<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T05:45:18.892064+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-07899</id>
    <title>bdu:2025-07899</title>
    <updated>2026-10-03T05:45:19.034519+00:00</updated>
    <content>bdu:2025-07899</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-07899"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2024-50239</id>
    <title>BELL-CVE-2024-50239</title>
    <updated>2026-10-03T05:45:19.034564+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2024-50239"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0152</id>
    <title>certfr-2025-avi-0152 — De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Certaines d'entre elles permettent à un a…</title>
    <updated>2026-10-03T05:45:19.034593+00:00</updated>
    <content>certfr-2025-avi-0152</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0152"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-313551</id>
    <title>EUVD-2026-313551</title>
    <updated>2026-10-03T05:45:19.034610+00:00</updated>
    <content>EUVD-2026-313551</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-313551"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-50239</id>
    <title>fkie_cve-2024-50239</title>
    <updated>2026-10-03T05:45:19.034621+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>phy: qcom: qmp-usb-legacy: fix NULL-deref on runtime suspend</p>
<p>Commit 413db06c05e7 ("phy: qcom-qmp-usb: clean up probe initialisation")
removed most users of the platform device driver data from the
qcom-qmp-usb driver, but mistakenly also removed the initialisation
despite the data still being used in the runtime PM callbacks. This bug
was later reproduced when the driver was copied to create the
qmp-usb-legacy driver.</p>
<p>Restore the driver data initialisation at probe to avoid a NULL-pointer
dereference on runtime suspend.</p>
<p>Apparently no one uses runtime PM, which currently needs to be enabled
manually through sysfs, with these drivers.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-50239"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-mc25-gf3g-fggc</id>
    <title>GHSA-mc25-gf3g-fggc</title>
    <updated>2026-10-03T05:45:19.034657+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>phy: qcom: qmp-usb-legacy: fix NULL-deref on runtime suspend</p>
<p>Commit 413db06c05e7 ("phy: qcom-qmp-usb: clean up probe initialisation")
removed most users of the platform device driver data from the
qcom-qmp-usb driver, but mistakenly also removed the initialisation
despite the data still being used in the runtime PM callbacks. This bug
was later reproduced when the driver was copied to create the
qmp-usb-legacy driver.</p>
<p>Restore the driver data initialisation at probe to avoid a NULL-pointer
dereference on runtime suspend.</p>
<p>Apparently no one uses runtime PM, which currently needs to be enabled
manually through sysfs, with these drivers.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-mc25-gf3g-fggc"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2024-50239</id>
    <title>msrc_CVE-2024-50239 — phy: qcom: qmp-usb-legacy: fix NULL-deref on runtime suspend</title>
    <updated>2026-10-03T05:45:19.034680+00:00</updated>
    <content>msrc_CVE-2024-50239</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2024-50239"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2024-2537</id>
    <title>OESA-2024-2537 — kernel security update</title>
    <updated>2026-10-03T05:45:19.034697+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):

In the Linux kernel, the following vulnerability has been resolved:  xhci: Handle TD clearing for multiple streams case  When multiple streams are in use, multiple TDs might be in flight when an endpoint is stopped. We need to issue a Set TR Dequeue Pointer for each, to ensure everything is reset properly and the caches cleared. Change the logic so that any N&amp;gt;1 TDs found active for different streams are deferred until after the first one is processed, calling xhci_invalidate_cancelled_tds() again from xhci_handle_cmd_set_deq() to queue another command until we are done with all of them. Also change the error/&amp;quot;should never happen&amp;quot; paths to ensure we at least clear any affected TDs, even if we can&amp;apos;t issue a command to clear the hardware cache, and complain loudly with an xhci_warn() if this ever happens.  This problem case dates back to commit e9df17eb1408 (&amp;quot;USB: xhci: Correct assumptions about number of rings per endpoint.&amp;quot;) early on in the XHCI driver&amp;apos;s life, when stream support was first added. It was then identified but not fixed nor made into a warning in commit 674f8438c121 (&amp;quot;xhci: split handling halted endpoints into two steps&amp;quot;), which added a FIXME comment for the problem case (without materially changing the behavior as far as I can tell, though the new logic made the problem more obvious).  Then later, in commit 94f339147fc3 (&amp;quot;xhci: Fix failure…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2024-2537"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:14500-1</id>
    <title>openSUSE-SU-2024:14500-1 — kernel-devel-6.11.8-1.1 on GA media</title>
    <updated>2026-10-03T05:45:19.034922+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel-devel-6.11.8-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:14500-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-50239</id>
    <title>UBUNTU-CVE-2024-50239</title>
    <updated>2026-10-03T05:45:19.035175+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 101 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: phy: qcom: qmp-usb-legacy: fix NULL-deref on runtime suspend Commit 413db06c05e7 ("phy: qcom-qmp-usb: clean up probe initialisation") removed most users of the platform device driver data from the qcom-qmp-usb driver, but mistakenly also removed the initialisation despite the data still being used in the runtime PM callbacks. This bug was later reproduced when the driver was copied to create the qmp-usb-legacy driver. Restore the driver data initialisation at probe to avoid a NULL-pointer dereference on runtime suspend. Apparently no one uses runtime PM, which currently needs to be enabled manually through sysfs, with these drivers.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-50239"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3397</id>
    <title>WID-SEC-W-2024-3397 — Linux Kernel: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff</title>
    <updated>2026-10-03T05:45:19.035343+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3397"/>
  </entry>
</feed>
