<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T14:34:39.438522+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-11808</id>
    <title>bdu:2025-11808</title>
    <updated>2026-10-03T14:34:39.798090+00:00</updated>
    <content>bdu:2025-11808</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-11808"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2024-58079</id>
    <title>BELL-CVE-2024-58079</title>
    <updated>2026-10-03T14:34:39.798156+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2024-58079"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0307</id>
    <title>certfr-2025-avi-0307 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
    <updated>2026-10-03T14:34:39.798190+00:00</updated>
    <content>certfr-2025-avi-0307</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0307"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-346597</id>
    <title>EUVD-2026-346597</title>
    <updated>2026-10-03T14:34:39.798209+00:00</updated>
    <content>EUVD-2026-346597</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-346597"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-58079</id>
    <title>fkie_cve-2024-58079</title>
    <updated>2026-10-03T14:34:39.798220+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>media: uvcvideo: Fix crash during unbind if gpio unit is in use</p>
<p>We used the wrong device for the device managed functions. We used the
usb device, when we should be using the interface device.</p>
<p>If we unbind the driver from the usb interface, the cleanup functions
are never called. In our case, the IRQ is never disabled.</p>
<p>If an IRQ is triggered, it will try to access memory sections that are
already free, causing an OOPS.</p>
<p>We cannot use the function devm_request_threaded_irq here. The devm_*
clean functions may be called after the main structure is released by
uvc_delete.</p>
<p>Luckily this bug has small impact, as it is only affected by devices
with gpio units and the user has to unbind the device, a disconnect will
not trigger this error.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-58079"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-fgjx-56hm-4qrp</id>
    <title>GHSA-fgjx-56hm-4qrp</title>
    <updated>2026-10-03T14:34:39.798254+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>media: uvcvideo: Fix crash during unbind if gpio unit is in use</p>
<p>We used the wrong device for the device managed functions. We used the
usb device, when we should be using the interface device.</p>
<p>If we unbind the driver from the usb interface, the cleanup functions
are never called. In our case, the IRQ is never disabled.</p>
<p>If an IRQ is triggered, it will try to access memory sections that are
already free, causing an OOPS.</p>
<p>We cannot use the function devm_request_threaded_irq here. The devm_*
clean functions may be called after the main structure is released by
uvc_delete.</p>
<p>Luckily this bug has small impact, as it is only affected by devices
with gpio units and the user has to unbind the device, a disconnect will
not trigger this error.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-fgjx-56hm-4qrp"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-1446</id>
    <title>OESA-2025-1446 — kernel security update</title>
    <updated>2026-10-03T14:34:39.798276+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP1: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>ntb_hw_switchtec: Fix shift-out-of-bounds in switchtec_ntb_mw_set_trans</p>
<p>There is a kernel API ntb_mw_clear_trans() would pass 0 to both addr and
size. This would make xlate_pos negative.</p>
<p>[   23.734156] switchtec switchtec0: MW 0: part 0 addr 0x0000000000000000 size 0x0000000000000000
[   23.734158] ================================================================================
[   23.734172] UBSAN: shift-out-of-bounds in drivers/ntb/hw/mscc/ntb_hw_switchtec.c:293:7
[   23.734418] shift exponent -1 is negative</p>
<p>Ensuring xlate_pos is a positive or zero before BIT.(CVE-2023-53034)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>drm/msm/gem: prevent integer overflow in msm_ioctl_gem_submit()</p>
<p>The &amp;quot;submit-&amp;gt;cmd[i].size&amp;quot; and &amp;quot;submit-&amp;gt;cmd[i].offset&amp;quot; variables are u32
values that come from the user via the submit_lookup_cmds() function.
This addition could lead to an integer wrapping bug so use size_add()
to prevent that.</p>
<p>Patchwork: https://patchwork.freedesktop.org/patch/624696/(CVE-2024-52559)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>fs/ntfs3: Mark inode as bad as soon as error detected in mi_enum_attr()</p>
<p>Extended the `mi_enum_attr()` function interface with an additional
parameter, `struct ntfs_inode *ni`, to allow marking the inode
as bad as soon as an error i…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-1446"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:01919-1</id>
    <title>SUSE-SU-2025:01919-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-03T14:34:39.799570+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:01919-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-58079</id>
    <title>UBUNTU-CVE-2024-58079</title>
    <updated>2026-10-03T14:34:39.799829+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 144 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Fix crash during unbind if gpio unit is in use We used the wrong device for the device managed functions. We used the usb device, when we should be using the interface device. If we unbind the driver from the usb interface, the cleanup functions are never called. In our case, the IRQ is never disabled. If an IRQ is triggered, it will try to access memory sections that are already free, causing an OOPS. We cannot use the function devm_request_threaded_irq here. The devm_* clean functions may be called after the main structure is released by uvc_delete. Luckily this bug has small impact, as it is only affected by devices with gpio units and the user has to unbind the device, a disconnect will not trigger this error.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-58079"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0499</id>
    <title>WID-SEC-W-2025-0499 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-03T14:34:39.800038+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um nicht spezifizierte Auswirkungen zu erzeugen oder einen Denial-of-Service-Zustand zu verursachen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0499"/>
  </entry>
</feed>
