<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T15:41:05.113850+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-01939</id>
    <title>bdu:2025-01939</title>
    <updated>2026-10-04T15:41:05.412530+00:00</updated>
    <content>bdu:2025-01939</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-01939"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2024-46693</id>
    <title>BELL-CVE-2024-46693</title>
    <updated>2026-10-04T15:41:05.412610+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2024-46693"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0870</id>
    <title>certfr-2024-avi-0870 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
    <updated>2026-10-04T15:41:05.412659+00:00</updated>
    <content>certfr-2024-avi-0870</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0870"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2024-39358</id>
    <title>cnvd-2024-39358</title>
    <updated>2026-10-04T15:41:05.412682+00:00</updated>
    <content>cnvd-2024-39358</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2024-39358"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-313229</id>
    <title>EUVD-2026-313229</title>
    <updated>2026-10-04T15:41:05.412695+00:00</updated>
    <content>EUVD-2026-313229</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-313229"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-46693</id>
    <title>fkie_cve-2024-46693</title>
    <updated>2026-10-04T15:41:05.412706+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>soc: qcom: pmic_glink: Fix race during initialization</p>
<p>As pointed out by Stephen Boyd it is possible that during initialization
of the pmic_glink child drivers, the protection-domain notifiers fires,
and the associated work is scheduled, before the client registration
returns and as a result the local "client" pointer has been initialized.</p>
<p>The outcome of this is a NULL pointer dereference as the "client"
pointer is blindly dereferenced.</p>
<p>Timeline provided by Stephen:
 CPU0                               CPU1
 ----                               ----
 ucsi-&gt;client = NULL;
 devm_pmic_glink_register_client()
  client-&gt;pdr_notify(client-&gt;priv, pg-&gt;client_state)
   pmic_glink_ucsi_pdr_notify()
    schedule_work(&amp;ucsi-&gt;register_work)
    &lt;schedule away&gt;
                                    pmic_glink_ucsi_register()
                                     ucsi_register()
                                      pmic_glink_ucsi_read_version()
                                       pmic_glink_ucsi_read()
                                        pmic_glink_ucsi_read()
                                         pmic_glink_send(ucsi-&gt;client)
                                         &lt;client is NULL BAD&gt;
 ucsi-&gt;client = client // Too late!</p>
<p>This code is identical across the altmode, battery manager and usci
child drivers.</p>
<p>Resolve this by splitting the allocation of the "client" object and the
registration thereof into two operati…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-46693"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-5qvx-cmvh-v55m</id>
    <title>GHSA-5qvx-cmvh-v55m</title>
    <updated>2026-10-04T15:41:05.412752+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>soc: qcom: pmic_glink: Fix race during initialization</p>
<p>As pointed out by Stephen Boyd it is possible that during initialization
of the pmic_glink child drivers, the protection-domain notifiers fires,
and the associated work is scheduled, before the client registration
returns and as a result the local "client" pointer has been initialized.</p>
<p>The outcome of this is a NULL pointer dereference as the "client"
pointer is blindly dereferenced.</p>
<p>Timeline provided by Stephen:
 CPU0                               CPU1
 ----                               ----
 ucsi-&gt;client = NULL;
 devm_pmic_glink_register_client()
  client-&gt;pdr_notify(client-&gt;priv, pg-&gt;client_state)
   pmic_glink_ucsi_pdr_notify()
    schedule_work(&amp;ucsi-&gt;register_work)
    &lt;schedule away&gt;
                                    pmic_glink_ucsi_register()
                                     ucsi_register()
                                      pmic_glink_ucsi_read_version()
                                       pmic_glink_ucsi_read()
                                        pmic_glink_ucsi_read()
                                         pmic_glink_send(ucsi-&gt;client)
                                         &lt;client is NULL BAD&gt;
 ucsi-&gt;client = client // Too late!</p>
<p>This code is identical across the altmode, battery manager and usci
child drivers.</p>
<p>Resolve this by splitting the allocation of the "client" object and the
registration thereof into two operati…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-5qvx-cmvh-v55m"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2024-46693</id>
    <title>msrc_CVE-2024-46693 — soc: qcom: pmic_glink: Fix race during initialization</title>
    <updated>2026-10-04T15:41:05.412786+00:00</updated>
    <content>msrc_CVE-2024-46693</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2024-46693"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-1097</id>
    <title>OESA-2025-1097 — kernel security update</title>
    <updated>2026-10-04T15:41:05.412816+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>ksmbd: fix potencial out-of-bounds when buffer offset is invalid</p>
<p>I found potencial out-of-bounds when buffer offset fields of a few requests
is invalid. This patch set the minimum value of buffer offset field to
-&amp;gt;Buffer offset to validate buffer length.(CVE-2024-26952)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>ksmbd: fix slab-out-of-bounds in smb_strndup_from_utf16()</p>
<p>If -&amp;gt;NameOffset of smb2_create_req is smaller than Buffer offset of
smb2_create_req, slab-out-of-bounds read can happen from smb2_open.
This patch set the minimum value of the name offset to the buffer offset
to validate name length of smb2_create_req().(CVE-2024-26954)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>fpga: bridge: add owner module and take its refcount</p>
<p>The current implementation of the fpga bridge assumes that the low-level
module registers a driver for the parent device and uses its owner pointer
to take the module&amp;apos;s refcount. This approach is problematic since it can
lead to a null pointer dereference while attempting to get the bridge if
the parent device does not have a driver.</p>
<p>To address this problem, add a module owner pointer to the fpga_bridge
struct and use it to take the module&amp;apos;s refcount. Modify the function for
registering a bridge to take an additional owner module paramet…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-1097"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2024:3551-1</id>
    <title>SUSE-SU-2024:3551-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-04T15:41:05.414505+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2024:3551-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-46693</id>
    <title>UBUNTU-CVE-2024-46693</title>
    <updated>2026-10-04T15:41:05.414648+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 89 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: soc: qcom: pmic_glink: Fix race during initialization As pointed out by Stephen Boyd it is possible that during initialization of the pmic_glink child drivers, the protection-domain notifiers fires, and the associated work is scheduled, before the client registration returns and as a result the local "client" pointer has been initialized. The outcome of this is a NULL pointer dereference as the "client" pointer is blindly dereferenced. Timeline provided by Stephen:  CPU0                               CPU1  ----                               ----  ucsi-&gt;client = NULL;  devm_pmic_glink_register_client()   client-&gt;pdr_notify(client-&gt;priv, pg-&gt;client_state)    pmic_glink_ucsi_pdr_notify()     schedule_work(&amp;ucsi-&gt;register_work)     &lt;schedule away&gt;                                     pmic_glink_ucsi_register()                                      ucsi_register()                                       pmic_glink_ucsi_read_version()                                        pmic_glink_ucsi_read()                                         pmic_glink_ucsi_read()                                          pmic_glink_send(ucsi-&gt;client)                                          &lt;client is NULL BAD&gt;  ucsi-&gt;client = client // Too late! This code is identical across the altmode, battery manager and usci child drivers. Resolve this by splitting the allocation of the "client" object and the registration thereof into two operations. T…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-46693"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-2133</id>
    <title>WID-SEC-W-2024-2133 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-04T15:41:05.414861+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder einen unspezifischen Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-2133"/>
  </entry>
</feed>
