<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T16:18:47.893367+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2021:2570</id>
    <title>ALSA-2021:2570 — Important: kernel security and bug fix update</title>
    <updated>2026-10-03T16:18:48.521767+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: kernel-tools-libs-devel</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: use-after-free in net/bluetooth/hci_event.c when destroying an hci_chan (CVE-2021-33034)</p>
<p>* kernel: security bypass in certs/blacklist.c and certs/system_keyring.c (CVE-2020-26541)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p>
<p>Bug Fix(es):</p>
<p>* [ESXi][AlmaLinux-8] VMXNET3 v4 causes invalid checksums of inner packets of VXLAN tunnel (BZ#1960702)</p>
<p>* fnic crash from invalid request pointer (BZ#1961705)</p>
<p>* GFS2: Failed FS thaw call makes the entire snapshot failed. (BZ#1961849)</p>
<p>* dm writecache: fix performance degradation in ssd mode (BZ#1962241)</p>
<p>* Kernel BUG with act_ct and IP fragments (BZ#1963940)</p>
<p>* core: backports from upstream (BZ#1963952)</p>
<p>* Hibernate resume on AlmaLinux fails in Amazon EC2 C5.18xlarge instance (BZ#1964930)</p>
<p>* [SanityOnly] panic caused by i40e_msix_clean_rings (BZ#1964962)</p>
<p>* tc reclassification limit is too low for OVN (BZ#1965148)</p>
<p>* tc action ct nat src addr does not work while used with ct nat dst addr together (BZ#1965150)</p>
<p>* CNB: Rebase/update TC subsystem for AlmaLinux 8.5 (BZ#1965457)</p>
<p>* sctp: crash due to use after free of sctp_transport structure (BZ#1965632)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2021:2570"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2021-04839</id>
    <title>bdu:2021-04839</title>
    <updated>2026-10-03T16:18:48.521879+00:00</updated>
    <content>bdu:2021-04839</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2021-04839"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2021-33034</id>
    <title>Withdrawn: BELL-CVE-2021-33034 — CVE-2021-33034 does not affect BellSoft software</title>
    <updated>2026-10-03T16:18:48.521897+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2021-33034"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2021-avi-452</id>
    <title>certfr-2021-avi-452 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de
SUSE. Certaines d'entre elles permettent à un at…</title>
    <updated>2026-10-03T16:18:48.521913+00:00</updated>
    <content>certfr-2021-avi-452</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2021-avi-452"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2021-38087</id>
    <title>cnvd-2021-38087</title>
    <updated>2026-10-03T16:18:48.521928+00:00</updated>
    <content>cnvd-2021-38087</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2021-38087"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-28249</id>
    <title>EUVD-2026-28249</title>
    <updated>2026-10-03T16:18:48.521940+00:00</updated>
    <content>EUVD-2026-28249</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-28249"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-33034</id>
    <title>fkie_cve-2021-33034</title>
    <updated>2026-10-03T16:18:48.521950+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In the Linux kernel before 5.12.4, net/bluetooth/hci_event.c has a use-after-free when destroying an hci_chan, aka CID-5c4c8c954409. This leads to writing an arbitrary value.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-33034"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3qpw-8jg3-xjrh</id>
    <title>GHSA-3qpw-8jg3-xjrh</title>
    <updated>2026-10-03T16:18:48.521972+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In the Linux kernel before 5.12.4, net/bluetooth/hci_event.c has a use-after-free when destroying an hci_chan, aka CID-5c4c8c954409. This leads to writing an arbitrary value.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3qpw-8jg3-xjrh"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-33034</id>
    <title>gsd-2021-33034</title>
    <updated>2026-10-03T16:18:48.521986+00:00</updated>
    <content>gsd-2021-33034</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-33034"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2021-33034</id>
    <title>msrc_CVE-2021-33034 — In the Linux kernel before 5.12.4 net/bluetooth/hci_event.c has a use-after-free when destroying an hci_chan aka CID-5c…</title>
    <updated>2026-10-03T16:18:48.521996+00:00</updated>
    <content>msrc_CVE-2021-33034</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2021-33034"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2021-1176</id>
    <title>OESA-2021-1176 — kernel security update</title>
    <updated>2026-10-03T16:18:48.522013+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: kernel</p>
<p>The Linux Kernel, the operating system core itself.



Security Fix(es):</p>
<p>An issue was discovered in the Linux kernel before 5.11.8. kernel/bpf/verifier.c performs undesirable out-of-bounds speculation on pointer arithmetic, leading to side-channel attacks that defeat Spectre mitigations and obtain sensitive information from kernel memory, aka CID-f232326f6966. This affects pointer types that do not define a ptr_limit.(CVE-2020-27170)</p>
<p>An issue was discovered in the Linux kernel before 5.11.8. kernel/bpf/verifier.c has an off-by-one error (with a resultant integer underflow) affecting out-of-bounds speculation on pointer arithmetic, leading to side-channel attacks that defeat Spectre mitigations and obtain sensitive information from kernel memory, aka CID-10d2bb2e6b1d.(CVE-2020-27171)</p>
<p>rtw_wx_set_scan in drivers/staging/rtl8188eu/os_dep/ioctl_linux.c in the Linux kernel through 5.11.6 allows writing beyond the end of the -&amp;gt;ssid[] array. NOTE: from the perspective of kernel.org releases, CVE IDs are not normally used for drivers/staging/* (unfinished work); however, system integrators may have situations in which a drivers/staging issue is relevant to their own customer base.(CVE-2021-28660)</p>
<p>A race condition was discovered in get_old_root in fs/btrfs/ctree.c in the Linux kernel through 5.11.8. It allows attackers to cause a denial of service (BUG) because of a lack of locking on an extent buffer before a cloning operation, aka CID-dbcc7d57bffc.(CVE-2021-28964)</p>
<p>In dri…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2021-1176"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2021:0843-1</id>
    <title>openSUSE-SU-2021:0843-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-03T16:18:48.522083+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2021:0843-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhba-2021:2854</id>
    <title>RHBA-2021:2854 — Red Hat Bug Fix Advisory: Migration Toolkit for Containers (MTC) 1.4.6 release advisory</title>
    <updated>2026-10-03T16:18:48.522107+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libwebp: heap-based buffer overflow in PutLE16() nss: TLS 1.3 CCS flood remote DoS Attack openldap: NULL pointer dereference for unauthenticated packet in slapd kernel: security bypass in certs/blacklist.c and certs/system_keyring.c jetty: local temporary directory hijacking vulnerability jetty: buffer not correctly recycled in Gzip Request inflation jetty: request containing multiple Accept headers with a large number of "quality" parameters may lead to DoS libwebp: heap-based buffer overflow in WebPDecode*Into functions libwebp: use-after-free in EmitFancyRGB() in dec/io_dec.c libxml2: Use-after-free in xmlEncodeEntitiesInternal() in entities.c libxml2: Heap-based buffer overflow in xmlEncodeEntitiesInternal() in entities.c libxml2: Use-after-free in xmlXIncludeDoProcess() in xinclude.c lz4: memory corruption due to an integer overflow bug caused by memmove argument libxml2: NULL pointer dereference when post-validating mixed content parsed in recovery mode libxml2: Exponential entity expansion attack bypasses all existing protection mechanisms rpm: Signature checks bypass via corrupted rpm package jenkins-2-plugins/config-file-provider: Does not configure its XML parser to prevent XML external entity (XXE) attacks. jenkins-2-plugins/config-file-provider: Does not correctly perform permission checks in several HTTP endpoints. jenkins-2-plugins/config-file-provider: does not require POST requests for an HTTP endpoint, resulting in a cross-site request forgery (CSRF) vulnera…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhba-2021:2854"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2021:1887-1</id>
    <title>SUSE-SU-2021:1887-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-03T16:18:48.522163+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2021:1887-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-33034</id>
    <title>UBUNTU-CVE-2021-33034</title>
    <updated>2026-10-03T16:18:48.522185+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 75 more</p>
<p>In the Linux kernel before 5.12.4, net/bluetooth/hci_event.c has a use-after-free when destroying an hci_chan, aka CID-5c4c8c954409. This leads to writing an arbitrary value.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-33034"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0063</id>
    <title>WID-SEC-W-2023-0063 — Juniper Junos Space: Mehrere Schwachstellen</title>
    <updated>2026-10-03T16:18:48.522316+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer aus dem angrenzenden Netzwerk oder ein entfernter anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in Juniper Junos Space ausnutzen, um Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand auszulösen, beliebigen Code auszuführen und seine Privilegien zu erweitern.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0063"/>
  </entry>
</feed>
