<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T10:42:47.564119+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-07714</id>
    <title>bdu:2025-07714</title>
    <updated>2026-10-03T10:42:48.673510+00:00</updated>
    <content>bdu:2025-07714</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-07714"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2023-52775</id>
    <title>BELL-CVE-2023-52775</title>
    <updated>2026-10-03T10:42:48.673613+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2023-52775"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0668</id>
    <title>certfr-2024-avi-0668 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Red Hat. Certaines d'entre elles permettent à un…</title>
    <updated>2026-10-03T10:42:48.673667+00:00</updated>
    <content>certfr-2024-avi-0668</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0668"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-345063</id>
    <title>EUVD-2026-345063</title>
    <updated>2026-10-03T10:42:48.673695+00:00</updated>
    <content>EUVD-2026-345063</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-345063"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-52775</id>
    <title>fkie_cve-2023-52775</title>
    <updated>2026-10-03T10:42:48.673714+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>net/smc: avoid data corruption caused by decline</p>
<p>We found a data corruption issue during testing of SMC-R on Redis
applications.</p>
<p>The benchmark has a low probability of reporting a strange error as
shown below.</p>
<p>"Error: Protocol error, got "\xe2" as reply type byte"</p>
<p>Finally, we found that the retrieved error data was as follows:</p>
<p>0xE2 0xD4 0xC3 0xD9 0x04 0x00 0x2C 0x20 0xA6 0x56 0x00 0x16 0x3E 0x0C
0xCB 0x04 0x02 0x01 0x00 0x00 0x20 0x00 0x00 0x00 0x00 0x00 0x00 0x00
0x00 0x00 0x00 0x00 0x00 0x00 0x00 0x00 0x00 0x00 0xE2</p>
<p>It is quite obvious that this is a SMC DECLINE message, which means that
the applications received SMC protocol message.
We found that this was caused by the following situations:</p>
<p>client                  server
        ¦  clc proposal
        -------------&gt;
        ¦  clc accept
        &lt;-------------
        ¦  clc confirm
        -------------&gt;
wait llc confirm
			send llc confirm
        ¦failed llc confirm
        ¦   x------
(after 2s)timeout
                        wait llc confirm rsp</p>
<p>wait decline</p>
<p>(after 1s) timeout
                        (after 2s) timeout
        ¦   decline
        --------------&gt;
        ¦   decline
        &lt;--------------</p>
<p>As a result, a decline message was sent in the implementation, and this
message was read from TCP by the already-fallback connection.</p>
<p>This patch double the client timeout as 2x of the server value,
With this simple change, the Decline…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-52775"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-mxqp-c4m3-mg6r</id>
    <title>GHSA-mxqp-c4m3-mg6r</title>
    <updated>2026-10-03T10:42:48.673795+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>net/smc: avoid data corruption caused by decline</p>
<p>We found a data corruption issue during testing of SMC-R on Redis
applications.</p>
<p>The benchmark has a low probability of reporting a strange error as
shown below.</p>
<p>"Error: Protocol error, got "\xe2" as reply type byte"</p>
<p>Finally, we found that the retrieved error data was as follows:</p>
<p>0xE2 0xD4 0xC3 0xD9 0x04 0x00 0x2C 0x20 0xA6 0x56 0x00 0x16 0x3E 0x0C
0xCB 0x04 0x02 0x01 0x00 0x00 0x20 0x00 0x00 0x00 0x00 0x00 0x00 0x00
0x00 0x00 0x00 0x00 0x00 0x00 0x00 0x00 0x00 0x00 0xE2</p>
<p>It is quite obvious that this is a SMC DECLINE message, which means that
the applications received SMC protocol message.
We found that this was caused by the following situations:</p>
<p>client                  server
        ¦  clc proposal
        -------------&gt;
        ¦  clc accept
        &lt;-------------
        ¦  clc confirm
        -------------&gt;
wait llc confirm
			send llc confirm
        ¦failed llc confirm
        ¦   x------
(after 2s)timeout
                        wait llc confirm rsp</p>
<p>wait decline</p>
<p>(after 1s) timeout
                        (after 2s) timeout
        ¦   decline
        --------------&gt;
        ¦   decline
        &lt;--------------</p>
<p>As a result, a decline message was sent in the implementation, and this
message was read from TCP by the already-fallback connection.</p>
<p>This patch double the client timeout as 2x of the server value,
With this simple change, the Decline…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-mxqp-c4m3-mg6r"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2024-1706</id>
    <title>OESA-2024-1706 — kernel security update</title>
    <updated>2026-10-03T10:42:48.673867+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP1: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):

In the Linux kernel, the following vulnerability has been resolved:

net/mlx5e: Fix use-after-free of encap entry in neigh update handler

Function mlx5e_rep_neigh_update() wasn&amp;apos;t updated to accommodate rtnl lock
removal from TC filter update path and properly handle concurrent encap
entry insertion/deletion which can lead to following use-after-free:

 [23827.464923] ==================================================================
 [23827.469446] BUG: KASAN: use-after-free in mlx5e_encap_take+0x72/0x140 [mlx5_core]
 [23827.470971] Read of size 4 at addr ffff8881d132228c by task kworker/u20:6/21635
 [23827.472251]
 [23827.472615] CPU: 9 PID: 21635 Comm: kworker/u20:6 Not tainted 5.13.0-rc3+ #5
 [23827.473788] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014
 [23827.475639] Workqueue: mlx5e mlx5e_rep_neigh_update [mlx5_core]
 [23827.476731] Call Trace:
 [23827.477260]  dump_stack+0xbb/0x107
 [23827.477906]  print_address_description.constprop.0+0x18/0x140
 [23827.478896]  ? mlx5e_encap_take+0x72/0x140 [mlx5_core]
 [23827.479879]  ? mlx5e_encap_take+0x72/0x140 [mlx5_core]
 [23827.480905]  kasan_report.cold+0x7c/0xd8
 [23827.481701]  ? mlx5e_encap_take+0x72/0x140 [mlx5_core]
 [23827.482744]  kasan_check_range+0x145/0x1a0
 [23827.493112]  mlx5e_encap_take+0x72/0x140 [mlx5_core]
 [23827.494054]  ? mlx5e_tc_tun_encap_info_equal_ge…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2024-1706"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:10771</id>
    <title>RHSA-2024:10771 — Red Hat Security Advisory: kernel security update</title>
    <updated>2026-10-03T10:42:48.674526+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: vt_ioctl: fix array_index_nospec in vt_setactivate kernel: pstore/ram: Fix crash when setting number of cpus to an odd number kernel: PM / devfreq: Synchronize devfreq_monitor_[start/stop] kernel: net/smc: avoid data corruption caused by decline kernel: scsi: ibmvfc: Remove BUG_ON in the case of an empty event pool kernel: ext4: allow ext4_get_group_info() to fail kernel: ext4: correct grp validation in ext4_mb_good_group kernel: ext4: regenerate buddy after block freeing failed if under fc replay kernel: net/smc: fix illegal rmb_desc access in SMC-D connection dump kernel: fs/proc: do_task_stat: use sig-&gt;stats_lock to gather the threads/children stats kernel: ext4: fix double-free of blocks due to wrong extents moved_len kernel: Bluetooth: l2cap: fix null-ptr-deref in l2cap_chan_timeout kernel: s390/qeth: Fix kernel panic after setting hsuid kernel: drm/vmwgfx: Fix invalid reads in fence signaled events kernel: blk-cgroup: fix list corruption from reorder of WRITE -&amp;gt;lqueued kernel: of: module: add buffer overflow check in of_modalias() kernel: net/mlx5: Discard command completions in internal error kernel: net: hns3: fix kernel crash problem in concurrent scenario kernel: cpufreq: amd-pstate: fix memory leak on CPU EPP exit kernel: tcp: avoid too many retransmit packets kernel: drm/amdgpu: change vm-&amp;gt;task_info handling kernel: bpf: Fix overrunning reservations in ringbuf kernel: mm/filemap: skip to create PMD-sized page cache if needed kernel: firmware: cs_dsp…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:10771"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:5101</id>
    <title>RHSA-2024:5101 — Red Hat Security Advisory: kernel security update</title>
    <updated>2026-10-03T10:42:48.674648+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: tracing: Restructure trace_clock_global() to never block kernel: ensure definition of the fixmap area is in a limit kernel: net: ieee802154: fix null deref in parse dev addr kernel: isdn: mISDN: netjet: Fix crash in nj_probe kernel: tcp: fix tcp_init_transfer() to not reset icsk_ca_initialized kernel: irqchip/gic-v3-its: Fix potential VPE leak on error kernel: netfilter: conntrack: serialize hash resizes and cleanups kernel: userfaultfd: fix a race between writeprotect and exit_mmap() kernel: isdn: mISDN: Fix sleeping function called from invalid context kernel: mm: khugepaged: skip huge page collapse for special files kernel: ethernet: hisilicon: hns: hns_dsaf_misc: fix a possible array overflow in hns_dsaf_ge_srst_by_port() kernel: ovl: fix warning in ovl_create_real() kernel: net/sunrpc: fix reference count leaks in rpc_sysfs_xprt_state_change kernel: i2c: mlxbf: prevent stack overflow in mlxbf_i2c_smbus_start_transaction() kernel: net: amd-xgbe: Fix skb data length underflow kernel: block: Fix wrong offset in bio_truncate() kernel: net: fix information leakage in /proc/net/ptype kernel: cifs: Fix memory leak when build ntlmssp negotiate blob failed kernel: x86/xen: Fix memory leak in xen_smp_intr_init{_pv}() kernel: Local information disclosure on Intel(R) Atom(R) processors kernel: powerpc: Fix access beyond end of drmem array kernel: efivarfs: force RO when remounting if SetVariable is not supported kernel: use-after-free in kv_parse_power_table kernel: null po…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:5101"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2024:2802-1</id>
    <title>SUSE-SU-2024:2802-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-03T10:42:48.675027+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2024:2802-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-52775</id>
    <title>UBUNTU-CVE-2023-52775</title>
    <updated>2026-10-03T10:42:48.675148+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 103 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: net/smc: avoid data corruption caused by decline We found a data corruption issue during testing of SMC-R on Redis applications. The benchmark has a low probability of reporting a strange error as shown below. "Error: Protocol error, got "\xe2" as reply type byte" Finally, we found that the retrieved error data was as follows: 0xE2 0xD4 0xC3 0xD9 0x04 0x00 0x2C 0x20 0xA6 0x56 0x00 0x16 0x3E 0x0C 0xCB 0x04 0x02 0x01 0x00 0x00 0x20 0x00 0x00 0x00 0x00 0x00 0x00 0x00 0x00 0x00 0x00 0x00 0x00 0x00 0x00 0x00 0x00 0x00 0xE2 It is quite obvious that this is a SMC DECLINE message, which means that the applications received SMC protocol message. We found that this was caused by the following situations: client                  server         ¦  clc proposal         -------------&gt;         ¦  clc accept         &lt;-------------         ¦  clc confirm         -------------&gt; wait llc confirm 			send llc confirm         ¦failed llc confirm         ¦   x------ (after 2s)timeout                         wait llc confirm rsp wait decline (after 1s) timeout                         (after 2s) timeout         ¦   decline         --------------&gt;         ¦   decline         &lt;-------------- As a result, a decline message was sent in the implementation, and this message was read from TCP by the already-fallback connection. This patch double the client timeout as 2x of the server value, With this simple change, the Decline messages sho…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-52775"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1197</id>
    <title>WID-SEC-W-2024-1197 — Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service und unspezifische Angriffe</title>
    <updated>2026-10-03T10:42:48.675458+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann mehrere Schwachstellen im Linux-Kernel ausnutzen, um einen Denial-of-Service-Zustand zu erzeugen oder unspezifische Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1197"/>
  </entry>
</feed>
