted argument list (CVE-2026-70456)
  * rsync: rsync &amp;lt; 3.5.0 Path Confinement Bypass via /./ Boundary Marker in Chroot Mode (CVE-2026-53793)
  * rsync: rsync: Denial of Service via Algorithmic Complexity (CVE-2026-70453)
  * rsync: rsync: Information disclosure and denial o…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: rsync, AlmaLinux:8: rsync-daemon&lt;/p&gt;
&lt;p&gt;The rsync utility enables the users to copy and synchronize files locally or across a network. Synchronization with rsync is fast because rsync only sends the differences in files over the network instead of sending whole files. The rsync utility is also used as a mirroring tool.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* rsync: rsync 2.3.3 &amp;lt; 3.5.0 Path Traversal via --partial-dir/--backup-dir Symlink (CVE-2026-70460)
  * rsync: rsync: Arbitrary file deletion via malicious file list (CVE-2026-53789)
  * rsync: rsync &amp;lt; 3.5.0 Command Injection via Multiple Code Paths (CVE-2026-53790)
  * rsync: rsync: Memory corruption via crafted file entries (CVE-2026-70458)
  * rsync: rsync: Denial of Service via handshake stall (CVE-2026-70464)
  * rsync: rsync: Local Privilege Escalation via Symlink Following (CVE-2026-53803)
  * rsync: rsync: Unauthorized File Access via Symlink Module Root (CVE-2026-53784)
  * rsync: rsync: Authorization bypass via `auth users` directive parsing (CVE-2026-70463)
  * rsync: rsync 3.1.0 &amp;lt; 3.5.0 Access Control Bypass via DNS Resolution Failure (CVE-2026-70452)
  * rsync: rsync: Arbitrary file write via --temp-dir or --link-dest options (CVE-2026-53795)
  * rsync: rsync: Heap Out-of-Bounds Write via crafted argument list (CVE-2026-70456)
  * rsync: rsync &amp;lt; 3.5.0 Path Confinement Bypass via /./ Boundary Marker in Chroot Mode (CVE-2026-53793)
  * rsync: rsync: Denial of Service via Algorithmic Complexity (CVE-2026-70453)
  * rsync: rsync: Information disclosure and denial o…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:74095</guid>
      <pubDate>Wed, 30 Sep 2026 00:00:00 +0000</pubDate>
    </item>
  </channel>
</rss>
