<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T10:33:53.787467+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2022:1988</id>
    <title>ALSA-2022:1988 — Important: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-02T10:33:55.158854+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: bpftool, AlmaLinux:8: kernel, AlmaLinux:8: kernel-abi-stablelists, AlmaLinux:8: kernel-core, AlmaLinux:8: kernel-cross-headers, AlmaLinux:8: kernel-debug, AlmaLinux:8: kernel-debug-core, AlmaLinux:8: kernel-debug-devel, AlmaLinux:8: kernel-debug-modules, AlmaLinux:8: kernel-debug-modules-extra and 10 more</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: fget: check that the fd still exists after getting a ref to it (CVE-2021-4083)</p>
<p>* kernel: avoid cyclic entity chains due to malformed USB descriptors (CVE-2020-0404)</p>
<p>* kernel: speculation on incompletely validated data on IBM Power9 (CVE-2020-4788)</p>
<p>* kernel: integer overflow in k_ascii() in drivers/tty/vt/keyboard.c (CVE-2020-13974)</p>
<p>* kernel: out-of-bounds read in bpf_skb_change_head() of filter.c due to a use-after-free (CVE-2021-0941)</p>
<p>* kernel: joydev: zero size passed to joydev_handle_JSIOCSBTNMAP() (CVE-2021-3612)</p>
<p>* kernel: reading /proc/sysvipc/shm does not scale with large shared memory segment counts (CVE-2021-3669)</p>
<p>* kernel: out-of-bound Read in qrtr_endpoint_post in net/qrtr/qrtr.c (CVE-2021-3743)</p>
<p>* kernel: crypto: ccp - fix resource leaks in ccp_run_aes_gcm_cmd() (CVE-2021-3744)</p>
<p>* kernel: possible use-after-free in bluetooth module (CVE-2021-3752)</p>
<p>* kernel: unaccounted ipc objects in Linux kernel lead to breaking memcg limits and DoS attacks (CVE-2021-3759)</p>
<p>* kernel: DoS in ccp_run_aes_gcm_cmd() function (CVE-2021-3764)</p>
<p>* kernel: sctp: Invalid chunks may be used to remotely remove existing associations (CVE-2021-3772)</p>
<p>* kernel: lack of port sanity checking in natd and netfilter leads to exploit of OpenVPN clients (CVE-2021-3773)</p>
<p>* kernel: possible leak or coruption of data residing on hugetlbfs (CVE-2021-4002)</p>
<p>* kernel: security regressi…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2022:1988"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2018-00003</id>
    <title>bdu:2018-00003</title>
    <updated>2026-10-02T10:33:55.158994+00:00</updated>
    <content>bdu:2018-00003</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2018-00003"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2018-ale-001</id>
    <title>certfr-2018-ale-001 — &lt;strong&gt;\[Mise à jour du 25/05/2018 : ajout de bulletins Microsoft (cf.
section Documentation)\]&lt;/strong&gt;

&lt;strong&gt;\[Mi…</title>
    <updated>2026-10-02T10:33:55.159014+00:00</updated>
    <content>certfr-2018-ale-001</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2018-ale-001"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2018-avi-004</id>
    <title>certfr-2018-avi-004 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de
RedHat . Elles permettent à un attaquant de prov…</title>
    <updated>2026-10-02T10:33:55.159099+00:00</updated>
    <content>certfr-2018-avi-004</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2018-avi-004"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cisco-sa-20180104-cpusidechannel</id>
    <title>cisco-sa-20180104-cpusidechannel — CPU Side-Channel Information Disclosure Vulnerabilities</title>
    <updated>2026-10-02T10:33:55.159114+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>On January 3, 2018, researchers disclosed three vulnerabilities that take advantage of the implementation of speculative execution of instructions on many modern microprocessor architectures to perform side-channel information disclosure attacks. These vulnerabilities could allow an unprivileged local attacker, in specific circumstances, to read privileged memory belonging to other processes or memory allocated to  the operating system kernel.

The first two vulnerabilities, CVE-2017-5753 and CVE-2017-5715,  are collectively known as Spectre. The third vulnerability, CVE-2017-5754, is known as Meltdown. The vulnerabilities are all variants of the same attack and differ in the way that speculative execution is exploited.

To exploit any of these vulnerabilities, an attacker must be able to run crafted code on an affected device. Although the underlying CPU and operating system combination in a product or service may be affected by these vulnerabilities, the majority of Cisco products are closed systems that do not allow customers to run custom code and are, therefore, not vulnerable. There is no vector to exploit them. Cisco products are considered potentially vulnerable only if they allow customers to execute custom code side-by-side with Cisco code on the same microprocessor.

A Cisco product that may be deployed as a virtual machine or a container, even while not directly affected by any of these vulnerabilities, could be targeted by such attacks if the hosting envir…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cisco-sa-20180104-cpusidechannel"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2018-00302</id>
    <title>cnvd-2018-00302</title>
    <updated>2026-10-02T10:33:55.159156+00:00</updated>
    <content>cnvd-2018-00302</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2018-00302"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-237872</id>
    <title>EUVD-2026-237872</title>
    <updated>2026-10-02T10:33:55.159169+00:00</updated>
    <content>EUVD-2026-237872</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-237872"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2017-5715</id>
    <title>fkie_cve-2017-5715</title>
    <updated>2026-10-02T10:33:55.159180+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2017-5715"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2017-5715</id>
    <title>gsd-2017-5715</title>
    <updated>2026-10-02T10:33:55.159201+00:00</updated>
    <content>gsd-2017-5715</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2017-5715"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-23-257-04</id>
    <title>ICSA-23-257-04 — Siemens RUGGEDCOM APE1808 Products</title>
    <updated>2026-10-02T10:33:55.159211+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An attacker with local access to the system could potentially disclose information
from protected memory areas via a side-channel attack on the processor cache. Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize. An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. IHISI function 0x17 verifies that the output buffer lies within the command buffer but does not verify that output data does not go beyond the end of the command buffer. In particular, the GetFlashTable function is called directly on the Command Buffer before the DataSize is check, leading to possible circumstances where the data immediately following the command buffer could be destroyed before returning a buffer size error. Using SPI injection, it is possible to modify the FDM contents after it has been measured. This TOCTOU attack could be used to alter data and code used by the remainder of the boot process. Some versions of InsydeH2O use the FreeType tools to embed fonts into the BIOS. InsydeH2O does not use the FreeType API at runtime and usage during build time does not produce a vulnerability in the BIOS. The CVSS reflects this limited usage. In UsbCoreDxe, untrusted input may allow SMRAM or OS memory tampering Use of untrusted pointers could allow OS or SMRAM memory tampering leading to escalation of privileges. This issue was discovered by Insyde during security review. https://www.insyde.com/security-pledge/SA-2022058 In UsbCor…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-23-257-04"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:10633-1</id>
    <title>openSUSE-SU-2024:10633-1 — arm-trusted-firmware-2.5-2.3 on GA media</title>
    <updated>2026-10-02T10:33:55.159289+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>arm-trusted-firmware-2.5-2.3 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:10633-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhba-2018:0042</id>
    <title>RHBA-2018:0042 — Red Hat Bug Fix Advisory: dracut bug fix update</title>
    <updated>2026-10-02T10:33:55.159307+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>hw: cpu: speculative execution branch target injection</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhba-2018:0042"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-ru-2018:0779-1</id>
    <title>SUSE-RU-2018:0779-1 — Recommended update for drbd and drbd-utils</title>
    <updated>2026-10-02T10:33:55.159323+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Recommended update for drbd and drbd-utils</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-ru-2018:0779-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2017-5715</id>
    <title>UBUNTU-CVE-2017-5715</title>
    <updated>2026-10-02T10:33:55.159338+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: amd64-microcode, Ubuntu:14.04:LTS: firefox, Ubuntu:14.04:LTS: intel-microcode, Ubuntu:14.04:LTS: libvirt, Ubuntu:14.04:LTS: linux, Ubuntu:14.04:LTS: linux-aws, Ubuntu:14.04:LTS: linux-lts-xenial, Ubuntu:14.04:LTS: qemu, Ubuntu:16.04:LTS: amd64-microcode, Ubuntu:16.04:LTS: firefox and 26 more</p>
<p>Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2017-5715"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2018-002</id>
    <title>VDE-2018-002 — Pepperl+Fuchs: HMI devices vulnerable to Meltdown and Spectre Attacks</title>
    <updated>2026-10-02T10:33:55.159398+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Critical vulnerabilities within several CPUs have been identified by security researchers. These hardware vulnerabilities allow programs to learn about the contents of a system's memory, using side-channel attacks. Potential attack vectors against these vulnerabilities have been published and dubbed Meltdown and Spectre. While programs are typically not permitted to read data from the OS kernel or from other programs, a malicious program can exploit Meltdown and Spectre to get hold of secrets stored in kernel memory or the memory of other programs executed on the same CPU. As a consequence, an exploit could allow attackers to get access to any sensitive data, including passwords or cryptographic keys.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2018-002"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2018-003</id>
    <title>VDE-2018-003 — PHOENIX CONTACT: addressing Meltdown and Spectre vulnerabilities</title>
    <updated>2026-10-02T10:33:55.159422+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Several CPUs manufactured by Intel, AMD or based on ARM technology may leak information due to their internal operation if attacked by specifically written software executed on the affected systems.</p>
<p>The information in this advisory is based on the statements of respective manufacturers.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2018-003"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0532</id>
    <title>WID-SEC-W-2022-0532 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-02T10:33:55.159442+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um beliebigen Programmcode mit Administratorrechten auszuführen, einen Denial of Service Angriff durchzuführen, Sicherheitsmechanismen zu umgehen, vertrauliche Daten einzusehen oder seine Privilegien zu erweitern.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0532"/>
  </entry>
</feed>
