<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T13:01:17.024134+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2025:20095</id>
    <title>ALSA-2025:20095 — Moderate: kernel security update</title>
    <updated>2026-10-02T13:01:17.259181+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:10: kernel, AlmaLinux:10: kernel-64k, AlmaLinux:10: kernel-64k-core, AlmaLinux:10: kernel-64k-debug, AlmaLinux:10: kernel-64k-debug-core, AlmaLinux:10: kernel-64k-debug-devel, AlmaLinux:10: kernel-64k-debug-devel-matched, AlmaLinux:10: kernel-64k-debug-modules, AlmaLinux:10: kernel-64k-debug-modules-core, AlmaLinux:10: kernel-64k-debug-modules-extra and 65 more</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: xen: Xen hypercall page unsafe against speculative attacks (Xen Security Advisory 466) (CVE-2024-53241)
  * kernel: exfat: fix out-of-bounds access of directory entries (CVE-2024-53147)
  * kernel: zram: fix NULL pointer in comp_algorithm_show() (CVE-2024-53222)
  * kernel: nfsd: release svc_expkey/svc_export with rcu_work (CVE-2024-53216)
  * kernel: acpi: nfit: vmalloc-out-of-bounds Read in acpi_nfit_ctl (CVE-2024-56662)
  * kernel: bpf: Fix UAF via mismatching bpf_prog/attachment RCU flavors (CVE-2024-56675)
  * kernel: crypto: pcrypt - Call crypto layer directly when padata_do_parallel() return -EBUSY (CVE-2024-56690)
  * kernel: igb: Fix potential invalid memory access in igb_init_module() (CVE-2024-52332)
  * kernel: af_packet: fix vlan_get_protocol_dgram() vs MSG_PEEK (CVE-2024-57901)
  * kernel: af_packet: fix vlan_get_tci() vs MSG_PEEK (CVE-2024-57902)
  * kernel: io_uring/sqpoll: zero sqd-&gt;thread on tctx errors (CVE-2025-21633)
  * kernel: ipvlan: Fix use-after-free in ipvlan_get_iflink(). (CVE-2025-21652)
  * kernel: sched: sch_cake: add bounds checks to host bulk flow fairness counts (CVE-2025-21647)
  * kernel: io_uring/eventfd: ensure io_eventfd_signal() defers another RCU period (CVE-2025-21655)
  * kernel: netfs: Fix the (non-)cancellation of copy when cache is temporarily disabled (CVE-2024-57941)
  * kernel: netfs: Fix ceph copy to cache…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2025:20095"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-06557</id>
    <title>bdu:2025-06557</title>
    <updated>2026-10-02T13:01:17.259398+00:00</updated>
    <content>bdu:2025-06557</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-06557"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-21655</id>
    <title>BELL-CVE-2025-21655</title>
    <updated>2026-10-02T13:01:17.259420+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-21655"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0133</id>
    <title>certfr-2025-avi-0133 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Elles permettent à un attaquant de provoqu…</title>
    <updated>2026-10-02T13:01:17.259443+00:00</updated>
    <content>certfr-2025-avi-0133</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0133"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-364481</id>
    <title>EUVD-2026-364481</title>
    <updated>2026-10-02T13:01:17.259459+00:00</updated>
    <content>EUVD-2026-364481</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-364481"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-21655</id>
    <title>fkie_cve-2025-21655</title>
    <updated>2026-10-02T13:01:17.259479+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>io_uring/eventfd: ensure io_eventfd_signal() defers another RCU period</p>
<p>io_eventfd_do_signal() is invoked from an RCU callback, but when
dropping the reference to the io_ev_fd, it calls io_eventfd_free()
directly if the refcount drops to zero. This isn't correct, as any
potential freeing of the io_ev_fd should be deferred another RCU grace
period.</p>
<p>Just call io_eventfd_put() rather than open-code the dec-and-test and
free, which will correctly defer it another RCU grace period.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-21655"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-vwm2-fvjj-vcv3</id>
    <title>GHSA-vwm2-fvjj-vcv3</title>
    <updated>2026-10-02T13:01:17.259510+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>io_uring/eventfd: ensure io_eventfd_signal() defers another RCU period</p>
<p>io_eventfd_do_signal() is invoked from an RCU callback, but when
dropping the reference to the io_ev_fd, it calls io_eventfd_free()
directly if the refcount drops to zero. This isn't correct, as any
potential freeing of the io_ev_fd should be deferred another RCU grace
period.</p>
<p>Just call io_eventfd_put() rather than open-code the dec-and-test and
free, which will correctly defer it another RCU grace period.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-vwm2-fvjj-vcv3"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-26-209-04</id>
    <title>ICSA-26-209-04 — Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</title>
    <updated>2026-10-02T13:01:17.259529+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).</p>
<p>Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-26-209-04"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-1320</id>
    <title>OESA-2025-1320 — kernel security update</title>
    <updated>2026-10-02T13:01:17.259752+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS: kernel</p>
<p>The Linux Kernel, the operating system core itself.</p>
<p>Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>RDMA/rtrs: Ensure &amp;apos;ib_sge list&amp;apos; is accessible</p>
<p>Move the declaration of the &amp;apos;ib_sge list&amp;apos; variable outside the
&amp;apos;always_invalidate&amp;apos; block to ensure it remains accessible for use
throughout the function.</p>
<p>Previously, &amp;apos;ib_sge list&amp;apos; was declared within the &amp;apos;always_invalidate&amp;apos;
block, limiting its accessibility, then caused a
&amp;apos;BUG: kernel NULL pointer dereference&amp;apos;[1].
 ? __die_body.cold+0x19/0x27
 ? page_fault_oops+0x15a/0x2d0
 ? search_module_extables+0x19/0x60
 ? search_bpf_extables+0x5f/0x80
 ? exc_page_fault+0x7e/0x180
 ? asm_exc_page_fault+0x26/0x30
 ? memcpy_orig+0xd5/0x140
 rxe_mr_copy+0x1c3/0x200 [rdma_rxe]
 ? rxe_pool_get_index+0x4b/0x80 [rdma_rxe]
 copy_data+0xa5/0x230 [rdma_rxe]
 rxe_requester+0xd9b/0xf70 [rdma_rxe]
 ? finish_task_switch.isra.0+0x99/0x2e0
 rxe_sender+0x13/0x40 [rdma_rxe]
 do_task+0x68/0x1e0 [rdma_rxe]
 process_one_work+0x177/0x330
 worker_thread+0x252/0x390
 ? __pfx_worker_thread+0x10/0x10</p>
<p>This change ensures the variable is available for subsequent operations
that require it.</p>
<p>[1] https://lore.kernel.org/linux-rdma/6a1f3e8f-deb0-49f9-bc69-a9b03ecfcda7@fujitsu.com/(CVE-2024-36476)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>drm/sti: avoid potential dereference of error pointers in sti_hqvdp_atomic_check</p>
<p>The return value of drm_at…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-1320"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:20095</id>
    <title>RHSA-2025:20095 — Red Hat Security Advisory: kernel security update</title>
    <updated>2026-10-02T13:01:17.259985+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>microcode_ctl: From CVEorg collector kernel: information leak via transient execution vulnerability in some AMD processors kernel: transient execution vulnerability in some AMD processors kernel: drm/xe/tracing: Fix a potential TP_printk UAF kernel: igb: Fix potential invalid memory access in igb_init_module() kernel: exfat: fix out-of-bounds access of directory entries kernel: nfsd: release svc_expkey/svc_export with rcu_work kernel: zram: fix NULL pointer in comp_algorithm_show() kernel: xen: Xen hypercall page unsafe against speculative attacks (Xen Security Advisory 466) kernel: NFS: Fix potential buffer overflowin nfs_sysfs_link_rpc_client() kernel: acpi: nfit: vmalloc-out-of-bounds Read in acpi_nfit_ctl kernel: bpf: Fix UAF via mismatching bpf_prog/attachment RCU flavors kernel: crypto: pcrypt - Call crypto layer directly when padata_do_parallel() return -EBUSY kernel: af_packet: fix vlan_get_protocol_dgram() vs MSG_PEEK kernel: af_packet: fix vlan_get_tci() vs MSG_PEEK kernel: netfs: Fix the (non-)cancellation of copy when cache is temporarily disabled kernel: netfs: Fix ceph copy to cache on write-begin kernel: memcg: fix soft lockup in the OOM process kernel: usb: xhci: Fix NULL pointer dereference on certain command aborts kernel: xfrm: state: fix out-of-bounds read during lookup kernel: i3c: dw: Fix use-after-free in dw_i3c_master driver due to race condition kernel: HID: core: Fix assumption that Resolution Multipliers must be in Logical Collections kernel: Bluet…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:20095"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ssa-019113</id>
    <title>SSA-019113 — SSA-019113: Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1.6</title>
    <updated>2026-10-02T13:01:17.260178+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).</p>
<p>Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ssa-019113"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:0428-1</id>
    <title>SUSE-SU-2025:0428-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-02T13:01:17.260404+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:0428-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-21655</id>
    <title>UBUNTU-CVE-2025-21655</title>
    <updated>2026-10-02T13:01:17.260586+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 105 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: io_uring/eventfd: ensure io_eventfd_signal() defers another RCU period io_eventfd_do_signal() is invoked from an RCU callback, but when dropping the reference to the io_ev_fd, it calls io_eventfd_free() directly if the refcount drops to zero. This isn't correct, as any potential freeing of the io_ev_fd should be deferred another RCU grace period. Just call io_eventfd_put() rather than open-code the dec-and-test and free, which will correctly defer it another RCU grace period.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-21655"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0132</id>
    <title>WID-SEC-W-2025-0132 — Linux Kernel: Schwachstelle ermöglicht Denial of Service</title>
    <updated>2026-10-02T13:01:17.260721+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann eine Schwachstelle in Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0132"/>
  </entry>
</feed>
