<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T23:49:58.797226+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2024:6997</id>
    <title>ALSA-2024:6997 — Important: kernel security update</title>
    <updated>2026-10-03T23:49:58.969090+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: bpftool, AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core and 52 more</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: uio: Fix use-after-free in uio_open (CVE-2023-52439)
  * kernel: net/sched: act_mirred: don't override retval if we already lost the skb (CVE-2024-26739)
  * kernel: ARM: 9359/1: flush: check if the folio is reserved for no-mapping addresses (CVE-2024-26947)
  * kernel: scsi: qla2xxx: Fix command flush on cable pull (CVE-2024-26931)
  * kernel: scsi: qla2xxx: Fix double free of the ha-&amp;gt;vp_map pointer (CVE-2024-26930)
  * kernel: scsi: qla2xxx: Fix double free of fcport (CVE-2024-26929)
  * kernel: fork: defer linking file vma until vma is fully initialized (CVE-2024-27022)
  * kernel: KVM: x86/mmu: x86: Don&amp;#39;t overflow lpage_info when checking attributes (CVE-2024-26991)
  * kernel: bpf, sockmap: Prevent lock inversion deadlock in map delete elem (CVE-2024-35895)
  * kernel: tty: n_gsm: fix possible out-of-bounds in gsm0_receive() (CVE-2024-36016)
  * kernel: gpiolib: cdev: Fix use after free in lineinfo_changed_notify (CVE-2024-36899)
  * kernel: cpufreq: exit() callback is optional (CVE-2024-38615)
  * kernel: ring-buffer: Fix a race between readers and resize checks (CVE-2024-38601)
  * kernel: cppc_cpufreq: Fix possible null pointer dereference (CVE-2024-38573)
  * kernel: gfs2: Fix potential glock use-after-free on unmount (CVE-2024-38570)
  * kernel: wifi: nl80211: Avoid address calculations via out of bounds array indexing (CVE-2024-38562)…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2024:6997"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-03498</id>
    <title>bdu:2026-03498</title>
    <updated>2026-10-03T23:49:58.969226+00:00</updated>
    <content>bdu:2026-03498</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-03498"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2024-26947</id>
    <title>BELL-CVE-2024-26947</title>
    <updated>2026-10-03T23:49:58.969246+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2024-26947"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0546</id>
    <title>certfr-2024-avi-0546 — De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Certaines d'entre elles permettent à un a…</title>
    <updated>2026-10-03T23:49:58.969267+00:00</updated>
    <content>certfr-2024-avi-0546</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0546"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-320569</id>
    <title>EUVD-2026-320569</title>
    <updated>2026-10-03T23:49:58.969282+00:00</updated>
    <content>EUVD-2026-320569</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-320569"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-26947</id>
    <title>fkie_cve-2024-26947</title>
    <updated>2026-10-03T23:49:58.969293+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>ARM: 9359/1: flush: check if the folio is reserved for no-mapping addresses</p>
<p>Since commit a4d5613c4dc6 ("arm: extend pfn_valid to take into account
freed memory map alignment") changes the semantics of pfn_valid() to check
presence of the memory map for a PFN. A valid page for an address which
is reserved but not mapped by the kernel[1], the system crashed during
some uio test with the following memory layout:</p>
<p>node   0: [mem 0x00000000c0a00000-0x00000000cc8fffff]
 node   0: [mem 0x00000000d0000000-0x00000000da1fffff]
 the uio layout is：0xc0900000, 0x100000</p>
<p>the crash backtrace like:</p>
<p>Unable to handle kernel paging request at virtual address bff00000
  [...]
  CPU: 1 PID: 465 Comm: startapp.bin Tainted: G           O      5.10.0 #1
  Hardware name: Generic DT based system
  PC is at b15_flush_kern_dcache_area+0x24/0x3c
  LR is at __sync_icache_dcache+0x6c/0x98
  [...]
   (b15_flush_kern_dcache_area) from (__sync_icache_dcache+0x6c/0x98)
   (__sync_icache_dcache) from (set_pte_at+0x28/0x54)
   (set_pte_at) from (remap_pfn_range+0x1a0/0x274)
   (remap_pfn_range) from (uio_mmap+0x184/0x1b8 [uio])
   (uio_mmap [uio]) from (__mmap_region+0x264/0x5f4)
   (__mmap_region) from (__do_mmap_mm+0x3ec/0x440)
   (__do_mmap_mm) from (do_mmap+0x50/0x58)
   (do_mmap) from (vm_mmap_pgoff+0xfc/0x188)
   (vm_mmap_pgoff) from (ksys_mmap_pgoff+0xac/0xc4)
   (ksys_mmap_pgoff) from (ret_fast_syscall+0x0/0x5c)
  Code: e0801001 e…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-26947"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xqwg-gh2q-g24c</id>
    <title>GHSA-xqwg-gh2q-g24c</title>
    <updated>2026-10-03T23:49:58.969334+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>ARM: 9359/1: flush: check if the folio is reserved for no-mapping addresses</p>
<p>Since commit a4d5613c4dc6 ("arm: extend pfn_valid to take into account
freed memory map alignment") changes the semantics of pfn_valid() to check
presence of the memory map for a PFN. A valid page for an address which
is reserved but not mapped by the kernel[1], the system crashed during
some uio test with the following memory layout:</p>
<p>node   0: [mem 0x00000000c0a00000-0x00000000cc8fffff]
 node   0: [mem 0x00000000d0000000-0x00000000da1fffff]
 the uio layout is：0xc0900000, 0x100000</p>
<p>the crash backtrace like:</p>
<p>Unable to handle kernel paging request at virtual address bff00000
  [...]
  CPU: 1 PID: 465 Comm: startapp.bin Tainted: G           O      5.10.0 #1
  Hardware name: Generic DT based system
  PC is at b15_flush_kern_dcache_area+0x24/0x3c
  LR is at __sync_icache_dcache+0x6c/0x98
  [...]
   (b15_flush_kern_dcache_area) from (__sync_icache_dcache+0x6c/0x98)
   (__sync_icache_dcache) from (set_pte_at+0x28/0x54)
   (set_pte_at) from (remap_pfn_range+0x1a0/0x274)
   (remap_pfn_range) from (uio_mmap+0x184/0x1b8 [uio])
   (uio_mmap [uio]) from (__mmap_region+0x264/0x5f4)
   (__mmap_region) from (__do_mmap_mm+0x3ec/0x440)
   (__do_mmap_mm) from (do_mmap+0x50/0x58)
   (do_mmap) from (vm_mmap_pgoff+0xfc/0x188)
   (vm_mmap_pgoff) from (ksys_mmap_pgoff+0xac/0xc4)
   (ksys_mmap_pgoff) from (ret_fast_syscall+0x0/0x5c)
  Code: e0801001 e…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xqwg-gh2q-g24c"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2024-26947</id>
    <title>gsd-2024-26947</title>
    <updated>2026-10-03T23:49:58.969367+00:00</updated>
    <content>gsd-2024-26947</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2024-26947"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2024-26947</id>
    <title>msrc_CVE-2024-26947 — ARM: 9359/1: flush: check if the folio is reserved for no-mapping addresses</title>
    <updated>2026-10-03T23:49:58.969378+00:00</updated>
    <content>msrc_CVE-2024-26947</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2024-26947"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2024-1737</id>
    <title>OESA-2024-1737 — kernel security update</title>
    <updated>2026-10-03T23:49:58.969394+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP1: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):

In the Linux kernel, the following vulnerability has been resolved:

afs: Fix corruption in reads at fpos 2G-4G from an OpenAFS server

AFS-3 has two data fetch RPC variants, FS.FetchData and FS.FetchData64, and
Linux&amp;apos;s afs client switches between them when talking to a non-YFS server
if the read size, the file position or the sum of the two have the upper 32
bits set of the 64-bit value.

This is a problem, however, since the file position and length fields of
FS.FetchData are *signed* 32-bit values.

Fix this by capturing the capability bits obtained from the fileserver when
it&amp;apos;s sent an FS.GetCapabilities RPC, rather than just discarding them, and
then picking out the VICED_CAPABILITY_64BITFILES flag.  This can then be
used to decide whether to use FS.FetchData or FS.FetchData64 - and also
FS.StoreData or FS.StoreData64 - rather than using upper_32_bits() to
switch on the parameter values.

This capabilities flag could also be used to limit the maximum size of the
file, but all servers must be checked for that.

Note that the issue does not exist with FS.StoreData - that uses *unsigned*
32-bit values.  It&amp;apos;s also not a problem with Auristor servers as its
YFS.FetchData64 op uses unsigned 64-bit values.

This can be tested by cloning a git repo through an OpenAFS client to an
OpenAFS server and then doing &amp;quot;git status&amp;quot; on it from a Linux afs
client[1].  Provided…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2024-1737"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:5066</id>
    <title>RHSA-2024:5066 — Red Hat Security Advisory: kernel security update</title>
    <updated>2026-10-03T23:49:58.969664+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: bnxt: prevent skb UAF after handing over to PTP worker kernel: block: null pointer dereference in ioctl.c when length and logical block size are misaligned kernel: PM / devfreq: Synchronize devfreq_monitor_[start/stop] kernel: scsi: libfc: Fix potential NULL pointer dereference in fc_lport_ptp_setup() kernel: SUNRPC: Fix UAF in svc_tcp_listen_data_ready() kernel: ext4: regenerate buddy after block freeing failed if under fc replay kernel: bpf: Fix racing between bpf_timer_cancel_and_free and bpf_timer_cancel kernel: scsi: qla2xxx: Fix double free of the ha-&amp;gt;vp_map pointer kernel: ARM: 9359/1: flush: check if the folio is reserved for no-mapping addresses kernel: octeontx2-af: race condition on interupts kernel: nouveau: lock the client object tree. kernel: ipvlan: Dont Use skb-&amp;gt;sk in ipvlan_process_v{4,6}_outbound kernel: vt: fix unicode buffer corruption when deleting characters kernel: mlxbf_gige: stop interface during shutdown kernel: netfilter: validate user input for expected length kernel: netfilter: complete validation of user input kernel: rtnetlink: Correct nested IFLA_VF_VLAN_LIST attribute validation kernel: i40e: fix vf may be used uninitialized in this function warning kernel: net: core: reject skb_copy(_expand) for fraglist GSO skbs kernel: drm/vmwgfx: Fix invalid reads in fence signaled events kernel: blk-cgroup: fix list corruption from reorder of WRITE -&amp;gt;lqueued kernel: blk-cgroup: fix list corruption from resetting io stat</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:5066"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:6997</id>
    <title>RHSA-2024:6997 — Red Hat Security Advisory: kernel security update</title>
    <updated>2026-10-03T23:49:58.969758+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: uio: Fix use-after-free in uio_open kernel: Input: cyapa - add missing input core locking to suspend/resume functions kernel: net/sched: act_mirred: don't override retval if we already lost the skb kernel: scsi: qla2xxx: Fix double free of fcport kernel: scsi: qla2xxx: Fix double free of the ha-&amp;gt;vp_map pointer kernel: scsi: qla2xxx: Fix command flush on cable pull kernel: ARM: 9359/1: flush: check if the folio is reserved for no-mapping addresses kernel: KVM: x86/mmu: x86: Don&amp;#39;t overflow lpage_info when checking attributes kernel: fork: defer linking file vma until vma is fully initialized kernel: bpf, sockmap: Prevent lock inversion deadlock in map delete elem kernel: tty: n_gsm: fix possible out-of-bounds in gsm0_receive() kernel: gpiolib: cdev: Fix use after free in lineinfo_changed_notify kernel: wifi: nl80211: Avoid address calculations via out of bounds array indexing kernel: gfs2: Fix potential glock use-after-free on unmount kernel: cppc_cpufreq: Fix possible null pointer dereference kernel: ring-buffer: Fix a race between readers and resize checks kernel: cpufreq: exit() callback is optional kernel: ACPICA: Revert &amp;#34;ACPICA: avoid Info: mapping multiple BARs. Your kernel is fine.&amp;#34; kernel: wifi: mac80211: Avoid address calculations via out of bounds array indexing kernel: wifi: mt76: replace skb_put with skb_put_zero kernel: net, sunrpc: Remap EPERM in case of connection failure in xs_tcp_setup_socket</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:6997"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-26947</id>
    <title>UBUNTU-CVE-2024-26947</title>
    <updated>2026-10-03T23:49:58.969808+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:Pro:18.04:LTS: linux-aws-5.4, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:Pro:18.04:LTS: linux-azure-5.4, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3 and 139 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: ARM: 9359/1: flush: check if the folio is reserved for no-mapping addresses Since commit a4d5613c4dc6 ("arm: extend pfn_valid to take into account freed memory map alignment") changes the semantics of pfn_valid() to check presence of the memory map for a PFN. A valid page for an address which is reserved but not mapped by the kernel[1], the system crashed during some uio test with the following memory layout:  node   0: [mem 0x00000000c0a00000-0x00000000cc8fffff]  node   0: [mem 0x00000000d0000000-0x00000000da1fffff]  the uio layout is：0xc0900000, 0x100000 the crash backtrace like:   Unable to handle kernel paging request at virtual address bff00000   [...]   CPU: 1 PID: 465 Comm: startapp.bin Tainted: G           O      5.10.0 #1   Hardware name: Generic DT based system   PC is at b15_flush_kern_dcache_area+0x24/0x3c   LR is at __sync_icache_dcache+0x6c/0x98   [...]    (b15_flush_kern_dcache_area) from (__sync_icache_dcache+0x6c/0x98)    (__sync_icache_dcache) from (set_pte_at+0x28/0x54)    (set_pte_at) from (remap_pfn_range+0x1a0/0x274)    (remap_pfn_range) from (uio_mmap+0x184/0x1b8 [uio])    (uio_mmap [uio]) from (__mmap_region+0x264/0x5f4)    (__mmap_region) from (__do_mmap_mm+0x3ec/0x440)    (__do_mmap_mm) from (do_mmap+0x50/0x58)    (do_mmap) from (vm_mmap_pgoff+0xfc/0x188)    (vm_mmap_pgoff) from (ksys_mmap_pgoff+0xac/0xc4)    (ksys_mmap_pgoff) from (ret_fast_syscall+0x0/0x5c)   Code: e0801001 e24230…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-26947"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1008</id>
    <title>WID-SEC-W-2024-1008 — Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service</title>
    <updated>2026-10-03T23:49:58.970017+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder sonstige Auswirkungen zu verursachen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1008"/>
  </entry>
</feed>
