<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T20:09:54.775441+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-07848</id>
    <title>bdu:2025-07848</title>
    <updated>2026-10-03T20:09:55.097300+00:00</updated>
    <content>bdu:2025-07848</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-07848"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2024-56718</id>
    <title>BELL-CVE-2024-56718</title>
    <updated>2026-10-03T20:09:55.097383+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2024-56718"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0184</id>
    <title>certfr-2025-avi-0184 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian LTS. Elles permettent à un attaquant de p…</title>
    <updated>2026-10-03T20:09:55.097418+00:00</updated>
    <content>certfr-2025-avi-0184</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0184"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-346527</id>
    <title>EUVD-2026-346527</title>
    <updated>2026-10-03T20:09:55.097436+00:00</updated>
    <content>EUVD-2026-346527</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-346527"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-56718</id>
    <title>fkie_cve-2024-56718</title>
    <updated>2026-10-03T20:09:55.097447+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>net/smc: protect link down work from execute after lgr freed</p>
<p>link down work may be scheduled before lgr freed but execute
after lgr freed, which may result in crash. So it is need to
hold a reference before shedule link down work, and put the
reference after work executed or canceled.</p>
<p>The relevant crash call stack as follows:
 list_del corruption. prev-&gt;next should be ffffb638c9c0fe20,
    but was 0000000000000000
 ------------[ cut here ]------------
 kernel BUG at lib/list_debug.c:51!
 invalid opcode: 0000 [#1] SMP NOPTI
 CPU: 6 PID: 978112 Comm: kworker/6:119 Kdump: loaded Tainted: G #1
 Hardware name: Alibaba Cloud Alibaba Cloud ECS, BIOS 2221b89 04/01/2014
 Workqueue: events smc_link_down_work [smc]
 RIP: 0010:__list_del_entry_valid.cold+0x31/0x47
 RSP: 0018:ffffb638c9c0fdd8 EFLAGS: 00010086
 RAX: 0000000000000054 RBX: ffff942fb75e5128 RCX: 0000000000000000
 RDX: ffff943520930aa0 RSI: ffff94352091fc80 RDI: ffff94352091fc80
 RBP: 0000000000000000 R08: 0000000000000000 R09: ffffb638c9c0fc38
 R10: ffffb638c9c0fc30 R11: ffffffffa015eb28 R12: 0000000000000002
 R13: ffffb638c9c0fe20 R14: 0000000000000001 R15: ffff942f9cd051c0
 FS:  0000000000000000(0000) GS:ffff943520900000(0000) knlGS:0000000000000000
 CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
 CR2: 00007f4f25214000 CR3: 000000025fbae004 CR4: 00000000007706e0
 DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
 DR3: 0000000000000000…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-56718"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-q325-c4qh-6g3c</id>
    <title>GHSA-q325-c4qh-6g3c</title>
    <updated>2026-10-03T20:09:55.097494+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>net/smc: protect link down work from execute after lgr freed</p>
<p>link down work may be scheduled before lgr freed but execute
after lgr freed, which may result in crash. So it is need to
hold a reference before shedule link down work, and put the
reference after work executed or canceled.</p>
<p>The relevant crash call stack as follows:
 list_del corruption. prev-&gt;next should be ffffb638c9c0fe20,
    but was 0000000000000000
 ------------[ cut here ]------------
 kernel BUG at lib/list_debug.c:51!
 invalid opcode: 0000 [#1] SMP NOPTI
 CPU: 6 PID: 978112 Comm: kworker/6:119 Kdump: loaded Tainted: G #1
 Hardware name: Alibaba Cloud Alibaba Cloud ECS, BIOS 2221b89 04/01/2014
 Workqueue: events smc_link_down_work [smc]
 RIP: 0010:__list_del_entry_valid.cold+0x31/0x47
 RSP: 0018:ffffb638c9c0fdd8 EFLAGS: 00010086
 RAX: 0000000000000054 RBX: ffff942fb75e5128 RCX: 0000000000000000
 RDX: ffff943520930aa0 RSI: ffff94352091fc80 RDI: ffff94352091fc80
 RBP: 0000000000000000 R08: 0000000000000000 R09: ffffb638c9c0fc38
 R10: ffffb638c9c0fc30 R11: ffffffffa015eb28 R12: 0000000000000002
 R13: ffffb638c9c0fe20 R14: 0000000000000001 R15: ffff942f9cd051c0
 FS:  0000000000000000(0000) GS:ffff943520900000(0000) knlGS:0000000000000000
 CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
 CR2: 00007f4f25214000 CR3: 000000025fbae004 CR4: 00000000007706e0
 DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
 DR3: 0000000000000000…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-q325-c4qh-6g3c"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2024-56718</id>
    <title>msrc_CVE-2024-56718 — net/smc: protect link down work from execute after lgr freed</title>
    <updated>2026-10-03T20:09:55.097526+00:00</updated>
    <content>msrc_CVE-2024-56718</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2024-56718"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-1093</id>
    <title>OESA-2025-1093 — kernel security update</title>
    <updated>2026-10-03T20:09:55.097544+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP1: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>ksmbd: fix potencial out-of-bounds when buffer offset is invalid</p>
<p>I found potencial out-of-bounds when buffer offset fields of a few requests
is invalid. This patch set the minimum value of buffer offset field to
-&amp;gt;Buffer offset to validate buffer length.(CVE-2024-26952)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>ksmbd: fix slab-out-of-bounds in smb_strndup_from_utf16()</p>
<p>If -&amp;gt;NameOffset of smb2_create_req is smaller than Buffer offset of
smb2_create_req, slab-out-of-bounds read can happen from smb2_open.
This patch set the minimum value of the name offset to the buffer offset
to validate name length of smb2_create_req().(CVE-2024-26954)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>net: dsa: improve shutdown sequence</p>
<p>Alexander Sverdlin presents 2 problems during shutdown with the
lan9303 driver. One is specific to lan9303 and the other just happens
to reproduce there.</p>
<p>The first problem is that lan9303 is unique among DSA drivers in that it
calls dev_get_drvdata() at &amp;quot;arbitrary runtime&amp;quot; (not probe, not shutdown,
not remove):</p>
<p>phy_state_machine()
-&amp;gt; ...
   -&amp;gt; dsa_user_phy_read()
      -&amp;gt; ds-&amp;gt;ops-&amp;gt;phy_read()
         -&amp;gt; lan9303_phy_read()
            -&amp;gt; chip-&amp;gt;ops-&amp;gt;phy_read()
               -&amp;gt; lan9303_mdio_phy_read()
                  -&amp;gt;…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-1093"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:01919-1</id>
    <title>SUSE-SU-2025:01919-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-03T20:09:55.097973+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:01919-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-56718</id>
    <title>UBUNTU-CVE-2024-56718</title>
    <updated>2026-10-03T20:09:55.098218+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 144 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: net/smc: protect link down work from execute after lgr freed link down work may be scheduled before lgr freed but execute after lgr freed, which may result in crash. So it is need to hold a reference before shedule link down work, and put the reference after work executed or canceled. The relevant crash call stack as follows:  list_del corruption. prev-&gt;next should be ffffb638c9c0fe20,     but was 0000000000000000  ------------[ cut here ]------------  kernel BUG at lib/list_debug.c:51!  invalid opcode: 0000 [#1] SMP NOPTI  CPU: 6 PID: 978112 Comm: kworker/6:119 Kdump: loaded Tainted: G #1  Hardware name: Alibaba Cloud Alibaba Cloud ECS, BIOS 2221b89 04/01/2014  Workqueue: events smc_link_down_work [smc]  RIP: 0010:__list_del_entry_valid.cold+0x31/0x47  RSP: 0018:ffffb638c9c0fdd8 EFLAGS: 00010086  RAX: 0000000000000054 RBX: ffff942fb75e5128 RCX: 0000000000000000  RDX: ffff943520930aa0 RSI: ffff94352091fc80 RDI: ffff94352091fc80  RBP: 0000000000000000 R08: 0000000000000000 R09: ffffb638c9c0fc38  R10: ffffb638c9c0fc30 R11: ffffffffa015eb28 R12: 0000000000000002  R13: ffffb638c9c0fe20 R14: 0000000000000001 R15: ffff942f9cd051c0  FS:  0000000000000000(0000) GS:ffff943520900000(0000) knlGS:0000000000000000  CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033  CR2: 00007f4f25214000 CR3: 000000025fbae004 CR4: 00000000007706e0  DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000  DR3: 0000000000000000 DR…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-56718"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3762</id>
    <title>WID-SEC-W-2024-3762 — Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service</title>
    <updated>2026-10-03T20:09:55.098444+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen und um nicht näher beschriebene Effekte zu erzielen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3762"/>
  </entry>
</feed>
