<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T22:06:08.987061+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-07931</id>
    <title>bdu:2025-07931</title>
    <updated>2026-10-02T22:06:09.955359+00:00</updated>
    <content>bdu:2025-07931</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-07931"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2024-50102</id>
    <title>BELL-CVE-2024-50102</title>
    <updated>2026-10-02T22:06:09.955438+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2024-50102"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-1102</id>
    <title>certfr-2024-avi-1102 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
    <updated>2026-10-02T22:06:09.955485+00:00</updated>
    <content>certfr-2024-avi-1102</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-1102"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-313486</id>
    <title>EUVD-2026-313486</title>
    <updated>2026-10-02T22:06:09.955505+00:00</updated>
    <content>EUVD-2026-313486</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-313486"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-50102</id>
    <title>fkie_cve-2024-50102</title>
    <updated>2026-10-02T22:06:09.955517+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>x86: fix user address masking non-canonical speculation issue</p>
<p>It turns out that AMD has a "Meltdown Lite(tm)" issue with non-canonical
accesses in kernel space.  And so using just the high bit to decide
whether an access is in user space or kernel space ends up with the good
old "leak speculative data" if you have the right gadget using the
result:</p>
<p>CVE-2020-12965 “Transient Execution of Non-Canonical Accesses“</p>
<p>Now, the kernel surrounds the access with a STAC/CLAC pair, and those
instructions end up serializing execution on older Zen architectures,
which closes the speculation window.</p>
<p>But that was true only up until Zen 5, which renames the AC bit [1].
That improves performance of STAC/CLAC a lot, but also means that the
speculation window is now open.</p>
<p>Note that this affects not just the new address masking, but also the
regular valid_user_address() check used by access_ok(), and the asm
version of the sign bit check in the get_user() helpers.</p>
<p>It does not affect put_user() or clear_user() variants, since there's no
speculative result to be used in a gadget for those operations.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-50102"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-mhcq-hvgj-xm2h</id>
    <title>GHSA-mhcq-hvgj-xm2h</title>
    <updated>2026-10-02T22:06:09.955561+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>x86: fix user address masking non-canonical speculation issue</p>
<p>It turns out that AMD has a "Meltdown Lite(tm)" issue with non-canonical
accesses in kernel space.  And so using just the high bit to decide
whether an access is in user space or kernel space ends up with the good
old "leak speculative data" if you have the right gadget using the
result:</p>
<p>CVE-2020-12965 “Transient Execution of Non-Canonical Accesses“</p>
<p>Now, the kernel surrounds the access with a STAC/CLAC pair, and those
instructions end up serializing execution on older Zen architectures,
which closes the speculation window.</p>
<p>But that was true only up until Zen 5, which renames the AC bit [1].
That improves performance of STAC/CLAC a lot, but also means that the
speculation window is now open.</p>
<p>Note that this affects not just the new address masking, but also the
regular valid_user_address() check used by access_ok(), and the asm
version of the sign bit check in the get_user() helpers.</p>
<p>It does not affect put_user() or clear_user() variants, since there's no
speculative result to be used in a gadget for those operations.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-mhcq-hvgj-xm2h"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2024-50102</id>
    <title>msrc_CVE-2024-50102 — x86: fix user address masking non-canonical speculation issue</title>
    <updated>2026-10-02T22:06:09.955591+00:00</updated>
    <content>msrc_CVE-2024-50102</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2024-50102"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-1337</id>
    <title>OESA-2026-1337 — kernel security update</title>
    <updated>2026-10-02T22:06:09.955611+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>md/dm-raid: don&amp;apos;t call md_reap_sync_thread() directly</p>
<p>Currently md_reap_sync_thread() is called from raid_message() directly
without holding &amp;apos;reconfig_mutex&amp;apos;, this is definitely unsafe because
md_reap_sync_thread() can change many fields that is protected by
&amp;apos;reconfig_mutex&amp;apos;.</p>
<p>However, hold &amp;apos;reconfig_mutex&amp;apos; here is still problematic because this
will cause deadlock, for example, commit 130443d60b1b (&amp;quot;md: refactor
idle/frozen_sync_thread() to fix deadlock&amp;quot;).</p>
<p>Fix this problem by using stop_sync_thread() to unregister sync_thread,
like md/raid did.(CVE-2024-35808)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>x86: fix user address masking non-canonical speculation issue</p>
<p>It turns out that AMD has a &amp;quot;Meltdown Lite(tm)&amp;quot; issue with non-canonical
accesses in kernel space.  And so using just the high bit to decide
whether an access is in user space or kernel space ends up with the good
old &amp;quot;leak speculative data&amp;quot; if you have the right gadget using the
result:</p>
<p>CVE-2020-12965 “Transient Execution of Non-Canonical Accesses“</p>
<p>Now, the kernel surrounds the access with a STAC/CLAC pair, and those
instructions end up serializing execution on older Zen architectures,
which closes the speculation window.</p>
<p>But that was true only up until Zen 5, which renames t…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-1337"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:14500-1</id>
    <title>openSUSE-SU-2024:14500-1 — kernel-devel-6.11.8-1.1 on GA media</title>
    <updated>2026-10-02T22:06:09.955729+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel-devel-6.11.8-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:14500-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:15668</id>
    <title>RHSA-2025:15668 — Red Hat Security Advisory: kernel security update</title>
    <updated>2026-10-02T22:06:09.956030+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: net/iucv: Avoid explicit cpumask var allocation on stack kernel: x86: fix user address masking non-canonical speculation issue kernel: drm/vkms: Fix use after free and double free on init error kernel: net_sched: ets: Fix double list add in class with netem as child qdisc kernel: mm/hugetlb: fix huge_pmd_unshare() vs GUP-fast race kernel: wifi: rtw88: fix the 'para' buffer size to avoid reading out of bounds kernel: Bluetooth: hci_core: Fix use-after-free in vhci_flush() kernel: scsi: lpfc: Use memcpy() for BIOS version kernel: posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del() kernel: tipc: Fix use-after-free in tipc_conn_close()</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:15668"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2024:4314-1</id>
    <title>SUSE-SU-2024:4314-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-02T22:06:09.956068+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2024:4314-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-50102</id>
    <title>UBUNTU-CVE-2024-50102</title>
    <updated>2026-10-02T22:06:09.956217+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 108 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: x86: fix user address masking non-canonical speculation issue It turns out that AMD has a "Meltdown Lite(tm)" issue with non-canonical accesses in kernel space.  And so using just the high bit to decide whether an access is in user space or kernel space ends up with the good old "leak speculative data" if you have the right gadget using the result:   CVE-2020-12965 “Transient Execution of Non-Canonical Accesses“ Now, the kernel surrounds the access with a STAC/CLAC pair, and those instructions end up serializing execution on older Zen architectures, which closes the speculation window. But that was true only up until Zen 5, which renames the AC bit [1]. That improves performance of STAC/CLAC a lot, but also means that the speculation window is now open. Note that this affects not just the new address masking, but also the regular valid_user_address() check used by access_ok(), and the asm version of the sign bit check in the get_user() helpers. It does not affect put_user() or clear_user() variants, since there's no speculative result to be used in a gadget for those operations.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-50102"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3339</id>
    <title>WID-SEC-W-2024-3339 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-02T22:06:09.956375+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3339"/>
  </entry>
</feed>
