<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T18:39:08.256761+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2025:11298</id>
    <title>ALSA-2025:11298 — Moderate: kernel security update</title>
    <updated>2026-10-02T18:39:08.449123+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: bpftool, AlmaLinux:8: kernel, AlmaLinux:8: kernel-abi-stablelists, AlmaLinux:8: kernel-core, AlmaLinux:8: kernel-cross-headers, AlmaLinux:8: kernel-debug, AlmaLinux:8: kernel-debug-core, AlmaLinux:8: kernel-debug-devel, AlmaLinux:8: kernel-debug-modules, AlmaLinux:8: kernel-debug-modules-extra and 15 more</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: cifs: potential buffer overflow in handling symlinks (CVE-2022-49058)
  * kernel: media: uvcvideo: Remove dangling pointers (CVE-2024-58002)
  * kernel: media: uvcvideo: Fix double free in error path (CVE-2024-57980)
  * kernel: x86/microcode/AMD: Fix out-of-bounds on systems with CPU-less NUMA nodes (CVE-2025-21991)
  * kernel: net: atm: fix use after free in lec_send() (CVE-2025-22004)
  * kernel: ext4: fix off-by-one error in do_split (CVE-2025-23150)
  * kernel: ext4: ignore xattrs past end (CVE-2025-37738)
  * kernel: misc/vmw_vmci: fix an infoleak in vmci_host_do_receive_datagram() (CVE-2022-49788)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2025:11298"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-10243</id>
    <title>bdu:2025-10243</title>
    <updated>2026-10-02T18:39:08.449254+00:00</updated>
    <content>bdu:2025-10243</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-10243"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2024-58002</id>
    <title>BELL-CVE-2024-58002</title>
    <updated>2026-10-02T18:39:08.449275+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2024-58002"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0307</id>
    <title>certfr-2025-avi-0307 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
    <updated>2026-10-02T18:39:08.449298+00:00</updated>
    <content>certfr-2025-avi-0307</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0307"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-346583</id>
    <title>EUVD-2026-346583</title>
    <updated>2026-10-02T18:39:08.449315+00:00</updated>
    <content>EUVD-2026-346583</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-346583"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-58002</id>
    <title>fkie_cve-2024-58002</title>
    <updated>2026-10-02T18:39:08.449327+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>media: uvcvideo: Remove dangling pointers</p>
<p>When an async control is written, we copy a pointer to the file handle
that started the operation. That pointer will be used when the device is
done. Which could be anytime in the future.</p>
<p>If the user closes that file descriptor, its structure will be freed,
and there will be one dangling pointer per pending async control, that
the driver will try to use.</p>
<p>Clean all the dangling pointers during release().</p>
<p>To avoid adding a performance penalty in the most common case (no async
operation), a counter has been introduced with some logic to make sure
that it is properly handled.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-58002"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-qc22-v4cr-4rv7</id>
    <title>GHSA-qc22-v4cr-4rv7</title>
    <updated>2026-10-02T18:39:08.449357+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>media: uvcvideo: Remove dangling pointers</p>
<p>When an async control is written, we copy a pointer to the file handle
that started the operation. That pointer will be used when the device is
done. Which could be anytime in the future.</p>
<p>If the user closes that file descriptor, its structure will be freed,
and there will be one dangling pointer per pending async control, that
the driver will try to use.</p>
<p>Clean all the dangling pointers during release().</p>
<p>To avoid adding a performance penalty in the most common case (no async
operation), a counter has been introduced with some logic to make sure
that it is properly handled.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-qc22-v4cr-4rv7"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2024-58002</id>
    <title>msrc_CVE-2024-58002 — media: uvcvideo: Remove dangling pointers</title>
    <updated>2026-10-02T18:39:08.449378+00:00</updated>
    <content>msrc_CVE-2024-58002</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2024-58002"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-1432</id>
    <title>OESA-2025-1432 — kernel security update</title>
    <updated>2026-10-02T18:39:08.449395+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP4: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>KVM: x86: Handle SRCU initialization failure during page track init</p>
<p>Check the return of init_srcu_struct(), which can fail due to OOM, when
initializing the page track mechanism.  Lack of checking leads to a NULL
pointer deref found by a modified syzkaller.</p>
<p>[Move the call towards the beginning of kvm_arch_init_vm. - Paolo](CVE-2021-47407)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>NFSD: prevent underflow in nfssvc_decode_writeargs()</p>
<p>Smatch complains:</p>
<p>fs/nfsd/nfsxdr.c:341 nfssvc_decode_writeargs()
	warn: no lower bound on &amp;apos;args-&amp;gt;len&amp;apos;</p>
<p>Change the type to unsigned to prevent this issue.(CVE-2022-49280)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>tty: synclink_gt: Fix null-pointer-dereference in slgt_clean()</p>
<p>When the driver fails at alloc_hdlcdev(), and then we remove the driver
module, we will get the following splat:</p>
<p>[   25.065966] general protection fault, probably for non-canonical address 0xdffffc0000000182: 0000 [#1] PREEMPT SMP KASAN PTI
[   25.066914] KASAN: null-ptr-deref in range [0x0000000000000c10-0x0000000000000c17]
[   25.069262] RIP: 0010:detach_hdlc_protocol+0x2a/0x3e0
[   25.077709] Call Trace:
[   25.077924]  &amp;lt;TASK&amp;gt;
[   25.078108]  unregister_hdlc_device+0x16/0x30
[   25.078481]  slgt_cleanup+0x157/0x9f0 [synclink_gt]</p>
<p>Fix this by checking whe…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-1432"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:11298</id>
    <title>RHSA-2025:11298 — Red Hat Security Advisory: kernel security update</title>
    <updated>2026-10-02T18:39:08.449506+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: cifs: potential buffer overflow in handling symlinks kernel: misc/vmw_vmci: fix an infoleak in vmci_host_do_receive_datagram() kernel: media: uvcvideo: Fix double free in error path kernel: media: uvcvideo: Remove dangling pointers kernel: x86/microcode/AMD: Fix out-of-bounds on systems with CPU-less NUMA nodes kernel: net: atm: fix use after free in lec_send() kernel: ext4: fix off-by-one error in do_split kernel: ext4: ignore xattrs past end</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:11298"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:11299</id>
    <title>RHSA-2025:11299 — Red Hat Security Advisory: kernel-rt security update</title>
    <updated>2026-10-02T18:39:08.449536+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: cifs: potential buffer overflow in handling symlinks kernel: misc/vmw_vmci: fix an infoleak in vmci_host_do_receive_datagram() kernel: media: uvcvideo: Fix double free in error path kernel: media: uvcvideo: Remove dangling pointers kernel: x86/microcode/AMD: Fix out-of-bounds on systems with CPU-less NUMA nodes kernel: net: atm: fix use after free in lec_send() kernel: ext4: fix off-by-one error in do_split kernel: ext4: ignore xattrs past end</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:11299"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:01919-1</id>
    <title>SUSE-SU-2025:01919-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-02T18:39:08.449563+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:01919-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-58002</id>
    <title>UBUNTU-CVE-2024-58002</title>
    <updated>2026-10-02T18:39:08.449811+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:Pro:18.04:LTS: linux-aws-5.4, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:Pro:18.04:LTS: linux-azure-5.4, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3 and 170 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Remove dangling pointers When an async control is written, we copy a pointer to the file handle that started the operation. That pointer will be used when the device is done. Which could be anytime in the future. If the user closes that file descriptor, its structure will be freed, and there will be one dangling pointer per pending async control, that the driver will try to use. Clean all the dangling pointers during release(). To avoid adding a performance penalty in the most common case (no async operation), a counter has been introduced with some logic to make sure that it is properly handled.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-58002"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0453</id>
    <title>WID-SEC-W-2025-0453 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-02T18:39:08.450022+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0453"/>
  </entry>
</feed>
