<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T01:50:39.377773+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2025:20518</id>
    <title>ALSA-2025:20518 — Moderate: kernel security update</title>
    <updated>2026-10-03T01:50:39.722926+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core, AlmaLinux:9: kernel-64k-debug-modules-extra and 64 more</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: can: isotp: fix potential CAN frame reception race in isotp_rcv() (CVE-2022-48830)
  * kernel: soc: qcom: cmd-db: Map shared memory as WC, not WB (CVE-2024-46689)
  * kernel: Squashfs: sanity check symbolic link size (CVE-2024-46744)
  * kernel: vfs: fix race between evice_inodes() and find_inode()&amp;#38;iput() (CVE-2024-47679)
  * kernel: x86/tdx: Fix "in-kernel MMIO" check (CVE-2024-47727)
  * kernel: rxrpc: Fix a race between socket set up and I/O thread creation (CVE-2024-49864)
  * kernel: io_uring: check if we need to reschedule during overflow flush (CVE-2024-50060)
  * kernel: can: m_can: pci: add missing m_can_class_free_dev() in probe/remove methods (CVE-2022-49024)
  * kernel: posix-clock: Fix missing timespec64 check in pc_clock_settime() (CVE-2024-50195)
  * kernel: rxrpc: Fix missing locking causing hanging calls (CVE-2024-50294)
  * kernel: io_uring/rw: fix missing NOWAIT check for O_DIRECT start write (CVE-2024-53052)
  * kernel: afs: Fix lock recursion (CVE-2024-53090)
  * kernel: virtio/vsock: Fix accept_queue memory leak (CVE-2024-53119)
  * kernel: KVM: VMX: Bury Intel PT virtualization (guest/host mode) behind CONFIG_BROKEN (CVE-2024-53135)
  * kernel: xen: Xen hypercall page unsafe against speculative attacks (Xen Security Advisory 466) (CVE-2024-53241)
  * kernel: RDMA/rxe: Fix the qp flush warnings in req (CVE-2024-53229)
  * kernel:…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2025:20518"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-07886</id>
    <title>bdu:2025-07886</title>
    <updated>2026-10-03T01:50:39.723149+00:00</updated>
    <content>bdu:2025-07886</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-07886"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2024-50294</id>
    <title>BELL-CVE-2024-50294</title>
    <updated>2026-10-03T01:50:39.723170+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2024-50294"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0152</id>
    <title>certfr-2025-avi-0152 — De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Certaines d'entre elles permettent à un a…</title>
    <updated>2026-10-03T01:50:39.723193+00:00</updated>
    <content>certfr-2025-avi-0152</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0152"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-346368</id>
    <title>EUVD-2026-346368</title>
    <updated>2026-10-03T01:50:39.723209+00:00</updated>
    <content>EUVD-2026-346368</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-346368"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-50294</id>
    <title>fkie_cve-2024-50294</title>
    <updated>2026-10-03T01:50:39.723746+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>rxrpc: Fix missing locking causing hanging calls</p>
<p>If a call gets aborted (e.g. because kafs saw a signal) between it being
queued for connection and the I/O thread picking up the call, the abort
will be prioritised over the connection and it will be removed from
local-&gt;new_client_calls by rxrpc_disconnect_client_call() without a lock
being held.  This may cause other calls on the list to disappear if a race
occurs.</p>
<p>Fix this by taking the client_call_lock when removing a call from whatever
list its -&gt;wait_link happens to be on.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-50294"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-gcxj-24rj-3795</id>
    <title>GHSA-gcxj-24rj-3795</title>
    <updated>2026-10-03T01:50:39.723785+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>rxrpc: Fix missing locking causing hanging calls</p>
<p>If a call gets aborted (e.g. because kafs saw a signal) between it being
queued for connection and the I/O thread picking up the call, the abort
will be prioritised over the connection and it will be removed from
local-&gt;new_client_calls by rxrpc_disconnect_client_call() without a lock
being held.  This may cause other calls on the list to disappear if a race
occurs.</p>
<p>Fix this by taking the client_call_lock when removing a call from whatever
list its -&gt;wait_link happens to be on.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-gcxj-24rj-3795"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2024-2492</id>
    <title>OESA-2024-2492 — kernel security update</title>
    <updated>2026-10-03T01:50:39.723807+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):

In the Linux kernel, the following vulnerability has been resolved:  bpf: support non-r10 register spill/fill to/from stack in precision tracking  Use instruction (jump) history to record instructions that performed register spill/fill to/from stack, regardless if this was done through read-only r10 register, or any other register after copying r10 into it *and* potentially adjusting offset.  To make this work reliably, we push extra per-instruction flags into instruction history, encoding stack slot index (spi) and stack frame number in extra 10 bit flags we take away from prev_idx in instruction history. We don&amp;apos;t touch idx field for maximum performance, as it&amp;apos;s checked most frequently during backtracking.  This change removes basically the last remaining practical limitation of precision backtracking logic in BPF verifier. It fixes known deficiencies, but also opens up new opportunities to reduce number of verified states, explored in the subsequent patches.  There are only three differences in selftests&amp;apos; BPF object files according to veristat, all in the positive direction (less states).  File                                    Program        Insns (A)  Insns (B)  Insns  (DIFF)  States (A)  States (B)  States (DIFF) --------------------------------------  -------------  ---------  ---------  -------------  ----------  ----------  ------------- test_cls_redirect_dynptr.bpf.linked3.o…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2024-2492"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:20518</id>
    <title>RHSA-2025:20518 — Red Hat Security Advisory: kernel security update</title>
    <updated>2026-10-03T01:50:39.724330+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: can: isotp: fix potential CAN frame reception race in isotp_rcv() kernel: can: m_can: pci: add missing m_can_class_free_dev() in probe/remove methods kernel: can: isotp: sanitize CAN ID checks in isotp_bind() kernel: powerpc/papr_scm: don't requests stats with '0' sized stats buffer kernel: efi: Do not import certificates from UEFI Secure Boot for T2 Macs kernel: powerpc/xics: fix refcount leak in icp_opal_init() kernel: powerpc/xive: Fix refcount leak in xive_spapr_init kernel: list: fix a data-race around ep-&gt;rdllist kernel: powerpc/xive/spapr: correct bitmap allocation size kernel: ima: Fix potential memory leak in ima_init_crypto() kernel: ima: Fix a potential integer overflow in ima_appraise_measurement kernel: tracing/histograms: Fix memory leak problem kernel: usbnet: fix memory leak in error case kernel: linux/dim: Fix divide by 0 in RDMA DIM kernel: net: tun: unlink NAPI from device on destruction kernel: can: j1939: j1939_send_one(): fix missing CAN header initialization kernel: intel_th: Fix a resource leak in an error handling path kernel: powerpc/rtas: avoid scheduling in rtas_os_term() kernel: can: isotp: split tx timer into transmission and timeout kernel: Linux kernel: Denial of Service in xsk_diag due to use-after-free during socket cleanup kernel: smc: Fix use-after-free in tcp_write_timer_handler() kernel: inotify: Avoid reporting event with invalid wd kernel: Linux kernel (CAN J1939): Denial of Service via deadlock kernel: net/smc: fix potential p…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:20518"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:01919-1</id>
    <title>SUSE-SU-2025:01919-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-03T01:50:39.724581+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:01919-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-50294</id>
    <title>UBUNTU-CVE-2024-50294</title>
    <updated>2026-10-03T01:50:39.724841+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 103 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix missing locking causing hanging calls If a call gets aborted (e.g. because kafs saw a signal) between it being queued for connection and the I/O thread picking up the call, the abort will be prioritised over the connection and it will be removed from local-&gt;new_client_calls by rxrpc_disconnect_client_call() without a lock being held.  This may cause other calls on the list to disappear if a race occurs. Fix this by taking the client_call_lock when removing a call from whatever list its -&gt;wait_link happens to be on.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-50294"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3497</id>
    <title>WID-SEC-W-2024-3497 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-03T01:50:39.725004+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial of Service Zustand herbeizuführen oderum einen nicht näher spezifizierten Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3497"/>
  </entry>
</feed>
