<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T08:19:20.197793+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-03695</id>
    <title>bdu:2024-03695</title>
    <updated>2026-10-03T08:19:20.404947+00:00</updated>
    <content>bdu:2024-03695</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-03695"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2024-26865</id>
    <title>BELL-CVE-2024-26865</title>
    <updated>2026-10-03T08:19:20.404999+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2024-26865"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0546</id>
    <title>certfr-2024-avi-0546 — De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Certaines d'entre elles permettent à un a…</title>
    <updated>2026-10-03T08:19:20.405032+00:00</updated>
    <content>certfr-2024-avi-0546</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0546"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-345545</id>
    <title>EUVD-2026-345545</title>
    <updated>2026-10-03T08:19:20.405050+00:00</updated>
    <content>EUVD-2026-345545</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-345545"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-26865</id>
    <title>fkie_cve-2024-26865</title>
    <updated>2026-10-03T08:19:20.405061+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>rds: tcp: Fix use-after-free of net in reqsk_timer_handler().</p>
<p>syzkaller reported a warning of netns tracker [0] followed by KASAN
splat [1] and another ref tracker warning [1].</p>
<p>syzkaller could not find a repro, but in the log, the only suspicious
sequence was as follows:</p>
<p>18:26:22 executing program 1:
  r0 = socket$inet6_mptcp(0xa, 0x1, 0x106)
  ...
  connect$inet6(r0, &amp;(0x7f0000000080)={0xa, 0x4001, 0x0, @loopback}, 0x1c) (async)</p>
<p>The notable thing here is 0x4001 in connect(), which is RDS_TCP_PORT.</p>
<p>So, the scenario would be:</p>
<p>1. unshare(CLONE_NEWNET) creates a per netns tcp listener in
      rds_tcp_listen_init().
  2. syz-executor connect()s to it and creates a reqsk.
  3. syz-executor exit()s immediately.
  4. netns is dismantled.  [0]
  5. reqsk timer is fired, and UAF happens while freeing reqsk.  [1]
  6. listener is freed after RCU grace period.  [2]</p>
<p>Basically, reqsk assumes that the listener guarantees netns safety
until all reqsk timers are expired by holding the listener's refcount.
However, this was not the case for kernel sockets.</p>
<p>Commit 740ea3c4a0b2 ("tcp: Clean up kernel listener's reqsk in
inet_twsk_purge()") fixed this issue only for per-netns ehash.</p>
<p>Let's apply the same fix for the global ehash.</p>
<p>[0]:
ref_tracker: net notrefcnt@0000000065449cc3 has 1/1 users at
     sk_alloc (./include/net/net_namespace.h:337 net/core/sock.c:2146)
     inet6_create (net/ipv6/af_inet6.c:192 net/ip…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-26865"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-vp2f-c695-vxrg</id>
    <title>GHSA-vp2f-c695-vxrg</title>
    <updated>2026-10-03T08:19:20.405116+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>rds: tcp: Fix use-after-free of net in reqsk_timer_handler().</p>
<p>syzkaller reported a warning of netns tracker [0] followed by KASAN
splat [1] and another ref tracker warning [1].</p>
<p>syzkaller could not find a repro, but in the log, the only suspicious
sequence was as follows:</p>
<p>18:26:22 executing program 1:
  r0 = socket$inet6_mptcp(0xa, 0x1, 0x106)
  ...
  connect$inet6(r0, &amp;(0x7f0000000080)={0xa, 0x4001, 0x0, @loopback}, 0x1c) (async)</p>
<p>The notable thing here is 0x4001 in connect(), which is RDS_TCP_PORT.</p>
<p>So, the scenario would be:</p>
<p>1. unshare(CLONE_NEWNET) creates a per netns tcp listener in
      rds_tcp_listen_init().
  2. syz-executor connect()s to it and creates a reqsk.
  3. syz-executor exit()s immediately.
  4. netns is dismantled.  [0]
  5. reqsk timer is fired, and UAF happens while freeing reqsk.  [1]
  6. listener is freed after RCU grace period.  [2]</p>
<p>Basically, reqsk assumes that the listener guarantees netns safety
until all reqsk timers are expired by holding the listener's refcount.
However, this was not the case for kernel sockets.</p>
<p>Commit 740ea3c4a0b2 ("tcp: Clean up kernel listener's reqsk in
inet_twsk_purge()") fixed this issue only for per-netns ehash.</p>
<p>Let's apply the same fix for the global ehash.</p>
<p>[0]:
ref_tracker: net notrefcnt@0000000065449cc3 has 1/1 users at
     sk_alloc (./include/net/net_namespace.h:337 net/core/sock.c:2146)
     inet6_create (net/ipv6/af_inet6.c:192 net/ip…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-vp2f-c695-vxrg"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2024-26865</id>
    <title>gsd-2024-26865</title>
    <updated>2026-10-03T08:19:20.405160+00:00</updated>
    <content>gsd-2024-26865</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2024-26865"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2024-26865</id>
    <title>msrc_CVE-2024-26865 — rds: tcp: Fix use-after-free of net in reqsk_timer_handler().</title>
    <updated>2026-10-03T08:19:20.405172+00:00</updated>
    <content>msrc_CVE-2024-26865</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2024-26865"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2024-1622</id>
    <title>OESA-2024-1622 — kernel security update</title>
    <updated>2026-10-03T08:19:20.405189+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP3: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):

In the Linux kernel, the following vulnerability has been resolved:

firmware: arm_scmi: Harden accesses to the reset domains

Accessing reset domains descriptors by the index upon the SCMI drivers
requests through the SCMI reset operations interface can potentially
lead to out-of-bound violations if the SCMI driver misbehave.

Add an internal consistency check before any such domains descriptors
accesses.(CVE-2022-48655)

In the Linux kernel, the following vulnerability has been resolved:

erofs: fix pcluster use-after-free on UP platforms

During stress testing with CONFIG_SMP disabled, KASAN reports as below:

==================================================================
BUG: KASAN: use-after-free in __mutex_lock+0xe5/0xc30
Read of size 8 at addr ffff8881094223f8 by task stress/7789

CPU: 0 PID: 7789 Comm: stress Not tainted 6.0.0-rc1-00002-g0d53d2e882f9 #3
Hardware name: Red Hat KVM, BIOS 0.5.1 01/01/2011
Call Trace:
 &amp;lt;TASK&amp;gt;
..
 __mutex_lock+0xe5/0xc30
..
 z_erofs_do_read_page+0x8ce/0x1560
..
 z_erofs_readahead+0x31c/0x580
..
Freed by task 7787
 kasan_save_stack+0x1e/0x40
 kasan_set_track+0x20/0x30
 kasan_set_free_info+0x20/0x40
 __kasan_slab_free+0x10c/0x190
 kmem_cache_free+0xed/0x380
 rcu_core+0x3d5/0xc90
 __do_softirq+0x12d/0x389

Last potentially related work creation:
 kasan_save_stack+0x1e/0x40
 __kasan_record_aux_stack+0x97/0xb0
 call_rcu+0x3d/0x3f0
 erofs_shr…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2024-1622"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13959-1</id>
    <title>openSUSE-SU-2024:13959-1 — kernel-devel-6.8.9-1.1 on GA media</title>
    <updated>2026-10-03T08:19:20.405638+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel-devel-6.8.9-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:13959-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:20008-1</id>
    <title>SUSE-SU-2025:20008-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-03T08:19:20.405657+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:20008-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-26865</id>
    <title>UBUNTU-CVE-2024-26865</title>
    <updated>2026-10-03T08:19:20.406096+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 78 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: rds: tcp: Fix use-after-free of net in reqsk_timer_handler(). syzkaller reported a warning of netns tracker [0] followed by KASAN splat [1] and another ref tracker warning [1]. syzkaller could not find a repro, but in the log, the only suspicious sequence was as follows:   18:26:22 executing program 1:   r0 = socket$inet6_mptcp(0xa, 0x1, 0x106)   ...   connect$inet6(r0, &amp;(0x7f0000000080)={0xa, 0x4001, 0x0, @loopback}, 0x1c) (async) The notable thing here is 0x4001 in connect(), which is RDS_TCP_PORT. So, the scenario would be:   1. unshare(CLONE_NEWNET) creates a per netns tcp listener in       rds_tcp_listen_init().   2. syz-executor connect()s to it and creates a reqsk.   3. syz-executor exit()s immediately.   4. netns is dismantled.  [0]   5. reqsk timer is fired, and UAF happens while freeing reqsk.  [1]   6. listener is freed after RCU grace period.  [2] Basically, reqsk assumes that the listener guarantees netns safety until all reqsk timers are expired by holding the listener's refcount. However, this was not the case for kernel sockets. Commit 740ea3c4a0b2 ("tcp: Clean up kernel listener's reqsk in inet_twsk_purge()") fixed this issue only for per-netns ehash. Let's apply the same fix for the global ehash. [0]: ref_tracker: net notrefcnt@0000000065449cc3 has 1/1 users at      sk_alloc (./include/net/net_namespace.h:337 net/core/sock.c:2146)      inet6_create (net/ipv6/af_inet6.c:192 net/ipv6/af_inet6…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-26865"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0920</id>
    <title>WID-SEC-W-2024-0920 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-03T08:19:20.406245+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann mehrere Schwachstellen im Linux-Kernel ausnutzen, um einen Denial-of-Service-Zustand herbeizuführen oder einen nicht spezifizierten Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0920"/>
  </entry>
</feed>
