<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T05:51:24.437504+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-04397</id>
    <title>bdu:2025-04397</title>
    <updated>2026-10-03T05:51:24.559094+00:00</updated>
    <content>bdu:2025-04397</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-04397"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2024-26732</id>
    <title>BELL-CVE-2024-26732</title>
    <updated>2026-10-03T05:51:24.559142+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2024-26732"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-312576</id>
    <title>EUVD-2026-312576</title>
    <updated>2026-10-03T05:51:24.559176+00:00</updated>
    <content>EUVD-2026-312576</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-312576"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-26732</id>
    <title>fkie_cve-2024-26732</title>
    <updated>2026-10-03T05:51:24.559190+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>net: implement lockless setsockopt(SO_PEEK_OFF)</p>
<p>syzbot reported a lockdep violation [1] involving af_unix
support of SO_PEEK_OFF.</p>
<p>Since SO_PEEK_OFF is inherently not thread safe (it uses a per-socket
sk_peek_off field), there is really no point to enforce a pointless
thread safety in the kernel.</p>
<p>After this patch :</p>
<p>- setsockopt(SO_PEEK_OFF) no longer acquires the socket lock.</p>
<p>- skb_consume_udp() no longer has to acquire the socket lock.</p>
<p>- af_unix no longer needs a special version of sk_set_peek_off(),
  because it does not lock u-&gt;iolock anymore.</p>
<p>As a followup, we could replace prot-&gt;set_peek_off to be a boolean
and avoid an indirect call, since we always use sk_set_peek_off().</p>
<p>[1]</p>
<p>WARNING: possible circular locking dependency detected
6.8.0-rc4-syzkaller-00267-g0f1dd5e91e2b #0 Not tainted</p>
<p>syz-executor.2/30025 is trying to acquire lock:
 ffff8880765e7d80 (&amp;u-&gt;iolock){+.+.}-{3:3}, at: unix_set_peek_off+0x26/0xa0 net/unix/af_unix.c:789</p>
<p>but task is already holding lock:
 ffff8880765e7930 (sk_lock-AF_UNIX){+.+.}-{0:0}, at: lock_sock include/net/sock.h:1691 [inline]
 ffff8880765e7930 (sk_lock-AF_UNIX){+.+.}-{0:0}, at: sockopt_lock_sock net/core/sock.c:1060 [inline]
 ffff8880765e7930 (sk_lock-AF_UNIX){+.+.}-{0:0}, at: sk_setsockopt+0xe52/0x3360 net/core/sock.c:1193</p>
<p>which lock already depends on the new lock.</p>
<p>the existing dependency chain (in reverse order) is:</p>
<p>-&gt; #1 (sk_lock-AF_UNIX){+.+.}-{0:0}:…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-26732"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-q4jh-g383-rjcg</id>
    <title>GHSA-q4jh-g383-rjcg</title>
    <updated>2026-10-03T05:51:24.559266+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>net: implement lockless setsockopt(SO_PEEK_OFF)</p>
<p>syzbot reported a lockdep violation [1] involving af_unix
support of SO_PEEK_OFF.</p>
<p>Since SO_PEEK_OFF is inherently not thread safe (it uses a per-socket
sk_peek_off field), there is really no point to enforce a pointless
thread safety in the kernel.</p>
<p>After this patch :</p>
<p>- setsockopt(SO_PEEK_OFF) no longer acquires the socket lock.</p>
<p>- skb_consume_udp() no longer has to acquire the socket lock.</p>
<p>- af_unix no longer needs a special version of sk_set_peek_off(),
  because it does not lock u-&gt;iolock anymore.</p>
<p>As a followup, we could replace prot-&gt;set_peek_off to be a boolean
and avoid an indirect call, since we always use sk_set_peek_off().</p>
<p>[1]</p>
<p>WARNING: possible circular locking dependency detected
6.8.0-rc4-syzkaller-00267-g0f1dd5e91e2b #0 Not tainted</p>
<p>syz-executor.2/30025 is trying to acquire lock:
 ffff8880765e7d80 (&amp;u-&gt;iolock){+.+.}-{3:3}, at: unix_set_peek_off+0x26/0xa0 net/unix/af_unix.c:789</p>
<p>but task is already holding lock:
 ffff8880765e7930 (sk_lock-AF_UNIX){+.+.}-{0:0}, at: lock_sock include/net/sock.h:1691 [inline]
 ffff8880765e7930 (sk_lock-AF_UNIX){+.+.}-{0:0}, at: sockopt_lock_sock net/core/sock.c:1060 [inline]
 ffff8880765e7930 (sk_lock-AF_UNIX){+.+.}-{0:0}, at: sk_setsockopt+0xe52/0x3360 net/core/sock.c:1193</p>
<p>which lock already depends on the new lock.</p>
<p>the existing dependency chain (in reverse order) is:</p>
<p>-&gt; #1 (sk_lock-AF_UNIX){+.+.}-{0:0}:…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-q4jh-g383-rjcg"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2024-26732</id>
    <title>gsd-2024-26732</title>
    <updated>2026-10-03T05:51:24.559315+00:00</updated>
    <content>gsd-2024-26732</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2024-26732"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-26732</id>
    <title>UBUNTU-CVE-2024-26732</title>
    <updated>2026-10-03T05:51:24.559327+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 56 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: net: implement lockless setsockopt(SO_PEEK_OFF) syzbot reported a lockdep violation [1] involving af_unix support of SO_PEEK_OFF. Since SO_PEEK_OFF is inherently not thread safe (it uses a per-socket sk_peek_off field), there is really no point to enforce a pointless thread safety in the kernel. After this patch : - setsockopt(SO_PEEK_OFF) no longer acquires the socket lock. - skb_consume_udp() no longer has to acquire the socket lock. - af_unix no longer needs a special version of sk_set_peek_off(),   because it does not lock u-&gt;iolock anymore. As a followup, we could replace prot-&gt;set_peek_off to be a boolean and avoid an indirect call, since we always use sk_set_peek_off(). [1] WARNING: possible circular locking dependency detected 6.8.0-rc4-syzkaller-00267-g0f1dd5e91e2b #0 Not tainted syz-executor.2/30025 is trying to acquire lock:  ffff8880765e7d80 (&amp;u-&gt;iolock){+.+.}-{3:3}, at: unix_set_peek_off+0x26/0xa0 net/unix/af_unix.c:789 but task is already holding lock:  ffff8880765e7930 (sk_lock-AF_UNIX){+.+.}-{0:0}, at: lock_sock include/net/sock.h:1691 [inline]  ffff8880765e7930 (sk_lock-AF_UNIX){+.+.}-{0:0}, at: sockopt_lock_sock net/core/sock.c:1060 [inline]  ffff8880765e7930 (sk_lock-AF_UNIX){+.+.}-{0:0}, at: sk_setsockopt+0xe52/0x3360 net/core/sock.c:1193 which lock already depends on the new lock. the existing dependency chain (in reverse order) is: -&gt; #1 (sk_lock-AF_UNIX){+.+.}-{0:0}:         lock_acqui…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-26732"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0773</id>
    <title>WID-SEC-W-2024-0773 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-03T05:51:24.559456+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen, seine Privilegien eskalieren oder einen nicht näher spezifizierten Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0773"/>
  </entry>
</feed>
