<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T22:14:22.055150+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-04559</id>
    <title>bdu:2026-04559</title>
    <updated>2026-10-03T22:14:22.246593+00:00</updated>
    <content>bdu:2026-04559</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-04559"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0587</id>
    <title>certfr-2025-avi-0587 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
    <updated>2026-10-03T22:14:22.246659+00:00</updated>
    <content>certfr-2025-avi-0587</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0587"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-310952</id>
    <title>EUVD-2026-310952</title>
    <updated>2026-10-03T22:14:22.246689+00:00</updated>
    <content>EUVD-2026-310952</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-310952"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-50008</id>
    <title>fkie_cve-2022-50008</title>
    <updated>2026-10-03T22:14:22.246708+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>kprobes: don't call disarm_kprobe() for disabled kprobes</p>
<p>The assumption in __disable_kprobe() is wrong, and it could try to disarm
an already disarmed kprobe and fire the WARN_ONCE() below. [0]  We can
easily reproduce this issue.</p>
<p>1. Write 0 to /sys/kernel/debug/kprobes/enabled.</p>
<p># echo 0 &gt; /sys/kernel/debug/kprobes/enabled</p>
<p>2. Run execsnoop.  At this time, one kprobe is disabled.</p>
<p># /usr/share/bcc/tools/execsnoop &amp;
  [1] 2460
  PCOMM            PID    PPID   RET ARGS</p>
<p># cat /sys/kernel/debug/kprobes/list
  ffffffff91345650  r  __x64_sys_execve+0x0    [FTRACE]
  ffffffff91345650  k  __x64_sys_execve+0x0    [DISABLED][FTRACE]</p>
<p>3. Write 1 to /sys/kernel/debug/kprobes/enabled, which changes
   kprobes_all_disarmed to false but does not arm the disabled kprobe.</p>
<p># echo 1 &gt; /sys/kernel/debug/kprobes/enabled</p>
<p># cat /sys/kernel/debug/kprobes/list
  ffffffff91345650  r  __x64_sys_execve+0x0    [FTRACE]
  ffffffff91345650  k  __x64_sys_execve+0x0    [DISABLED][FTRACE]</p>
<p>4. Kill execsnoop, when __disable_kprobe() calls disarm_kprobe() for the
   disabled kprobe and hits the WARN_ONCE() in __disarm_kprobe_ftrace().</p>
<p># fg
  /usr/share/bcc/tools/execsnoop
  ^C</p>
<p>Actually, WARN_ONCE() is fired twice, and __unregister_kprobe_top() misses
some cleanups and leaves the aggregated kprobe in the hash table.  Then,
__unregister_trace_kprobe() initialises tk-&gt;rp.kp.list and creates an
infinite loop like this.</p>
<p>aggr…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-50008"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-q44m-58pc-8rr7</id>
    <title>GHSA-q44m-58pc-8rr7</title>
    <updated>2026-10-03T22:14:22.246803+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>kprobes: don't call disarm_kprobe() for disabled kprobes</p>
<p>The assumption in __disable_kprobe() is wrong, and it could try to disarm
an already disarmed kprobe and fire the WARN_ONCE() below. [0]  We can
easily reproduce this issue.</p>
<p>1. Write 0 to /sys/kernel/debug/kprobes/enabled.</p>
<p># echo 0 &gt; /sys/kernel/debug/kprobes/enabled</p>
<p>2. Run execsnoop.  At this time, one kprobe is disabled.</p>
<p># /usr/share/bcc/tools/execsnoop &amp;
  [1] 2460
  PCOMM            PID    PPID   RET ARGS</p>
<p># cat /sys/kernel/debug/kprobes/list
  ffffffff91345650  r  __x64_sys_execve+0x0    [FTRACE]
  ffffffff91345650  k  __x64_sys_execve+0x0    [DISABLED][FTRACE]</p>
<p>3. Write 1 to /sys/kernel/debug/kprobes/enabled, which changes
   kprobes_all_disarmed to false but does not arm the disabled kprobe.</p>
<p># echo 1 &gt; /sys/kernel/debug/kprobes/enabled</p>
<p># cat /sys/kernel/debug/kprobes/list
  ffffffff91345650  r  __x64_sys_execve+0x0    [FTRACE]
  ffffffff91345650  k  __x64_sys_execve+0x0    [DISABLED][FTRACE]</p>
<p>4. Kill execsnoop, when __disable_kprobe() calls disarm_kprobe() for the
   disabled kprobe and hits the WARN_ONCE() in __disarm_kprobe_ftrace().</p>
<p># fg
  /usr/share/bcc/tools/execsnoop
  ^C</p>
<p>Actually, WARN_ONCE() is fired twice, and __unregister_kprobe_top() misses
some cleanups and leaves the aggregated kprobe in the hash table.  Then,
__unregister_trace_kprobe() initialises tk-&gt;rp.kp.list and creates an
infinite loop like this.</p>
<p>aggr…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-q44m-58pc-8rr7"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:02264-1</id>
    <title>SUSE-SU-2025:02264-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-03T22:14:22.246878+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:02264-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-50008</id>
    <title>UBUNTU-CVE-2022-50008</title>
    <updated>2026-10-03T22:14:22.247084+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:Pro:16.04:LTS: linux-oracle, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws and 145 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: kprobes: don't call disarm_kprobe() for disabled kprobes The assumption in __disable_kprobe() is wrong, and it could try to disarm an already disarmed kprobe and fire the WARN_ONCE() below. [0]  We can easily reproduce this issue. 1. Write 0 to /sys/kernel/debug/kprobes/enabled.   # echo 0 &gt; /sys/kernel/debug/kprobes/enabled 2. Run execsnoop.  At this time, one kprobe is disabled.   # /usr/share/bcc/tools/execsnoop &amp;   [1] 2460   PCOMM            PID    PPID   RET ARGS   # cat /sys/kernel/debug/kprobes/list   ffffffff91345650  r  __x64_sys_execve+0x0    [FTRACE]   ffffffff91345650  k  __x64_sys_execve+0x0    [DISABLED][FTRACE] 3. Write 1 to /sys/kernel/debug/kprobes/enabled, which changes    kprobes_all_disarmed to false but does not arm the disabled kprobe.   # echo 1 &gt; /sys/kernel/debug/kprobes/enabled   # cat /sys/kernel/debug/kprobes/list   ffffffff91345650  r  __x64_sys_execve+0x0    [FTRACE]   ffffffff91345650  k  __x64_sys_execve+0x0    [DISABLED][FTRACE] 4. Kill execsnoop, when __disable_kprobe() calls disarm_kprobe() for the    disabled kprobe and hits the WARN_ONCE() in __disarm_kprobe_ftrace().   # fg   /usr/share/bcc/tools/execsnoop   ^C Actually, WARN_ONCE() is fired twice, and __unregister_kprobe_top() misses some cleanups and leaves the aggregated kprobe in the hash table.  Then, __unregister_trace_kprobe() initialises tk-&gt;rp.kp.list and creates an infinite loop like this.   aggregated kprobe.…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-50008"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1350</id>
    <title>WID-SEC-W-2025-1350 — Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service</title>
    <updated>2026-10-03T22:14:22.247450+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1350"/>
  </entry>
</feed>
