<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T08:38:14.414264+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-05936</id>
    <title>bdu:2025-05936</title>
    <updated>2026-10-04T08:38:14.526371+00:00</updated>
    <content>bdu:2025-05936</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-05936"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2024-46847</id>
    <title>BELL-CVE-2024-46847</title>
    <updated>2026-10-04T08:38:14.526407+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2024-46847"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-1080</id>
    <title>certfr-2024-avi-1080 — De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Elles permettent à un attaquant de provoq…</title>
    <updated>2026-10-04T08:38:14.526437+00:00</updated>
    <content>certfr-2024-avi-1080</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-1080"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-346144</id>
    <title>EUVD-2026-346144</title>
    <updated>2026-10-04T08:38:14.526454+00:00</updated>
    <content>EUVD-2026-346144</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-346144"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-46847</id>
    <title>fkie_cve-2024-46847</title>
    <updated>2026-10-04T08:38:14.526465+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>mm: vmalloc: ensure vmap_block is initialised before adding to queue</p>
<p>Commit 8c61291fd850 ("mm: fix incorrect vbq reference in
purge_fragmented_block") extended the 'vmap_block' structure to contain a
'cpu' field which is set at allocation time to the id of the initialising
CPU.</p>
<p>When a new 'vmap_block' is being instantiated by new_vmap_block(), the
partially initialised structure is added to the local 'vmap_block_queue'
xarray before the 'cpu' field has been initialised.  If another CPU is
concurrently walking the xarray (e.g.  via vm_unmap_aliases()), then it
may perform an out-of-bounds access to the remote queue thanks to an
uninitialised index.</p>
<p>This has been observed as UBSAN errors in Android:</p>
<p>| Internal error: UBSAN: array index out of bounds: 00000000f2005512 [#1] PREEMPT SMP
 |
 | Call trace:
 |  purge_fragmented_block+0x204/0x21c
 |  _vm_unmap_aliases+0x170/0x378
 |  vm_unmap_aliases+0x1c/0x28
 |  change_memory_common+0x1dc/0x26c
 |  set_memory_ro+0x18/0x24
 |  module_enable_ro+0x98/0x238
 |  do_init_module+0x1b0/0x310</p>
<p>Move the initialisation of 'vb-&gt;cpu' in new_vmap_block() ahead of the
addition to the xarray.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-46847"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-9r77-32hh-rxf4</id>
    <title>GHSA-9r77-32hh-rxf4</title>
    <updated>2026-10-04T08:38:14.526503+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>mm: vmalloc: ensure vmap_block is initialised before adding to queue</p>
<p>Commit 8c61291fd850 ("mm: fix incorrect vbq reference in
purge_fragmented_block") extended the 'vmap_block' structure to contain a
'cpu' field which is set at allocation time to the id of the initialising
CPU.</p>
<p>When a new 'vmap_block' is being instantiated by new_vmap_block(), the
partially initialised structure is added to the local 'vmap_block_queue'
xarray before the 'cpu' field has been initialised.  If another CPU is
concurrently walking the xarray (e.g.  via vm_unmap_aliases()), then it
may perform an out-of-bounds access to the remote queue thanks to an
uninitialised index.</p>
<p>This has been observed as UBSAN errors in Android:</p>
<p>| Internal error: UBSAN: array index out of bounds: 00000000f2005512 [#1] PREEMPT SMP
 |
 | Call trace:
 |  purge_fragmented_block+0x204/0x21c
 |  _vm_unmap_aliases+0x170/0x378
 |  vm_unmap_aliases+0x1c/0x28
 |  change_memory_common+0x1dc/0x26c
 |  set_memory_ro+0x18/0x24
 |  module_enable_ro+0x98/0x238
 |  do_init_module+0x1b0/0x310</p>
<p>Move the initialisation of 'vb-&gt;cpu' in new_vmap_block() ahead of the
addition to the xarray.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-9r77-32hh-rxf4"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2024-46847</id>
    <title>msrc_CVE-2024-46847 — mm: vmalloc: ensure vmap_block is initialised before adding to queue</title>
    <updated>2026-10-04T08:38:14.526531+00:00</updated>
    <content>msrc_CVE-2024-46847</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2024-46847"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-1097</id>
    <title>OESA-2025-1097 — kernel security update</title>
    <updated>2026-10-04T08:38:14.526548+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>ksmbd: fix potencial out-of-bounds when buffer offset is invalid</p>
<p>I found potencial out-of-bounds when buffer offset fields of a few requests
is invalid. This patch set the minimum value of buffer offset field to
-&amp;gt;Buffer offset to validate buffer length.(CVE-2024-26952)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>ksmbd: fix slab-out-of-bounds in smb_strndup_from_utf16()</p>
<p>If -&amp;gt;NameOffset of smb2_create_req is smaller than Buffer offset of
smb2_create_req, slab-out-of-bounds read can happen from smb2_open.
This patch set the minimum value of the name offset to the buffer offset
to validate name length of smb2_create_req().(CVE-2024-26954)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>fpga: bridge: add owner module and take its refcount</p>
<p>The current implementation of the fpga bridge assumes that the low-level
module registers a driver for the parent device and uses its owner pointer
to take the module&amp;apos;s refcount. This approach is problematic since it can
lead to a null pointer dereference while attempting to get the bridge if
the parent device does not have a driver.</p>
<p>To address this problem, add a module owner pointer to the fpga_bridge
struct and use it to take the module&amp;apos;s refcount. Modify the function for
registering a bridge to take an additional owner module paramet…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-1097"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-46847</id>
    <title>UBUNTU-CVE-2024-46847</title>
    <updated>2026-10-04T08:38:14.527581+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 87 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: mm: vmalloc: ensure vmap_block is initialised before adding to queue Commit 8c61291fd850 ("mm: fix incorrect vbq reference in purge_fragmented_block") extended the 'vmap_block' structure to contain a 'cpu' field which is set at allocation time to the id of the initialising CPU. When a new 'vmap_block' is being instantiated by new_vmap_block(), the partially initialised structure is added to the local 'vmap_block_queue' xarray before the 'cpu' field has been initialised.  If another CPU is concurrently walking the xarray (e.g.  via vm_unmap_aliases()), then it may perform an out-of-bounds access to the remote queue thanks to an uninitialised index. This has been observed as UBSAN errors in Android:  | Internal error: UBSAN: array index out of bounds: 00000000f2005512 [#1] PREEMPT SMP  |  | Call trace:  |  purge_fragmented_block+0x204/0x21c  |  _vm_unmap_aliases+0x170/0x378  |  vm_unmap_aliases+0x1c/0x28  |  change_memory_common+0x1dc/0x26c  |  set_memory_ro+0x18/0x24  |  module_enable_ro+0x98/0x238  |  do_init_module+0x1b0/0x310 Move the initialisation of 'vb-&gt;cpu' in new_vmap_block() ahead of the addition to the xarray.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-46847"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3050</id>
    <title>WID-SEC-W-2024-3050 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-04T08:38:14.527720+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen und andere nicht spezifizierte Auswirkungen zu verursachen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3050"/>
  </entry>
</feed>
