<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T19:08:24.813502+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2022:7318</id>
    <title>ALSA-2022:7318 — Important: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-02T19:08:25.223789+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: bpftool, AlmaLinux:9: kernel, AlmaLinux:9: kernel-abi-stablelists, AlmaLinux:9: kernel-core, AlmaLinux:9: kernel-cross-headers, AlmaLinux:9: kernel-debug, AlmaLinux:9: kernel-debug-core, AlmaLinux:9: kernel-debug-devel, AlmaLinux:9: kernel-debug-devel-matched, AlmaLinux:9: kernel-debug-modules and 18 more</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* posix cpu timer use-after-free may lead to local privilege escalation (CVE-2022-2585)
* Unprivileged users may use PTRACE_SEIZE to set PTRACE_O_SUSPEND_SECCOMP option (CVE-2022-30594)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p>
<p>Bug Fix(es):</p>
<p>* kernel crash after reboot of T14/G2 AMD laptop (mt7921e module) (BZ#2095653)
* execve exit tracepoint not called (BZ#2106661)
* Matrox black screen on VGA output on some systems. (BZ#2112017)
* The kernel needs to offer a way to reseed the Crypto DRBG and atomically extract random numbers from it (BZ#2121129)
* watchdog BUG: soft lockup - CPU#30 stuck for 34s! [swapper/30:0] (BZ#2127857)
* Update cifs to 5.16 (BZ#2127858)
* Bad page state in process qemu-kvm  pfn:68a74600 (BZ#2127859)
* vfio zero page mappings fail after 2M instances (BZ#2128791)
* The kernel needs to offer a way to reseed the Crypto DRBG and atomically extract random numbers from it (part 2) (BZ#2128970)</p>
<p>Enhancement(s):</p>
<p>* Need to enable hpilo to support new HPE RL300 Gen11 for ARM (aarch64) (BZ#2129453)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2022:7318"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2022-05633</id>
    <title>bdu:2022-05633</title>
    <updated>2026-10-02T19:08:25.223920+00:00</updated>
    <content>bdu:2022-05633</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2022-05633"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2022-2585</id>
    <title>Withdrawn: BELL-CVE-2022-2585 — CVE-2022-2585 does not affect BellSoft software</title>
    <updated>2026-10-02T19:08:25.223949+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2022-2585"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2022-avi-740</id>
    <title>certfr-2022-avi-740 — De multiples vulnérabilités ont été découvertes dans le noyau Linux
d'Ubuntu. Certaines d'entre elles permettent à un a…</title>
    <updated>2026-10-02T19:08:25.223977+00:00</updated>
    <content>certfr-2022-avi-740</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2022-avi-740"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-161423</id>
    <title>EUVD-2026-161423</title>
    <updated>2026-10-02T19:08:25.224011+00:00</updated>
    <content>EUVD-2026-161423</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-161423"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-2585</id>
    <title>fkie_cve-2022-2585</title>
    <updated>2026-10-02T19:08:25.224032+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>It was discovered that when exec'ing from a non-leader thread, armed POSIX CPU timers would be left on a list but freed, leading to a use-after-free.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-2585"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-2585</id>
    <title>gsd-2022-2585</title>
    <updated>2026-10-02T19:08:25.224067+00:00</updated>
    <content>gsd-2022-2585</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-2585"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-23-166-10</id>
    <title>ICSA-23-166-10 — Siemens SIMATIC S7-1500 TM MFP BIOS</title>
    <updated>2026-10-02T19:08:25.224085+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The iconv program in the GNU C Library (aka glibc or libc6) 2.31 and earlier, when invoked with multiple suffixes in the destination encoding (TRANSLATE or IGNORE) along with the -c option, enters an infinite loop when processing invalid multi-byte input sequences, leading to a denial of service. The iconv feature in the GNU C Library (aka glibc or libc6) through 2.32, when processing invalid multi-byte input sequences in the EUC-KR encoding, may have a buffer over-read. A use-after-free vulnerability introduced in glibc upstream version 2.14 was found in the way the tilde expansion was carried out. Directory paths containing an initial tilde followed by a valid username were affected by this issue. A local attacker could exploit this flaw by creating a specially crafted path that, when processed by the glob function, would potentially lead to arbitrary code execution. This was fixed in version 2.32. The GNU C Library (aka glibc or libc6) before 2.32 could overflow an on-stack buffer during range reduction if an input to an 80-bit long double function contains a non-canonical bit pattern, a seen when passing a 0x5d414141414141410000 value to sinl on x86 targets. This is related to sysdeps/ieee754/ldbl-96/e_rem_pio2l.c. The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid multi-byte input sequences in IBM1364, IBM1371, IBM1388, IBM1390, and IBM1399 encodings, fails to advance the input state, which could lead to an infinite lo…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-23-166-10"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2022-2585</id>
    <title>msrc_CVE-2022-2585 — It was discovered that when exec'ing from a non-leader thread armed POSIX CPU timers would be left on a list but freed…</title>
    <updated>2026-10-02T19:08:25.224296+00:00</updated>
    <content>msrc_CVE-2022-2585</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2022-2585"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2022-1845</id>
    <title>OESA-2022-1845 — kernel security update</title>
    <updated>2026-10-02T19:08:25.224320+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS: kernel</p>
<p>Security Fix(es):

st21nfca_connectivity_event_received in drivers/nfc/st21nfca/se.c in the Linux kernel through 5.16.12 has EVT_TRANSACTION buffer overflows because of untrusted length parameters.(CVE-2022-26490)

The Linux kernel before 5.18.13 lacks a certain clear operation for the block starting symbol (.bss). This allows Xen PV guest OS users to cause a denial of service or gain privileges.(CVE-2022-36123)</p>
<p>A use-after-free flaw was found in route4_change in the net/sched/cls_route.c filter implementation in the Linux kernel. This flaw allows a local, privileged attacker to crash the system, possibly leading to a local privilege escalation issue.(CVE-2022-2588)</p>
<p>It was discovered that when exec ing from a non-leader thread, armed POSIX CPU timers would be left on a list but freed, leading to a use-after-free.(CVE-2022-2585)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2022-1845"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2022:7318</id>
    <title>RHSA-2022:7318 — Red Hat Security Advisory: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-02T19:08:25.224367+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: posix cpu timer use-after-free may lead to local privilege escalation kernel: Unprivileged users may use PTRACE_SEIZE to set PTRACE_O_SUSPEND_SECCOMP option kernel: cifs: fix handlecache and multiuser kernel: posix-cpu-timers: Cleanup CPU timers before freeing them during exec</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2022:7318"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2022:7319</id>
    <title>RHSA-2022:7319 — Red Hat Security Advisory: kernel-rt security and bug fix update</title>
    <updated>2026-10-02T19:08:25.224418+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: posix cpu timer use-after-free may lead to local privilege escalation kernel: Unprivileged users may use PTRACE_SEIZE to set PTRACE_O_SUSPEND_SECCOMP option</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2022:7319"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2022:3072-1</id>
    <title>SUSE-SU-2022:3072-1 — Security update for the Linux Kernel (Live Patch 1 for SLE 15 SP4)</title>
    <updated>2026-10-02T19:08:25.224450+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel (Live Patch 1 for SLE 15 SP4)</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2022:3072-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-2585</id>
    <title>UBUNTU-CVE-2022-2585</title>
    <updated>2026-10-02T19:08:25.224478+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-hwe and 55 more</p>
<p>It was discovered that when exec'ing from a non-leader thread, armed POSIX CPU timers would be left on a list but freed, leading to a use-after-free.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-2585"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0997</id>
    <title>WID-SEC-W-2022-0997 — Linux Kernel: Mehrere Schwachstellen ermöglichen Privilegieneskalation</title>
    <updated>2026-10-02T19:08:25.224680+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um seine Privilegien zu erhöhen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0997"/>
  </entry>
</feed>
