<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T21:40:31.355698+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-02969</id>
    <title>bdu:2025-02969</title>
    <updated>2026-10-03T21:40:32.352038+00:00</updated>
    <content>bdu:2025-02969</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-02969"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2024-47678</id>
    <title>BELL-CVE-2024-47678</title>
    <updated>2026-10-03T21:40:32.352118+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2024-47678"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0002</id>
    <title>certfr-2025-avi-0002 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian LTS. Elles permettent à un attaquant de p…</title>
    <updated>2026-10-03T21:40:32.352151+00:00</updated>
    <content>certfr-2025-avi-0002</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0002"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-346165</id>
    <title>EUVD-2026-346165</title>
    <updated>2026-10-03T21:40:32.352169+00:00</updated>
    <content>EUVD-2026-346165</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-346165"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-47678</id>
    <title>fkie_cve-2024-47678</title>
    <updated>2026-10-03T21:40:32.352181+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>icmp: change the order of rate limits</p>
<p>ICMP messages are ratelimited :</p>
<p>After the blamed commits, the two rate limiters are applied in this order:</p>
<p>1) host wide ratelimit (icmp_global_allow())</p>
<p>2) Per destination ratelimit (inetpeer based)</p>
<p>In order to avoid side-channels attacks, we need to apply
the per destination check first.</p>
<p>This patch makes the following change :</p>
<p>1) icmp_global_allow() checks if the host wide limit is reached.
   But credits are not yet consumed. This is deferred to 3)</p>
<p>2) The per destination limit is checked/updated.
   This might add a new node in inetpeer tree.</p>
<p>3) icmp_global_consume() consumes tokens if prior operations succeeded.</p>
<p>This means that host wide ratelimit is still effective
in keeping inetpeer tree small even under DDOS.</p>
<p>As a bonus, I removed icmp_global.lock as the fast path
can use a lock-free operation.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-47678"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-522v-vw33-wcv7</id>
    <title>GHSA-522v-vw33-wcv7</title>
    <updated>2026-10-03T21:40:32.352218+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>icmp: change the order of rate limits</p>
<p>ICMP messages are ratelimited :</p>
<p>After the blamed commits, the two rate limiters are applied in this order:</p>
<p>1) host wide ratelimit (icmp_global_allow())</p>
<p>2) Per destination ratelimit (inetpeer based)</p>
<p>In order to avoid side-channels attacks, we need to apply
the per destination check first.</p>
<p>This patch makes the following change :</p>
<p>1) icmp_global_allow() checks if the host wide limit is reached.
   But credits are not yet consumed. This is deferred to 3)</p>
<p>2) The per destination limit is checked/updated.
   This might add a new node in inetpeer tree.</p>
<p>3) icmp_global_consume() consumes tokens if prior operations succeeded.</p>
<p>This means that host wide ratelimit is still effective
in keeping inetpeer tree small even under DDOS.</p>
<p>As a bonus, I removed icmp_global.lock as the fast path
can use a lock-free operation.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-522v-vw33-wcv7"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2024-47678</id>
    <title>msrc_CVE-2024-47678 — icmp: change the order of rate limits</title>
    <updated>2026-10-03T21:40:32.352245+00:00</updated>
    <content>msrc_CVE-2024-47678</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2024-47678"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2024-2492</id>
    <title>OESA-2024-2492 — kernel security update</title>
    <updated>2026-10-03T21:40:32.352262+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):

In the Linux kernel, the following vulnerability has been resolved:  bpf: support non-r10 register spill/fill to/from stack in precision tracking  Use instruction (jump) history to record instructions that performed register spill/fill to/from stack, regardless if this was done through read-only r10 register, or any other register after copying r10 into it *and* potentially adjusting offset.  To make this work reliably, we push extra per-instruction flags into instruction history, encoding stack slot index (spi) and stack frame number in extra 10 bit flags we take away from prev_idx in instruction history. We don&amp;apos;t touch idx field for maximum performance, as it&amp;apos;s checked most frequently during backtracking.  This change removes basically the last remaining practical limitation of precision backtracking logic in BPF verifier. It fixes known deficiencies, but also opens up new opportunities to reduce number of verified states, explored in the subsequent patches.  There are only three differences in selftests&amp;apos; BPF object files according to veristat, all in the positive direction (less states).  File                                    Program        Insns (A)  Insns (B)  Insns  (DIFF)  States (A)  States (B)  States (DIFF) --------------------------------------  -------------  ---------  ---------  -------------  ----------  ----------  ------------- test_cls_redirect_dynptr.bpf.linked3.o…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2024-2492"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:14500-1</id>
    <title>openSUSE-SU-2024:14500-1 — kernel-devel-6.11.8-1.1 on GA media</title>
    <updated>2026-10-03T21:40:32.352812+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel-devel-6.11.8-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:14500-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:0117-1</id>
    <title>SUSE-SU-2025:0117-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-03T21:40:32.353093+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:0117-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-47678</id>
    <title>UBUNTU-CVE-2024-47678</title>
    <updated>2026-10-03T21:40:32.353171+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:16.04:LTS: linux-hwe-edge and 193 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: icmp: change the order of rate limits ICMP messages are ratelimited : After the blamed commits, the two rate limiters are applied in this order: 1) host wide ratelimit (icmp_global_allow()) 2) Per destination ratelimit (inetpeer based) In order to avoid side-channels attacks, we need to apply the per destination check first. This patch makes the following change : 1) icmp_global_allow() checks if the host wide limit is reached.    But credits are not yet consumed. This is deferred to 3) 2) The per destination limit is checked/updated.    This might add a new node in inetpeer tree. 3) icmp_global_consume() consumes tokens if prior operations succeeded. This means that host wide ratelimit is still effective in keeping inetpeer tree small even under DDOS. As a bonus, I removed icmp_global.lock as the fast path can use a lock-free operation.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-47678"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3251</id>
    <title>WID-SEC-W-2024-3251 — Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service</title>
    <updated>2026-10-03T21:40:32.353439+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen oder andere, nicht näher bekannte Auswirkungen zu erzielen..</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3251"/>
  </entry>
</feed>
