<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T20:53:15.488259+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-03694</id>
    <title>bdu:2024-03694</title>
    <updated>2026-10-04T20:53:15.594949+00:00</updated>
    <content>bdu:2024-03694</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-03694"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-309461</id>
    <title>EUVD-2026-309461</title>
    <updated>2026-10-04T20:53:15.594985+00:00</updated>
    <content>EUVD-2026-309461</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-309461"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-46954</id>
    <title>fkie_cve-2021-46954</title>
    <updated>2026-10-04T20:53:15.595000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>net/sched: sch_frag: fix stack OOB read while fragmenting IPv4 packets</p>
<p>when 'act_mirred' tries to fragment IPv4 packets that had been previously
re-assembled using 'act_ct', splats like the following can be observed on
kernels built with KASAN:</p>
<p>BUG: KASAN: stack-out-of-bounds in ip_do_fragment+0x1b03/0x1f60
 Read of size 1 at addr ffff888147009574 by task ping/947</p>
<p>CPU: 0 PID: 947 Comm: ping Not tainted 5.12.0-rc6+ #418
 Hardware name: Red Hat KVM, BIOS 1.11.1-4.module+el8.1.0+4066+0f1aadab 04/01/2014
 Call Trace:
  &lt;IRQ&gt;
  dump_stack+0x92/0xc1
  print_address_description.constprop.7+0x1a/0x150
  kasan_report.cold.13+0x7f/0x111
  ip_do_fragment+0x1b03/0x1f60
  sch_fragment+0x4bf/0xe40
  tcf_mirred_act+0xc3d/0x11a0 [act_mirred]
  tcf_action_exec+0x104/0x3e0
  fl_classify+0x49a/0x5e0 [cls_flower]
  tcf_classify_ingress+0x18a/0x820
  __netif_receive_skb_core+0xae7/0x3340
  __netif_receive_skb_one_core+0xb6/0x1b0
  process_backlog+0x1ef/0x6c0
  __napi_poll+0xaa/0x500
  net_rx_action+0x702/0xac0
  __do_softirq+0x1e4/0x97f
  do_softirq+0x71/0x90
  &lt;/IRQ&gt;
  __local_bh_enable_ip+0xdb/0xf0
  ip_finish_output2+0x760/0x2120
  ip_do_fragment+0x15a5/0x1f60
  __ip_finish_output+0x4c2/0xea0
  ip_output+0x1ca/0x4d0
  ip_send_skb+0x37/0xa0
  raw_sendmsg+0x1c4b/0x2d00
  sock_sendmsg+0xdb/0x110
  __sys_sendto+0x1d7/0x2b0
  __x64_sys_sendto+0xdd/0x1b0
  do_syscall_64+0x33/0x40
  entry_SYSCALL_64_after_hwframe+0x44/0xae
 RI…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-46954"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-6jf4-4jp9-4wmw</id>
    <title>GHSA-6jf4-4jp9-4wmw</title>
    <updated>2026-10-04T20:53:15.595058+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>net/sched: sch_frag: fix stack OOB read while fragmenting IPv4 packets</p>
<p>when 'act_mirred' tries to fragment IPv4 packets that had been previously
re-assembled using 'act_ct', splats like the following can be observed on
kernels built with KASAN:</p>
<p>BUG: KASAN: stack-out-of-bounds in ip_do_fragment+0x1b03/0x1f60
 Read of size 1 at addr ffff888147009574 by task ping/947</p>
<p>CPU: 0 PID: 947 Comm: ping Not tainted 5.12.0-rc6+ #418
 Hardware name: Red Hat KVM, BIOS 1.11.1-4.module+el8.1.0+4066+0f1aadab 04/01/2014
 Call Trace:
  &lt;IRQ&gt;
  dump_stack+0x92/0xc1
  print_address_description.constprop.7+0x1a/0x150
  kasan_report.cold.13+0x7f/0x111
  ip_do_fragment+0x1b03/0x1f60
  sch_fragment+0x4bf/0xe40
  tcf_mirred_act+0xc3d/0x11a0 [act_mirred]
  tcf_action_exec+0x104/0x3e0
  fl_classify+0x49a/0x5e0 [cls_flower]
  tcf_classify_ingress+0x18a/0x820
  __netif_receive_skb_core+0xae7/0x3340
  __netif_receive_skb_one_core+0xb6/0x1b0
  process_backlog+0x1ef/0x6c0
  __napi_poll+0xaa/0x500
  net_rx_action+0x702/0xac0
  __do_softirq+0x1e4/0x97f
  do_softirq+0x71/0x90
  &lt;/IRQ&gt;
  __local_bh_enable_ip+0xdb/0xf0
  ip_finish_output2+0x760/0x2120
  ip_do_fragment+0x15a5/0x1f60
  __ip_finish_output+0x4c2/0xea0
  ip_output+0x1ca/0x4d0
  ip_send_skb+0x37/0xa0
  raw_sendmsg+0x1c4b/0x2d00
  sock_sendmsg+0xdb/0x110
  __sys_sendto+0x1d7/0x2b0
  __x64_sys_sendto+0xdd/0x1b0
  do_syscall_64+0x33/0x40
  entry_SYSCALL_64_after_hwframe+0x44/0xae
 RI…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-6jf4-4jp9-4wmw"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2021-46954</id>
    <title>gsd-2021-46954</title>
    <updated>2026-10-04T20:53:15.595100+00:00</updated>
    <content>gsd-2021-46954</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2021-46954"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-46954</id>
    <title>UBUNTU-CVE-2021-46954</title>
    <updated>2026-10-04T20:53:15.595112+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 57 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_frag: fix stack OOB read while fragmenting IPv4 packets when 'act_mirred' tries to fragment IPv4 packets that had been previously re-assembled using 'act_ct', splats like the following can be observed on kernels built with KASAN:  BUG: KASAN: stack-out-of-bounds in ip_do_fragment+0x1b03/0x1f60  Read of size 1 at addr ffff888147009574 by task ping/947  CPU: 0 PID: 947 Comm: ping Not tainted 5.12.0-rc6+ #418  Hardware name: Red Hat KVM, BIOS 1.11.1-4.module+el8.1.0+4066+0f1aadab 04/01/2014  Call Trace:   &lt;IRQ&gt;   dump_stack+0x92/0xc1   print_address_description.constprop.7+0x1a/0x150   kasan_report.cold.13+0x7f/0x111   ip_do_fragment+0x1b03/0x1f60   sch_fragment+0x4bf/0xe40   tcf_mirred_act+0xc3d/0x11a0 [act_mirred]   tcf_action_exec+0x104/0x3e0   fl_classify+0x49a/0x5e0 [cls_flower]   tcf_classify_ingress+0x18a/0x820   __netif_receive_skb_core+0xae7/0x3340   __netif_receive_skb_one_core+0xb6/0x1b0   process_backlog+0x1ef/0x6c0   __napi_poll+0xaa/0x500   net_rx_action+0x702/0xac0   __do_softirq+0x1e4/0x97f   do_softirq+0x71/0x90   &lt;/IRQ&gt;   __local_bh_enable_ip+0xdb/0xf0   ip_finish_output2+0x760/0x2120   ip_do_fragment+0x15a5/0x1f60   __ip_finish_output+0x4c2/0xea0   ip_output+0x1ca/0x4d0   ip_send_skb+0x37/0xa0   raw_sendmsg+0x1c4b/0x2d00   sock_sendmsg+0xdb/0x110   __sys_sendto+0x1d7/0x2b0   __x64_sys_sendto+0xdd/0x1b0   do_syscall_64+0x33/0x40   entry_SYSCALL_64_after_hwframe+0x44/0xae  RIP: 0…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-46954"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0500</id>
    <title>WID-SEC-W-2024-0500 — Linux Kernel: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff</title>
    <updated>2026-10-04T20:53:15.595257+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0500"/>
  </entry>
</feed>
