<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T20:33:06.500009+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2025:19102</id>
    <title>ALSA-2025:19102 — Moderate: kernel security update</title>
    <updated>2026-10-02T20:33:07.108550+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: bpftool, AlmaLinux:8: kernel, AlmaLinux:8: kernel-abi-stablelists, AlmaLinux:8: kernel-core, AlmaLinux:8: kernel-cross-headers, AlmaLinux:8: kernel-debug, AlmaLinux:8: kernel-debug-core, AlmaLinux:8: kernel-debug-devel, AlmaLinux:8: kernel-debug-modules, AlmaLinux:8: kernel-debug-modules-extra and 15 more</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: Bluetooth: L2CAP: fix "bad unlock balance" in l2cap_disconnect_rsp (CVE-2023-53297)
  * kernel: efivarfs: Fix slab-out-of-bounds in efivarfs_d_compare (CVE-2025-39817)
  * kernel: Bluetooth: Fix potential use-after-free when clear keys (CVE-2023-53386)
  * kernel: Bluetooth: L2CAP: Fix user-after-free (CVE-2022-50386)
  * kernel: wifi: cfg80211: sme: cap SSID length in __cfg80211_connect_result() (CVE-2025-39849)
  * kernel: scsi: lpfc: Fix buffer free/clear order in deferred receive path (CVE-2025-39841)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2025:19102"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-03330</id>
    <title>bdu:2026-03330</title>
    <updated>2026-10-02T20:33:07.108691+00:00</updated>
    <content>bdu:2026-03330</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-03330"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2023-53386</id>
    <title>BELL-CVE-2023-53386</title>
    <updated>2026-10-02T20:33:07.108712+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2023-53386"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0895</id>
    <title>certfr-2025-avi-0895 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
    <updated>2026-10-02T20:33:07.108735+00:00</updated>
    <content>certfr-2025-avi-0895</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0895"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-345198</id>
    <title>EUVD-2026-345198</title>
    <updated>2026-10-02T20:33:07.108752+00:00</updated>
    <content>EUVD-2026-345198</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-345198"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-53386</id>
    <title>fkie_cve-2023-53386</title>
    <updated>2026-10-02T20:33:07.108764+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>Bluetooth: Fix potential use-after-free when clear keys</p>
<p>Similar to commit c5d2b6fa26b5 ("Bluetooth: Fix use-after-free in
hci_remove_ltk/hci_remove_irk"). We can not access k after kfree_rcu()
call.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-53386"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-m38w-46xg-v336</id>
    <title>GHSA-m38w-46xg-v336</title>
    <updated>2026-10-02T20:33:07.108789+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>Bluetooth: Fix potential use-after-free when clear keys</p>
<p>Similar to commit c5d2b6fa26b5 ("Bluetooth: Fix use-after-free in
hci_remove_ltk/hci_remove_irk"). We can not access k after kfree_rcu()
call.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-m38w-46xg-v336"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-2349</id>
    <title>OESA-2025-2349 — kernel security update</title>
    <updated>2026-10-02T20:33:07.108806+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP3: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>tracing: Fix reading strings from synthetic events</p>
<p>The follow commands caused a crash:</p>
<p># cd /sys/kernel/tracing
  # echo &amp;apos;s:open char file[]&amp;apos; &amp;gt; dynamic_events
  # echo &amp;apos;hist:keys=common_pid:file=filename:onchange($file).trace(open,$file)&amp;apos; &amp;gt; events/syscalls/sys_enter_openat/trigger&amp;apos;
  # echo 1 &amp;gt; events/synthetic/open/enable</p>
<p>BOOM!</p>
<p>The problem is that the synthetic event field &amp;quot;char file[]&amp;quot; will read
the value given to it as a string without any memory checks to make sure
the address is valid. The above example will pass in the user space
address and the sythetic event code will happily call strlen() on it
and then strscpy() where either one will cause an oops when accessing
user space addresses.</p>
<p>Use the helper functions from trace_kprobe and trace_eprobe that can
read strings safely (and actually succeed when the address is from user
space and the memory is mapped in).</p>
<p>Now the above can show:</p>
<p>packagekitd-1721    [000] ...2.   104.597170: open: file=/usr/lib/rpm/fileattrs/cmake.attr
    in:imjournal-978     [006] ...2.   104.599642: open: file=/var/lib/rsyslog/imjournal.state.tmp
     packagekitd-1721    [000] ...2.   104.626308: open: file=/usr/lib/rpm/fileattrs/debuginfo.attr(CVE-2022-50255)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>kprobes: Fix check…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-2349"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:19102</id>
    <title>RHSA-2025:19102 — Red Hat Security Advisory: kernel security update</title>
    <updated>2026-10-02T20:33:07.108896+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: Bluetooth: L2CAP: Fix user-after-free kernel: Bluetooth: L2CAP: fix "bad unlock balance" in l2cap_disconnect_rsp kernel: Bluetooth: Fix potential use-after-free when clear keys kernel: x86/mm: Fix flush_tlb_range() when used for zapping normal PMDs kernel: efivarfs: Fix slab-out-of-bounds in efivarfs_d_compare kernel: scsi: lpfc: Fix buffer free/clear order in deferred receive path kernel: wifi: cfg80211: sme: cap SSID length in __cfg80211_connect_result()</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:19102"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:19103</id>
    <title>RHSA-2025:19103 — Red Hat Security Advisory: kernel-rt security update</title>
    <updated>2026-10-02T20:33:07.108933+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: Bluetooth: L2CAP: Fix user-after-free kernel: Bluetooth: L2CAP: fix "bad unlock balance" in l2cap_disconnect_rsp kernel: Bluetooth: Fix potential use-after-free when clear keys kernel: efivarfs: Fix slab-out-of-bounds in efivarfs_d_compare kernel: scsi: lpfc: Fix buffer free/clear order in deferred receive path kernel: wifi: cfg80211: sme: cap SSID length in __cfg80211_connect_result()</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:19103"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:03600-1</id>
    <title>SUSE-SU-2025:03600-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-02T20:33:07.108961+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:03600-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-53386</id>
    <title>UBUNTU-CVE-2023-53386</title>
    <updated>2026-10-02T20:33:07.109194+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 115 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Fix potential use-after-free when clear keys Similar to commit c5d2b6fa26b5 ("Bluetooth: Fix use-after-free in hci_remove_ltk/hci_remove_irk"). We can not access k after kfree_rcu() call.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-53386"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2092</id>
    <title>WID-SEC-W-2025-2092 — Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service</title>
    <updated>2026-10-02T20:33:07.109336+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen und um nicht nähere beschriebene Effekte zu verursachen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2092"/>
  </entry>
</feed>
