<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T15:51:26.702356+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2024:4928</id>
    <title>ALSA-2024:4928 — Moderate: kernel security update</title>
    <updated>2026-10-02T15:51:27.112405+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: bpftool, AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core and 52 more</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: block: null pointer dereference in ioctl.c when length and logical block size are misaligned (CVE-2023-52458)
  * kernel: ext4: avoid allocating blocks from corrupted group in ext4_mb_try_best_found() (CVE-2024-26773)
  * kernel: bpf: Fix racing between bpf_timer_cancel_and_free and bpf_timer_cancel (CVE-2024-26737)
  * kernel: dm: call the resume method on internal suspend (CVE-2024-26880)
  * kernel: net/ipv6: avoid possible UAF in ip6_route_mpath_notify() (CVE-2024-26852)
  * kernel: Squashfs: check the inode number is not the invalid value of zero (CVE-2024-26982)
  * kernel: nfp: flower: handle acti_netdevs allocation failure (CVE-2024-27046)
  * kernel: octeontx2-af: Use separate handlers for interrupts (CVE-2024-27030)
  * kernel: icmp: prevent possible NULL dereferences from icmp_build_probe() (CVE-2024-35857)
  * kernel: mlxbf_gige: call request_irq() after NAPI initialized (CVE-2024-35907)
  * kernel: mlxbf_gige: stop interface during shutdown (CVE-2024-35885)
  * kernel: scsi: libfc: Fix potential NULL pointer dereference in fc_lport_ptp_setup() (CVE-2023-52809)
  * kernel: can: j1939: j1939_netdev_start(): fix UAF for rx_kref of j1939_priv (CVE-2021-47459)
  * kernel: scsi: lpfc: Release hbalock before calling lpfc_worker_wake_up() (CVE-2024-36924)
  * kernel: scsi: lpfc: Move NPIV's transport unregistration to after resource clean up (CVE-202…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2024:4928"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-04446</id>
    <title>bdu:2025-04446</title>
    <updated>2026-10-02T15:51:27.112645+00:00</updated>
    <content>bdu:2025-04446</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-04446"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0578</id>
    <title>certfr-2024-avi-0578 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
    <updated>2026-10-02T15:51:27.112675+00:00</updated>
    <content>certfr-2024-avi-0578</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0578"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-344571</id>
    <title>EUVD-2026-344571</title>
    <updated>2026-10-02T15:51:27.112702+00:00</updated>
    <content>EUVD-2026-344571</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-344571"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-48743</id>
    <title>fkie_cve-2022-48743</title>
    <updated>2026-10-02T15:51:27.112721+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>net: amd-xgbe: Fix skb data length underflow</p>
<p>There will be BUG_ON() triggered in include/linux/skbuff.h leading to
intermittent kernel panic, when the skb length underflow is detected.</p>
<p>Fix this by dropping the packet if such length underflows are seen
because of inconsistencies in the hardware descriptors.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-48743"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-hj37-jcv3-rcw4</id>
    <title>GHSA-hj37-jcv3-rcw4</title>
    <updated>2026-10-02T15:51:27.112761+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>net: amd-xgbe: Fix skb data length underflow</p>
<p>There will be BUG_ON() triggered in include/linux/skbuff.h leading to
intermittent kernel panic, when the skb length underflow is detected.</p>
<p>Fix this by dropping the packet if such length underflows are seen
because of inconsistencies in the hardware descriptors.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-hj37-jcv3-rcw4"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2024-1835</id>
    <title>OESA-2024-1835 — kernel security update</title>
    <updated>2026-10-02T15:51:27.112789+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP4: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):

In the Linux kernel, the following vulnerability has been resolved:

usb: fix various gadgets null ptr deref on 10gbps cabling.

This avoids a null pointer dereference in
f_{ecm,eem,hid,loopback,printer,rndis,serial,sourcesink,subset,tcm}
by simply reusing the 5gbps config for 10gbps.(CVE-2021-47270)

In the Linux kernel, the following vulnerability has been resolved:

seg6: fix the iif in the IPv6 socket control block

When an IPv4 packet is received, the ip_rcv_core(...) sets the receiving
interface index into the IPv4 socket control block (v5.16-rc4,
net/ipv4/ip_input.c line 510):

    IPCB(skb)-&amp;gt;iif = skb-&amp;gt;skb_iif;

If that IPv4 packet is meant to be encapsulated in an outer IPv6+SRH
header, the seg6_do_srh_encap(...) performs the required encapsulation.
In this case, the seg6_do_srh_encap function clears the IPv6 socket control
block (v5.16-rc4 net/ipv6/seg6_iptunnel.c line 163):

    memset(IP6CB(skb), 0, sizeof(*IP6CB(skb)));

The memset(...) was introduced in commit ef489749aae5 (&amp;quot;ipv6: sr: clear
IP6CB(skb) on SRH ip4ip6 encapsulation&amp;quot;) a long time ago (2019-01-29).

Since the IPv6 socket control block and the IPv4 socket control block share
the same memory area (skb-&amp;gt;cb), the receiving interface index info is lost
(IP6CB(skb)-&amp;gt;iif is set to zero).

As a side effect, that condition triggers a NULL pointer dereference if
commit 0857d6f8c759 (&amp;quot;ip…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2024-1835"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:4823</id>
    <title>RHSA-2024:4823 — Red Hat Security Advisory: kernel security update</title>
    <updated>2026-10-02T15:51:27.113259+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: can: j1939: j1939_netdev_start(): fix UAF for rx_kref of j1939_priv kernel: vmwgfx: integer overflow in vmwgfx_execbuf.c kernel: vmwgfx: use-after-free in vmw_cmd_res_check kernel: vmwgfx: use-after-free in vmw_execbuf_tie_context kernel: net: amd-xgbe: Fix skb data length underflow kernel: vmwgfx: reference count issue leads to use-after-free in surface handling kernel: vmwgfx: race condition leading to information disclosure vulnerability kernel: vmwgfx: double free within the handling of vmw_buffer_object objects kernel: smb: client: fix potential OOBs in smb2_parse_contexts() kernel: uio: Fix use-after-free in uio_open kernel: intel: Fix NULL pointer dereference issue in upi_fill_topology() kernel: Bluetooth: hci_codec: Fix leaking content of local_codecs kernel: net: bridge: data races indata-races in br_handle_frame_finish() kernel: sched/psi: Fix use-after-free in ep_remove_wait_queue() kernel: scsi: ibmvfc: Remove BUG_ON in the case of an empty event pool kernel: blk-cgroup: Reinit blkg_iostat_set after clearing in blkcg_reset_stats() kernel: stack overflow problem in Open vSwitch kernel module leading to DoS kernel: nftables: nft_set_rbtree skip end interval element from gc kernel: netfilter: nft_limit: reject configurations that cause integer overflow kernel: hv_netvsc: Fix race condition between netvsc_probe and netvsc_remove kernel: ext4: fix double-free of blocks due to wrong extents moved_len kernel: net/sched: act_mirred: don't override retval if we al…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:4823"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:4928</id>
    <title>RHSA-2024:4928 — Red Hat Security Advisory: kernel security update</title>
    <updated>2026-10-02T15:51:27.113379+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: can: j1939: j1939_netdev_start(): fix UAF for rx_kref of j1939_priv kernel: net: amd-xgbe: Fix skb data length underflow kernel: block: null pointer dereference in ioctl.c when length and logical block size are misaligned kernel: scsi: libfc: Fix potential NULL pointer dereference in fc_lport_ptp_setup() kernel: bpf: Fix racing between bpf_timer_cancel_and_free and bpf_timer_cancel kernel: ext4: avoid allocating blocks from corrupted group in ext4_mb_try_best_found() kernel: net/ipv6: avoid possible UAF in ip6_route_mpath_notify() kernel: dm: call the resume method on internal suspend kernel: Squashfs: check the inode number is not the invalid value of zero kernel: octeontx2-af: race condition on interupts kernel: nfp: flower: handle acti_netdevs allocation failure kernel: icmp: prevent possible NULL dereferences from icmp_build_probe() kernel: mlxbf_gige: stop interface during shutdown kernel: mlxbf_gige: call request_irq() after NAPI initialized kernel: drm/ast: Fix soft lockup kernel: scsi: lpfc: Release hbalock before calling lpfc_worker_wake_up() kernel: scsi: lpfc: Move NPIV's transport unregistration to after resource clean up kernel: epoll: be better about file lifetimes</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:4928"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2024:2360-1</id>
    <title>SUSE-SU-2024:2360-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-02T15:51:27.113431+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2024:2360-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-48743</id>
    <title>UBUNTU-CVE-2022-48743</title>
    <updated>2026-10-02T15:51:27.113536+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:Pro:16.04:LTS: linux-oracle, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws and 110 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: net: amd-xgbe: Fix skb data length underflow There will be BUG_ON() triggered in include/linux/skbuff.h leading to intermittent kernel panic, when the skb length underflow is detected. Fix this by dropping the packet if such length underflows are seen because of inconsistencies in the hardware descriptors.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-48743"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1422</id>
    <title>WID-SEC-W-2024-1422 — Linux Kernel: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff</title>
    <updated>2026-10-02T15:51:27.113721+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1422"/>
  </entry>
</feed>
