<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T11:55:29.428050+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-04110</id>
    <title>bdu:2026-04110</title>
    <updated>2026-10-03T11:55:29.808319+00:00</updated>
    <content>bdu:2026-04110</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-04110"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2023-53659</id>
    <title>BELL-CVE-2023-53659</title>
    <updated>2026-10-03T11:55:29.808387+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2023-53659"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-1009</id>
    <title>certfr-2025-avi-1009 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Elles permettent à un attaquant de provoqu…</title>
    <updated>2026-10-03T11:55:29.808420+00:00</updated>
    <content>certfr-2025-avi-1009</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-1009"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-345279</id>
    <title>EUVD-2026-345279</title>
    <updated>2026-10-03T11:55:29.808439+00:00</updated>
    <content>EUVD-2026-345279</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-345279"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-53659</id>
    <title>fkie_cve-2023-53659</title>
    <updated>2026-10-03T11:55:29.808450+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>iavf: Fix out-of-bounds when setting channels on remove</p>
<p>If we set channels greater during iavf_remove(), and waiting reset done
would be timeout, then returned with error but changed num_active_queues
directly, that will lead to OOB like the following logs. Because the
num_active_queues is greater than tx/rx_rings[] allocated actually.</p>
<p>Reproducer:</p>
<p>[root@host ~]# cat repro.sh
  #!/bin/bash</p>
<p>pf_dbsf="0000:41:00.0"
  vf0_dbsf="0000:41:02.0"
  g_pids=()</p>
<p>function do_set_numvf()
  {
      echo 2 &gt;/sys/bus/pci/devices/${pf_dbsf}/sriov_numvfs
      sleep $((RANDOM%3+1))
      echo 0 &gt;/sys/bus/pci/devices/${pf_dbsf}/sriov_numvfs
      sleep $((RANDOM%3+1))
  }</p>
<p>function do_set_channel()
  {
      local nic=$(ls -1 --indicator-style=none /sys/bus/pci/devices/${vf0_dbsf}/net/)
      [ -z "$nic" ] &amp;&amp; { sleep $((RANDOM%3)) ; return 1; }
      ifconfig $nic 192.168.18.5 netmask 255.255.255.0
      ifconfig $nic up
      ethtool -L $nic combined 1
      ethtool -L $nic combined 4
      sleep $((RANDOM%3))
  }</p>
<p>function on_exit()
  {
      local pid
      for pid in "${g_pids[@]}"; do
          kill -0 "$pid" &amp;&gt;/dev/null &amp;&amp; kill "$pid" &amp;&gt;/dev/null
      done
      g_pids=()
  }</p>
<p>trap "on_exit; exit" EXIT</p>
<p>while :; do do_set_numvf ; done &amp;
  g_pids+=($!)
  while :; do do_set_channel ; done &amp;
  g_pids+=($!)</p>
<p>wait</p>
<p>Result:</p>
<p>[ 3506.152887] iavf 0000:41:02.0: Removing device
[ 3510.400799] ==================…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-53659"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-h9wv-v64w-rmq6</id>
    <title>GHSA-h9wv-v64w-rmq6</title>
    <updated>2026-10-03T11:55:29.808512+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>iavf: Fix out-of-bounds when setting channels on remove</p>
<p>If we set channels greater during iavf_remove(), and waiting reset done
would be timeout, then returned with error but changed num_active_queues
directly, that will lead to OOB like the following logs. Because the
num_active_queues is greater than tx/rx_rings[] allocated actually.</p>
<p>Reproducer:</p>
<p>[root@host ~]# cat repro.sh
  #!/bin/bash</p>
<p>pf_dbsf="0000:41:00.0"
  vf0_dbsf="0000:41:02.0"
  g_pids=()</p>
<p>function do_set_numvf()
  {
      echo 2 &gt;/sys/bus/pci/devices/${pf_dbsf}/sriov_numvfs
      sleep $((RANDOM%3+1))
      echo 0 &gt;/sys/bus/pci/devices/${pf_dbsf}/sriov_numvfs
      sleep $((RANDOM%3+1))
  }</p>
<p>function do_set_channel()
  {
      local nic=$(ls -1 --indicator-style=none /sys/bus/pci/devices/${vf0_dbsf}/net/)
      [ -z "$nic" ] &amp;&amp; { sleep $((RANDOM%3)) ; return 1; }
      ifconfig $nic 192.168.18.5 netmask 255.255.255.0
      ifconfig $nic up
      ethtool -L $nic combined 1
      ethtool -L $nic combined 4
      sleep $((RANDOM%3))
  }</p>
<p>function on_exit()
  {
      local pid
      for pid in "${g_pids[@]}"; do
          kill -0 "$pid" &amp;&gt;/dev/null &amp;&amp; kill "$pid" &amp;&gt;/dev/null
      done
      g_pids=()
  }</p>
<p>trap "on_exit; exit" EXIT</p>
<p>while :; do do_set_numvf ; done &amp;
  g_pids+=($!)
  while :; do do_set_channel ; done &amp;
  g_pids+=($!)</p>
<p>wait</p>
<p>Result:</p>
<p>[ 3506.152887] iavf 0000:41:02.0: Removing device
[ 3510.400799] ==================…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-h9wv-v64w-rmq6"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:21040-1</id>
    <title>SUSE-SU-2025:21040-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-03T11:55:29.808560+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:21040-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-53659</id>
    <title>UBUNTU-CVE-2023-53659</title>
    <updated>2026-10-03T11:55:29.808684+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 109 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: iavf: Fix out-of-bounds when setting channels on remove If we set channels greater during iavf_remove(), and waiting reset done would be timeout, then returned with error but changed num_active_queues directly, that will lead to OOB like the following logs. Because the num_active_queues is greater than tx/rx_rings[] allocated actually. Reproducer:   [root@host ~]# cat repro.sh   #!/bin/bash   pf_dbsf="0000:41:00.0"   vf0_dbsf="0000:41:02.0"   g_pids=()   function do_set_numvf()   {       echo 2 &gt;/sys/bus/pci/devices/${pf_dbsf}/sriov_numvfs       sleep $((RANDOM%3+1))       echo 0 &gt;/sys/bus/pci/devices/${pf_dbsf}/sriov_numvfs       sleep $((RANDOM%3+1))   }   function do_set_channel()   {       local nic=$(ls -1 --indicator-style=none /sys/bus/pci/devices/${vf0_dbsf}/net/)       [ -z "$nic" ] &amp;&amp; { sleep $((RANDOM%3)) ; return 1; }       ifconfig $nic 192.168.18.5 netmask 255.255.255.0       ifconfig $nic up       ethtool -L $nic combined 1       ethtool -L $nic combined 4       sleep $((RANDOM%3))   }   function on_exit()   {       local pid       for pid in "${g_pids[@]}"; do           kill -0 "$pid" &amp;&gt;/dev/null &amp;&amp; kill "$pid" &amp;&gt;/dev/null       done       g_pids=()   }   trap "on_exit; exit" EXIT   while :; do do_set_numvf ; done &amp;   g_pids+=($!)   while :; do do_set_channel ; done &amp;   g_pids+=($!)   wait Result: [ 3506.152887] iavf 0000:41:02.0: Removing device [ 3510.400799] ===============================…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-53659"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2229</id>
    <title>WID-SEC-W-2025-2229 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-03T11:55:29.808932+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen und andere nicht näher spezifizierte Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2229"/>
  </entry>
</feed>
