<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T19:08:53.421387+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-08403</id>
    <title>bdu:2024-08403</title>
    <updated>2026-10-03T19:08:53.919134+00:00</updated>
    <content>bdu:2024-08403</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-08403"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2023-52493</id>
    <title>BELL-CVE-2023-52493</title>
    <updated>2026-10-03T19:08:53.919194+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2023-52493"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0329</id>
    <title>certfr-2024-avi-0329 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;le noyau Linux de SUSE&lt;/span&gt;. Certaines d'en…</title>
    <updated>2026-10-03T19:08:53.919245+00:00</updated>
    <content>certfr-2024-avi-0329</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0329"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-311537</id>
    <title>EUVD-2026-311537</title>
    <updated>2026-10-03T19:08:53.919265+00:00</updated>
    <content>EUVD-2026-311537</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-311537"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-52493</id>
    <title>fkie_cve-2023-52493</title>
    <updated>2026-10-03T19:08:53.919276+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>bus: mhi: host: Drop chan lock before queuing buffers</p>
<p>Ensure read and write locks for the channel are not taken in succession by
dropping the read lock from parse_xfer_event() such that a callback given
to client can potentially queue buffers and acquire the write lock in that
process. Any queueing of buffers should be done without channel read lock
acquired as it can result in multiple locks and a soft lockup.</p>
<p>[mani: added fixes tag and cc'ed stable]</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-52493"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-7vjh-prmq-cfm3</id>
    <title>GHSA-7vjh-prmq-cfm3</title>
    <updated>2026-10-03T19:08:53.919306+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>bus: mhi: host: Drop chan lock before queuing buffers</p>
<p>Ensure read and write locks for the channel are not taken in succession by
dropping the read lock from parse_xfer_event() such that a callback given
to client can potentially queue buffers and acquire the write lock in that
process. Any queueing of buffers should be done without channel read lock
acquired as it can result in multiple locks and a soft lockup.</p>
<p>[mani: added fixes tag and cc'ed stable]</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-7vjh-prmq-cfm3"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-52493</id>
    <title>gsd-2023-52493</title>
    <updated>2026-10-03T19:08:53.919325+00:00</updated>
    <content>gsd-2023-52493</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-52493"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2024-1498</id>
    <title>OESA-2024-1498 — kernel security update</title>
    <updated>2026-10-03T19:08:53.919335+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):

In the Linux kernel, the following vulnerability has been resolved:

crypto: qcom-rng - ensure buffer for generate is completely filled

The generate function in struct rng_alg expects that the destination
buffer is completely filled if the function returns 0. qcom_rng_read()
can run into a situation where the buffer is partially filled with
randomness and the remaining part of the buffer is zeroed since
qcom_rng_generate() doesn&amp;apos;t check the return value. This issue can
be reproduced by running the following from libkcapi:

    kcapi-rng -b 9000000 &amp;gt; OUTFILE

The generated OUTFILE will have three huge sections that contain all
zeros, and this is caused by the code where the test
&amp;apos;val &amp;amp; PRNG_STATUS_DATA_AVAIL&amp;apos; fails.

Let&amp;apos;s fix this issue by ensuring that qcom_rng_read() always returns
with a full buffer if the function returns success. Let&amp;apos;s also have
qcom_rng_generate() return the correct value.

Here&amp;apos;s some statistics from the ent project
(https://www.fourmilab.ch/random/) that shows information about the
quality of the generated numbers:

    $ ent -c qcom-random-before
    Value Char Occurrences Fraction
      0           606748   0.067416
      1            33104   0.003678
      2            33001   0.003667
    ...
    253   �        32883   0.003654
    254   �        33035   0.003671
    255   �        33239   0.003693

    Total:       90…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2024-1498"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2024:1466-1</id>
    <title>SUSE-SU-2024:1466-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-03T19:08:53.919490+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2024:1466-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-52493</id>
    <title>UBUNTU-CVE-2023-52493</title>
    <updated>2026-10-03T19:08:53.919600+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 104 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: bus: mhi: host: Drop chan lock before queuing buffers Ensure read and write locks for the channel are not taken in succession by dropping the read lock from parse_xfer_event() such that a callback given to client can potentially queue buffers and acquire the write lock in that process. Any queueing of buffers should be done without channel read lock acquired as it can result in multiple locks and a soft lockup. [mani: added fixes tag and cc'ed stable]</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-52493"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0527</id>
    <title>WID-SEC-W-2024-0527 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-03T19:08:53.919759+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Zustand zu verursachen und einen nicht näher spezifizierten Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0527"/>
  </entry>
</feed>
