<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T23:30:38.425221+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2022:0825</id>
    <title>ALSA-2022:0825 — Important: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-03T23:30:39.543881+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: kernel-tools-libs-devel</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>The following packages have been upgraded to a later upstream version: kernel (4.18.0). (BZ#2036888)</p>
<p>Security Fix(es):</p>
<p>* kernel: improper initialization of the "flags" member of the new pipe_buffer (CVE-2022-0847)</p>
<p>* kernel: Use After Free in unix_gc() which could result in a local privilege escalation (CVE-2021-0920)</p>
<p>* kernel: local privilege escalation by exploiting the fsconfig syscall parameter leads to container breakout (CVE-2021-4154)</p>
<p>* kernel: possible privileges escalation due to missing TLB flush (CVE-2022-0330)</p>
<p>* kernel: remote stack overflow via kernel panic on systems using TIPC may lead to DoS (CVE-2022-0435)</p>
<p>* kernel: cgroups v1 release_agent feature may allow privilege escalation (CVE-2022-0492)</p>
<p>* kernel: missing check in ioctl allows kernel memory read/write (CVE-2022-0516)</p>
<p>* kernel: failing usercopy allows for use-after-free exploitation (CVE-2022-22942)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p>
<p>Bug Fix(es):</p>
<p>* Intel QAT Kernel power up fix (BZ#2016437)</p>
<p>* AlmaLinux8.4 seeing scsi_dma_map failed with mpt3sas driver and affecting performance (BZ#2018928)</p>
<p>* [Lenovo 8.4 bug] audio_HDMI certification failed on AlmaLinux 8.4GA (No hdmi out) (BZ#2027335)</p>
<p>* [AlmaLinux-8.5][4.18.0-323.el8.ppc64le][POWER8/9/10] security_flav…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2022:0825"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2022-00836</id>
    <title>bdu:2022-00836</title>
    <updated>2026-10-03T23:30:39.544058+00:00</updated>
    <content>bdu:2022-00836</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2022-00836"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2021-avi-837</id>
    <title>certfr-2021-avi-837 — De multiples vulnérabilités ont été découvertes dans Google Android.
Certaines d'entre elles permettent à un attaquant…</title>
    <updated>2026-10-03T23:30:39.544097+00:00</updated>
    <content>certfr-2021-avi-837</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2021-avi-837"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2021-101428</id>
    <title>cnvd-2021-101428</title>
    <updated>2026-10-03T23:30:39.544128+00:00</updated>
    <content>cnvd-2021-101428</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2021-101428"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-255897</id>
    <title>EUVD-2026-255897</title>
    <updated>2026-10-03T23:30:39.544143+00:00</updated>
    <content>EUVD-2026-255897</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-255897"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-0920</id>
    <title>fkie_cve-2021-0920</title>
    <updated>2026-10-03T23:30:39.544167+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In unix_scm_to_skb of af_unix.c, there is a possible use after free bug due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-196926917References: Upstream kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-0920"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-r93f-j2vf-vmc4</id>
    <title>GHSA-r93f-j2vf-vmc4</title>
    <updated>2026-10-03T23:30:39.544194+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In unix_scm_to_skb of af_unix.c, there is a possible use after free bug due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-196926917References: Upstream kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-r93f-j2vf-vmc4"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-0920</id>
    <title>gsd-2021-0920</title>
    <updated>2026-10-03T23:30:39.544211+00:00</updated>
    <content>gsd-2021-0920</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-0920"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-24-074-07</id>
    <title>ICSA-24-074-07 — Siemens SIMATIC</title>
    <updated>2026-10-03T23:30:39.544222+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An attacker could cause a crash or potentially execute arbitrary code by sending specially crafted DNS responses to the DNSmasq process. In order to exploit this vulnerability, an attacker must be able to trigger DNS requests from the device, and must be in a privileged position to inject malicious DNS responses. An issue was discovered in net/ipv6/ip6mr.c in the Linux kernel before 4.11. By setting a specific socket option, an attacker can control a pointer in kernel land and cause an inet_csk_listen_stop general protection fault, or potentially execute arbitrary code under certain circumstances. The issue can be triggered as root (e.g., inside a default LXC container or with the CAP_NET_ADMIN capability) or after namespace unsharing. This occurs because sk_type and protocol are not checked in the appropriate part of the ip6_mroute_* functions. NOTE: this affects Linux distributions that use 4.9.x longterm kernels before 4.9.187. In checkKeyIntent of AccountManagerService.java, there is a possible permission bypass. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-10, Android-9 Android ID: A-123700107 In setNiNotification of GpsNetInitiatedHandler.java, there is a possible permissions bypass due to an empty mutable PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploit…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-24-074-07"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2021-1475</id>
    <title>OESA-2021-1475 — kernel security update</title>
    <updated>2026-10-03T23:30:39.544571+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: kernel, openEuler:20.03-LTS-SP2: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):

A memory leak flaw in the Linux kernel&amp;apos;s hugetlbfs memory usage was found in the way the user maps some regions of memory twice using shmget() which are aligned to PUD alignment with the fault of some of the memory pages. A local user could use this flaw to get unauthorized access to some data.(CVE-2021-4002)

In unix_scm_to_skb of af_unix.c, there is a possible use after free bug due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-196926917References: Upstream kernel(CVE-2021-0920)

A vulnerability was found in the fs/inode.c:inode_init_owner() function logic of the LInux kernel that allows local users to create files for the XFS file-system with an unintended group ownership and with group execution and SGID permission bits set, in a scenario where a directory is SGID and belongs to a certain group and is writable by a user who is not a member of this group. This can lead to excessive permissions granted in case when they should not. This vulnerability is similar to the previous CVE-2018-13405 and adds the missed fix for the XFS.(CVE-2021-4037)

A race condition accessing file object in the Linux kernel OverlayFS subsystem was found in the way users do rename in specific way with OverlayFS. A local user could use this flaw to…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2021-1475"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2022:0366-1</id>
    <title>openSUSE-SU-2022:0366-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-03T23:30:39.544623+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2022:0366-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2022:0590</id>
    <title>RHSA-2022:0590 — Red Hat Security Advisory: kpatch-patch security update</title>
    <updated>2026-10-03T23:30:39.544660+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: Use After Free in unix_gc() which could result in a local privilege escalation kernel: use-after-free in RDMA listen() kernel: xfs: raw block device data leak in XFS_IOC_ALLOCSP IOCTL</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2022:0590"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2022:0068-1</id>
    <title>SUSE-SU-2022:0068-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-03T23:30:39.544683+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2022:0068-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-0920</id>
    <title>UBUNTU-CVE-2021-0920</title>
    <updated>2026-10-03T23:30:39.544708+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 83 more</p>
<p>In unix_scm_to_skb of af_unix.c, there is a possible use after free bug due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-196926917References: Upstream kernel</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-0920"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0049</id>
    <title>WID-SEC-W-2022-0049 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-03T23:30:39.544858+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um seine Privilegien zu erhöhen, um Sicherheitsmechanismen zu umgehen und um Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0049"/>
  </entry>
</feed>
