<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T13:10:26.248623+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-01977</id>
    <title>bdu:2025-01977</title>
    <updated>2026-10-03T13:10:26.633556+00:00</updated>
    <content>bdu:2025-01977</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-01977"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2024-57947</id>
    <title>BELL-CVE-2024-57947</title>
    <updated>2026-10-03T13:10:26.633654+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2024-57947"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0307</id>
    <title>certfr-2025-avi-0307 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
    <updated>2026-10-03T13:10:26.633691+00:00</updated>
    <content>certfr-2025-avi-0307</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0307"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-346568</id>
    <title>EUVD-2026-346568</title>
    <updated>2026-10-03T13:10:26.633710+00:00</updated>
    <content>EUVD-2026-346568</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-346568"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-57947</id>
    <title>fkie_cve-2024-57947</title>
    <updated>2026-10-03T13:10:26.633723+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>netfilter: nf_set_pipapo: fix initial map fill</p>
<p>The initial buffer has to be inited to all-ones, but it must restrict
it to the size of the first field, not the total field size.</p>
<p>After each round in the map search step, the result and the fill map
are swapped, so if we have a set where f-&gt;bsize of the first element
is smaller than m-&gt;bsize_max, those one-bits are leaked into future
rounds result map.</p>
<p>This makes pipapo find an incorrect matching results for sets where
first field size is not the largest.</p>
<p>Followup patch adds a test case to nft_concat_range.sh selftest script.</p>
<p>Thanks to Stefano Brivio for pointing out that we need to zero out
the remainder explicitly, only correcting memset() argument isn't enough.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-57947"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-2885-grqh-2673</id>
    <title>GHSA-2885-grqh-2673</title>
    <updated>2026-10-03T13:10:26.633759+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>netfilter: nf_set_pipapo: fix initial map fill</p>
<p>The initial buffer has to be inited to all-ones, but it must restrict
it to the size of the first field, not the total field size.</p>
<p>After each round in the map search step, the result and the fill map
are swapped, so if we have a set where f-&gt;bsize of the first element
is smaller than m-&gt;bsize_max, those one-bits are leaked into future
rounds result map.</p>
<p>This makes pipapo find an incorrect matching results for sets where
first field size is not the largest.</p>
<p>Followup patch adds a test case to nft_concat_range.sh selftest script.</p>
<p>Thanks to Stefano Brivio for pointing out that we need to zero out
the remainder explicitly, only correcting memset() argument isn't enough.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-2885-grqh-2673"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-1110</id>
    <title>OESA-2025-1110 — kernel security update</title>
    <updated>2026-10-03T13:10:26.633783+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>i3c: Use i3cdev-&amp;gt;desc-&amp;gt;info instead of calling i3c_device_get_info() to avoid deadlock</p>
<p>A deadlock may happen since the i3c_master_register() acquires
&amp;amp;i3cbus-&amp;gt;lock twice. See the log below.
Use i3cdev-&amp;gt;desc-&amp;gt;info instead of calling i3c_device_info() to
avoid acquiring the lock twice.</p>
<p>v2:
  - Modified the title and commit message</p>
<p>============================================
WARNING: possible recursive locking detected
6.11.0-mainline
--------------------------------------------
init/1 is trying to acquire lock:
f1ffff80a6a40dc0 (&amp;amp;i3cbus-&amp;gt;lock){++++}-{3:3}, at: i3c_bus_normaluse_lock</p>
<p>but task is already holding lock:
f1ffff80a6a40dc0 (&amp;amp;i3cbus-&amp;gt;lock){++++}-{3:3}, at: i3c_master_register</p>
<p>other info that might help us debug this:
 Possible unsafe locking scenario:</p>
<p>CPU0
       ----
  lock(&amp;amp;i3cbus-&amp;gt;lock);
  lock(&amp;amp;i3cbus-&amp;gt;lock);</p>
<p>*** DEADLOCK ***</p>
<p>May be due to missing lock nesting notation</p>
<p>2 locks held by init/1:
 #0: fcffff809b6798f8 (&amp;amp;dev-&amp;gt;mutex){....}-{3:3}, at: __driver_attach
 #1: f1ffff80a6a40dc0 (&amp;amp;i3cbus-&amp;gt;lock){++++}-{3:3}, at: i3c_master_register</p>
<p>stack backtrace:
CPU: 6 UID: 0 PID: 1 Comm: init
Call trace:
 dump_backtrace+0xfc/0x17c
 show_stack+0x18/0x28
 dump_stack_lvl+0x40/0xc0
 dump_stack+0x18/0x24
 print_deadlock_bug+0x388/0x390
 __lock_acquire+0x18bc/0…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-1110"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:0578</id>
    <title>RHSA-2025:0578 — Red Hat Security Advisory: kernel security update</title>
    <updated>2026-10-03T13:10:26.633980+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: tcp/dccp: Don&amp;#39;t use timer_pending() in reqsk_queue_unlink(). kernel: arm64/sve: Discard stale CPU state when handling SVE traps kernel: i40e: fix race condition by adding filter's intermediate sync state kernel: netfilter: nf_set_pipapo: fix initial map fill</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:0578"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:01919-1</id>
    <title>SUSE-SU-2025:01919-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-03T13:10:26.634008+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:01919-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-57947</id>
    <title>UBUNTU-CVE-2024-57947</title>
    <updated>2026-10-03T13:10:26.634268+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 134 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_set_pipapo: fix initial map fill The initial buffer has to be inited to all-ones, but it must restrict it to the size of the first field, not the total field size. After each round in the map search step, the result and the fill map are swapped, so if we have a set where f-&gt;bsize of the first element is smaller than m-&gt;bsize_max, those one-bits are leaked into future rounds result map. This makes pipapo find an incorrect matching results for sets where first field size is not the largest. Followup patch adds a test case to nft_concat_range.sh selftest script. Thanks to Stefano Brivio for pointing out that we need to zero out the remainder explicitly, only correcting memset() argument isn't enough.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-57947"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0188</id>
    <title>WID-SEC-W-2025-0188 — Linux Kernel: Schwachstelle ermöglicht Denial of Service</title>
    <updated>2026-10-03T13:10:26.634442+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Linux Kernel ausnutzen, um einen Denial of Service Zustand herbeizuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0188"/>
  </entry>
</feed>
