<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T21:16:53.286729+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-03254</id>
    <title>bdu:2025-03254</title>
    <updated>2026-10-03T21:16:53.759180+00:00</updated>
    <content>bdu:2025-03254</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-03254"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2024-46857</id>
    <title>BELL-CVE-2024-46857</title>
    <updated>2026-10-03T21:16:53.759282+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2024-46857"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0837</id>
    <title>certfr-2024-avi-0837 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian. Elles permettent à un attaquant de provo…</title>
    <updated>2026-10-03T21:16:53.759320+00:00</updated>
    <content>certfr-2024-avi-0837</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0837"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-313318</id>
    <title>EUVD-2026-313318</title>
    <updated>2026-10-03T21:16:53.759353+00:00</updated>
    <content>EUVD-2026-313318</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-313318"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-46857</id>
    <title>fkie_cve-2024-46857</title>
    <updated>2026-10-03T21:16:53.759367+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>net/mlx5: Fix bridge mode operations when there are no VFs</p>
<p>Currently, trying to set the bridge mode attribute when numvfs=0 leads to a
crash:</p>
<p>bridge link set dev eth2 hwmode vepa</p>
<p>[  168.967392] BUG: kernel NULL pointer dereference, address: 0000000000000030
[...]
[  168.969989] RIP: 0010:mlx5_add_flow_rules+0x1f/0x300 [mlx5_core]
[...]
[  168.976037] Call Trace:
[  168.976188]  &lt;TASK&gt;
[  168.978620]  _mlx5_eswitch_set_vepa_locked+0x113/0x230 [mlx5_core]
[  168.979074]  mlx5_eswitch_set_vepa+0x7f/0xa0 [mlx5_core]
[  168.979471]  rtnl_bridge_setlink+0xe9/0x1f0
[  168.979714]  rtnetlink_rcv_msg+0x159/0x400
[  168.980451]  netlink_rcv_skb+0x54/0x100
[  168.980675]  netlink_unicast+0x241/0x360
[  168.980918]  netlink_sendmsg+0x1f6/0x430
[  168.981162]  ____sys_sendmsg+0x3bb/0x3f0
[  168.982155]  ___sys_sendmsg+0x88/0xd0
[  168.985036]  __sys_sendmsg+0x59/0xa0
[  168.985477]  do_syscall_64+0x79/0x150
[  168.987273]  entry_SYSCALL_64_after_hwframe+0x76/0x7e
[  168.987773] RIP: 0033:0x7f8f7950f917</p>
<p>(esw-&gt;fdb_table.legacy.vepa_fdb is null)</p>
<p>The bridge mode is only relevant when there are multiple functions per
port. Therefore, prevent setting and getting this setting when there are no
VFs.</p>
<p>Note that after this change, there are no settings to change on the PF
interface using `bridge link` when there are no VFs, so the interface no
longer appears in the `bridge link` output.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-46857"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3rw3-pfv7-m7r7</id>
    <title>GHSA-3rw3-pfv7-m7r7</title>
    <updated>2026-10-03T21:16:53.759411+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>net/mlx5: Fix bridge mode operations when there are no VFs</p>
<p>Currently, trying to set the bridge mode attribute when numvfs=0 leads to a
crash:</p>
<p>bridge link set dev eth2 hwmode vepa</p>
<p>[  168.967392] BUG: kernel NULL pointer dereference, address: 0000000000000030
[...]
[  168.969989] RIP: 0010:mlx5_add_flow_rules+0x1f/0x300 [mlx5_core]
[...]
[  168.976037] Call Trace:
[  168.976188]  &lt;TASK&gt;
[  168.978620]  _mlx5_eswitch_set_vepa_locked+0x113/0x230 [mlx5_core]
[  168.979074]  mlx5_eswitch_set_vepa+0x7f/0xa0 [mlx5_core]
[  168.979471]  rtnl_bridge_setlink+0xe9/0x1f0
[  168.979714]  rtnetlink_rcv_msg+0x159/0x400
[  168.980451]  netlink_rcv_skb+0x54/0x100
[  168.980675]  netlink_unicast+0x241/0x360
[  168.980918]  netlink_sendmsg+0x1f6/0x430
[  168.981162]  ____sys_sendmsg+0x3bb/0x3f0
[  168.982155]  ___sys_sendmsg+0x88/0xd0
[  168.985036]  __sys_sendmsg+0x59/0xa0
[  168.985477]  do_syscall_64+0x79/0x150
[  168.987273]  entry_SYSCALL_64_after_hwframe+0x76/0x7e
[  168.987773] RIP: 0033:0x7f8f7950f917</p>
<p>(esw-&gt;fdb_table.legacy.vepa_fdb is null)</p>
<p>The bridge mode is only relevant when there are multiple functions per
port. Therefore, prevent setting and getting this setting when there are no
VFs.</p>
<p>Note that after this change, there are no settings to change on the PF
interface using `bridge link` when there are no VFs, so the interface no
longer appears in the `bridge link` output.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3rw3-pfv7-m7r7"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2024-46857</id>
    <title>msrc_CVE-2024-46857 — net/mlx5: Fix bridge mode operations when there are no VFs</title>
    <updated>2026-10-03T21:16:53.759442+00:00</updated>
    <content>msrc_CVE-2024-46857</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2024-46857"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2024-2216</id>
    <title>OESA-2024-2216 — kernel security update</title>
    <updated>2026-10-03T21:16:53.759460+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP3: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):

In the Linux kernel, the following vulnerability has been resolved:

ALSA: usb-audio: Stop parsing channels bits when all channels are found.

If a usb audio device sets more bits than the amount of channels
it could write outside of the map array.(CVE-2024-27436)

In the Linux kernel, the following vulnerability has been resolved:

usb: gadget: f_fs: Fix race between aio_cancel() and AIO request complete

FFS based applications can utilize the aio_cancel() callback to dequeue
pending USB requests submitted to the UDC.  There is a scenario where the
FFS application issues an AIO cancel call, while the UDC is handling a
soft disconnect.  For a DWC3 based implementation, the callstack looks
like the following:

    DWC3 Gadget                               FFS Application
dwc3_gadget_soft_disconnect()              ...
  --&amp;gt; dwc3_stop_active_transfers()
    --&amp;gt; dwc3_gadget_giveback(-ESHUTDOWN)
      --&amp;gt; ffs_epfile_async_io_complete()   ffs_aio_cancel()
        --&amp;gt; usb_ep_free_request()            --&amp;gt; usb_ep_dequeue()

There is currently no locking implemented between the AIO completion
handler and AIO cancel, so the issue occurs if the completion routine is
running in parallel to an AIO cancel call coming from the FFS application.
As the completion call frees the USB request (io_data-&amp;gt;req) the FFS
application is also referencing it for the usb_ep_dequeue() call.  This can…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2024-2216"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2024:3587-1</id>
    <title>SUSE-SU-2024:3587-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-03T21:16:53.759663+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2024:3587-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-46857</id>
    <title>UBUNTU-CVE-2024-46857</title>
    <updated>2026-10-03T21:16:53.759757+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:Pro:18.04:LTS: linux-aws-5.4, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:Pro:18.04:LTS: linux-azure-5.4, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3 and 161 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix bridge mode operations when there are no VFs Currently, trying to set the bridge mode attribute when numvfs=0 leads to a crash: bridge link set dev eth2 hwmode vepa [  168.967392] BUG: kernel NULL pointer dereference, address: 0000000000000030 [...] [  168.969989] RIP: 0010:mlx5_add_flow_rules+0x1f/0x300 [mlx5_core] [...] [  168.976037] Call Trace: [  168.976188]  &lt;TASK&gt; [  168.978620]  _mlx5_eswitch_set_vepa_locked+0x113/0x230 [mlx5_core] [  168.979074]  mlx5_eswitch_set_vepa+0x7f/0xa0 [mlx5_core] [  168.979471]  rtnl_bridge_setlink+0xe9/0x1f0 [  168.979714]  rtnetlink_rcv_msg+0x159/0x400 [  168.980451]  netlink_rcv_skb+0x54/0x100 [  168.980675]  netlink_unicast+0x241/0x360 [  168.980918]  netlink_sendmsg+0x1f6/0x430 [  168.981162]  ____sys_sendmsg+0x3bb/0x3f0 [  168.982155]  ___sys_sendmsg+0x88/0xd0 [  168.985036]  __sys_sendmsg+0x59/0xa0 [  168.985477]  do_syscall_64+0x79/0x150 [  168.987273]  entry_SYSCALL_64_after_hwframe+0x76/0x7e [  168.987773] RIP: 0033:0x7f8f7950f917 (esw-&gt;fdb_table.legacy.vepa_fdb is null) The bridge mode is only relevant when there are multiple functions per port. Therefore, prevent setting and getting this setting when there are no VFs. Note that after this change, there are no settings to change on the PF interface using `bridge link` when there are no VFs, so the interface no longer appears in the `bridge link` output.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-46857"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3050</id>
    <title>WID-SEC-W-2024-3050 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-03T21:16:53.759966+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen und andere nicht spezifizierte Auswirkungen zu verursachen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3050"/>
  </entry>
</feed>
