<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T17:24:40.240339+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-04674</id>
    <title>bdu:2025-04674</title>
    <updated>2026-10-03T17:24:41.134959+00:00</updated>
    <content>bdu:2025-04674</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-04674"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2024-56664</id>
    <title>BELL-CVE-2024-56664</title>
    <updated>2026-10-03T17:24:41.135031+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2024-56664"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0088</id>
    <title>certfr-2025-avi-0088 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
    <updated>2026-10-03T17:24:41.135087+00:00</updated>
    <content>certfr-2025-avi-0088</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0088"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-346512</id>
    <title>EUVD-2026-346512</title>
    <updated>2026-10-03T17:24:41.135119+00:00</updated>
    <content>EUVD-2026-346512</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-346512"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-56664</id>
    <title>fkie_cve-2024-56664</title>
    <updated>2026-10-03T17:24:41.135138+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>bpf, sockmap: Fix race between element replace and close()</p>
<p>Element replace (with a socket different from the one stored) may race
with socket's close() link popping &amp; unlinking. __sock_map_delete()
unconditionally unrefs the (wrong) element:</p>
<p>// set map[0] = s0
map_update_elem(map, 0, s0)</p>
<p>// drop fd of s0
close(s0)
  sock_map_close()
    lock_sock(sk)               (s0!)
    sock_map_remove_links(sk)
      link = sk_psock_link_pop()
      sock_map_unlink(sk, link)
        sock_map_delete_from_link
                                        // replace map[0] with s1
                                        map_update_elem(map, 0, s1)
                                          sock_map_update_elem
                                (s1!)       lock_sock(sk)
                                            sock_map_update_common
                                              psock = sk_psock(sk)
                                              spin_lock(&amp;stab-&gt;lock)
                                              osk = stab-&gt;sks[idx]
                                              sock_map_add_link(..., &amp;stab-&gt;sks[idx])
                                              sock_map_unref(osk, &amp;stab-&gt;sks[idx])
                                                psock = sk_psock(osk)
                                                sk_psock_put(sk, psock)
                                                  if (refcount_dec_and_test(&amp;psock))…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-56664"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-22x4-j6vj-fmm5</id>
    <title>GHSA-22x4-j6vj-fmm5</title>
    <updated>2026-10-03T17:24:41.135284+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>bpf, sockmap: Fix race between element replace and close()</p>
<p>Element replace (with a socket different from the one stored) may race
with socket's close() link popping &amp; unlinking. __sock_map_delete()
unconditionally unrefs the (wrong) element:</p>
<p>// set map[0] = s0
map_update_elem(map, 0, s0)</p>
<p>// drop fd of s0
close(s0)
  sock_map_close()
    lock_sock(sk)               (s0!)
    sock_map_remove_links(sk)
      link = sk_psock_link_pop()
      sock_map_unlink(sk, link)
        sock_map_delete_from_link
                                        // replace map[0] with s1
                                        map_update_elem(map, 0, s1)
                                          sock_map_update_elem
                                (s1!)       lock_sock(sk)
                                            sock_map_update_common
                                              psock = sk_psock(sk)
                                              spin_lock(&amp;stab-&gt;lock)
                                              osk = stab-&gt;sks[idx]
                                              sock_map_add_link(..., &amp;stab-&gt;sks[idx])
                                              sock_map_unref(osk, &amp;stab-&gt;sks[idx])
                                                psock = sk_psock(osk)
                                                sk_psock_put(sk, psock)
                                                  if (refcount_dec_and_test(&amp;psock))…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-22x4-j6vj-fmm5"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2024-56664</id>
    <title>msrc_CVE-2024-56664 — bpf, sockmap: Fix race between element replace and close()</title>
    <updated>2026-10-03T17:24:41.135400+00:00</updated>
    <content>msrc_CVE-2024-56664</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2024-56664"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-1409</id>
    <title>OESA-2025-1409 — kernel security update</title>
    <updated>2026-10-03T17:24:41.135429+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP3: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>fs/ntfs3: Fix some memory leaks in an error handling path of &amp;apos;log_replay()&amp;apos;</p>
<p>All error handling paths lead to &amp;apos;out&amp;apos; where many resources are freed.</p>
<p>Do it as well here instead of a direct return, otherwise &amp;apos;log&amp;apos;, &amp;apos;ra&amp;apos; and
&amp;apos;log-&amp;gt;one_page_buf&amp;apos; (at least) will leak.(CVE-2021-47660)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>list: fix a data-race around ep-&amp;gt;rdllist</p>
<p>ep_poll() first calls ep_events_available() with no lock held and checks
if ep-&amp;gt;rdllist is empty by list_empty_careful(), which reads
rdllist-&amp;gt;prev.  Thus all accesses to it need some protection to avoid
store/load-tearing.</p>
<p>Note INIT_LIST_HEAD_RCU() already has the annotation for both prev
and next.</p>
<p>Commit bf3b9f6372c4 (&amp;quot;epoll: Add busy poll support to epoll with socket
fds.&amp;quot;) added the first lockless ep_events_available(), and commit
c5a282e9635e (&amp;quot;fs/epoll: reduce the scope of wq lock in epoll_wait()&amp;quot;)
made some ep_events_available() calls lockless and added single call under
a lock, finally commit e59d3c64cba6 (&amp;quot;epoll: eliminate unnecessary lock
for zero timeout&amp;quot;) made the last ep_events_available() lockless.</p>
<p>BUG: KCSAN: data-race in do_epoll_wait / do_epoll_wait</p>
<p>write to 0xffff88810480c7d8 of 8 bytes by task 1802 on cpu 0:
 INIT_LIST_HEAD include/linux…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-1409"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:6966</id>
    <title>RHSA-2025:6966 — Red Hat Security Advisory: kernel security update</title>
    <updated>2026-10-03T17:24:41.135654+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: xen-netfront: Fix NULL sring after live migration kernel: fscache: Fix oops due to race with cookie_lru and use_cookie kernel: tracing: Free buffers when a used dynamic event is removed kernel: net: tun: Fix use-after-free in tun_detach() kernel: hwmon: (ibmpex) Fix possible UAF when ibmpex_register_bmc() fails kernel: erofs/zmap.c: Fix incorrect offset calculation kernel: arm64/mm: fix incorrect file_map_count for non-leaf pmd/pud kernel: s390: avoid using global register for current_stack_pointer kernel: erofs: fix missing xas_retry() in fscache mode kernel: rpmsg: qcom_smd: Fix refcount leak in qcom_smd_parse_edge kernel: remoteproc: k3-r5: Fix refcount leak in k3_r5_cluster_of_init kernel: of: check previous kernel's ima-kexec-buffer against memory bounds kernel: coresight: Clear the connection field properly kernel: Linux kernel: Denial of Service in coresight: trbe kernel: rpmsg: char: Avoid double destroy of default endpoint kernel: coresight: cti: Fix hang in cti_disable_hw() kernel: lib/fonts: fix undefined behavior in bit shift for get_default_font kernel: Kernel: Denial of Service in pci_endpoint_test due to zero-length DMA mapping kernel: Linux kernel: Denial of Service in erofs due to memory leak kernel: erofs: fix missing unmap if z_erofs_get_extent_compressedlen() fails kernel: pipe: wakeup wr_wait after setting max_usage kernel: ntb: intel: Fix the NULL vs IS_ERR() bug for debugfs_create_dir() kernel: qed/qed_sriov: guard against NULL derefs from qed_…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:6966"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:0236-1</id>
    <title>SUSE-SU-2025:0236-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-03T17:24:41.136452+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:0236-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-56664</id>
    <title>UBUNTU-CVE-2024-56664</title>
    <updated>2026-10-03T17:24:41.136555+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:Pro:18.04:LTS: linux-aws-5.4, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:Pro:18.04:LTS: linux-azure-5.4, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3 and 169 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: Fix race between element replace and close() Element replace (with a socket different from the one stored) may race with socket's close() link popping &amp; unlinking. __sock_map_delete() unconditionally unrefs the (wrong) element: // set map[0] = s0 map_update_elem(map, 0, s0) // drop fd of s0 close(s0)   sock_map_close()     lock_sock(sk)               (s0!)     sock_map_remove_links(sk)       link = sk_psock_link_pop()       sock_map_unlink(sk, link)         sock_map_delete_from_link                                         // replace map[0] with s1                                         map_update_elem(map, 0, s1)                                           sock_map_update_elem                                 (s1!)       lock_sock(sk)                                             sock_map_update_common                                               psock = sk_psock(sk)                                               spin_lock(&amp;stab-&gt;lock)                                               osk = stab-&gt;sks[idx]                                               sock_map_add_link(..., &amp;stab-&gt;sks[idx])                                               sock_map_unref(osk, &amp;stab-&gt;sks[idx])                                                 psock = sk_psock(osk)                                                 sk_psock_put(sk, psock)                                                   if (refcount_dec_and_test(&amp;psock))…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-56664"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3762</id>
    <title>WID-SEC-W-2024-3762 — Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service</title>
    <updated>2026-10-03T17:24:41.137010+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen und um nicht näher beschriebene Effekte zu erzielen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3762"/>
  </entry>
</feed>
