by EGI CSIRT | Aug 26, 2024 | Advisories, News
There is a HIGH-risk vulnerability CVE-2024-5564 in libndp. This flaw allows a local malicious user to cause a buffer overflow in NetworkManager, triggered by sending a malformed IPv6 router advertisement packet. Further information on this vulnerability can be found...
by EGI CSIRT | Aug 26, 2024 | Advisories, News
OpenSSH has a high-risk vulnerability, allowing an Unauthenticated Remote Code Execution due to a race condition in signal handling. The vulnerability only affects RHEL9 and derivates. Check our SVG Advisory to learn more about this vulnerability.
by EGI CSIRT | Aug 26, 2024 | Advisories, News
A vulnerability CVE-2024-32498 has been found in QCOW2 image processing for Cinder, Glance and Nova. By supplying a specially created QCOW2 image which references a specific data file path, an authenticated user may convince systems to return a copy of that file...
by EGI CSIRT | Aug 9, 2024 | News, Recommendations
Many sites use Docker for development or to provide automated deployment of software or containers via Gitlab runners or similar solutions. In the past weeks have seen some incidents related to Docker API misconfiguration and would like to address the security...
by EGI CSIRT | Aug 5, 2024 | News
It has been reported that there is a vulnerability in the Slurm interconnect plugin switch/hpe_slingshot, which leverages the capabilities of Slingshot interconnect. There is a problem with isolating the communication from other channels. Same issue with...
Recent Comments