<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T14:34:56.841340+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-07898</id>
    <title>bdu:2025-07898</title>
    <updated>2026-10-03T14:34:57.289332+00:00</updated>
    <content>bdu:2025-07898</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-07898"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2024-50240</id>
    <title>BELL-CVE-2024-50240</title>
    <updated>2026-10-03T14:34:57.289400+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2024-50240"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-1102</id>
    <title>certfr-2024-avi-1102 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
    <updated>2026-10-03T14:34:57.289443+00:00</updated>
    <content>certfr-2024-avi-1102</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-1102"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-313552</id>
    <title>EUVD-2026-313552</title>
    <updated>2026-10-03T14:34:57.289518+00:00</updated>
    <content>EUVD-2026-313552</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-313552"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-50240</id>
    <title>fkie_cve-2024-50240</title>
    <updated>2026-10-03T14:34:57.289544+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>phy: qcom: qmp-usb: fix NULL-deref on runtime suspend</p>
<p>Commit 413db06c05e7 ("phy: qcom-qmp-usb: clean up probe initialisation")
removed most users of the platform device driver data, but mistakenly
also removed the initialisation despite the data still being used in the
runtime PM callbacks.</p>
<p>Restore the driver data initialisation at probe to avoid a NULL-pointer
dereference on runtime suspend.</p>
<p>Apparently no one uses runtime PM, which currently needs to be enabled
manually through sysfs, with this driver.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-50240"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-2fwq-2wwr-qrww</id>
    <title>GHSA-2fwq-2wwr-qrww</title>
    <updated>2026-10-03T14:34:57.289581+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>phy: qcom: qmp-usb: fix NULL-deref on runtime suspend</p>
<p>Commit 413db06c05e7 ("phy: qcom-qmp-usb: clean up probe initialisation")
removed most users of the platform device driver data, but mistakenly
also removed the initialisation despite the data still being used in the
runtime PM callbacks.</p>
<p>Restore the driver data initialisation at probe to avoid a NULL-pointer
dereference on runtime suspend.</p>
<p>Apparently no one uses runtime PM, which currently needs to be enabled
manually through sysfs, with this driver.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-2fwq-2wwr-qrww"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2024-50240</id>
    <title>msrc_CVE-2024-50240 — phy: qcom: qmp-usb: fix NULL-deref on runtime suspend</title>
    <updated>2026-10-03T14:34:57.289602+00:00</updated>
    <content>msrc_CVE-2024-50240</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2024-50240"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-1097</id>
    <title>OESA-2025-1097 — kernel security update</title>
    <updated>2026-10-03T14:34:57.289620+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>ksmbd: fix potencial out-of-bounds when buffer offset is invalid</p>
<p>I found potencial out-of-bounds when buffer offset fields of a few requests
is invalid. This patch set the minimum value of buffer offset field to
-&amp;gt;Buffer offset to validate buffer length.(CVE-2024-26952)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>ksmbd: fix slab-out-of-bounds in smb_strndup_from_utf16()</p>
<p>If -&amp;gt;NameOffset of smb2_create_req is smaller than Buffer offset of
smb2_create_req, slab-out-of-bounds read can happen from smb2_open.
This patch set the minimum value of the name offset to the buffer offset
to validate name length of smb2_create_req().(CVE-2024-26954)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>fpga: bridge: add owner module and take its refcount</p>
<p>The current implementation of the fpga bridge assumes that the low-level
module registers a driver for the parent device and uses its owner pointer
to take the module&amp;apos;s refcount. This approach is problematic since it can
lead to a null pointer dereference while attempting to get the bridge if
the parent device does not have a driver.</p>
<p>To address this problem, add a module owner pointer to the fpga_bridge
struct and use it to take the module&amp;apos;s refcount. Modify the function for
registering a bridge to take an additional owner module paramet…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-1097"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:14500-1</id>
    <title>openSUSE-SU-2024:14500-1 — kernel-devel-6.11.8-1.1 on GA media</title>
    <updated>2026-10-03T14:34:57.290706+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel-devel-6.11.8-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:14500-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2024:4314-1</id>
    <title>SUSE-SU-2024:4314-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-03T14:34:57.290996+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2024:4314-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-50240</id>
    <title>UBUNTU-CVE-2024-50240</title>
    <updated>2026-10-03T14:34:57.291142+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 101 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: phy: qcom: qmp-usb: fix NULL-deref on runtime suspend Commit 413db06c05e7 ("phy: qcom-qmp-usb: clean up probe initialisation") removed most users of the platform device driver data, but mistakenly also removed the initialisation despite the data still being used in the runtime PM callbacks. Restore the driver data initialisation at probe to avoid a NULL-pointer dereference on runtime suspend. Apparently no one uses runtime PM, which currently needs to be enabled manually through sysfs, with this driver.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-50240"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3397</id>
    <title>WID-SEC-W-2024-3397 — Linux Kernel: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff</title>
    <updated>2026-10-03T14:34:57.291354+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3397"/>
  </entry>
</feed>
