<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T19:15:16.410333+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-07860</id>
    <title>bdu:2025-07860</title>
    <updated>2026-10-03T19:15:16.770151+00:00</updated>
    <content>bdu:2025-07860</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-07860"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2024-56617</id>
    <title>BELL-CVE-2024-56617</title>
    <updated>2026-10-03T19:15:16.770216+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2024-56617"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0088</id>
    <title>certfr-2025-avi-0088 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
    <updated>2026-10-03T19:15:16.770249+00:00</updated>
    <content>certfr-2025-avi-0088</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0088"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-313763</id>
    <title>EUVD-2026-313763</title>
    <updated>2026-10-03T19:15:16.770267+00:00</updated>
    <content>EUVD-2026-313763</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-313763"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-56617</id>
    <title>fkie_cve-2024-56617</title>
    <updated>2026-10-03T19:15:16.770279+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>cacheinfo: Allocate memory during CPU hotplug if not done from the primary CPU</p>
<p>Commit</p>
<p>5944ce092b97 ("arch_topology: Build cacheinfo from primary CPU")</p>
<p>adds functionality that architectures can use to optionally allocate and
build cacheinfo early during boot. Commit</p>
<p>6539cffa9495 ("cacheinfo: Add arch specific early level initializer")</p>
<p>lets secondary CPUs correct (and reallocate memory) cacheinfo data if
needed.</p>
<p>If the early build functionality is not used and cacheinfo does not need
correction, memory for cacheinfo is never allocated. x86 does not use
the early build functionality. Consequently, during the cacheinfo CPU
hotplug callback, last_level_cache_is_valid() attempts to dereference
a NULL pointer:</p>
<p>BUG: kernel NULL pointer dereference, address: 0000000000000100
  #PF: supervisor read access in kernel mode
  #PF: error_code(0x0000) - not present page
  PGD 0 P4D 0
  Oops: 0000 [#1] PREEPMT SMP NOPTI
  CPU: 0 PID 19 Comm: cpuhp/0 Not tainted 6.4.0-rc2 #1
  RIP: 0010: last_level_cache_is_valid+0x95/0xe0a</p>
<p>Allocate memory for cacheinfo during the cacheinfo CPU hotplug callback
if not done earlier.</p>
<p>Moreover, before determining the validity of the last-level cache info,
ensure that it has been allocated. Simply checking for non-zero
cache_leaves() is not sufficient, as some architectures (e.g., Intel
processors) have non-zero cache_leaves() before allocation.</p>
<p>Dereferencing NULL cacheinfo can o…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-56617"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-pq66-h8qj-7xg9</id>
    <title>GHSA-pq66-h8qj-7xg9</title>
    <updated>2026-10-03T19:15:16.770327+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>cacheinfo: Allocate memory during CPU hotplug if not done from the primary CPU</p>
<p>Commit</p>
<p>5944ce092b97 ("arch_topology: Build cacheinfo from primary CPU")</p>
<p>adds functionality that architectures can use to optionally allocate and
build cacheinfo early during boot. Commit</p>
<p>6539cffa9495 ("cacheinfo: Add arch specific early level initializer")</p>
<p>lets secondary CPUs correct (and reallocate memory) cacheinfo data if
needed.</p>
<p>If the early build functionality is not used and cacheinfo does not need
correction, memory for cacheinfo is never allocated. x86 does not use
the early build functionality. Consequently, during the cacheinfo CPU
hotplug callback, last_level_cache_is_valid() attempts to dereference
a NULL pointer:</p>
<p>BUG: kernel NULL pointer dereference, address: 0000000000000100
  #PF: supervisor read access in kernel mode
  #PF: error_code(0x0000) - not present page
  PGD 0 P4D 0
  Oops: 0000 [#1] PREEPMT SMP NOPTI
  CPU: 0 PID 19 Comm: cpuhp/0 Not tainted 6.4.0-rc2 #1
  RIP: 0010: last_level_cache_is_valid+0x95/0xe0a</p>
<p>Allocate memory for cacheinfo during the cacheinfo CPU hotplug callback
if not done earlier.</p>
<p>Moreover, before determining the validity of the last-level cache info,
ensure that it has been allocated. Simply checking for non-zero
cache_leaves() is not sufficient, as some architectures (e.g., Intel
processors) have non-zero cache_leaves() before allocation.</p>
<p>Dereferencing NULL cacheinfo can o…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-pq66-h8qj-7xg9"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2024-56617</id>
    <title>msrc_CVE-2024-56617 — cacheinfo: Allocate memory during CPU hotplug if not done from the primary CPU</title>
    <updated>2026-10-03T19:15:16.770362+00:00</updated>
    <content>msrc_CVE-2024-56617</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2024-56617"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-1110</id>
    <title>OESA-2025-1110 — kernel security update</title>
    <updated>2026-10-03T19:15:16.770381+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>i3c: Use i3cdev-&amp;gt;desc-&amp;gt;info instead of calling i3c_device_get_info() to avoid deadlock</p>
<p>A deadlock may happen since the i3c_master_register() acquires
&amp;amp;i3cbus-&amp;gt;lock twice. See the log below.
Use i3cdev-&amp;gt;desc-&amp;gt;info instead of calling i3c_device_info() to
avoid acquiring the lock twice.</p>
<p>v2:
  - Modified the title and commit message</p>
<p>============================================
WARNING: possible recursive locking detected
6.11.0-mainline
--------------------------------------------
init/1 is trying to acquire lock:
f1ffff80a6a40dc0 (&amp;amp;i3cbus-&amp;gt;lock){++++}-{3:3}, at: i3c_bus_normaluse_lock</p>
<p>but task is already holding lock:
f1ffff80a6a40dc0 (&amp;amp;i3cbus-&amp;gt;lock){++++}-{3:3}, at: i3c_master_register</p>
<p>other info that might help us debug this:
 Possible unsafe locking scenario:</p>
<p>CPU0
       ----
  lock(&amp;amp;i3cbus-&amp;gt;lock);
  lock(&amp;amp;i3cbus-&amp;gt;lock);</p>
<p>*** DEADLOCK ***</p>
<p>May be due to missing lock nesting notation</p>
<p>2 locks held by init/1:
 #0: fcffff809b6798f8 (&amp;amp;dev-&amp;gt;mutex){....}-{3:3}, at: __driver_attach
 #1: f1ffff80a6a40dc0 (&amp;amp;i3cbus-&amp;gt;lock){++++}-{3:3}, at: i3c_master_register</p>
<p>stack backtrace:
CPU: 6 UID: 0 PID: 1 Comm: init
Call trace:
 dump_backtrace+0xfc/0x17c
 show_stack+0x18/0x28
 dump_stack_lvl+0x40/0xc0
 dump_stack+0x18/0x24
 print_deadlock_bug+0x388/0x390
 __lock_acquire+0x18bc/0…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-1110"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:0289-1</id>
    <title>SUSE-SU-2025:0289-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-03T19:15:16.770630+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:0289-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-56617</id>
    <title>UBUNTU-CVE-2024-56617</title>
    <updated>2026-10-03T19:15:16.770824+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 112 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: cacheinfo: Allocate memory during CPU hotplug if not done from the primary CPU Commit   5944ce092b97 ("arch_topology: Build cacheinfo from primary CPU") adds functionality that architectures can use to optionally allocate and build cacheinfo early during boot. Commit   6539cffa9495 ("cacheinfo: Add arch specific early level initializer") lets secondary CPUs correct (and reallocate memory) cacheinfo data if needed. If the early build functionality is not used and cacheinfo does not need correction, memory for cacheinfo is never allocated. x86 does not use the early build functionality. Consequently, during the cacheinfo CPU hotplug callback, last_level_cache_is_valid() attempts to dereference a NULL pointer:   BUG: kernel NULL pointer dereference, address: 0000000000000100   #PF: supervisor read access in kernel mode   #PF: error_code(0x0000) - not present page   PGD 0 P4D 0   Oops: 0000 [#1] PREEPMT SMP NOPTI   CPU: 0 PID 19 Comm: cpuhp/0 Not tainted 6.4.0-rc2 #1   RIP: 0010: last_level_cache_is_valid+0x95/0xe0a Allocate memory for cacheinfo during the cacheinfo CPU hotplug callback if not done earlier. Moreover, before determining the validity of the last-level cache info, ensure that it has been allocated. Simply checking for non-zero cache_leaves() is not sufficient, as some architectures (e.g., Intel processors) have non-zero cache_leaves() before allocation. Dereferencing NULL cacheinfo can occur in upd…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-56617"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3762</id>
    <title>WID-SEC-W-2024-3762 — Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service</title>
    <updated>2026-10-03T19:15:16.770983+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen und um nicht näher beschriebene Effekte zu erzielen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3762"/>
  </entry>
</feed>
