<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T07:09:21.741361+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-10579</id>
    <title>bdu:2025-10579</title>
    <updated>2026-10-03T07:09:22.351112+00:00</updated>
    <content>bdu:2025-10579</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-10579"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0252</id>
    <title>certfr-2025-avi-0252 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
    <updated>2026-10-03T07:09:22.351197+00:00</updated>
    <content>certfr-2025-avi-0252</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0252"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-344722</id>
    <title>EUVD-2026-344722</title>
    <updated>2026-10-03T07:09:22.351249+00:00</updated>
    <content>EUVD-2026-344722</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-344722"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-49377</id>
    <title>fkie_cve-2022-49377</title>
    <updated>2026-10-03T07:09:22.351270+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>blk-mq: don't touch -&gt;tagset in blk_mq_get_sq_hctx</p>
<p>blk_mq_run_hw_queues() could be run when there isn't queued request and
after queue is cleaned up, at that time tagset is freed, because tagset
lifetime is covered by driver, and often freed after blk_cleanup_queue()
returns.</p>
<p>So don't touch -&gt;tagset for figuring out current default hctx by the mapping
built in request queue, so use-after-free on tagset can be avoided. Meantime
this way should be fast than retrieving mapping from tagset.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-49377"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-4v4x-mh67-4m6p</id>
    <title>GHSA-4v4x-mh67-4m6p</title>
    <updated>2026-10-03T07:09:22.351337+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>blk-mq: don't touch -&gt;tagset in blk_mq_get_sq_hctx</p>
<p>blk_mq_run_hw_queues() could be run when there isn't queued request and
after queue is cleaned up, at that time tagset is freed, because tagset
lifetime is covered by driver, and often freed after blk_cleanup_queue()
returns.</p>
<p>So don't touch -&gt;tagset for figuring out current default hctx by the mapping
built in request queue, so use-after-free on tagset can be avoided. Meantime
this way should be fast than retrieving mapping from tagset.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-4v4x-mh67-4m6p"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-2081</id>
    <title>OESA-2025-2081 — kernel security update</title>
    <updated>2026-10-03T07:09:22.351377+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP3: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>blk-mq: don&amp;apos;t touch -&amp;gt;tagset in blk_mq_get_sq_hctx</p>
<p>blk_mq_run_hw_queues() could be run when there isn&amp;apos;t queued request and
after queue is cleaned up, at that time tagset is freed, because tagset
lifetime is covered by driver, and often freed after blk_cleanup_queue()
returns.</p>
<p>So don&amp;apos;t touch -&amp;gt;tagset for figuring out current default hctx by the mapping
built in request queue, so use-after-free on tagset can be avoided. Meantime
this way should be fast than retrieving mapping from tagset.(CVE-2022-49377)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>macsec: fix UAF bug for real_dev</p>
<p>Create a new macsec device but not get reference to real_dev. That can
not ensure that real_dev is freed after macsec. That will trigger the
UAF bug for real_dev as following:</p>
<p>==================================================================
BUG: KASAN: use-after-free in macsec_get_iflink+0x5f/0x70 drivers/net/macsec.c:3662
Call Trace:
 ...
 macsec_get_iflink+0x5f/0x70 drivers/net/macsec.c:3662
 dev_get_iflink+0x73/0xe0 net/core/dev.c:637
 default_operstate net/core/link_watch.c:42 [inline]
 rfc2863_policy+0x233/0x2d0 net/core/link_watch.c:54
 linkwatch_do_dev+0x2a/0x150 net/core/link_watch.c:161</p>
<p>Allocated by task 22209:
 ...
 alloc_netdev_mqs+0x98/0x1100 net/core/dev.c:10549
 rtnl_create_link+0x9d7/0xc00 net…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-2081"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:10174</id>
    <title>RHSA-2025:10174 — Red Hat Security Advisory: kernel security update</title>
    <updated>2026-10-03T07:09:22.351665+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: Bluetooth: Fix use after free in hci_send_acl kernel: scsi: libfc: Fix use after free in fc_exch_abts_resp() kernel: blk-mq: don't touch -&gt;tagset in blk_mq_get_sq_hctx kernel: dlm: fix plock invalid read Kernel: use-after-free in nfsd4_ssc_setup_dul in fs/nfsd/nfs4proc.c</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:10174"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:1176-1</id>
    <title>SUSE-SU-2025:1176-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-03T07:09:22.351711+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:1176-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-49377</id>
    <title>UBUNTU-CVE-2022-49377</title>
    <updated>2026-10-03T07:09:22.352177+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 92 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: blk-mq: don't touch -&gt;tagset in blk_mq_get_sq_hctx blk_mq_run_hw_queues() could be run when there isn't queued request and after queue is cleaned up, at that time tagset is freed, because tagset lifetime is covered by driver, and often freed after blk_cleanup_queue() returns. So don't touch -&gt;tagset for figuring out current default hctx by the mapping built in request queue, so use-after-free on tagset can be avoided. Meantime this way should be fast than retrieving mapping from tagset.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-49377"/>
  </entry>
</feed>
