<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Alpine Linux</title>
  <link>https://cvedaily.com/pages/tags/alpine-linux.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/alpine-linux.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Alpine Linux</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:11 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2022-22704 – The zabbix-agent2 package before 5.4.9-r1 for Alpine Linux sometimes allows priv...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-22704</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-22704</guid>
    <pubDate>Thu, 06 Jan 2022 05:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-22704</strong></p>
  <p>The zabbix-agent2 package before 5.4.9-r1 for Alpine Linux sometimes allows privilege escalation to root because the design incorrectly expected that systemd would (in effect) determine part of the configuration.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-909</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-22704">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-36158 – In the xrdp package (in branches through 3.14) for Alpine Linux, RDP sessions ar...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36158</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36158</guid>
    <pubDate>Mon, 05 Jul 2021 23:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-36158</strong></p>
  <p>In the xrdp package (in branches through 3.14) for Alpine Linux, RDP sessions are vulnerable to man-in-the-middle attacks because pre-generated RSA certificates and private keys are used.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-312</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36158">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-30139 – In Alpine Linux apk-tools before 2.12.5, the tarball parser allows a buffer over...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-30139</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-30139</guid>
    <pubDate>Wed, 21 Apr 2021 16:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-30139</strong></p>
  <p>In Alpine Linux apk-tools before 2.12.5, the tarball parser allows a buffer overflow and crash.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-30139">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-29133 – Lack of verification in haserl, a component of Alpine Linux Configuration Framew...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-29133</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-29133</guid>
    <pubDate>Wed, 24 Mar 2021 07:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-29133</strong></p>
  <p>Lack of verification in haserl, a component of Alpine Linux Configuration Framework, before 0.9.36 allows local users to read the contents of any file on the filesystem.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-29133">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-12875 – Alpine Linux abuild through 3.4.0 allows an unprivileged member of the abuild gr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-12875</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-12875</guid>
    <pubDate>Tue, 18 Jun 2019 19:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-12875</strong></p>
  <p>Alpine Linux abuild through 3.4.0 allows an unprivileged member of the abuild group to add an untrusted package via a --keys-dir option that causes acceptance of an untrusted signing key.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-668</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-12875">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-5021 – Versions of the Official Alpine Linux Docker images (since v3.3) contain a NULL ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5021</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5021</guid>
    <pubDate>Wed, 08 May 2019 17:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-5021</strong></p>
  <p>Versions of the Official Alpine Linux Docker images (since v3.3) contain a NULL password for the `root` user. This vulnerability appears to be the result of a regression introduced in December of 2015. Due to the nature of this issue, systems deployed using affected versions of the Alpine Linux container which utilize Linux PAM, or some other mechanism which uses the system shadow file as an auth…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-258</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5021">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-1000849 – Alpine Linux version Versions prior to 2.6.10, 2.7.6, and 2.10.1 contains a Othe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1000849</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1000849</guid>
    <pubDate>Thu, 20 Dec 2018 15:29:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-1000849</strong></p>
  <p>Alpine Linux version Versions prior to 2.6.10, 2.7.6, and 2.10.1 contains a Other/Unknown vulnerability in apk-tools (Alpine Linux' package manager) that can result in Remote Code Execution. This attack appear to be exploitable via A specially crafted APK-file can cause apk to write arbitrary data to an attacker-specified file, due to bugs in handling long link target name and the way a regular f…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1000849">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-9671 – A heap overflow in apk (Alpine Linux's package manager) allows a remote attacker...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-9671</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-9671</guid>
    <pubDate>Mon, 17 Jul 2017 21:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-9671</strong></p>
  <p>A heap overflow in apk (Alpine Linux's package manager) allows a remote attacker to cause a denial of service, or achieve code execution, by crafting a malicious APKINDEX.tar.gz file with a bad pax header block.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-9671">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-9669 – A heap overflow in apk (Alpine Linux's package manager) allows a remote attacker...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-9669</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-9669</guid>
    <pubDate>Mon, 17 Jul 2017 21:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-9669</strong></p>
  <p>A heap overflow in apk (Alpine Linux's package manager) allows a remote attacker to cause a denial of service, or achieve code execution by crafting a malicious APKINDEX.tar.gz file.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-9669">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
