<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T15:30:11.546171+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2024:6567</id>
    <title>ALSA-2024:6567 — Moderate: kernel security update</title>
    <updated>2026-10-04T15:30:12.073921+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: bpftool, AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core and 52 more</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: efivarfs: force RO when remounting if SetVariable is not supported (CVE-2023-52463)
  * kernel: nfsd: fix RELEASE_LOCKOWNER (CVE-2024-26629)
  * kernel: mm: cachestat: fix folio read-after-free in cache walk (CVE-2024-26630)
  * kernel: mm/writeback: fix possible divide-by-zero in wb_dirty_limits(), again (CVE-2024-26720)
  * kernel: Bluetooth: af_bluetooth: Fix deadlock (CVE-2024-26886)
  * kernel: kprobes/x86: Use copy_from_kernel_nofault() to read from unsafe address (CVE-2024-26946)
  * kernel: KVM: SVM: Flush pages under kvm-&amp;gt;lock to fix UAF in svm_register_enc_region() (CVE-2024-35791)
  * kernel: mm: cachestat: fix two shmem bugs (CVE-2024-35797)
  * kernel: x86/coco: Require seeding RNG with RDRAND on CoCo systems (CVE-2024-35875)
  * kernel: mm/hugetlb: fix missing hugetlb_lock for resv uncharge (CVE-2024-36000)
  * kernel: iommufd: Fix missing update of domains_itree after splitting iopt_area (CVE-2023-52801)
  * kernel: net: fix out-of-bounds access in ops_init (CVE-2024-36883)
  * kernel: regmap: maple: Fix cache corruption in regcache_maple_drop() (CVE-2024-36019)
  * kernel: usb-storage: alauda: Check whether the media is initialized (CVE-2024-38619)
  * kernel: net: bridge: mst: fix vlan use-after-free (CVE-2024-36979)
  * kernel: scsi: qedf: Ensure the copied buf is NUL terminated (CVE-2024-38559)
  * kernel: xhci: Handle TD clearing fo…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2024:6567"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-07927</id>
    <title>bdu:2024-07927</title>
    <updated>2026-10-04T15:30:12.074102+00:00</updated>
    <content>bdu:2024-07927</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-07927"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2024-41096</id>
    <title>BELL-CVE-2024-41096</title>
    <updated>2026-10-04T15:30:12.074124+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2024-41096"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0777</id>
    <title>certfr-2024-avi-0777 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Red Hat. Certaines d'entre elles permettent à un…</title>
    <updated>2026-10-04T15:30:12.074148+00:00</updated>
    <content>certfr-2024-avi-0777</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0777"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-345945</id>
    <title>EUVD-2026-345945</title>
    <updated>2026-10-04T15:30:12.074165+00:00</updated>
    <content>EUVD-2026-345945</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-345945"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-41096</id>
    <title>fkie_cve-2024-41096</title>
    <updated>2026-10-04T15:30:12.074177+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>PCI/MSI: Fix UAF in msi_capability_init</p>
<p>KFENCE reports the following UAF:</p>
<p>BUG: KFENCE: use-after-free read in __pci_enable_msi_range+0x2c0/0x488</p>
<p>Use-after-free read at 0x0000000024629571 (in kfence-#12):
  __pci_enable_msi_range+0x2c0/0x488
  pci_alloc_irq_vectors_affinity+0xec/0x14c
  pci_alloc_irq_vectors+0x18/0x28</p>
<p>kfence-#12: 0x0000000008614900-0x00000000e06c228d, size=104, cache=kmalloc-128</p>
<p>allocated by task 81 on cpu 7 at 10.808142s:
  __kmem_cache_alloc_node+0x1f0/0x2bc
  kmalloc_trace+0x44/0x138
  msi_alloc_desc+0x3c/0x9c
  msi_domain_insert_msi_desc+0x30/0x78
  msi_setup_msi_desc+0x13c/0x184
  __pci_enable_msi_range+0x258/0x488
  pci_alloc_irq_vectors_affinity+0xec/0x14c
  pci_alloc_irq_vectors+0x18/0x28</p>
<p>freed by task 81 on cpu 7 at 10.811436s:
  msi_domain_free_descs+0xd4/0x10c
  msi_domain_free_locked.part.0+0xc0/0x1d8
  msi_domain_alloc_irqs_all_locked+0xb4/0xbc
  pci_msi_setup_msi_irqs+0x30/0x4c
  __pci_enable_msi_range+0x2a8/0x488
  pci_alloc_irq_vectors_affinity+0xec/0x14c
  pci_alloc_irq_vectors+0x18/0x28</p>
<p>Descriptor allocation done in:
__pci_enable_msi_range
    msi_capability_init
        msi_setup_msi_desc
            msi_insert_msi_desc
                msi_domain_insert_msi_desc
                    msi_alloc_desc
                        ...</p>
<p>Freed in case of failure in __msi_domain_alloc_locked()
__pci_enable_msi_range
    msi_capability_init
        pci_msi_setup_msi_irqs…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-41096"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-f5xx-949w-7ch3</id>
    <title>GHSA-f5xx-949w-7ch3</title>
    <updated>2026-10-04T15:30:12.074221+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>PCI/MSI: Fix UAF in msi_capability_init</p>
<p>KFENCE reports the following UAF:</p>
<p>BUG: KFENCE: use-after-free read in __pci_enable_msi_range+0x2c0/0x488</p>
<p>Use-after-free read at 0x0000000024629571 (in kfence-#12):
  __pci_enable_msi_range+0x2c0/0x488
  pci_alloc_irq_vectors_affinity+0xec/0x14c
  pci_alloc_irq_vectors+0x18/0x28</p>
<p>kfence-#12: 0x0000000008614900-0x00000000e06c228d, size=104, cache=kmalloc-128</p>
<p>allocated by task 81 on cpu 7 at 10.808142s:
  __kmem_cache_alloc_node+0x1f0/0x2bc
  kmalloc_trace+0x44/0x138
  msi_alloc_desc+0x3c/0x9c
  msi_domain_insert_msi_desc+0x30/0x78
  msi_setup_msi_desc+0x13c/0x184
  __pci_enable_msi_range+0x258/0x488
  pci_alloc_irq_vectors_affinity+0xec/0x14c
  pci_alloc_irq_vectors+0x18/0x28</p>
<p>freed by task 81 on cpu 7 at 10.811436s:
  msi_domain_free_descs+0xd4/0x10c
  msi_domain_free_locked.part.0+0xc0/0x1d8
  msi_domain_alloc_irqs_all_locked+0xb4/0xbc
  pci_msi_setup_msi_irqs+0x30/0x4c
  __pci_enable_msi_range+0x2a8/0x488
  pci_alloc_irq_vectors_affinity+0xec/0x14c
  pci_alloc_irq_vectors+0x18/0x28</p>
<p>Descriptor allocation done in:
__pci_enable_msi_range
    msi_capability_init
        msi_setup_msi_desc
            msi_insert_msi_desc
                msi_domain_insert_msi_desc
                    msi_alloc_desc
                        ...</p>
<p>Freed in case of failure in __msi_domain_alloc_locked()
__pci_enable_msi_range
    msi_capability_init
        pci_msi_setup_msi_irqs…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-f5xx-949w-7ch3"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2024-41096</id>
    <title>msrc_CVE-2024-41096 — PCI/MSI: Fix UAF in msi_capability_init</title>
    <updated>2026-10-04T15:30:12.074256+00:00</updated>
    <content>msrc_CVE-2024-41096</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2024-41096"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2024-1960</id>
    <title>OESA-2024-1960 — kernel security update</title>
    <updated>2026-10-04T15:30:12.074273+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):

In the Linux kernel, the following vulnerability has been resolved:

efi: libstub: only free priv.runtime_map when allocated

priv.runtime_map is only allocated when efi_novamap is not set.
Otherwise, it is an uninitialized value.  In the error path, it is freed
unconditionally.  Avoid passing an uninitialized value to free_pool.
Free priv.runtime_map only when it was allocated.

This bug was discovered and resolved using Coverity Static Analysis
Security Testing (SAST) by Synopsys, Inc.(CVE-2024-33619)

In the Linux kernel, the following vulnerability has been resolved:

fpga: region: add owner module and take its refcount

The current implementation of the fpga region assumes that the low-level
module registers a driver for the parent device and uses its owner pointer
to take the module&amp;apos;s refcount. This approach is problematic since it can
lead to a null pointer dereference while attempting to get the region
during programming if the parent device does not have a driver.

To address this problem, add a module owner pointer to the fpga_region
struct and use it to take the module&amp;apos;s refcount. Modify the functions for
registering a region to take an additional owner module parameter and
rename them to avoid conflicts. Use the old function names for helper
macros that automatically set the module that registers the region as the
owner. This ensures compatibility with existing low…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2024-1960"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:6567</id>
    <title>RHSA-2024:6567 — Red Hat Security Advisory: kernel security update</title>
    <updated>2026-10-04T15:30:12.074578+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: efivarfs: force RO when remounting if SetVariable is not supported kernel: iommufd: Fix missing update of domains_itree after splitting iopt_area kernel: nfsd: fix RELEASE_LOCKOWNER kernel: mm: cachestat: fix folio read-after-free in cache walk kernel: mm/writeback: fix possible divide-by-zero in wb_dirty_limits(), again kernel: Bluetooth: af_bluetooth: Fix deadlock kernel: kprobes/x86: Use copy_from_kernel_nofault() to read from unsafe address kernel: KVM: SVM: Flush pages under kvm-&amp;gt;lock to fix UAF in svm_register_enc_region() kernel: mm: cachestat: fix two shmem bugs kernel: x86/coco: Require seeding RNG with RDRAND on CoCo systems kernel: mm/hugetlb: fix missing hugetlb_lock for resv uncharge kernel: regmap: maple: Fix cache corruption in regcache_maple_drop() kernel: net: fix out-of-bounds access in ops_init kernel: net: bridge: mst: fix vlan use-after-free kernel: scsi: qedf: Ensure the copied buf is NUL terminated kernel: usb-storage: alauda: Check whether the media is initialized kernel: xhci: Handle TD clearing for multiple streams case kernel: cxl/region: Fix memregion leaks in devm_cxl_add_region() kernel: net/sched: Fix UAF when resolving a clash kernel: ppp: reject claimed-as-LCP but actually malformed packets kernel: mm: prevent derefencing NULL ptr in pfn_section_valid() kernel: nvme: avoid double free special payload kernel: PCI/MSI: Fix UAF in msi_capability_init kernel: xdp: Remove WARN() from __xdp_reg_mem_model() kernel: x86: stop playing stack…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:6567"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2024:3194-1</id>
    <title>SUSE-SU-2024:3194-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-04T15:30:12.074648+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2024:3194-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-41096</id>
    <title>UBUNTU-CVE-2024-41096</title>
    <updated>2026-10-04T15:30:12.074948+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 89 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: PCI/MSI: Fix UAF in msi_capability_init KFENCE reports the following UAF:  BUG: KFENCE: use-after-free read in __pci_enable_msi_range+0x2c0/0x488  Use-after-free read at 0x0000000024629571 (in kfence-#12):   __pci_enable_msi_range+0x2c0/0x488   pci_alloc_irq_vectors_affinity+0xec/0x14c   pci_alloc_irq_vectors+0x18/0x28  kfence-#12: 0x0000000008614900-0x00000000e06c228d, size=104, cache=kmalloc-128  allocated by task 81 on cpu 7 at 10.808142s:   __kmem_cache_alloc_node+0x1f0/0x2bc   kmalloc_trace+0x44/0x138   msi_alloc_desc+0x3c/0x9c   msi_domain_insert_msi_desc+0x30/0x78   msi_setup_msi_desc+0x13c/0x184   __pci_enable_msi_range+0x258/0x488   pci_alloc_irq_vectors_affinity+0xec/0x14c   pci_alloc_irq_vectors+0x18/0x28  freed by task 81 on cpu 7 at 10.811436s:   msi_domain_free_descs+0xd4/0x10c   msi_domain_free_locked.part.0+0xc0/0x1d8   msi_domain_alloc_irqs_all_locked+0xb4/0xbc   pci_msi_setup_msi_irqs+0x30/0x4c   __pci_enable_msi_range+0x2a8/0x488   pci_alloc_irq_vectors_affinity+0xec/0x14c   pci_alloc_irq_vectors+0x18/0x28 Descriptor allocation done in: __pci_enable_msi_range     msi_capability_init         msi_setup_msi_desc             msi_insert_msi_desc                 msi_domain_insert_msi_desc                     msi_alloc_desc                         ... Freed in case of failure in __msi_domain_alloc_locked() __pci_enable_msi_range     msi_capability_init         pci_msi_setup_msi_irqs             m…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-41096"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1722</id>
    <title>WID-SEC-W-2024-1722 — Linux Kernel: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff</title>
    <updated>2026-10-04T15:30:12.075297+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1722"/>
  </entry>
</feed>
