<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T08:13:59.029326+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-07459</id>
    <title>bdu:2025-07459</title>
    <updated>2026-10-03T08:13:59.779442+00:00</updated>
    <content>bdu:2025-07459</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-07459"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0496</id>
    <title>certfr-2024-avi-0496 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
    <updated>2026-10-03T08:13:59.779498+00:00</updated>
    <content>certfr-2024-avi-0496</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0496"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-344463</id>
    <title>EUVD-2026-344463</title>
    <updated>2026-10-03T08:13:59.779549+00:00</updated>
    <content>EUVD-2026-344463</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-344463"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2021-47358</id>
    <title>fkie_cve-2021-47358</title>
    <updated>2026-10-03T08:13:59.779594+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>staging: greybus: uart: fix tty use after free</p>
<p>User space can hold a tty open indefinitely and tty drivers must not
release the underlying structures until the last user is gone.</p>
<p>Switch to using the tty-port reference counter to manage the life time
of the greybus tty state to avoid use after free after a disconnect.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2021-47358"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xp4x-rp64-962g</id>
    <title>GHSA-xp4x-rp64-962g</title>
    <updated>2026-10-03T08:13:59.779645+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>staging: greybus: uart: fix tty use after free</p>
<p>User space can hold a tty open indefinitely and tty drivers must not
release the underlying structures until the last user is gone.</p>
<p>Switch to using the tty-port reference counter to manage the life time
of the greybus tty state to avoid use after free after a disconnect.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xp4x-rp64-962g"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-3701</id>
    <title>OESA-2026-3701 — kernel security update</title>
    <updated>2026-10-03T08:13:59.779681+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP4: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>staging: greybus: uart: fix tty use after free</p>
<p>User space can hold a tty open indefinitely and tty drivers must not
release the underlying structures until the last user is gone.</p>
<p>Switch to using the tty-port reference counter to manage the life time
of the greybus tty state to avoid use after free after a disconnect.(CVE-2021-47358)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>net: sched: avoid qdisc_reset_all_tx_gt() vs dequeue race for lockless qdiscs</p>
<p>When shrinking the number of real tx queues,
netif_set_real_num_tx_queues() calls qdisc_reset_all_tx_gt() to flush
qdiscs for queues which will no longer be used.</p>
<p>qdisc_reset_all_tx_gt() currently serializes qdisc_reset() with
qdisc_lock(). However, for lockless qdiscs, the dequeue path is
serialized by qdisc_run_begin/end() using qdisc-&amp;gt;seqlock instead, so
qdisc_reset() can run concurrently with __qdisc_run() and free skbs
while they are still being dequeued, leading to UAF.</p>
<p>This can easily be reproduced on e.g. virtio-net by imposing heavy
traffic while frequently changing the number of queue pairs:</p>
<p>iperf3 -ub0 -c $peer -t 0 &amp;amp;
  while :; do
    ethtool -L eth0 combined 1
    ethtool -L eth0 combined 2
  done</p>
<p>With KASAN enabled, this leads to reports like:</p>
<p>BUG: KASAN: slab-use-after-free in __qdisc_run+0x133f/0x1760
  ...
  Call Trace:
   &amp;l…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-3701"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ssa-202008</id>
    <title>SSA-202008 — SSA-202008: Multiple Vulnerabilities in Ruggedcom Rox Before V2.17.0</title>
    <updated>2026-10-03T08:13:59.779863+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An issue was discovered in shadow 4.5. newgidmap (in shadow-utils) is setuid and allows an unprivileged user to be placed in a user namespace where setgroups(2) is permitted. This allows an attacker to remove themselves from a supplementary group, which may allow access to certain filesystem paths if the administrator has used "group blacklisting" (e.g., chmod g-rwx) to restrict access to paths. This flaw effectively reverts a security feature in the kernel (in particular, the /proc/self/setgroups knob) to prevent this sort of privilege escalation. GnuPG 2.2.4 and 2.2.5 does not enforce a configuration in which key certification requires an offline master Certify key, which results in apparently valid certifications that occurred only with access to a signing subkey. remember_Ktype in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30, allows attackers to trigger excessive memory consumption (aka OOM). This can occur during execution of cxxfilt. binutils version 2.32 and earlier contains a Integer Overflow vulnerability in objdump, bfd_get_dynamic_reloc_upper_bound,bfd_canonicalize_dynamic_reloc that can result in Integer overflow trigger heap overflow. Successful exploitation allows execution of arbitrary code.. This attack appear to be exploitable via Local. This vulnerability appears to have been fixed in after commit 3a551c7a1b80fca579461774860574eabfd7f18f. libseccomp before 2.4.0 did not correctly generate 64-bit syscall argument comparisons using the ar…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ssa-202008"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2024:2008-1</id>
    <title>SUSE-SU-2024:2008-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-03T08:13:59.780210+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2024:2008-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-47358</id>
    <title>UBUNTU-CVE-2021-47358</title>
    <updated>2026-10-03T08:13:59.780528+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:Pro:16.04:LTS: linux-oracle, Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux, Ubuntu:18.04:LTS: linux-aws, Ubuntu:18.04:LTS: linux-aws-5.4 and 101 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: staging: greybus: uart: fix tty use after free User space can hold a tty open indefinitely and tty drivers must not release the underlying structures until the last user is gone. Switch to using the tty-port reference counter to manage the life time of the greybus tty state to avoid use after free after a disconnect.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-47358"/>
  </entry>
</feed>
