<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T09:01:12.597681+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:63013</id>
    <title>ALSA-2026:63013 — Important: kernel-rt security, bug fix, and enhancement update</title>
    <updated>2026-10-04T09:01:13.235497+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: kernel-rt, AlmaLinux:8: kernel-rt-core, AlmaLinux:8: kernel-rt-debug, AlmaLinux:8: kernel-rt-debug-core, AlmaLinux:8: kernel-rt-debug-devel, AlmaLinux:8: kernel-rt-debug-modules, AlmaLinux:8: kernel-rt-debug-modules-extra, AlmaLinux:8: kernel-rt-devel, AlmaLinux:8: kernel-rt-modules, AlmaLinux:8: kernel-rt-modules-extra</p>
<p>The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.</p>
<p>Security Fix(es):</p>
<p>* kernel: s390/cpum_sf: Handle CPU hotplug remove during sampling (CVE-2024-57849)
  * kernel: smc91x: fix broken irq-context in PREEMPT_RT (CVE-2025-71132)
  * kernel: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (CVE-2026-45970)
  * kernel: zram: fix use-after-free in zram_bvec_write_partial() (CVE-2026-53185)
  * kernel: pNFS: Fix use-after-free in pnfs_update_layout() (CVE-2026-63800)
  * kernel: nfsd: fix posix_acl leak on SETACL decode failure (CVE-2026-53397)
  * kernel: nfsd: release layout stid on setlease failure (CVE-2026-53399)
  * kernel: NFSv4/flexfiles: reject zero filehandle version count (CVE-2026-53392)
  * kernel: NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr (CVE-2026-53391)
  * kernel: net: mana: validate rx_req_idx to prevent out-of-bounds array access (CVE-2026-64018)
  * kernel: Kernel: Remote out-of-bounds write in RDMA/siw (CVE-2026-64268)
  * kernel: NFSv4: include MAY_WRITE in open permission mask for O_TRUNC (CVE-2026-64298)
  * kernel: AMD-SN-7061: Safe RET Interrupt Vulnerability (CVE-2026-68480)
  * kernel: net: ipv6: use-after-free in fib6_rule_suppress due to stale res-&gt;rt6 pointer (CVE-2026-74581)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* qede: build_skb failure causes off-by-one BD ring corruption and kernel panic [almalinux-8.10.z] (JIRA:AlmaL…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:63013"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-06153</id>
    <title>bdu:2025-06153</title>
    <updated>2026-10-04T09:01:13.235649+00:00</updated>
    <content>bdu:2025-06153</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-06153"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2024-57849</id>
    <title>BELL-CVE-2024-57849</title>
    <updated>2026-10-04T09:01:13.235669+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2024-57849"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0088</id>
    <title>certfr-2025-avi-0088 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
    <updated>2026-10-04T09:01:13.235692+00:00</updated>
    <content>certfr-2025-avi-0088</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0088"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-346548</id>
    <title>EUVD-2026-346548</title>
    <updated>2026-10-04T09:01:13.235709+00:00</updated>
    <content>EUVD-2026-346548</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-346548"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-57849</id>
    <title>fkie_cve-2024-57849</title>
    <updated>2026-10-04T09:01:13.235720+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>s390/cpum_sf: Handle CPU hotplug remove during sampling</p>
<p>CPU hotplug remove handling triggers the following function
call sequence:</p>
<p>CPUHP_AP_PERF_S390_SF_ONLINE  --&gt; s390_pmu_sf_offline_cpu()
   ...
   CPUHP_AP_PERF_ONLINE          --&gt; perf_event_exit_cpu()</p>
<p>The s390 CPUMF sampling CPU hotplug handler invokes:</p>
<p>s390_pmu_sf_offline_cpu()
 +--&gt;  cpusf_pmu_setup()
       +--&gt; setup_pmc_cpu()
            +--&gt; deallocate_buffers()</p>
<p>This function de-allocates all sampling data buffers (SDBs) allocated
for that CPU at event initialization. It also clears the
PMU_F_RESERVED bit. The CPU is gone and can not be sampled.</p>
<p>With the event still being active on the removed CPU, the CPU event
hotplug support in kernel performance subsystem triggers the
following function calls on the removed CPU:</p>
<p>perf_event_exit_cpu()
  +--&gt; perf_event_exit_cpu_context()
       +--&gt; __perf_event_exit_context()
	    +--&gt; __perf_remove_from_context()
	         +--&gt; event_sched_out()
	              +--&gt; cpumsf_pmu_del()
	                   +--&gt; cpumsf_pmu_stop()
                                +--&gt; hw_perf_event_update()</p>
<p>to stop and remove the event. During removal of the event, the
sampling device driver tries to read out the remaining samples from
the sample data buffers (SDBs). But they have already been freed
(and may have been re-assigned). This may lead to a use after free
situation in which case the samples are most likely in…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-57849"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-q4cg-m7j8-ggr6</id>
    <title>GHSA-q4cg-m7j8-ggr6</title>
    <updated>2026-10-04T09:01:13.235764+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>s390/cpum_sf: Handle CPU hotplug remove during sampling</p>
<p>CPU hotplug remove handling triggers the following function
call sequence:</p>
<p>CPUHP_AP_PERF_S390_SF_ONLINE  --&gt; s390_pmu_sf_offline_cpu()
   ...
   CPUHP_AP_PERF_ONLINE          --&gt; perf_event_exit_cpu()</p>
<p>The s390 CPUMF sampling CPU hotplug handler invokes:</p>
<p>s390_pmu_sf_offline_cpu()
 +--&gt;  cpusf_pmu_setup()
       +--&gt; setup_pmc_cpu()
            +--&gt; deallocate_buffers()</p>
<p>This function de-allocates all sampling data buffers (SDBs) allocated
for that CPU at event initialization. It also clears the
PMU_F_RESERVED bit. The CPU is gone and can not be sampled.</p>
<p>With the event still being active on the removed CPU, the CPU event
hotplug support in kernel performance subsystem triggers the
following function calls on the removed CPU:</p>
<p>perf_event_exit_cpu()
  +--&gt; perf_event_exit_cpu_context()
       +--&gt; __perf_event_exit_context()
	    +--&gt; __perf_remove_from_context()
	         +--&gt; event_sched_out()
	              +--&gt; cpumsf_pmu_del()
	                   +--&gt; cpumsf_pmu_stop()
                                +--&gt; hw_perf_event_update()</p>
<p>to stop and remove the event. During removal of the event, the
sampling device driver tries to read out the remaining samples from
the sample data buffers (SDBs). But they have already been freed
(and may have been re-assigned). This may lead to a use after free
situation in which case the samples are most likely in…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-q4cg-m7j8-ggr6"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-1158</id>
    <title>OESA-2025-1158 — kernel security update</title>
    <updated>2026-10-04T09:01:13.235797+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP4: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>ila: call nf_unregister_net_hooks() sooner</p>
<p>syzbot found an use-after-free Read in ila_nf_input [1]</p>
<p>Issue here is that ila_xlat_exit_net() frees the rhashtable,
then call nf_unregister_net_hooks().</p>
<p>It should be done in the reverse way, with a synchronize_rcu().</p>
<p>This is a good match for a pre_exit() method.</p>
<p>[1]
 BUG: KASAN: use-after-free in rht_key_hashfn include/linux/rhashtable.h:159 [inline]
 BUG: KASAN: use-after-free in __rhashtable_lookup include/linux/rhashtable.h:604 [inline]
 BUG: KASAN: use-after-free in rhashtable_lookup include/linux/rhashtable.h:646 [inline]
 BUG: KASAN: use-after-free in rhashtable_lookup_fast+0x77a/0x9b0 include/linux/rhashtable.h:672
Read of size 4 at addr ffff888064620008 by task ksoftirqd/0/16</p>
<p>CPU: 0 UID: 0 PID: 16 Comm: ksoftirqd/0 Not tainted 6.11.0-rc4-syzkaller-00238-g2ad6d23f465a #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 08/06/2024
Call Trace:
 &amp;lt;TASK&amp;gt;
  __dump_stack lib/dump_stack.c:93 [inline]
  dump_stack_lvl+0x241/0x360 lib/dump_stack.c:119
  print_address_description mm/kasan/report.c:377 [inline]
  print_report+0x169/0x550 mm/kasan/report.c:488
  kasan_report+0x143/0x180 mm/kasan/report.c:601
  rht_key_hashfn include/linux/rhashtable.h:159 [inline]
  __rhashtable_lookup include/linux/rhashtable.h:604 [inline]
  rhashtable_lookup include/lin…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-1158"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:63013</id>
    <title>RHSA-2026:63013 — Red Hat Security Advisory: kernel-rt security, bug fix, and enhancement update</title>
    <updated>2026-10-04T09:01:13.235899+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: s390/cpum_sf: Handle CPU hotplug remove during sampling kernel: smc91x: fix broken irq-context in PREEMPT_RT kernel: bonding: alb: fix UAF in rlb_arp_recv during bond up/down kernel: zram: fix use-after-free in zram_bvec_write_partial() kernel: NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr kernel: NFSv4/flexfiles: reject zero filehandle version count kernel: nfsd: fix posix_acl leak on SETACL decode failure kernel: nfsd: release layout stid on setlease failure kernel: pNFS: Fix use-after-free in pnfs_update_layout() kernel: net: mana: validate rx_req_idx to prevent out-of-bounds array access kernel: Kernel: Remote out-of-bounds write in RDMA/siw kernel: NFSv4: include MAY_WRITE in open permission mask for O_TRUNC kernel: AMD-SN-7061: Safe RET Interrupt Vulnerability kernel: net: ipv6: use-after-free in fib6_rule_suppress due to stale res-&gt;rt6 pointer</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:63013"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:63014</id>
    <title>RHSA-2026:63014 — Red Hat Security Advisory: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-04T09:01:13.235948+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: s390/cpum_sf: Handle CPU hotplug remove during sampling kernel: smc91x: fix broken irq-context in PREEMPT_RT kernel: bonding: alb: fix UAF in rlb_arp_recv during bond up/down kernel: zram: fix use-after-free in zram_bvec_write_partial() kernel: NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr kernel: NFSv4/flexfiles: reject zero filehandle version count kernel: nfsd: fix posix_acl leak on SETACL decode failure kernel: nfsd: release layout stid on setlease failure kernel: pNFS: Fix use-after-free in pnfs_update_layout() kernel: net: mana: validate rx_req_idx to prevent out-of-bounds array access kernel: Kernel: Remote out-of-bounds write in RDMA/siw kernel: NFSv4: include MAY_WRITE in open permission mask for O_TRUNC kernel: AMD-SN-7061: Safe RET Interrupt Vulnerability kernel: net: ipv6: use-after-free in fib6_rule_suppress due to stale res-&gt;rt6 pointer</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:63014"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:63013</id>
    <title>RLSA-2026:63013 — Important: kernel-rt security, bug fix, and enhancement update</title>
    <updated>2026-10-04T09:01:13.235993+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:8: kernel-rt</p>
<p>The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.</p>
<p>Security Fix(es):</p>
<p>* kernel: s390/cpum_sf: Handle CPU hotplug remove during sampling (CVE-2024-57849)</p>
<p>* kernel: smc91x: fix broken irq-context in PREEMPT_RT (CVE-2025-71132)</p>
<p>* kernel: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (CVE-2026-45970)</p>
<p>* kernel: zram: fix use-after-free in zram_bvec_write_partial() (CVE-2026-53185)</p>
<p>* kernel: pNFS: Fix use-after-free in pnfs_update_layout() (CVE-2026-63800)</p>
<p>* kernel: nfsd: fix posix_acl leak on SETACL decode failure (CVE-2026-53397)</p>
<p>* kernel: nfsd: release layout stid on setlease failure (CVE-2026-53399)</p>
<p>* kernel: NFSv4/flexfiles: reject zero filehandle version count (CVE-2026-53392)</p>
<p>* kernel: NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr (CVE-2026-53391)</p>
<p>* kernel: net: mana: validate rx_req_idx to prevent out-of-bounds array access (CVE-2026-64018)</p>
<p>* kernel: Kernel: Remote out-of-bounds write in RDMA/siw (CVE-2026-64268)</p>
<p>* kernel: NFSv4: include MAY_WRITE in open permission mask for O_TRUNC (CVE-2026-64298)</p>
<p>* kernel: AMD-SN-7061: Safe RET Interrupt Vulnerability (CVE-2026-68480)</p>
<p>* kernel: net: ipv6: use-after-free in fib6_rule_suppress due to stale res-&gt;rt6 pointer (CVE-2026-74581)</p>
<p>Bug Fix(es) and Enhancement(s):</p>
<p>* qede: build_skb failure causes off-by-one BD ring corruption and kernel panic [rhel-8.10.z] (JIRA:Rocky Linux-193045)</p>
<p>* powerpc/pse…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:63013"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:0236-1</id>
    <title>SUSE-SU-2025:0236-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-04T09:01:13.236036+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:0236-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-57849</id>
    <title>UBUNTU-CVE-2024-57849</title>
    <updated>2026-10-04T09:01:13.236103+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:Pro:16.04:LTS: linux-oracle, Ubuntu:Pro:18.04:LTS: linux, Ubuntu:Pro:18.04:LTS: linux-aws, Ubuntu:18.04:LTS: linux-aws-5.0 and 188 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: s390/cpum_sf: Handle CPU hotplug remove during sampling CPU hotplug remove handling triggers the following function call sequence:    CPUHP_AP_PERF_S390_SF_ONLINE  --&gt; s390_pmu_sf_offline_cpu()    ...    CPUHP_AP_PERF_ONLINE          --&gt; perf_event_exit_cpu() The s390 CPUMF sampling CPU hotplug handler invokes:  s390_pmu_sf_offline_cpu()  +--&gt;  cpusf_pmu_setup()        +--&gt; setup_pmc_cpu()             +--&gt; deallocate_buffers() This function de-allocates all sampling data buffers (SDBs) allocated for that CPU at event initialization. It also clears the PMU_F_RESERVED bit. The CPU is gone and can not be sampled. With the event still being active on the removed CPU, the CPU event hotplug support in kernel performance subsystem triggers the following function calls on the removed CPU:   perf_event_exit_cpu()   +--&gt; perf_event_exit_cpu_context()        +--&gt; __perf_event_exit_context() 	    +--&gt; __perf_remove_from_context() 	         +--&gt; event_sched_out() 	              +--&gt; cpumsf_pmu_del() 	                   +--&gt; cpumsf_pmu_stop()                                 +--&gt; hw_perf_event_update() to stop and remove the event. During removal of the event, the sampling device driver tries to read out the remaining samples from the sample data buffers (SDBs). But they have already been freed (and may have been re-assigned). This may lead to a use after free situation in which case the samples are most likely invalid. In…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-57849"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0047</id>
    <title>WID-SEC-W-2025-0047 — Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service</title>
    <updated>2026-10-04T09:01:13.236337+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann mehrere Schwachstellen im Linux-Kernel ausnutzen, um einen Denial-of-Service-Zustand zu erzeugen und weitere nicht spezifizierte Angriffe zu starten.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0047"/>
  </entry>
</feed>
