<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T09:36:02.244393+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-03028</id>
    <title>bdu:2025-03028</title>
    <updated>2026-10-03T09:36:02.879422+00:00</updated>
    <content>bdu:2025-03028</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-03028"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2024-40910</id>
    <title>BELL-CVE-2024-40910</title>
    <updated>2026-10-03T09:36:02.879508+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2024-40910"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0613</id>
    <title>certfr-2024-avi-0613 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian. Elles permettent à un attaquant de provo…</title>
    <updated>2026-10-03T09:36:02.879545+00:00</updated>
    <content>certfr-2024-avi-0613</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0613"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-345868</id>
    <title>EUVD-2026-345868</title>
    <updated>2026-10-03T09:36:02.879564+00:00</updated>
    <content>EUVD-2026-345868</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-345868"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-40910</id>
    <title>fkie_cve-2024-40910</title>
    <updated>2026-10-03T09:36:02.879575+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>ax25: Fix refcount imbalance on inbound connections</p>
<p>When releasing a socket in ax25_release(), we call netdev_put() to
decrease the refcount on the associated ax.25 device. However, the
execution path for accepting an incoming connection never calls
netdev_hold(). This imbalance leads to refcount errors, and ultimately
to kernel crashes.</p>
<p>A typical call trace for the above situation will start with one of the
following errors:</p>
<p>refcount_t: decrement hit 0; leaking memory.
    refcount_t: underflow; use-after-free.</p>
<p>And will then have a trace like:</p>
<p>Call Trace:
    &lt;TASK&gt;
    ? show_regs+0x64/0x70
    ? __warn+0x83/0x120
    ? refcount_warn_saturate+0xb2/0x100
    ? report_bug+0x158/0x190
    ? prb_read_valid+0x20/0x30
    ? handle_bug+0x3e/0x70
    ? exc_invalid_op+0x1c/0x70
    ? asm_exc_invalid_op+0x1f/0x30
    ? refcount_warn_saturate+0xb2/0x100
    ? refcount_warn_saturate+0xb2/0x100
    ax25_release+0x2ad/0x360
    __sock_release+0x35/0xa0
    sock_close+0x19/0x20
    [...]</p>
<p>On reboot (or any attempt to remove the interface), the kernel gets
stuck in an infinite loop:</p>
<p>unregister_netdevice: waiting for ax0 to become free. Usage count = 0</p>
<p>This patch corrects these issues by ensuring that we call netdev_hold()
and ax25_dev_hold() for new connections in ax25_accept(). This makes the
logic leading to ax25_accept() match the logic for ax25_bind(): in both
cases we increment the refcount, which…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-40910"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-37qc-prgq-xwcm</id>
    <title>GHSA-37qc-prgq-xwcm</title>
    <updated>2026-10-03T09:36:02.879622+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>ax25: Fix refcount imbalance on inbound connections</p>
<p>When releasing a socket in ax25_release(), we call netdev_put() to
decrease the refcount on the associated ax.25 device. However, the
execution path for accepting an incoming connection never calls
netdev_hold(). This imbalance leads to refcount errors, and ultimately
to kernel crashes.</p>
<p>A typical call trace for the above situation will start with one of the
following errors:</p>
<p>refcount_t: decrement hit 0; leaking memory.
    refcount_t: underflow; use-after-free.</p>
<p>And will then have a trace like:</p>
<p>Call Trace:
    &lt;TASK&gt;
    ? show_regs+0x64/0x70
    ? __warn+0x83/0x120
    ? refcount_warn_saturate+0xb2/0x100
    ? report_bug+0x158/0x190
    ? prb_read_valid+0x20/0x30
    ? handle_bug+0x3e/0x70
    ? exc_invalid_op+0x1c/0x70
    ? asm_exc_invalid_op+0x1f/0x30
    ? refcount_warn_saturate+0xb2/0x100
    ? refcount_warn_saturate+0xb2/0x100
    ax25_release+0x2ad/0x360
    __sock_release+0x35/0xa0
    sock_close+0x19/0x20
    [...]</p>
<p>On reboot (or any attempt to remove the interface), the kernel gets
stuck in an infinite loop:</p>
<p>unregister_netdevice: waiting for ax0 to become free. Usage count = 0</p>
<p>This patch corrects these issues by ensuring that we call netdev_hold()
and ax25_dev_hold() for new connections in ax25_accept(). This makes the
logic leading to ax25_accept() match the logic for ax25_bind(): in both
cases we increment the refcount, which…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-37qc-prgq-xwcm"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2024-1961</id>
    <title>OESA-2024-1961 — kernel security update</title>
    <updated>2026-10-03T09:36:02.879655+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP4: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):

In the Linux kernel, the following vulnerability has been resolved:

NFSD: Fix the behavior of READ near OFFSET_MAX

Dan Aloni reports:
&amp;gt; Due to commit 8cfb9015280d (&amp;quot;NFS: Always provide aligned buffers to
&amp;gt; the RPC read layers&amp;quot;) on the client, a read of 0xfff is aligned up
&amp;gt; to server rsize of 0x1000.
&amp;gt;
&amp;gt; As a result, in a test where the server has a file of size
&amp;gt; 0x7fffffffffffffff, and the client tries to read from the offset
&amp;gt; 0x7ffffffffffff000, the read causes loff_t overflow in the server
&amp;gt; and it returns an NFS code of EINVAL to the client. The client as
&amp;gt; a result indefinitely retries the request.

The Linux NFS client does not handle NFS?ERR_INVAL, even though all
NFS specifications permit servers to return that status code for a
READ.

Instead of NFS?ERR_INVAL, have out-of-range READ requests succeed
and return a short result. Set the EOF flag in the result to prevent
the client from retrying the READ request. This behavior appears to
be consistent with Solaris NFS servers.

Note that NFSv3 and NFSv4 use u64 offset values on the wire. These
must be converted to loff_t internally before use -- an implicit
type cast is not adequate for this purpose. Otherwise VFS checks
against sb-&amp;gt;s_maxbytes do not work properly.(CVE-2022-48827)

In the Linux kernel, the following vulnerability has been resolved:

net: can: j1939: enhanced error handlin…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2024-1961"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2024:3194-1</id>
    <title>SUSE-SU-2024:3194-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-03T09:36:02.879861+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2024:3194-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-40910</id>
    <title>UBUNTU-CVE-2024-40910</title>
    <updated>2026-10-03T09:36:02.880096+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:Pro:16.04:LTS: linux-kvm and 174 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: ax25: Fix refcount imbalance on inbound connections When releasing a socket in ax25_release(), we call netdev_put() to decrease the refcount on the associated ax.25 device. However, the execution path for accepting an incoming connection never calls netdev_hold(). This imbalance leads to refcount errors, and ultimately to kernel crashes. A typical call trace for the above situation will start with one of the following errors:     refcount_t: decrement hit 0; leaking memory.     refcount_t: underflow; use-after-free. And will then have a trace like:     Call Trace:     &lt;TASK&gt;     ? show_regs+0x64/0x70     ? __warn+0x83/0x120     ? refcount_warn_saturate+0xb2/0x100     ? report_bug+0x158/0x190     ? prb_read_valid+0x20/0x30     ? handle_bug+0x3e/0x70     ? exc_invalid_op+0x1c/0x70     ? asm_exc_invalid_op+0x1f/0x30     ? refcount_warn_saturate+0xb2/0x100     ? refcount_warn_saturate+0xb2/0x100     ax25_release+0x2ad/0x360     __sock_release+0x35/0xa0     sock_close+0x19/0x20     [...] On reboot (or any attempt to remove the interface), the kernel gets stuck in an infinite loop:     unregister_netdevice: waiting for ax0 to become free. Usage count = 0 This patch corrects these issues by ensuring that we call netdev_hold() and ax25_dev_hold() for new connections in ax25_accept(). This makes the logic leading to ax25_accept() match the logic for ax25_bind(): in both cases we increment the refcount, which is ultim…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-40910"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1607</id>
    <title>WID-SEC-W-2024-1607 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-03T09:36:02.880341+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann mehrere Schwachstellen im Linux-Kernel ausnutzen, um seine Privilegien zu erweitern, einen Denial-of-Service-Zustand zu erzeugen, vertrauliche Informationen offenzulegen oder einen unspezifischen Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1607"/>
  </entry>
</feed>
