<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T16:27:12.117422+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-05878</id>
    <title>bdu:2026-05878</title>
    <updated>2026-10-02T16:27:12.138770+00:00</updated>
    <content>bdu:2026-05878</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-05878"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2023-53240</id>
    <title>BELL-CVE-2023-53240</title>
    <updated>2026-10-02T16:27:12.138813+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2023-53240"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-1070</id>
    <title>certfr-2025-avi-1070 — De multiples vulnérabilités ont été découvertes dans Microsoft CBL Mariner. Elles permettent à un attaquant de provoque…</title>
    <updated>2026-10-02T16:27:12.138841+00:00</updated>
    <content>certfr-2025-avi-1070</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-1070"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-320471</id>
    <title>EUVD-2026-320471</title>
    <updated>2026-10-02T16:27:12.138859+00:00</updated>
    <content>EUVD-2026-320471</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-320471"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-53240</id>
    <title>fkie_cve-2023-53240</title>
    <updated>2026-10-02T16:27:12.138870+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>xsk: check IFF_UP earlier in Tx path</p>
<p>Xsk Tx can be triggered via either sendmsg() or poll() syscalls. These
two paths share a call to common function xsk_xmit() which has two
sanity checks within. A pseudo code example to show the two paths:</p>
<p>__xsk_sendmsg() :                       xsk_poll():
if (unlikely(!xsk_is_bound(xs)))        if (unlikely(!xsk_is_bound(xs)))
    return -ENXIO;                          return mask;
if (unlikely(need_wait))                (...)
    return -EOPNOTSUPP;                 xsk_xmit()
mark napi id
(...)
xsk_xmit()</p>
<p>xsk_xmit():
if (unlikely(!(xs-&gt;dev-&gt;flags &amp; IFF_UP)))
	return -ENETDOWN;
if (unlikely(!xs-&gt;tx))
	return -ENOBUFS;</p>
<p>As it can be observed above, in sendmsg() napi id can be marked on
interface that was not brought up and this causes a NULL ptr
dereference:</p>
<p>[31757.505631] BUG: kernel NULL pointer dereference, address: 0000000000000018
[31757.512710] #PF: supervisor read access in kernel mode
[31757.517936] #PF: error_code(0x0000) - not-present page
[31757.523149] PGD 0 P4D 0
[31757.525726] Oops: 0000 [#1] PREEMPT SMP NOPTI
[31757.530154] CPU: 26 PID: 95641 Comm: xdpsock Not tainted 6.2.0-rc5+ #40
[31757.536871] Hardware name: Intel Corporation S2600WFT/S2600WFT, BIOS SE5C620.86B.02.01.0008.031920191559 03/19/2019
[31757.547457] RIP: 0010:xsk_sendmsg+0xde/0x180
[31757.551799] Code: 00 75 a2 48 8b 00 a8 04 75 9b 84 d2 74 69 8b 85 14 01 00 00 85 c0 75 1b 48 8b 85 28 0…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-53240"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-5qr9-cjj5-7m79</id>
    <title>GHSA-5qr9-cjj5-7m79</title>
    <updated>2026-10-02T16:27:12.138921+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>xsk: check IFF_UP earlier in Tx path</p>
<p>Xsk Tx can be triggered via either sendmsg() or poll() syscalls. These
two paths share a call to common function xsk_xmit() which has two
sanity checks within. A pseudo code example to show the two paths:</p>
<p>__xsk_sendmsg() :                       xsk_poll():
if (unlikely(!xsk_is_bound(xs)))        if (unlikely(!xsk_is_bound(xs)))
    return -ENXIO;                          return mask;
if (unlikely(need_wait))                (...)
    return -EOPNOTSUPP;                 xsk_xmit()
mark napi id
(...)
xsk_xmit()</p>
<p>xsk_xmit():
if (unlikely(!(xs-&gt;dev-&gt;flags &amp; IFF_UP)))
	return -ENETDOWN;
if (unlikely(!xs-&gt;tx))
	return -ENOBUFS;</p>
<p>As it can be observed above, in sendmsg() napi id can be marked on
interface that was not brought up and this causes a NULL ptr
dereference:</p>
<p>[31757.505631] BUG: kernel NULL pointer dereference, address: 0000000000000018
[31757.512710] #PF: supervisor read access in kernel mode
[31757.517936] #PF: error_code(0x0000) - not-present page
[31757.523149] PGD 0 P4D 0
[31757.525726] Oops: 0000 [#1] PREEMPT SMP NOPTI
[31757.530154] CPU: 26 PID: 95641 Comm: xdpsock Not tainted 6.2.0-rc5+ #40
[31757.536871] Hardware name: Intel Corporation S2600WFT/S2600WFT, BIOS SE5C620.86B.02.01.0008.031920191559 03/19/2019
[31757.547457] RIP: 0010:xsk_sendmsg+0xde/0x180
[31757.551799] Code: 00 75 a2 48 8b 00 a8 04 75 9b 84 d2 74 69 8b 85 14 01 00 00 85 c0 75 1b 48 8b 85 28 0…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-5qr9-cjj5-7m79"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2023-53240</id>
    <title>msrc_CVE-2023-53240 — xsk: check IFF_UP earlier in Tx path</title>
    <updated>2026-10-02T16:27:12.138960+00:00</updated>
    <content>msrc_CVE-2023-53240</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2023-53240"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:1441</id>
    <title>RHSA-2026:1441 — Red Hat Security Advisory: kernel security update</title>
    <updated>2026-10-02T16:27:12.138978+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: Linux kernel: Information disclosure and denial of service in ntb_hw_switchtec module kernel: xsk: check IFF_UP earlier in Tx path kernel: drm/i915: mark requests for GuC virtual engines to avoid use-after-free kernel: net/mlx5e: Check for NOT_READY flag state after locking kernel: ipv6: Fix out-of-bounds access in ipv6_find_tlv() kernel: Linux kernel: iommufd/iova_bitmap shift-out-of-bounds vulnerability kernel: Linux kernel: SCTP use-after-free due to race condition in sendmsg kernel: Linux kernel (openvswitch): Denial of Service and limited data exposure via improper key length validation kernel: KVM: arm64: Tear down vGIC on failed vCPU creation kernel: e1000e: fix heap overflow in e1000_set_eeprom kernel: i40e: fix idx validation in config queues msg kernel: Bluetooth: ISO: Fix possible UAF on iso_conn_free kernel: ASoC: Intel: bytcr_rt5640: Fix invalid quirk input mapping kernel: drm/vmwgfx: Validate command header size against SVGA_CMD_MAX_DATASIZE</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:1441"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-53240</id>
    <title>UBUNTU-CVE-2023-53240</title>
    <updated>2026-10-02T16:27:12.139018+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 117 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: xsk: check IFF_UP earlier in Tx path Xsk Tx can be triggered via either sendmsg() or poll() syscalls. These two paths share a call to common function xsk_xmit() which has two sanity checks within. A pseudo code example to show the two paths: __xsk_sendmsg() :                       xsk_poll(): if (unlikely(!xsk_is_bound(xs)))        if (unlikely(!xsk_is_bound(xs)))     return -ENXIO;                          return mask; if (unlikely(need_wait))                (...)     return -EOPNOTSUPP;                 xsk_xmit() mark napi id (...) xsk_xmit() xsk_xmit(): if (unlikely(!(xs-&gt;dev-&gt;flags &amp; IFF_UP))) 	return -ENETDOWN; if (unlikely(!xs-&gt;tx)) 	return -ENOBUFS; As it can be observed above, in sendmsg() napi id can be marked on interface that was not brought up and this causes a NULL ptr dereference: [31757.505631] BUG: kernel NULL pointer dereference, address: 0000000000000018 [31757.512710] #PF: supervisor read access in kernel mode [31757.517936] #PF: error_code(0x0000) - not-present page [31757.523149] PGD 0 P4D 0 [31757.525726] Oops: 0000 [#1] PREEMPT SMP NOPTI [31757.530154] CPU: 26 PID: 95641 Comm: xdpsock Not tainted 6.2.0-rc5+ #40 [31757.536871] Hardware name: Intel Corporation S2600WFT/S2600WFT, BIOS SE5C620.86B.02.01.0008.031920191559 03/19/2019 [31757.547457] RIP: 0010:xsk_sendmsg+0xde/0x180 [31757.551799] Code: 00 75 a2 48 8b 00 a8 04 75 9b 84 d2 74 69 8b 85 14 01 00 00 85 c0 75 1b 48 8b 85 28 03 00 0…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-53240"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2053</id>
    <title>WID-SEC-W-2025-2053 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-02T16:27:12.139205+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder nicht näher beschriebene Auswirkungen zu erzielen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2053"/>
  </entry>
</feed>
