<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T19:41:39.594026+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-12403</id>
    <title>bdu:2026-12403</title>
    <updated>2026-10-02T19:41:39.877949+00:00</updated>
    <content>bdu:2026-12403</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-12403"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2023-53586</id>
    <title>BELL-CVE-2023-53586</title>
    <updated>2026-10-02T19:41:39.877991+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2023-53586"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-345255</id>
    <title>EUVD-2026-345255</title>
    <updated>2026-10-02T19:41:39.878018+00:00</updated>
    <content>EUVD-2026-345255</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-345255"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-53586</id>
    <title>fkie_cve-2023-53586</title>
    <updated>2026-10-02T19:41:39.878031+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>scsi: target: Fix multiple LUN_RESET handling</p>
<p>This fixes a bug where an initiator thinks a LUN_RESET has cleaned up
running commands when it hasn't. The bug was added in commit 51ec502a3266
("target: Delete tmr from list before processing").</p>
<p>The problem occurs when:</p>
<p>1. We have N I/O cmds running in the target layer spread over 2 sessions.</p>
<p>2. The initiator sends a LUN_RESET for each session.</p>
<p>3. session1's LUN_RESET loops over all the running commands from both
    sessions and moves them to its local drain_task_list.</p>
<p>4. session2's LUN_RESET does not see the LUN_RESET from session1 because
    the commit above has it remove itself. session2 also does not see any
    commands since the other reset moved them off the state lists.</p>
<p>5. sessions2's LUN_RESET will then complete with a successful response.</p>
<p>6. sessions2's inititor believes the running commands on its session are
    now cleaned up due to the successful response and cleans up the running
    commands from its side. It then restarts them.</p>
<p>7. The commands do eventually complete on the backend and the target
    starts to return aborted task statuses for them. The initiator will
    either throw a invalid ITT error or might accidentally lookup a new
    task if the ITT has been reallocated already.</p>
<p>Fix the bug by reverting the patch, and serialize the execution of
LUN_RESETs and Preempt and Aborts.</p>
<p>Also prevent us from waiting on LUN_RES…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-53586"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-8mqg-3fc7-qr47</id>
    <title>GHSA-8mqg-3fc7-qr47</title>
    <updated>2026-10-02T19:41:39.878081+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>scsi: target: Fix multiple LUN_RESET handling</p>
<p>This fixes a bug where an initiator thinks a LUN_RESET has cleaned up
running commands when it hasn't. The bug was added in commit 51ec502a3266
("target: Delete tmr from list before processing").</p>
<p>The problem occurs when:</p>
<p>1. We have N I/O cmds running in the target layer spread over 2 sessions.</p>
<p>2. The initiator sends a LUN_RESET for each session.</p>
<p>3. session1's LUN_RESET loops over all the running commands from both
    sessions and moves them to its local drain_task_list.</p>
<p>4. session2's LUN_RESET does not see the LUN_RESET from session1 because
    the commit above has it remove itself. session2 also does not see any
    commands since the other reset moved them off the state lists.</p>
<p>5. sessions2's LUN_RESET will then complete with a successful response.</p>
<p>6. sessions2's inititor believes the running commands on its session are
    now cleaned up due to the successful response and cleans up the running
    commands from its side. It then restarts them.</p>
<p>7. The commands do eventually complete on the backend and the target
    starts to return aborted task statuses for them. The initiator will
    either throw a invalid ITT error or might accidentally lookup a new
    task if the ITT has been reallocated already.</p>
<p>Fix the bug by reverting the patch, and serialize the execution of
LUN_RESETs and Preempt and Aborts.</p>
<p>Also prevent us from waiting on LUN_RES…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-8mqg-3fc7-qr47"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:2394</id>
    <title>RHSA-2024:2394 — Red Hat Security Advisory: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-02T19:41:39.878118+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: Bluetooth BR/EDR PIN Pairing procedure is vulnerable to an impersonation attack kernel: ovl: fix warning in ovl_create_real() kernel: memcg does not limit the number of POSIX file locks allowing memory exhaustion kernel: vmwgfx: NULL pointer dereference in vmw_cmd_dx_define_query kernel: integer overflow in l2cap_config_req() in net/bluetooth/l2cap_core.c kernel: i2c: mlxbf: prevent stack overflow in mlxbf_i2c_smbus_start_transaction() kernel: Bluetooth: L2CAP: Fix u8 overflow kernel: hwmon: (coretemp) fix pci device refcount leak in nv1a_ram_new() kernel: tracing: Fix sleeping function called from invalid context on RT kernel kernel: net: mdio: unexport __init-annotated mdio_bus_init() kernel: arm64: ftrace: consistently handle PLTs. kernel: mm/uffd: fix pte marker when fork() without fork event kernel: Bluetooth: Fix a buffer overflow in mgmt_mesh_add() kernel: tty: n_gsm: add sanity check for gsm-&gt;receive in gsm_receive_buf() kernel: ftrace: Fix NULL pointer dereference in is_ftrace_trampoline when ftrace is dead kernel: tee: add overflow check in register_shm_helper() kernel: tty: n_gsm: fix deadlock and link starvation in outgoing data path kernel: PM: hibernate: defer device probing when resuming from hibernation kernel: ext4: don't allow journal inode to have encrypt flag kernel: ext4: fix delayed allocation bug in ext4_clu_mapped for bigalloc + inline kernel: erofs: fix order &gt;= MAX_ORDER warning due to crafted negative i_size kernel: perf/x86/intel/uncore: F…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:2394"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rxsa-2024:3138</id>
    <title>RXSA-2024:3138 — Moderate: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-02T19:41:39.878622+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:8: kernel</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p>
<p>Additional Changes:</p>
<p>For detailed information on changes in this release, see the Rocky Linux SIG Cloud 8.10 Release Notes linked from the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rxsa-2024:3138"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-53586</id>
    <title>UBUNTU-CVE-2023-53586</title>
    <updated>2026-10-02T19:41:39.878650+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:Pro:16.04:LTS: linux-oracle, Ubuntu:Pro:18.04:LTS: linux, Ubuntu:Pro:18.04:LTS: linux-aws, Ubuntu:18.04:LTS: linux-aws-5.0 and 155 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: scsi: target: Fix multiple LUN_RESET handling This fixes a bug where an initiator thinks a LUN_RESET has cleaned up running commands when it hasn't. The bug was added in commit 51ec502a3266 ("target: Delete tmr from list before processing"). The problem occurs when:  1. We have N I/O cmds running in the target layer spread over 2 sessions.  2. The initiator sends a LUN_RESET for each session.  3. session1's LUN_RESET loops over all the running commands from both     sessions and moves them to its local drain_task_list.  4. session2's LUN_RESET does not see the LUN_RESET from session1 because     the commit above has it remove itself. session2 also does not see any     commands since the other reset moved them off the state lists.  5. sessions2's LUN_RESET will then complete with a successful response.  6. sessions2's inititor believes the running commands on its session are     now cleaned up due to the successful response and cleans up the running     commands from its side. It then restarts them.  7. The commands do eventually complete on the backend and the target     starts to return aborted task statuses for them. The initiator will     either throw a invalid ITT error or might accidentally lookup a new     task if the ITT has been reallocated already. Fix the bug by reverting the patch, and serialize the execution of LUN_RESETs and Preempt and Aborts. Also prevent us from waiting on LUN_RESETs in core_…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-53586"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2194</id>
    <title>WID-SEC-W-2025-2194 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-02T19:41:39.878871+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um nicht näher spezifizierte Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2194"/>
  </entry>
</feed>
