⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Drafts

Create draft to convert the suggestion into a draft security issue that can be edited before publishing.

Dismiss to remove a suggestion from the queue.

CVE-2025-31827
4.9 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): HIGH
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): NONE
  • Availability impact (A): NONE
updated 3 days, 13 hours ago by @Erethon Activity log
  • Created automatic suggestion
  • @LeSuisse dismissed
  • @Erethon accepted as draft
WordPress Fonto plugin <= 1.2.2 - Arbitrary File Download vulnerability

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in vlad.olaru Fonto allows Path Traversal. This issue affects Fonto: from n/a through 1.2.2.

fonto
=<1.2.2

pkgs.texlivePackages.fontools

Tools to simplify using fonts (especially TT/OTF ones)

pkgs.texlivePackages.fontools.x86_64-linux

Tools to simplify using fonts (especially TT/OTF ones)
CVE-2025-31384
7.1 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): REQUIRED
  • Scope (S): CHANGED
  • Confidentiality impact (C): LOW
  • Integrity impact (I): LOW
  • Availability impact (A): LOW
updated 3 days, 13 hours ago by @Erethon Activity log
  • Created automatic suggestion
  • @LeSuisse dismissed
  • @Erethon accepted as draft
WordPress Videos plugin <= 1.0.5 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Aviplugins Videos allows Reflected XSS.This issue affects Videos: from n/a through 1.0.5.

videos
=<1.0.5

pkgs.pantheon.elementary-videos.x86_64-linux

Video player and library app designed for elementary OS

pkgs.pantheon.elementary-videos.aarch64-linux

Video player and library app designed for elementary OS
Notify package maintainers: 2
CVE-2024-2947
7.3 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): LOCAL
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): REQUIRED
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): HIGH
updated 3 days, 13 hours ago by @Erethon Activity log
  • Created automatic suggestion
  • @fricklerhandwerk removed
    7 packages
    • pkgs.texlivePackages.tlcockpit 1.2
    • pkgs.texlivePackages.tlcockpit 1.2
    • pkgs.texlivePackages.tlcockpit 1.2
    • pkgs.texlivePackages.tlcockpit 1.2
    • pkgs.texlivePackages.tlcockpit 1.2
    • pkgs.texlivePackages.tlcockpit 1.2
    • pkgs.texlivePackages.tlcockpit 1.2
  • @Erethon removed
    210 packages
    • pkgs.cockpit 338
    • pkgs.cockpit 338
    • pkgs.cockpit 331
    • pkgs.cockpit 338
    • pkgs.cockpit 338
    • pkgs.cockpit 331
    • pkgs.cockpit 331
    • pkgs.cockpit 338
    • pkgs.cockpit 338
    • pkgs.cockpit 340
    • pkgs.cockpit 340
    • pkgs.cockpit 329.1
    • pkgs.cockpit 329.1
    • pkgs.cockpit 338
    • pkgs.cockpit 338
    • pkgs.cockpit 338
    • pkgs.cockpit 338
    • pkgs.cockpit 329.1
    • pkgs.cockpit 329.1
    • pkgs.cockpit 331
    • pkgs.cockpit 338
    • pkgs.cockpit 338
    • pkgs.cockpit 329.1
    • pkgs.cockpit 329.1
    • pkgs.cockpit 331
    • pkgs.cockpit 331
    • pkgs.cockpit 331
    • pkgs.cockpit 331
    • pkgs.cockpit 331
    • pkgs.cockpit 329.1
    • pkgs.cockpit 329.1
    • pkgs.cockpit 316
    • pkgs.cockpit 338
    • pkgs.cockpit 338
    • pkgs.cockpit 331
    • pkgs.cockpit 331
    • pkgs.cockpit 338
    • pkgs.cockpit 338
    • pkgs.cockpit 340
    • pkgs.cockpit 340
    • pkgs.cockpit 338
    • pkgs.cockpit 338
    • pkgs.cockpit 338
    • pkgs.cockpit 338
    • pkgs.cockpit 338
    • pkgs.cockpit 338
    • pkgs.cockpit 328
    • pkgs.cockpit 328
    • pkgs.cockpit 338
    • pkgs.cockpit 338
    • pkgs.cockpit 316
    • pkgs.cockpit 338
    • pkgs.cockpit 338
    • pkgs.cockpit 331
    • pkgs.cockpit 331
    • pkgs.cockpit 328
    • pkgs.cockpit 328
    • pkgs.cockpit 331
    • pkgs.cockpit 331
    • pkgs.cockpit 340
    • pkgs.cockpit 340
    • pkgs.cockpit 338
    • pkgs.cockpit 338
    • pkgs.cockpit 331
    • pkgs.cockpit 331
    • pkgs.cockpit 338
    • pkgs.cockpit 338
    • pkgs.cockpit 338
    • pkgs.cockpit 338
    • pkgs.cockpit 338
    • pkgs.cockpit 338
    • pkgs.cockpit 338
    • pkgs.cockpit 328
    • pkgs.cockpit 328
    • pkgs.cockpit 338
    • pkgs.cockpit 338
    • pkgs.cockpit 338
    • pkgs.cockpit 338
    • pkgs.cockpit 338
    • pkgs.cockpit 338
    • pkgs.cockpit 338
    • pkgs.cockpit 329.1
    • pkgs.cockpit 329.1
    • pkgs.cockpit 331
    • pkgs.cockpit 331
    • pkgs.cockpit 338
    • pkgs.cockpit 338
    • pkgs.cockpit 338
    • pkgs.cockpit 338
    • pkgs.cockpit 338
    • pkgs.cockpit 338
    • pkgs.cockpit 316
    • pkgs.cockpit 338
    • pkgs.cockpit 338
    • pkgs.cockpit 340
    • pkgs.cockpit 340
    • pkgs.cockpit 331
    • pkgs.cockpit 331
    • pkgs.cockpit 338
    • pkgs.cockpit 338
    • pkgs.cockpit 328
    • pkgs.cockpit 328
    • pkgs.cockpit 338
    • pkgs.cockpit 338
    • pkgs.cockpit 316
    • pkgs.cockpit 316
    • pkgs.cockpit 338
    • pkgs.cockpit 338
    • pkgs.cockpit 340
    • pkgs.cockpit 340
    • pkgs.cockpit 331
    • pkgs.cockpit 331
    • pkgs.cockpit 338
    • pkgs.cockpit 338
    • pkgs.cockpit 338
    • pkgs.cockpit 338
    • pkgs.cockpit 338
    • pkgs.cockpit 338
    • pkgs.cockpit 338
    • pkgs.cockpit 338
    • pkgs.cockpit 338
    • pkgs.cockpit 338
    • pkgs.cockpit 331
    • pkgs.cockpit 331
    • pkgs.cockpit 331
    • pkgs.cockpit 331
    • pkgs.cockpit 331
    • pkgs.cockpit 338
    • pkgs.cockpit 338
    • pkgs.cockpit 331
    • pkgs.cockpit 331
    • pkgs.cockpit 316
    • pkgs.cockpit 316
    • pkgs.cockpit 329.1
    • pkgs.cockpit 329.1
    • pkgs.cockpit 316
    • pkgs.cockpit 328
    • pkgs.cockpit 316
    • pkgs.cockpit 329.1
    • pkgs.cockpit 329.1
    • pkgs.cockpit 328
    • pkgs.emacsPackages.test-cockpit 20240604.1943
    • pkgs.emacsPackages.test-cockpit 20240604.1943
    • pkgs.emacsPackages.test-cockpit 20240604.1943
    • pkgs.emacsPackages.test-cockpit 20240604.1943
    • pkgs.emacsPackages.test-cockpit 20240604.1943
    • pkgs.emacsPackages.test-cockpit 20240604.1943
    • pkgs.emacsPackages.test-cockpit 20240604.1943
    • pkgs.emacsPackages.test-cockpit 20240604.1943
    • pkgs.emacsPackages.test-cockpit 20240604.1943
    • pkgs.emacsPackages.test-cockpit 20240604.1943
    • pkgs.emacsPackages.test-cockpit 20240604.1943
    • pkgs.emacsPackages.test-cockpit 20240604.1943
    • pkgs.emacsPackages.test-cockpit 20240604.1943
    • pkgs.emacsPackages.test-cockpit 20240604.1943
    • pkgs.emacsPackages.test-cockpit 20240604.1943
    • pkgs.emacsPackages.test-cockpit 20240604.1943
    • pkgs.emacsPackages.test-cockpit 20240220.2058
    • pkgs.emacsPackages.test-cockpit 20240220.2058
    • pkgs.emacsPackages.test-cockpit 20240220.2058
    • pkgs.emacsPackages.test-cockpit 20240220.2058
    • pkgs.emacsPackages.test-cockpit 20240604.1943
    • pkgs.emacsPackages.test-cockpit 20240604.1943
    • pkgs.emacsPackages.test-cockpit 20240604.1943
    • pkgs.emacsPackages.test-cockpit 20240604.1943
    • pkgs.emacsPackages.test-cockpit 20240604.1943
    • pkgs.emacsPackages.test-cockpit 20240604.1943
    • pkgs.emacsPackages.test-cockpit 20240604.1943
    • pkgs.emacsPackages.test-cockpit 20240604.1943
    • pkgs.emacsPackages.test-cockpit 20240604.1943
    • pkgs.emacsPackages.test-cockpit 20240604.1943
    • pkgs.emacsPackages.test-cockpit 20240604.1943
    • pkgs.emacsPackages.test-cockpit 20240604.1943
    • pkgs.emacsPackages.test-cockpit 20240220.2058
    • pkgs.emacsPackages.test-cockpit 20240220.2058
    • pkgs.emacsPackages.test-cockpit 20240220.2058
    • pkgs.emacsPackages.test-cockpit 20240220.2058
    • pkgs.emacsPackages.test-cockpit 20240220.2058
    • pkgs.emacsPackages.test-cockpit 20240220.2058
    • pkgs.emacsPackages.test-cockpit 20240220.2058
    • pkgs.emacsPackages.test-cockpit 20240220.2058
    • pkgs.emacsPackages.test-cockpit 20240220.2058
    • pkgs.emacsPackages.test-cockpit 20240220.2058
    • pkgs.emacsPackages.test-cockpit 20240220.2058
    • pkgs.emacsPackages.test-cockpit 20240220.2058
    • pkgs.emacsPackages.test-cockpit 20240604.1943
    • pkgs.emacsPackages.test-cockpit 20240604.1943
    • pkgs.emacsPackages.test-cockpit 20240604.1943
    • pkgs.emacsPackages.test-cockpit 20240604.1943
    • pkgs.emacsPackages.test-cockpit 20240604.1943
    • pkgs.emacsPackages.test-cockpit 20240604.1943
    • pkgs.emacsPackages.test-cockpit 20240220.2058
    • pkgs.emacsPackages.test-cockpit 20240604.1943
    • pkgs.emacsPackages.test-cockpit 20240220.2058
    • pkgs.emacsPackages.test-cockpit 20240220.2058
    • pkgs.emacsPackages.test-cockpit 20240220.2058
    • pkgs.emacsPackages.test-cockpit 20240604.1943
    • pkgs.emacsPackages.test-cockpit 20240604.1943
    • pkgs.emacsPackages.test-cockpit 20240604.1943
    • pkgs.emacsPackages.test-cockpit 20240220.2058
    • pkgs.emacsPackages.test-cockpit 20240220.2058
    • pkgs.emacsPackages.test-cockpit 20240220.2058
    • pkgs.emacsPackages.test-cockpit 20240220.2058
    • pkgs.emacsPackages.test-cockpit 20240604.1943
    • pkgs.emacsPackages.test-cockpit 20240604.1943
    • pkgs.emacsPackages.test-cockpit 20240220.2058
    • pkgs.emacsPackages.test-cockpit 20240604.1943
    • pkgs.emacsPackages.test-cockpit 20240220.2058
    • pkgs.emacsPackages.test-cockpit 20240220.2058
    • pkgs.emacsPackages.test-cockpit 20240220.2058
  • @Erethon dismissed
  • @Erethon accepted as draft
Cockpit: command injection when deleting a sosreport with a crafted name

A flaw was found in Cockpit. Deleting a sosreport with a crafted name via the Cockpit web interface can lead to a command injection vulnerability, resulting in privilege escalation. This issue affects Cockpit versions 270 and newer.

cockpit
*
*
Notify package maintainers: 1
CVE-2024-11738
5.3 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): NONE
  • Integrity impact (I): NONE
  • Availability impact (A): LOW
updated 3 days, 13 hours ago by @Erethon Activity log
  • Created automatic suggestion
  • @Erethon dismissed
  • @Erethon accepted as draft
Rustls: rustls network-reachable panic in `acceptor::accept`

A flaw was found in Rustls 0.23.13 and related APIs. This vulnerability allows denial of service (panic) via a fragmented TLS ClientHello message.

rustls
<0.23.18
rhtas/tuffer-rhel9
rhtas/tuftool-rhel9

pkgs.rustls-ffi.x86_64-linux

C-to-rustls bindings

pkgs.rustls-ffi.aarch64-linux

C-to-rustls bindings

pkgs.rustls-ffi.x86_64-darwin

C-to-rustls bindings

pkgs.rustls-ffi.aarch64-darwin

C-to-rustls bindings
Notify package maintainers: 1
CVE-2025-1399
3.1 LOW
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): HIGH
  • Privileges required (PR): NONE
  • User interaction (UI): REQUIRED
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): LOW
  • Integrity impact (I): NONE
  • Availability impact (A): NONE
updated 1 month, 2 weeks ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse accepted as draft
Out-of-bounds Read in libplctag library

Out-of-bounds Read vulnerability in unpack_response (session.c) in libplctag from 2.0 through 2.6.3 allows Overread Buffers via network.

libplctag
=<2.6.3

pkgs.libplctag

Library that uses EtherNet/IP or Modbus TCP to read and write tags in PLCs

pkgs.libplctag.x86_64-linux

Library that uses EtherNet/IP or Modbus TCP to read and write tags in PLCs

pkgs.libplctag.aarch64-linux

Library that uses EtherNet/IP or Modbus TCP to read and write tags in PLCs

pkgs.libplctag.x86_64-darwin

Library that uses EtherNet/IP or Modbus TCP to read and write tags in PLCs

pkgs.libplctag.aarch64-darwin

Library that uses EtherNet/IP or Modbus TCP to read and write tags in PLCs
Notify package maintainers: 1
CVE-2025-31162
6.6 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): LOCAL
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): LOW
  • Integrity impact (I): LOW
  • Availability impact (A): HIGH
updated 1 week ago by @fricklerhandwerk Activity log
  • Created automatic suggestion
  • @LeSuisse accepted as draft
  • @mweinelt dismissed
  • @mweinelt accepted as draft
  • @fricklerhandwerk removed
    10 packages
    • pkgs.fig2dev 3.2.9
    • pkgs.fig2dev 3.2.9
    • pkgs.fig2dev 3.2.9
    • pkgs.fig2dev 3.2.9
    • pkgs.fig2dev 3.2.9
    • pkgs.fig2dev 3.2.9
    • pkgs.fig2dev 3.2.9
    • pkgs.fig2dev 3.2.9
    • pkgs.fig2dev 3.2.9
    • pkgs.fig2dev 3.2.9
fig2dev float point exception

Floating point exception in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via get_slope function.

fig2dev
==3.2.9a

pkgs.fig2dev.x86_64-linux

Tool to convert Xfig files to other formats

pkgs.fig2dev.aarch64-darwin

Tool to convert Xfig files to other formats
Notify package maintainers: 1
CVE-2025-30673
6.5 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): LOW
  • Integrity impact (I): LOW
  • Availability impact (A): NONE
updated 2 months, 3 weeks ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse accepted as draft
Sub::HandlesVia for Perl allows untrusted code to be included from the current working directory

Sub::HandlesVia for Perl before 0.050002 allows untrusted code from the current working directory ('.') to be loaded similar to CVE-2016-1238. If an attacker can place a malicious file in current working directory, it may be loaded instead of the intended file, potentially leading to arbitrary code execution. Sub::HandlesVia uses Mite to produce the affected code section due to CVE-2025-30672

Sub-HandlesVia
<0.050002

pkgs.perl536Packages.SubHandlesVia

Alternative handles_via implementation

pkgs.perl536Packages.SubHandlesVia.x86_64-linux

Alternative handles_via implementation

pkgs.perl536Packages.SubHandlesVia.aarch64-linux

Alternative handles_via implementation

pkgs.perl536Packages.SubHandlesVia.x86_64-darwin

Alternative handles_via implementation

pkgs.perl536Packages.SubHandlesVia.aarch64-darwin

Alternative handles_via implementation
CVE-2025-1828
8.8 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): REQUIRED
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): HIGH
updated 3 months, 2 weeks ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse accepted as draft
Perl's Crypt::Random module after 1.05 and before 1.56 may use rand() function for cryptographic functions

Crypt::Random Perl package 1.05 through 1.55 may use rand() function, which is not cryptographically strong, for cryptographic functions. Crypt::Random::rand 1.05 through 1.55 uses the rand() function. If the Provider is not specified and /dev/urandom or an Entropy Gathering Daemon (egd) service is not available Crypt::Random will default to use the insecure Crypt::Random::rand provider. In particular, Windows versions of perl will encounter this issue by default.

Crypt-Random
<1.56

pkgs.perl536Packages.CryptRandom

Interface to /dev/random and /dev/urandom

pkgs.perl538Packages.CryptRandom

Interface to /dev/random and /dev/urandom

pkgs.perl540Packages.CryptRandom

Interface to /dev/random and /dev/urandom

pkgs.perl536Packages.CryptRandomSeed

Provide strong randomness for seeding

pkgs.perl538Packages.CryptRandomSeed

Provide strong randomness for seeding

pkgs.perl540Packages.CryptRandomSeed

Provide strong randomness for seeding

pkgs.perl536Packages.CryptRandomSource

Get weak or strong random data from pluggable sources

pkgs.perl536Packages.CryptRandomTESHA2

Random numbers using timer/schedule entropy, aka userspace voodoo entropy

pkgs.perl538Packages.CryptRandomSource

Get weak or strong random data from pluggable sources

pkgs.perl540Packages.CryptRandomSource

Get weak or strong random data from pluggable sources

pkgs.perl536Packages.CryptRandom.x86_64-linux

Interface to /dev/random and /dev/urandom

pkgs.perl538Packages.CryptRandom.x86_64-linux

Interface to /dev/random and /dev/urandom

pkgs.perl540Packages.CryptRandom.x86_64-linux

Interface to /dev/random and /dev/urandom

pkgs.perl536Packages.CryptRandom.aarch64-linux

Interface to /dev/random and /dev/urandom

pkgs.perl536Packages.CryptRandom.x86_64-darwin

Interface to /dev/random and /dev/urandom

pkgs.perl538Packages.CryptRandom.aarch64-linux

Interface to /dev/random and /dev/urandom

pkgs.perl538Packages.CryptRandom.x86_64-darwin

Interface to /dev/random and /dev/urandom

pkgs.perl540Packages.CryptRandom.aarch64-linux

Interface to /dev/random and /dev/urandom

pkgs.perl540Packages.CryptRandom.x86_64-darwin

Interface to /dev/random and /dev/urandom

pkgs.perl536Packages.CryptRandom.aarch64-darwin

Interface to /dev/random and /dev/urandom

pkgs.perl538Packages.CryptRandom.aarch64-darwin

Interface to /dev/random and /dev/urandom

pkgs.perl540Packages.CryptRandom.aarch64-darwin

Interface to /dev/random and /dev/urandom

pkgs.perl536Packages.CryptRandomSeed.x86_64-linux

Provide strong randomness for seeding

pkgs.perl538Packages.CryptRandomSeed.x86_64-linux

Provide strong randomness for seeding

pkgs.perl540Packages.CryptRandomSeed.x86_64-linux

Provide strong randomness for seeding

pkgs.perl536Packages.CryptRandomSeed.aarch64-linux

Provide strong randomness for seeding

pkgs.perl536Packages.CryptRandomSeed.x86_64-darwin

Provide strong randomness for seeding

pkgs.perl538Packages.CryptRandomSeed.aarch64-linux

Provide strong randomness for seeding

pkgs.perl538Packages.CryptRandomSeed.x86_64-darwin

Provide strong randomness for seeding

pkgs.perl540Packages.CryptRandomSeed.aarch64-linux

Provide strong randomness for seeding

pkgs.perl540Packages.CryptRandomSeed.x86_64-darwin

Provide strong randomness for seeding

pkgs.perl536Packages.CryptRandomSeed.aarch64-darwin

Provide strong randomness for seeding

pkgs.perl536Packages.CryptRandomSource.x86_64-linux

Get weak or strong random data from pluggable sources

pkgs.perl536Packages.CryptRandomTESHA2.x86_64-linux

Random numbers using timer/schedule entropy, aka userspace voodoo entropy

pkgs.perl538Packages.CryptRandomSeed.aarch64-darwin

Provide strong randomness for seeding

pkgs.perl538Packages.CryptRandomSource.x86_64-linux

Get weak or strong random data from pluggable sources

pkgs.perl540Packages.CryptRandomSeed.aarch64-darwin

Provide strong randomness for seeding

pkgs.perl540Packages.CryptRandomSource.x86_64-linux

Get weak or strong random data from pluggable sources

pkgs.perl536Packages.CryptRandomSource.aarch64-linux

Get weak or strong random data from pluggable sources

pkgs.perl536Packages.CryptRandomSource.x86_64-darwin

Get weak or strong random data from pluggable sources

pkgs.perl536Packages.CryptRandomTESHA2.aarch64-linux

Random numbers using timer/schedule entropy, aka userspace voodoo entropy

pkgs.perl536Packages.CryptRandomTESHA2.x86_64-darwin

Random numbers using timer/schedule entropy, aka userspace voodoo entropy

pkgs.perl538Packages.CryptRandomSource.aarch64-linux

Get weak or strong random data from pluggable sources

pkgs.perl538Packages.CryptRandomSource.x86_64-darwin

Get weak or strong random data from pluggable sources

pkgs.perl540Packages.CryptRandomSource.aarch64-linux

Get weak or strong random data from pluggable sources

pkgs.perl540Packages.CryptRandomSource.x86_64-darwin

Get weak or strong random data from pluggable sources

pkgs.perl536Packages.CryptRandomSource.aarch64-darwin

Get weak or strong random data from pluggable sources

pkgs.perl536Packages.CryptRandomTESHA2.aarch64-darwin

Random numbers using timer/schedule entropy, aka userspace voodoo entropy

pkgs.perl538Packages.CryptRandomSource.aarch64-darwin

Get weak or strong random data from pluggable sources

pkgs.perl540Packages.CryptRandomSource.aarch64-darwin

Get weak or strong random data from pluggable sources
Notify package maintainers: 1
CVE-2025-0750
6.6 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): LOCAL
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): LOW
  • Integrity impact (I): LOW
  • Availability impact (A): HIGH
updated 4 months, 3 weeks ago by @fricklerhandwerk Activity log
  • Created automatic suggestion
  • @fricklerhandwerk accepted as draft
Cri-o: cri-o path traversal in log handling functions allows arbitrary unmounting

A vulnerability was found in CRI-O. A path traversal issue in the log management functions (UnMountPodLogs and LinkContainerLogs) may allow an attacker with permissions to create and delete Pods to unmount arbitrary host paths, leading to node-level denial of service by unmounting critical system directories.

cri-o
*
<1.33.1
rhcos

pkgs.cri-o.x86_64-linux

Open Container Initiative-based implementation of the Kubernetes Container Runtime Interface

pkgs.cri-o.aarch64-linux

Open Container Initiative-based implementation of the Kubernetes Container Runtime Interface

pkgs.cri-o-unwrapped.x86_64-linux

Open Container Initiative-based implementation of the Kubernetes Container Runtime Interface

pkgs.cri-o-unwrapped.aarch64-linux

Open Container Initiative-based implementation of the Kubernetes Container Runtime Interface
Notify package maintainers: 2
CVE-2024-11218
8.6 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): LOCAL
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): REQUIRED
  • Scope (S): CHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): HIGH
updated 5 months ago by @fricklerhandwerk Activity log
  • Created automatic suggestion
  • @fricklerhandwerk removed
    370 packages
    • pkgs.buildah-unwrapped 1.38.0
    • pkgs.buildah-unwrapped 1.38.0
    • pkgs.buildah-unwrapped 1.38.0
    • pkgs.buildah-unwrapped 1.38.0
    • pkgs.buildah-unwrapped 1.38.0
    • pkgs.buildah-unwrapped 1.38.0
    • pkgs.buildah-unwrapped 1.38.0
    • pkgs.buildah-unwrapped 1.38.0
    • pkgs.buildah-unwrapped 1.38.0
    • pkgs.buildah-unwrapped 1.38.0
    • pkgs.buildah-unwrapped 1.38.0
    • pkgs.buildah-unwrapped 1.38.0
    • pkgs.buildah-unwrapped 1.38.0
    • pkgs.buildah-unwrapped 1.38.0
    • pkgs.buildah-unwrapped 1.38.0
    • pkgs.buildah-unwrapped 1.38.0
    • pkgs.buildah-unwrapped 1.35.4
    • pkgs.buildah-unwrapped 1.38.0
    • pkgs.buildah-unwrapped 1.38.0
    • pkgs.buildah-unwrapped 1.38.0
    • pkgs.buildah-unwrapped 1.38.0
    • pkgs.buildah-unwrapped 1.38.0
    • pkgs.buildah-unwrapped 1.38.0
    • pkgs.buildah-unwrapped 1.38.0
    • pkgs.buildah-unwrapped 1.38.0
    • pkgs.buildah-unwrapped 1.35.4
    • pkgs.buildah-unwrapped 1.35.4
    • pkgs.buildah-unwrapped 1.35.4
    • pkgs.buildah-unwrapped 1.35.4
    • pkgs.buildah-unwrapped 1.35.4
    • pkgs.buildah-unwrapped 1.35.4
    • pkgs.buildah-unwrapped 1.35.4
    • pkgs.buildah-unwrapped 1.35.4
    • pkgs.buildah-unwrapped 1.35.4
    • pkgs.buildah-unwrapped 1.35.4
    • pkgs.buildah-unwrapped 1.35.4
    • pkgs.buildah-unwrapped 1.38.0
    • pkgs.buildah-unwrapped 1.38.0
    • pkgs.buildah-unwrapped 1.38.0
    • pkgs.buildah-unwrapped 1.38.0
    • pkgs.buildah-unwrapped 1.38.0
    • pkgs.buildah-unwrapped 1.38.0
    • pkgs.buildah-unwrapped 1.38.0
    • pkgs.buildah-unwrapped 1.38.0
    • pkgs.buildah-unwrapped 1.35.4
    • pkgs.buildah-unwrapped 1.35.4
    • pkgs.buildah-unwrapped 1.35.4
    • pkgs.buildah-unwrapped 1.35.4
    • pkgs.buildah-unwrapped 1.38.0
    • pkgs.buildah-unwrapped 1.38.0
    • pkgs.buildah-unwrapped 1.38.0
    • pkgs.buildah-unwrapped 1.38.0
    • pkgs.buildah-unwrapped 1.38.0
    • pkgs.buildah-unwrapped 1.38.0
    • pkgs.buildah-unwrapped 1.38.0
    • pkgs.buildah-unwrapped 1.38.0
    • pkgs.buildah-unwrapped 1.35.4
    • pkgs.buildah-unwrapped 1.35.4
    • pkgs.buildah-unwrapped 1.35.4
    • pkgs.buildah-unwrapped 1.35.4
    • pkgs.buildah-unwrapped 1.35.4
    • pkgs.buildah-unwrapped 1.35.4
    • pkgs.buildah-unwrapped 1.35.4
    • pkgs.buildah-unwrapped 1.35.4
    • pkgs.buildah-unwrapped 1.38.0
    • pkgs.buildah-unwrapped 1.38.0
    • pkgs.buildah-unwrapped 1.38.0
    • pkgs.buildah-unwrapped 1.38.0
    • pkgs.buildah-unwrapped 1.35.4
    • pkgs.buildah-unwrapped 1.35.4
    • pkgs.buildah-unwrapped 1.35.4
    • pkgs.buildah-unwrapped 1.35.4
    • pkgs.buildah-unwrapped 1.35.4
    • pkgs.buildah-unwrapped 1.35.4
    • pkgs.buildah-unwrapped 1.35.4
    • pkgs.buildah-unwrapped 1.35.4
    • pkgs.buildah-unwrapped 1.38.0
    • pkgs.buildah-unwrapped 1.38.0
    • pkgs.buildah-unwrapped 1.38.0
    • pkgs.buildah-unwrapped 1.38.0
    • pkgs.buildah-unwrapped 1.35.4
    • pkgs.buildah-unwrapped 1.35.4
    • pkgs.buildah-unwrapped 1.35.4
    • pkgs.buildah-unwrapped 1.35.4
    • pkgs.python312Packages.podman 5.0.0
    • pkgs.python312Packages.podman 5.0.0
    • pkgs.python312Packages.podman 5.0.0
    • pkgs.python312Packages.podman 5.0.0
    • pkgs.python311Packages.podman 5.3.0
    • pkgs.python311Packages.podman 5.3.0
    • pkgs.python311Packages.podman 5.3.0
    • pkgs.python311Packages.podman 5.3.0
    • pkgs.nomad-driver-podman 0.5.2
    • pkgs.nomad-driver-podman 0.5.2
    • pkgs.podman-compose 1.2.0
    • pkgs.podman-compose 1.2.0
    • pkgs.podman-compose 1.2.0
    • pkgs.podman-compose 1.2.0
    • pkgs.podman-desktop 1.13.2
    • pkgs.podman-desktop 1.13.2
    • pkgs.podman-compose 1.2.0
    • pkgs.podman-compose 1.2.0
    • pkgs.podman-compose 1.2.0
    • pkgs.python311Packages.podman 5.3.0
    • pkgs.python311Packages.podman 5.3.0
    • pkgs.python311Packages.podman 5.3.0
    • pkgs.python311Packages.podman 5.3.0
    • pkgs.python312Packages.podman 5.0.0
    • pkgs.python312Packages.podman 5.0.0
    • pkgs.python312Packages.podman 5.0.0
    • pkgs.python312Packages.podman 5.0.0
    • pkgs.nvidia-podman
    • pkgs.nvidia-podman
    • pkgs.podman-compose 1.1.0
    • pkgs.podman-compose 1.1.0
    • pkgs.podman-compose 1.1.0
    • pkgs.podman-compose 1.1.0
    • pkgs.podman-desktop 0.12.0
    • pkgs.podman-desktop 0.12.0
    • pkgs.python312Packages.podman 5.2.0
    • pkgs.python312Packages.podman 5.2.0
    • pkgs.python312Packages.podman 5.2.0
    • pkgs.python312Packages.podman 5.2.0
    • pkgs.python311Packages.podman 5.0.0
    • pkgs.python311Packages.podman 5.0.0
    • pkgs.python311Packages.podman 5.0.0
    • pkgs.python311Packages.podman 5.0.0
    • pkgs.python311Packages.podman 5.0.0
    • pkgs.python311Packages.podman 5.0.0
    • pkgs.python311Packages.podman 5.0.0
    • pkgs.python311Packages.podman 5.0.0
    • pkgs.podman-compose 1.2.0
    • pkgs.podman-desktop 1.13.2
    • pkgs.podman-desktop 1.13.2
    • pkgs.nomad-driver-podman 0.6.1
    • pkgs.nomad-driver-podman 0.6.1
    • pkgs.nomad-driver-podman 0.6.1
    • pkgs.nomad-driver-podman 0.6.1
    • pkgs.python311Packages.podman 5.0.0
    • pkgs.python311Packages.podman 5.0.0
    • pkgs.python311Packages.podman 5.0.0
    • pkgs.python311Packages.podman 5.0.0
    • pkgs.python311Packages.podman 5.3.0
    • pkgs.python311Packages.podman 5.3.0
    • pkgs.python311Packages.podman 5.3.0
    • pkgs.python311Packages.podman 5.3.0
    • pkgs.python312Packages.podman 5.0.0
    • pkgs.python312Packages.podman 5.0.0
    • pkgs.python312Packages.podman 5.0.0
    • pkgs.python312Packages.podman 5.0.0
    • pkgs.python311Packages.podman 5.0.0
    • pkgs.python311Packages.podman 5.0.0
    • pkgs.python311Packages.podman 5.0.0
    • pkgs.python311Packages.podman 5.0.0
    • pkgs.podman-compose 1.2.0
    • pkgs.podman-compose 1.2.0
    • pkgs.podman-compose 1.2.0
    • pkgs.podman-compose 1.2.0
    • pkgs.podman-desktop 1.13.2
    • pkgs.podman-desktop 1.13.2
    • pkgs.python311Packages.podman 5.3.0
    • pkgs.python311Packages.podman 5.3.0
    • pkgs.python311Packages.podman 5.3.0
    • pkgs.python311Packages.podman 5.3.0
    • pkgs.python311Packages.podman 5.2.0
    • pkgs.python311Packages.podman 5.2.0
    • pkgs.python311Packages.podman 5.2.0
    • pkgs.python311Packages.podman 5.2.0
    • pkgs.podman-compose 1.2.0
    • pkgs.podman-compose 1.2.0
    • pkgs.podman-compose 1.2.0
    • pkgs.podman-compose 1.2.0
    • pkgs.podman-desktop 1.13.2
    • pkgs.podman-desktop 1.13.2
    • pkgs.nomad-driver-podman 0.5.2
    • pkgs.nomad-driver-podman 0.5.2
    • pkgs.nvidia-podman
    • pkgs.nvidia-podman
    • pkgs.podman-compose 1.1.0
    • pkgs.podman-compose 1.1.0
    • pkgs.podman-compose 1.1.0
    • pkgs.podman-compose 1.1.0
    • pkgs.podman-desktop 0.12.0
    • pkgs.podman-desktop 0.12.0
    • pkgs.podman-compose 1.1.0
    • pkgs.podman-compose 1.1.0
    • pkgs.podman-compose 1.1.0
    • pkgs.podman-compose 1.1.0
    • pkgs.podman-desktop 0.12.0
    • pkgs.podman-desktop 0.12.0
    • pkgs.podman-compose 1.2.0
    • pkgs.podman-compose 1.2.0
    • pkgs.podman-compose 1.2.0
    • pkgs.podman-compose 1.2.0
    • pkgs.podman-desktop 1.13.2
    • pkgs.podman-desktop 1.13.2
    • pkgs.podman-compose 1.1.0
    • pkgs.podman-compose 1.1.0
    • pkgs.podman-compose 1.1.0
    • pkgs.podman-compose 1.1.0
    • pkgs.podman-desktop 0.12.0
    • pkgs.podman-desktop 0.12.0
    • pkgs.nomad-driver-podman 0.6.1
    • pkgs.nomad-driver-podman 0.6.1
    • pkgs.python311Packages.podman 5.3.0
    • pkgs.python311Packages.podman 5.3.0
    • pkgs.python311Packages.podman 5.3.0
    • pkgs.python311Packages.podman 5.3.0
    • pkgs.nomad-driver-podman 0.6.1
    • pkgs.nomad-driver-podman 0.6.1
    • pkgs.python311Packages.podman 5.0.0
    • pkgs.python311Packages.podman 5.0.0
    • pkgs.python311Packages.podman 5.0.0
    • pkgs.python311Packages.podman 5.0.0
    • pkgs.nomad-driver-podman 0.6.1
    • pkgs.nomad-driver-podman 0.6.1
    • pkgs.python312Packages.podman 5.3.0
    • pkgs.python312Packages.podman 5.3.0
    • pkgs.python312Packages.podman 5.3.0
    • pkgs.python312Packages.podman 5.3.0
    • pkgs.python312Packages.podman 5.0.0
    • pkgs.python312Packages.podman 5.0.0
    • pkgs.python312Packages.podman 5.0.0
    • pkgs.python312Packages.podman 5.0.0
    • pkgs.python312Packages.podman 5.3.0
    • pkgs.python312Packages.podman 5.3.0
    • pkgs.python312Packages.podman 5.3.0
    • pkgs.python312Packages.podman 5.3.0
    • pkgs.podman-compose 1.2.0
    • pkgs.podman-compose 1.2.0
    • pkgs.podman-compose 1.2.0
    • pkgs.podman-compose 1.1.0
    • pkgs.podman-compose 1.1.0
    • pkgs.podman-compose 1.1.0
    • pkgs.podman-compose 1.1.0
    • pkgs.podman-desktop 0.12.0
    • pkgs.podman-desktop 0.12.0
    • pkgs.nomad-driver-podman 0.5.2
    • pkgs.nomad-driver-podman 0.5.2
    • pkgs.python311Packages.podman 5.3.0
    • pkgs.python311Packages.podman 5.3.0
    • pkgs.python311Packages.podman 5.3.0
    • pkgs.python311Packages.podman 5.3.0
    • pkgs.nomad-driver-podman 0.5.2
    • pkgs.nomad-driver-podman 0.5.2
    • pkgs.python312Packages.podman 5.2.0
    • pkgs.python312Packages.podman 5.2.0
    • pkgs.python312Packages.podman 5.2.0
    • pkgs.python312Packages.podman 5.2.0
    • pkgs.nomad-driver-podman 0.6.1
    • pkgs.nomad-driver-podman 0.6.1
    • pkgs.python312Packages.podman 5.3.0
    • pkgs.python312Packages.podman 5.3.0
    • pkgs.python312Packages.podman 5.3.0
    • pkgs.python312Packages.podman 5.3.0
    • pkgs.nomad-driver-podman 0.5.2
    • pkgs.nomad-driver-podman 0.5.2
    • pkgs.podman-compose 1.2.0
    • pkgs.podman-compose 1.2.0
    • pkgs.podman-compose 1.2.0
    • pkgs.podman-compose 1.2.0
    • pkgs.podman-desktop 1.13.2
    • pkgs.podman-desktop 1.13.2
    • pkgs.nvidia-podman
    • pkgs.nvidia-podman
    • pkgs.python311Packages.podman 5.0.0
    • pkgs.python311Packages.podman 5.0.0
    • pkgs.python311Packages.podman 5.0.0
    • pkgs.python311Packages.podman 5.0.0
    • pkgs.podman-compose 1.1.0
    • pkgs.podman-compose 1.1.0
    • pkgs.podman-compose 1.1.0
    • pkgs.podman-compose 1.1.0
    • pkgs.podman-desktop 0.12.0
    • pkgs.podman-desktop 0.12.0
    • pkgs.python311Packages.podman 5.2.0
    • pkgs.python311Packages.podman 5.2.0
    • pkgs.python311Packages.podman 5.2.0
    • pkgs.python311Packages.podman 5.2.0
    • pkgs.python311Packages.podman 5.2.0
    • pkgs.python311Packages.podman 5.2.0
    • pkgs.python311Packages.podman 5.2.0
    • pkgs.python311Packages.podman 5.2.0
    • pkgs.nomad-driver-podman 0.6.1
    • pkgs.nomad-driver-podman 0.6.1
    • pkgs.nomad-driver-podman 0.5.2
    • pkgs.nomad-driver-podman 0.5.2
    • pkgs.podman-compose 1.2.0
    • pkgs.podman-compose 1.2.0
    • pkgs.podman-compose 1.2.0
    • pkgs.podman-compose 1.2.0
    • pkgs.podman-desktop 1.13.2
    • pkgs.podman-desktop 1.13.2
    • pkgs.python312Packages.podman 5.3.0
    • pkgs.python312Packages.podman 5.3.0
    • pkgs.python312Packages.podman 5.3.0
    • pkgs.python312Packages.podman 5.3.0
    • pkgs.podman-compose 1.2.0
    • pkgs.podman-compose 1.2.0
    • pkgs.podman-compose 1.2.0
    • pkgs.podman-compose 1.2.0
    • pkgs.podman-desktop 1.13.2
    • pkgs.podman-desktop 1.13.2
    • pkgs.python312Packages.podman 5.0.0
    • pkgs.python312Packages.podman 5.0.0
    • pkgs.python312Packages.podman 5.0.0
    • pkgs.python312Packages.podman 5.0.0
    • pkgs.nomad-driver-podman 0.6.1
    • pkgs.nomad-driver-podman 0.6.1
    • pkgs.python312Packages.podman 5.3.0
    • pkgs.python312Packages.podman 5.3.0
    • pkgs.python312Packages.podman 5.3.0
    • pkgs.python312Packages.podman 5.3.0
    • pkgs.nvidia-podman
    • pkgs.nvidia-podman
    • pkgs.podman-compose 1.2.0
    • pkgs.podman-compose 1.2.0
    • pkgs.podman-compose 1.2.0
    • pkgs.podman-compose 1.2.0
    • pkgs.podman-desktop 1.13.2
    • pkgs.podman-desktop 1.13.2
    • pkgs.nomad-driver-podman 0.6.1
    • pkgs.nomad-driver-podman 0.6.1
    • pkgs.nomad-driver-podman 0.5.2
    • pkgs.nomad-driver-podman 0.5.2
    • pkgs.podman-compose 1.1.0
    • pkgs.podman-compose 1.1.0
    • pkgs.podman-compose 1.1.0
    • pkgs.nvidia-podman
    • pkgs.nvidia-podman
    • pkgs.podman-compose 1.1.0
    • pkgs.podman-desktop 0.12.0
    • pkgs.podman-desktop 0.12.0
    • pkgs.podman-compose 1.2.0
    • pkgs.podman-desktop 1.13.2
    • pkgs.nomad-driver-podman 0.6.1
    • pkgs.nomad-driver-podman 0.6.1
    • pkgs.podman-desktop 1.13.2
    • pkgs.nvidia-podman
    • pkgs.nvidia-podman
    • pkgs.python311Packages.podman 5.2.0
    • pkgs.python311Packages.podman 5.2.0
    • pkgs.python311Packages.podman 5.2.0
    • pkgs.python311Packages.podman 5.2.0
    • pkgs.python312Packages.podman 5.2.0
    • pkgs.python312Packages.podman 5.2.0
    • pkgs.python312Packages.podman 5.2.0
    • pkgs.python312Packages.podman 5.2.0
    • pkgs.python312Packages.podman 5.2.0
    • pkgs.python312Packages.podman 5.2.0
    • pkgs.python312Packages.podman 5.2.0
    • pkgs.python312Packages.podman 5.2.0
    • pkgs.python312Packages.podman 5.3.0
    • pkgs.python312Packages.podman 5.3.0
    • pkgs.python312Packages.podman 5.3.0
    • pkgs.python312Packages.podman 5.3.0
    • pkgs.python311Packages.podman 5.0.0
    • pkgs.python311Packages.podman 5.0.0
    • pkgs.python311Packages.podman 5.0.0
    • pkgs.python311Packages.podman 5.0.0
    • pkgs.python312Packages.podman 5.0.0
    • pkgs.python312Packages.podman 5.0.0
    • pkgs.python312Packages.podman 5.0.0
    • pkgs.python312Packages.podman 5.0.0
    • pkgs.python312Packages.podman 5.0.0
    • pkgs.python312Packages.podman 5.0.0
    • pkgs.python312Packages.podman 5.0.0
    • pkgs.python312Packages.podman 5.0.0
    • pkgs.nvidia-podman
    • pkgs.nvidia-podman
  • @fricklerhandwerk accepted as draft
Podman: buildah: container breakout by using --jobs=2 and a race condition when building a malicious containerfile

A vulnerability was found in `podman build` and `buildah.` This issue occurs in a container breakout by using --jobs=2 and a race condition when building a malicious Containerfile. SELinux might mitigate it, but even with SELinux on, it still allows the enumeration of files and directories on the host.

rhcos
*
podman
*
buildah
<1.37.6
<1.33.12
<1.38.1
<1.35.5
*
container-tools:rhel8
*
container-tools:rhel8/podman
container-tools:rhel8/buildah

pkgs.podman

A program for managing pods, containers and container images
Notify package maintainers: 3