<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T11:21:49.998408+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-07607</id>
    <title>bdu:2024-07607</title>
    <updated>2026-10-04T11:21:50.173703+00:00</updated>
    <content>bdu:2024-07607</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-07607"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2023-52894</id>
    <title>BELL-CVE-2023-52894</title>
    <updated>2026-10-04T11:21:50.173771+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2023-52894"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0779</id>
    <title>certfr-2024-avi-0779 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
    <updated>2026-10-04T11:21:50.173800+00:00</updated>
    <content>certfr-2024-avi-0779</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0779"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-311743</id>
    <title>EUVD-2026-311743</title>
    <updated>2026-10-04T11:21:50.173818+00:00</updated>
    <content>EUVD-2026-311743</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-311743"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-52894</id>
    <title>fkie_cve-2023-52894</title>
    <updated>2026-10-04T11:21:50.173829+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>usb: gadget: f_ncm: fix potential NULL ptr deref in ncm_bitrate()</p>
<p>In Google internal bug 265639009 we've received an (as yet) unreproducible
crash report from an aarch64 GKI 5.10.149-android13 running device.</p>
<p>AFAICT the source code is at:
  https://android.googlesource.com/kernel/common/+/refs/tags/ASB-2022-12-05_13-5.10</p>
<p>The call stack is:
  ncm_close() -&gt; ncm_notify() -&gt; ncm_do_notify()
with the crash at:
  ncm_do_notify+0x98/0x270
Code: 79000d0b b9000a6c f940012a f9400269 (b9405d4b)</p>
<p>Which I believe disassembles to (I don't know ARM assembly, but it looks sane enough to me...):</p>
<p>// halfword (16-bit) store presumably to event-&gt;wLength (at offset 6 of struct usb_cdc_notification)
  0B 0D 00 79    strh w11, [x8, #6]</p>
<p>// word (32-bit) store presumably to req-&gt;Length (at offset 8 of struct usb_request)
  6C 0A 00 B9    str  w12, [x19, #8]</p>
<p>// x10 (NULL) was read here from offset 0 of valid pointer x9
  // IMHO we're reading 'cdev-&gt;gadget' and getting NULL
  // gadget is indeed at offset 0 of struct usb_composite_dev
  2A 01 40 F9    ldr  x10, [x9]</p>
<p>// loading req-&gt;buf pointer, which is at offset 0 of struct usb_request
  69 02 40 F9    ldr  x9, [x19]</p>
<p>// x10 is null, crash, appears to be attempt to read cdev-&gt;gadget-&gt;max_speed
  4B 5D 40 B9    ldr  w11, [x10, #0x5c]</p>
<p>which seems to line up with ncm_do_notify() case NCM_NOTIFY_SPEED code fragment:</p>
<p>event-&gt;wLength = cpu_to_le16(8);
  req-&gt;length =…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-52894"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-9r79-4jhv-2rfr</id>
    <title>GHSA-9r79-4jhv-2rfr</title>
    <updated>2026-10-04T11:21:50.173882+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>usb: gadget: f_ncm: fix potential NULL ptr deref in ncm_bitrate()</p>
<p>In Google internal bug 265639009 we've received an (as yet) unreproducible
crash report from an aarch64 GKI 5.10.149-android13 running device.</p>
<p>AFAICT the source code is at:
  https://android.googlesource.com/kernel/common/+/refs/tags/ASB-2022-12-05_13-5.10</p>
<p>The call stack is:
  ncm_close() -&gt; ncm_notify() -&gt; ncm_do_notify()
with the crash at:
  ncm_do_notify+0x98/0x270
Code: 79000d0b b9000a6c f940012a f9400269 (b9405d4b)</p>
<p>Which I believe disassembles to (I don't know ARM assembly, but it looks sane enough to me...):</p>
<p>// halfword (16-bit) store presumably to event-&gt;wLength (at offset 6 of struct usb_cdc_notification)
  0B 0D 00 79    strh w11, [x8, #6]</p>
<p>// word (32-bit) store presumably to req-&gt;Length (at offset 8 of struct usb_request)
  6C 0A 00 B9    str  w12, [x19, #8]</p>
<p>// x10 (NULL) was read here from offset 0 of valid pointer x9
  // IMHO we're reading 'cdev-&gt;gadget' and getting NULL
  // gadget is indeed at offset 0 of struct usb_composite_dev
  2A 01 40 F9    ldr  x10, [x9]</p>
<p>// loading req-&gt;buf pointer, which is at offset 0 of struct usb_request
  69 02 40 F9    ldr  x9, [x19]</p>
<p>// x10 is null, crash, appears to be attempt to read cdev-&gt;gadget-&gt;max_speed
  4B 5D 40 B9    ldr  w11, [x10, #0x5c]</p>
<p>which seems to line up with ncm_do_notify() case NCM_NOTIFY_SPEED code fragment:</p>
<p>event-&gt;wLength = cpu_to_le16(8);
  req-&gt;length =…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-9r79-4jhv-2rfr"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2024-2122</id>
    <title>OESA-2024-2122 — kernel security update</title>
    <updated>2026-10-04T11:21:50.173922+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP4: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):

In the Linux kernel, the following vulnerability has been resolved:

ibmvnic: free reset-work-item when flushing

Fix a tiny memory leak when flushing the reset work queue.(CVE-2022-48905)

In the Linux kernel, the following vulnerability has been resolved:

xen/netfront: destroy queues before real_num_tx_queues is zeroed

xennet_destroy_queues() relies on info-&amp;gt;netdev-&amp;gt;real_num_tx_queues to
delete queues. Since d7dac083414eb5bb99a6d2ed53dc2c1b405224e5
(&amp;quot;net-sysfs: update the queue counts in the unregistration path&amp;quot;),
unregister_netdev() indirectly sets real_num_tx_queues to 0. Those two
facts together means, that xennet_destroy_queues() called from
xennet_remove() cannot do its job, because it&amp;apos;s called after
unregister_netdev(). This results in kfree-ing queues that are still
linked in napi, which ultimately crashes:

    BUG: kernel NULL pointer dereference, address: 0000000000000000
    #PF: supervisor read access in kernel mode
    #PF: error_code(0x0000) - not-present page
    PGD 0 P4D 0
    Oops: 0000 [#1] PREEMPT SMP PTI
    CPU: 1 PID: 52 Comm: xenwatch Tainted: G        W         5.16.10-1.32.fc32.qubes.x86_64+ #226
    RIP: 0010:free_netdev+0xa3/0x1a0
    Code: ff 48 89 df e8 2e e9 00 00 48 8b 43 50 48 8b 08 48 8d b8 a0 fe ff ff 48 8d a9 a0 fe ff ff 49 39 c4 75 26 eb 47 e8 ed c1 66 ff &amp;lt;48&amp;gt; 8b 85 60 01 00 00 48 8d 95 60 01 00 00 48 89 ef 48 2d 60 01 00…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2024-2122"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2024:3190-1</id>
    <title>SUSE-SU-2024:3190-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-04T11:21:50.174011+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2024:3190-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-52894</id>
    <title>UBUNTU-CVE-2023-52894</title>
    <updated>2026-10-04T11:21:50.174197+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:Pro:16.04:LTS: linux-oracle, Ubuntu:Pro:16.04:LTS: linux and 147 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_ncm: fix potential NULL ptr deref in ncm_bitrate() In Google internal bug 265639009 we've received an (as yet) unreproducible crash report from an aarch64 GKI 5.10.149-android13 running device. AFAICT the source code is at: https://android.googlesource.com/kernel/common/+/refs/tags/ASB-2022-12-05_13-5.10 The call stack is:   ncm_close() -&gt; ncm_notify() -&gt; ncm_do_notify() with the crash at:   ncm_do_notify+0x98/0x270 Code: 79000d0b b9000a6c f940012a f9400269 (b9405d4b) Which I believe disassembles to (I don't know ARM assembly, but it looks sane enough to me...):   // halfword (16-bit) store presumably to event-&gt;wLength (at offset 6 of struct usb_cdc_notification)   0B 0D 00 79    strh w11, [x8, #6]   // word (32-bit) store presumably to req-&gt;Length (at offset 8 of struct usb_request)   6C 0A 00 B9    str  w12, [x19, #8]   // x10 (NULL) was read here from offset 0 of valid pointer x9   // IMHO we're reading 'cdev-&gt;gadget' and getting NULL   // gadget is indeed at offset 0 of struct usb_composite_dev   2A 01 40 F9    ldr  x10, [x9]   // loading req-&gt;buf pointer, which is at offset 0 of struct usb_request   69 02 40 F9    ldr  x9, [x19]   // x10 is null, crash, appears to be attempt to read cdev-&gt;gadget-&gt;max_speed   4B 5D 40 B9    ldr  w11, [x10, #0x5c] which seems to line up with ncm_do_notify() case NCM_NOTIFY_SPEED code fragment:   event-&gt;wLength = cpu_to_le16(8);   req-&gt;length = NCM_STATUS_BY…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-52894"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1888</id>
    <title>WID-SEC-W-2024-1888 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-04T11:21:50.174411+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann mehrere Schwachstellen im Linux-Kernel ausnutzen, um einen Denial-of-Service-Zustand zu erzeugen oder einen unspezifischen Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1888"/>
  </entry>
</feed>
