<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T22:08:35.078954+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-08871</id>
    <title>bdu:2026-08871</title>
    <updated>2026-10-02T22:08:35.336092+00:00</updated>
    <content>bdu:2026-08871</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-08871"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0108</id>
    <title>certfr-2026-avi-0108 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
    <updated>2026-10-02T22:08:35.336160+00:00</updated>
    <content>certfr-2026-avi-0108</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0108"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-311459</id>
    <title>EUVD-2026-311459</title>
    <updated>2026-10-02T22:08:35.336183+00:00</updated>
    <content>EUVD-2026-311459</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-311459"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-50828</id>
    <title>fkie_cve-2022-50828</title>
    <updated>2026-10-02T22:08:35.336196+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>clk: zynqmp: Fix stack-out-of-bounds in strncpy`</p>
<p>"BUG: KASAN: stack-out-of-bounds in strncpy+0x30/0x68"</p>
<p>Linux-ATF interface is using 16 bytes of SMC payload. In case clock name is
longer than 15 bytes, string terminated NULL character will not be received
by Linux. Add explicit NULL character at last byte to fix issues when clock
name is longer.</p>
<p>This fixes below bug reported by KASAN:</p>
<p>==================================================================
 BUG: KASAN: stack-out-of-bounds in strncpy+0x30/0x68
 Read of size 1 at addr ffff0008c89a7410 by task swapper/0/1</p>
<p>CPU: 1 PID: 1 Comm: swapper/0 Not tainted 5.4.0-00396-g81ef9e7-dirty #3
 Hardware name: Xilinx Versal vck190 Eval board revA (QSPI) (DT)
 Call trace:
  dump_backtrace+0x0/0x1e8
  show_stack+0x14/0x20
  dump_stack+0xd4/0x108
  print_address_description.isra.0+0xbc/0x37c
  __kasan_report+0x144/0x198
  kasan_report+0xc/0x18
  __asan_load1+0x5c/0x68
  strncpy+0x30/0x68
  zynqmp_clock_probe+0x238/0x7b8
  platform_drv_probe+0x6c/0xc8
  really_probe+0x14c/0x418
  driver_probe_device+0x74/0x130
  __device_attach_driver+0xc4/0xe8
  bus_for_each_drv+0xec/0x150
  __device_attach+0x160/0x1d8
  device_initial_probe+0x10/0x18
  bus_probe_device+0xe0/0xf0
  device_add+0x528/0x950
  of_device_add+0x5c/0x80
  of_platform_device_create_pdata+0x120/0x168
  of_platform_bus_create+0x244/0x4e0
  of_platform_populate+0x50/0xe8
  zynqmp_firmware_probe+0x370/0x3a8…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-50828"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-m8pm-m36r-6prw</id>
    <title>GHSA-m8pm-m36r-6prw</title>
    <updated>2026-10-02T22:08:35.336252+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>clk: zynqmp: Fix stack-out-of-bounds in strncpy`</p>
<p>"BUG: KASAN: stack-out-of-bounds in strncpy+0x30/0x68"</p>
<p>Linux-ATF interface is using 16 bytes of SMC payload. In case clock name is
longer than 15 bytes, string terminated NULL character will not be received
by Linux. Add explicit NULL character at last byte to fix issues when clock
name is longer.</p>
<p>This fixes below bug reported by KASAN:</p>
<p>==================================================================
 BUG: KASAN: stack-out-of-bounds in strncpy+0x30/0x68
 Read of size 1 at addr ffff0008c89a7410 by task swapper/0/1</p>
<p>CPU: 1 PID: 1 Comm: swapper/0 Not tainted 5.4.0-00396-g81ef9e7-dirty #3
 Hardware name: Xilinx Versal vck190 Eval board revA (QSPI) (DT)
 Call trace:
  dump_backtrace+0x0/0x1e8
  show_stack+0x14/0x20
  dump_stack+0xd4/0x108
  print_address_description.isra.0+0xbc/0x37c
  __kasan_report+0x144/0x198
  kasan_report+0xc/0x18
  __asan_load1+0x5c/0x68
  strncpy+0x30/0x68
  zynqmp_clock_probe+0x238/0x7b8
  platform_drv_probe+0x6c/0xc8
  really_probe+0x14c/0x418
  driver_probe_device+0x74/0x130
  __device_attach_driver+0xc4/0xe8
  bus_for_each_drv+0xec/0x150
  __device_attach+0x160/0x1d8
  device_initial_probe+0x10/0x18
  bus_probe_device+0xe0/0xf0
  device_add+0x528/0x950
  of_device_add+0x5c/0x80
  of_platform_device_create_pdata+0x120/0x168
  of_platform_bus_create+0x244/0x4e0
  of_platform_populate+0x50/0xe8
  zynqmp_firmware_probe+0x370/0x3a8…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-m8pm-m36r-6prw"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:0263-1</id>
    <title>SUSE-SU-2026:0263-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-02T22:08:35.336290+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:0263-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-50828</id>
    <title>UBUNTU-CVE-2022-50828</title>
    <updated>2026-10-02T22:08:35.336570+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 156 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: clk: zynqmp: Fix stack-out-of-bounds in strncpy` "BUG: KASAN: stack-out-of-bounds in strncpy+0x30/0x68" Linux-ATF interface is using 16 bytes of SMC payload. In case clock name is longer than 15 bytes, string terminated NULL character will not be received by Linux. Add explicit NULL character at last byte to fix issues when clock name is longer. This fixes below bug reported by KASAN:  ==================================================================  BUG: KASAN: stack-out-of-bounds in strncpy+0x30/0x68  Read of size 1 at addr ffff0008c89a7410 by task swapper/0/1  CPU: 1 PID: 1 Comm: swapper/0 Not tainted 5.4.0-00396-g81ef9e7-dirty #3  Hardware name: Xilinx Versal vck190 Eval board revA (QSPI) (DT)  Call trace:   dump_backtrace+0x0/0x1e8   show_stack+0x14/0x20   dump_stack+0xd4/0x108   print_address_description.isra.0+0xbc/0x37c   __kasan_report+0x144/0x198   kasan_report+0xc/0x18   __asan_load1+0x5c/0x68   strncpy+0x30/0x68   zynqmp_clock_probe+0x238/0x7b8   platform_drv_probe+0x6c/0xc8   really_probe+0x14c/0x418   driver_probe_device+0x74/0x130   __device_attach_driver+0xc4/0xe8   bus_for_each_drv+0xec/0x150   __device_attach+0x160/0x1d8   device_initial_probe+0x10/0x18   bus_probe_device+0xe0/0xf0   device_add+0x528/0x950   of_device_add+0x5c/0x80   of_platform_device_create_pdata+0x120/0x168   of_platform_bus_create+0x244/0x4e0   of_platform_populate+0x50/0xe8   zynqmp_firmware_probe+0x370/0x3a8   platf…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-50828"/>
  </entry>
</feed>
