<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T15:02:03.679752+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-01444</id>
    <title>bdu:2026-01444</title>
    <updated>2026-10-04T15:02:03.802236+00:00</updated>
    <content>bdu:2026-01444</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-01444"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2024-41067</id>
    <title>BELL-CVE-2024-41067</title>
    <updated>2026-10-04T15:02:03.802275+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2024-41067"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0957</id>
    <title>certfr-2024-avi-0957 — De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Certaines d'entre elles permettent à un a…</title>
    <updated>2026-10-04T15:02:03.802306+00:00</updated>
    <content>certfr-2024-avi-0957</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0957"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-313000</id>
    <title>EUVD-2026-313000</title>
    <updated>2026-10-04T15:02:03.802324+00:00</updated>
    <content>EUVD-2026-313000</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-313000"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-41067</id>
    <title>fkie_cve-2024-41067</title>
    <updated>2026-10-04T15:02:03.802337+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>btrfs: scrub: handle RST lookup error correctly</p>
<p>[BUG]
When running btrfs/060 with forced RST feature, it would crash the
following ASSERT() inside scrub_read_endio():</p>
<p>ASSERT(sector_nr &lt; stripe-&gt;nr_sectors);</p>
<p>Before that, we would have tree dump from
btrfs_get_raid_extent_offset(), as we failed to find the RST entry for
the range.</p>
<p>[CAUSE]
Inside scrub_submit_extent_sector_read() every time we allocated a new
bbio we immediately called btrfs_map_block() to make sure there was some
RST range covering the scrub target.</p>
<p>But if btrfs_map_block() fails, we immediately call endio for the bbio,
while the bbio is newly allocated, it's completely empty.</p>
<p>Then inside scrub_read_endio(), we go through the bvecs to find
the sector number (as bi_sector is no longer reliable if the bio is
submitted to lower layers).</p>
<p>And since the bio is empty, such bvecs iteration would not find any
sector matching the sector, and return sector_nr == stripe-&gt;nr_sectors,
triggering the ASSERT().</p>
<p>[FIX]
Instead of calling btrfs_map_block() after allocating a new bbio, call
btrfs_map_block() first.</p>
<p>Since our only objective of calling btrfs_map_block() is only to update
stripe_len, there is really no need to do that after btrfs_alloc_bio().</p>
<p>This new timing would avoid the problem of handling empty bbio
completely, and in fact fixes a possible race window for the old code,
where if the submission thread is the only owner of the pending_…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-41067"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-36gh-mcf5-3vpm</id>
    <title>GHSA-36gh-mcf5-3vpm</title>
    <updated>2026-10-04T15:02:03.802383+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>btrfs: scrub: handle RST lookup error correctly</p>
<p>[BUG]
When running btrfs/060 with forced RST feature, it would crash the
following ASSERT() inside scrub_read_endio():</p>
<p>ASSERT(sector_nr &lt; stripe-&gt;nr_sectors);</p>
<p>Before that, we would have tree dump from
btrfs_get_raid_extent_offset(), as we failed to find the RST entry for
the range.</p>
<p>[CAUSE]
Inside scrub_submit_extent_sector_read() every time we allocated a new
bbio we immediately called btrfs_map_block() to make sure there was some
RST range covering the scrub target.</p>
<p>But if btrfs_map_block() fails, we immediately call endio for the bbio,
while the bbio is newly allocated, it's completely empty.</p>
<p>Then inside scrub_read_endio(), we go through the bvecs to find
the sector number (as bi_sector is no longer reliable if the bio is
submitted to lower layers).</p>
<p>And since the bio is empty, such bvecs iteration would not find any
sector matching the sector, and return sector_nr == stripe-&gt;nr_sectors,
triggering the ASSERT().</p>
<p>[FIX]
Instead of calling btrfs_map_block() after allocating a new bbio, call
btrfs_map_block() first.</p>
<p>Since our only objective of calling btrfs_map_block() is only to update
stripe_len, there is really no need to do that after btrfs_alloc_bio().</p>
<p>This new timing would avoid the problem of handling empty bbio
completely, and in fact fixes a possible race window for the old code,
where if the submission thread is the only owner of the pending_…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-36gh-mcf5-3vpm"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2024-41067</id>
    <title>msrc_CVE-2024-41067 — btrfs: scrub: handle RST lookup error correctly</title>
    <updated>2026-10-04T15:02:03.802418+00:00</updated>
    <content>msrc_CVE-2024-41067</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2024-41067"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-41067</id>
    <title>UBUNTU-CVE-2024-41067</title>
    <updated>2026-10-04T15:02:03.802436+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 188 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: btrfs: scrub: handle RST lookup error correctly [BUG] When running btrfs/060 with forced RST feature, it would crash the following ASSERT() inside scrub_read_endio(): 	ASSERT(sector_nr &lt; stripe-&gt;nr_sectors); Before that, we would have tree dump from btrfs_get_raid_extent_offset(), as we failed to find the RST entry for the range. [CAUSE] Inside scrub_submit_extent_sector_read() every time we allocated a new bbio we immediately called btrfs_map_block() to make sure there was some RST range covering the scrub target. But if btrfs_map_block() fails, we immediately call endio for the bbio, while the bbio is newly allocated, it's completely empty. Then inside scrub_read_endio(), we go through the bvecs to find the sector number (as bi_sector is no longer reliable if the bio is submitted to lower layers). And since the bio is empty, such bvecs iteration would not find any sector matching the sector, and return sector_nr == stripe-&gt;nr_sectors, triggering the ASSERT(). [FIX] Instead of calling btrfs_map_block() after allocating a new bbio, call btrfs_map_block() first. Since our only objective of calling btrfs_map_block() is only to update stripe_len, there is really no need to do that after btrfs_alloc_bio(). This new timing would avoid the problem of handling empty bbio completely, and in fact fixes a possible race window for the old code, where if the submission thread is the only owner of the pending_io, the scr…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-41067"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1722</id>
    <title>WID-SEC-W-2024-1722 — Linux Kernel: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff</title>
    <updated>2026-10-04T15:02:03.802707+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1722"/>
  </entry>
</feed>
