<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T18:40:19.937350+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2024:5363</id>
    <title>ALSA-2024:5363 — Important: kernel security update</title>
    <updated>2026-10-02T18:40:20.994012+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: bpftool, AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core and 52 more</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.  
Security Fix(es):</p>
<p>* kernel: phy: (CVE-2024-26600)
  * kernel: netfilter: multiple flaws (CVE-2024-26808, CVE-2024-27065, CVE-2024-35899, CVE-2024-36005)
  * kernel: cifs: (CVE-2024-26828)
  * kernel: wifi: multiple flaws (CVE-2024-26897, CVE-2024-27052, CVE-2024-27049, CVE-2023-52651, CVE-2024-35789, CVE-2024-27434, CVE-2024-35845, CVE-2024-35937, CVE-2024-36941, CVE-2024-36922, CVE-2024-36921, CVE-2024-38575)
  * kernel: nfs: (CVE-2024-26868)
  * kernel: igc: (CVE-2024-26853)
  * kernel: dmaengine/idxd: (CVE-2024-21823)
  * kernel: ipv6: multiple flaws (CVE-2024-27417, CVE-2024-35969, CVE-2024-36903, CVE-2024-40961)
  * kernel: vt: (CVE-2024-35823)
  * kernel: efi: (CVE-2024-35800)
  * kernel: mlxsw: (CVE-2024-35852)
  * kernel: eeprom: (CVE-2024-35848)
  * kernel: ice: (CVE-2024-35911)
  * kernel: platform/x86: (CVE-2023-52864)
  * kernel: i40e: (CVE-2024-36020)
  * kernel: rtnetlink: (CVE-2024-36017)
  * kernel: net: multiple flaws (CVE-2024-36929, CVE-2024-36971, CVE-2021-47606, CVE-2024-38558, CVE-2024-40928, CVE-2024-40954)
  * kernel: ipvlan: (CVE-2024-33621)
  * kernel: tcp: (CVE-2024-37356)
  * kernel: virtio: (CVE-2024-37353)
  * kernel: tls: (CVE-2024-36489)
  * kernel: cxl/region: (CVE-2024-38391)
  * kernel: bonding: (CVE-2024-39487)
  * kernel: netns: (CVE-2024-40958)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, an…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2024:5363"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-10068</id>
    <title>bdu:2024-10068</title>
    <updated>2026-10-02T18:40:20.994170+00:00</updated>
    <content>bdu:2024-10068</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-10068"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2024-35848</id>
    <title>BELL-CVE-2024-35848</title>
    <updated>2026-10-02T18:40:20.994190+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2024-35848"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0472</id>
    <title>certfr-2024-avi-0472 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian. Elles permettent à un attaquant de provo…</title>
    <updated>2026-10-02T18:40:20.994213+00:00</updated>
    <content>certfr-2024-avi-0472</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0472"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-345672</id>
    <title>EUVD-2026-345672</title>
    <updated>2026-10-02T18:40:20.994229+00:00</updated>
    <content>EUVD-2026-345672</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-345672"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-35848</id>
    <title>fkie_cve-2024-35848</title>
    <updated>2026-10-02T18:40:20.994239+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>eeprom: at24: fix memory corruption race condition</p>
<p>If the eeprom is not accessible, an nvmem device will be registered, the
read will fail, and the device will be torn down. If another driver
accesses the nvmem device after the teardown, it will reference
invalid memory.</p>
<p>Move the failure point before registering the nvmem device.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-35848"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-gr49-4mw7-963q</id>
    <title>GHSA-gr49-4mw7-963q</title>
    <updated>2026-10-02T18:40:20.994267+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>eeprom: at24: fix memory corruption race condition</p>
<p>If the eeprom is not accessible, an nvmem device will be registered, the
read will fail, and the device will be torn down. If another driver
accesses the nvmem device after the teardown, it will reference
invalid memory.</p>
<p>Move the failure point before registering the nvmem device.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-gr49-4mw7-963q"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-25-226-15</id>
    <title>ICSA-25-226-15 — Siemens SINEC OS</title>
    <updated>2026-10-02T18:40:20.994285+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In gc_data_segment in fs/f2fs/gc.c in the Linux kernel before 5.16.3, special files are not considered, leading to a move_data_page NULL pointer dereference. In the Linux kernel, the following vulnerability has been resolved:</p>
<p>firmware: arm_scmi: Harden accesses to the reset domains</p>
<p>Accessing reset domains descriptors by the index upon the SCMI drivers
requests through the SCMI reset operations interface can potentially
lead to out-of-bound violations if the SCMI driver misbehave.</p>
<p>Add an internal consistency check before any such domains descriptors
accesses. In the Linux kernel, the following vulnerability has been resolved:</p>
<p>media: lgdt3306a: Add a check against null-pointer-def</p>
<p>The driver should check whether the client provides the platform_data.</p>
<p>The following log reveals it:</p>
<p>[   29.610324] BUG: KASAN: null-ptr-deref in kmemdup+0x30/0x40
[   29.610730] Read of size 40 at addr 0000000000000000 by task bash/414
[   29.612820] Call Trace:
[   29.613030]  &lt;TASK&gt;
[   29.613201]  dump_stack_lvl+0x56/0x6f
[   29.613496]  ? kmemdup+0x30/0x40
[   29.613754]  print_report.cold+0x494/0x6b7
[   29.614082]  ? kmemdup+0x30/0x40
[   29.614340]  kasan_report+0x8a/0x190
[   29.614628]  ? kmemdup+0x30/0x40
[   29.614888]  kasan_check_range+0x14d/0x1d0
[   29.615213]  memcpy+0x20/0x60
[   29.615454]  kmemdup+0x30/0x40
[   29.615700]  lgdt3306a_probe+0x52/0x310
[   29.616339]  i2c_device_probe+0x951/0xa90 In the Linux kernel, the following vulnerability has been resolved:

netfilter:…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-25-226-15"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2024-35848</id>
    <title>msrc_CVE-2024-35848 — eeprom: at24: fix memory corruption race condition</title>
    <updated>2026-10-02T18:40:20.995103+00:00</updated>
    <content>msrc_CVE-2024-35848</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2024-35848"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2024-1680</id>
    <title>OESA-2024-1680 — kernel security update</title>
    <updated>2026-10-02T18:40:20.995121+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP1: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):

In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu: handle the case of pci_channel_io_frozen only in amdgpu_pci_resume

In current code, when a PCI error state pci_channel_io_normal is detectd,
it will report PCI_ERS_RESULT_CAN_RECOVER status to PCI driver, and PCI
driver will continue the execution of PCI resume callback report_resume by
pci_walk_bridge, and the callback will go into amdgpu_pci_resume
finally, where write lock is releasd unconditionally without acquiring
such lock first. In this case, a deadlock will happen when other threads
start to acquire the read lock.

To fix this, add a member in amdgpu_device strucutre to cache
pci_channel_state, and only continue the execution in amdgpu_pci_resume
when it&amp;apos;s pci_channel_io_frozen.(CVE-2021-47421)

In the Linux kernel, the following vulnerability has been resolved:

ptp: Fix possible memory leak in ptp_clock_register()

I got memory leak as follows when doing fault injection test:

unreferenced object 0xffff88800906c618 (size 8):
  comm &amp;quot;i2c-idt82p33931&amp;quot;, pid 4421, jiffies 4294948083 (age 13.188s)
  hex dump (first 8 bytes):
    70 74 70 30 00 00 00 00                          ptp0....
  backtrace:
    [&amp;lt;00000000312ed458&amp;gt;] __kmalloc_track_caller+0x19f/0x3a0
    [&amp;lt;0000000079f6e2ff&amp;gt;] kvasprintf+0xb5/0x150
    [&amp;lt;0000000026aae54f&amp;gt;] kvasprintf_const+0x60/0x190
    [&amp;lt;000…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2024-1680"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:5363</id>
    <title>RHSA-2024:5363 — Red Hat Security Advisory: kernel security update</title>
    <updated>2026-10-02T18:40:20.995375+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: net: netlink: af_netlink: Prevent empty skb by adding a check on len. kernel: wifi: ath10k: fix NULL pointer dereference in ath10k_wmi_tlv_op_pull_mgmt_tx_compl_ev() kernel: ipvlan: add ipvlan_route_v6_outbound() helper kernel: platform/x86: wmi: Fix opening of char device kernel: dmaengine/idxd: hardware erratum allows potential security problem with direct access by untrusted application kernel: phy: ti: phy-omap-usb2: Fix NULL pointer dereference for SRP kernel: netfilter: nft_chain_filter: handle NETDEV_UNREGISTER for inet/ingress basechain kernel: cifs: fix underflow in parse_server_interfaces() kernel: igc: avoid returning frame twice in XDP_REDIRECT kernel: nfs: fix panic when nfs4_ff_layout_prepare_ds() fails kernel: wifi: ath9k: delay all of ath9k_wmi_event_tasklet() until init is complete kernel: wifi: mt76: mt7925e: fix use-after-free in free_irq() kernel: wifi: rtl8xxxu: add cancel_work_sync() for c2hcmd_work kernel: netfilter: nf_tables: do not compare internal table flags on updates kernel: ipv6: fix potential &amp;#34;struct net&amp;#34; leak in inet6_rtm_getaddr() kernel: wifi: iwlwifi: mvm: don&amp;#39;t set the MFP flag for the GTK kernel: ipvlan: Dont Use skb-&amp;gt;sk in ipvlan_process_v{4,6}_outbound kernel: wifi: mac80211: check/clear fast rx for non-4addr sta VLAN changes kernel: efi: fix panic in kdump kernel kernel: vt: fix unicode buffer corruption when deleting characters kernel: wifi: iwlwifi: dbg-tlv: ensure NUL termination kernel: eeprom: at24: fix mem…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:5363"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ssa-613116</id>
    <title>SSA-613116 — SSA-613116: Multiple Vulnerabilities in Third-Party Components in SINEC OS before V3.1</title>
    <updated>2026-10-02T18:40:20.995500+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In gc_data_segment in fs/f2fs/gc.c in the Linux kernel before 5.16.3, special files are not considered, leading to a move_data_page NULL pointer dereference. In the Linux kernel, the following vulnerability has been resolved:</p>
<p>firmware: arm_scmi: Harden accesses to the reset domains</p>
<p>Accessing reset domains descriptors by the index upon the SCMI drivers
requests through the SCMI reset operations interface can potentially
lead to out-of-bound violations if the SCMI driver misbehave.</p>
<p>Add an internal consistency check before any such domains descriptors
accesses. In the Linux kernel, the following vulnerability has been resolved:</p>
<p>media: lgdt3306a: Add a check against null-pointer-def</p>
<p>The driver should check whether the client provides the platform_data.</p>
<p>The following log reveals it:</p>
<p>[   29.610324] BUG: KASAN: null-ptr-deref in kmemdup+0x30/0x40
[   29.610730] Read of size 40 at addr 0000000000000000 by task bash/414
[   29.612820] Call Trace:
[   29.613030]  &lt;TASK&gt;
[   29.613201]  dump_stack_lvl+0x56/0x6f
[   29.613496]  ? kmemdup+0x30/0x40
[   29.613754]  print_report.cold+0x494/0x6b7
[   29.614082]  ? kmemdup+0x30/0x40
[   29.614340]  kasan_report+0x8a/0x190
[   29.614628]  ? kmemdup+0x30/0x40
[   29.614888]  kasan_check_range+0x14d/0x1d0
[   29.615213]  memcpy+0x20/0x60
[   29.615454]  kmemdup+0x30/0x40
[   29.615700]  lgdt3306a_probe+0x52/0x310
[   29.616339]  i2c_device_probe+0x951/0xa90 In the Linux kernel, the following vulnerability has been resolved:

netfilter:…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ssa-613116"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2024:2372-1</id>
    <title>SUSE-SU-2024:2372-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-02T18:40:20.996353+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2024:2372-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-35848</id>
    <title>UBUNTU-CVE-2024-35848</title>
    <updated>2026-10-02T18:40:20.996501+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:Pro:18.04:LTS: linux-aws-5.4, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:Pro:18.04:LTS: linux-azure-5.4, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3 and 157 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: eeprom: at24: fix memory corruption race condition If the eeprom is not accessible, an nvmem device will be registered, the read will fail, and the device will be torn down. If another driver accesses the nvmem device after the teardown, it will reference invalid memory. Move the failure point before registering the nvmem device.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-35848"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1188</id>
    <title>WID-SEC-W-2024-1188 — Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service</title>
    <updated>2026-10-02T18:40:20.996701+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1188"/>
  </entry>
</feed>
