<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T15:52:17.117521+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2025:20095</id>
    <title>ALSA-2025:20095 — Moderate: kernel security update</title>
    <updated>2026-10-02T15:52:17.255862+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:10: kernel, AlmaLinux:10: kernel-64k, AlmaLinux:10: kernel-64k-core, AlmaLinux:10: kernel-64k-debug, AlmaLinux:10: kernel-64k-debug-core, AlmaLinux:10: kernel-64k-debug-devel, AlmaLinux:10: kernel-64k-debug-devel-matched, AlmaLinux:10: kernel-64k-debug-modules, AlmaLinux:10: kernel-64k-debug-modules-core, AlmaLinux:10: kernel-64k-debug-modules-extra and 65 more</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: xen: Xen hypercall page unsafe against speculative attacks (Xen Security Advisory 466) (CVE-2024-53241)
  * kernel: exfat: fix out-of-bounds access of directory entries (CVE-2024-53147)
  * kernel: zram: fix NULL pointer in comp_algorithm_show() (CVE-2024-53222)
  * kernel: nfsd: release svc_expkey/svc_export with rcu_work (CVE-2024-53216)
  * kernel: acpi: nfit: vmalloc-out-of-bounds Read in acpi_nfit_ctl (CVE-2024-56662)
  * kernel: bpf: Fix UAF via mismatching bpf_prog/attachment RCU flavors (CVE-2024-56675)
  * kernel: crypto: pcrypt - Call crypto layer directly when padata_do_parallel() return -EBUSY (CVE-2024-56690)
  * kernel: igb: Fix potential invalid memory access in igb_init_module() (CVE-2024-52332)
  * kernel: af_packet: fix vlan_get_protocol_dgram() vs MSG_PEEK (CVE-2024-57901)
  * kernel: af_packet: fix vlan_get_tci() vs MSG_PEEK (CVE-2024-57902)
  * kernel: io_uring/sqpoll: zero sqd-&gt;thread on tctx errors (CVE-2025-21633)
  * kernel: ipvlan: Fix use-after-free in ipvlan_get_iflink(). (CVE-2025-21652)
  * kernel: sched: sch_cake: add bounds checks to host bulk flow fairness counts (CVE-2025-21647)
  * kernel: io_uring/eventfd: ensure io_eventfd_signal() defers another RCU period (CVE-2025-21655)
  * kernel: netfs: Fix the (non-)cancellation of copy when cache is temporarily disabled (CVE-2024-57941)
  * kernel: netfs: Fix ceph copy to cache…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2025:20095"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-01800</id>
    <title>bdu:2025-01800</title>
    <updated>2026-10-02T15:52:17.256153+00:00</updated>
    <content>bdu:2025-01800</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-01800"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-21691</id>
    <title>BELL-CVE-2025-21691</title>
    <updated>2026-10-02T15:52:17.256180+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-21691"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0349</id>
    <title>certfr-2025-avi-0349 — De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Certaines d'entre elles permettent à un a…</title>
    <updated>2026-10-02T15:52:17.256210+00:00</updated>
    <content>certfr-2025-avi-0349</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0349"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/essa-2026:0153</id>
    <title>ESSA-2026:0153 — Important: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-02T15:52:17.256239+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Important: kernel security, bug fix, and enhancement update</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/essa-2026:0153"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-314010</id>
    <title>EUVD-2026-314010</title>
    <updated>2026-10-02T15:52:17.256282+00:00</updated>
    <content>EUVD-2026-314010</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-314010"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-21691</id>
    <title>fkie_cve-2025-21691</title>
    <updated>2026-10-02T15:52:17.256299+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>cachestat: fix page cache statistics permission checking</p>
<p>When the 'cachestat()' system call was added in commit cf264e1329fb
("cachestat: implement cachestat syscall"), it was meant to be a much
more convenient (and performant) version of mincore() that didn't need
mapping things into the user virtual address space in order to work.</p>
<p>But it ended up missing the "check for writability or ownership" fix for
mincore(), done in commit 134fca9063ad ("mm/mincore.c: make mincore()
more conservative").</p>
<p>This just adds equivalent logic to 'cachestat()', modified for the file
context (rather than vma).</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-21691"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3m25-8xh3-c6p2</id>
    <title>GHSA-3m25-8xh3-c6p2</title>
    <updated>2026-10-02T15:52:17.256342+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>cachestat: fix page cache statistics permission checking</p>
<p>When the 'cachestat()' system call was added in commit cf264e1329fb
("cachestat: implement cachestat syscall"), it was meant to be a much
more convenient (and performant) version of mincore() that didn't need
mapping things into the user virtual address space in order to work.</p>
<p>But it ended up missing the "check for writability or ownership" fix for
mincore(), done in commit 134fca9063ad ("mm/mincore.c: make mincore()
more conservative").</p>
<p>This just adds equivalent logic to 'cachestat()', modified for the file
context (rather than vma).</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3m25-8xh3-c6p2"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-1371</id>
    <title>OESA-2025-1371 — kernel security update</title>
    <updated>2026-10-02T15:52:17.256375+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>fs: relax assertions on failure to encode file handles</p>
<p>Encoding file handles is usually performed by a filesystem &amp;gt;encode_fh()
method that may fail for various reasons.</p>
<p>The legacy users of exportfs_encode_fh(), namely, nfsd and
name_to_handle_at(2) syscall are ready to cope with the possibility
of failure to encode a file handle.</p>
<p>There are a few other users of exportfs_encode_{fh,fid}() that
currently have a WARN_ON() assertion when -&amp;gt;encode_fh() fails.
Relax those assertions because they are wrong.</p>
<p>The second linked bug report states commit 16aac5ad1fa9 (&amp;quot;ovl: support
encoding non-decodable file handles&amp;quot;) in v6.6 as the regressing commit,
but this is not accurate.</p>
<p>The aforementioned commit only increases the chances of the assertion
and allows triggering the assertion with the reproducer using overlayfs,
inotify and drop_caches.</p>
<p>Triggering this assertion was always possible with other filesystems and
other reasons of -&amp;gt;encode_fh() failures and more particularly, it was
also possible with the exact same reproducer using overlayfs that is
mounted with options index=on,nfs_export=on also on kernels &amp;lt; v6.6.
Therefore, I am not listing the aforementioned commit as a Fixes commit.</p>
<p>Backport hint: this patch will have a trivial conflict applying to
v6.6.y, and other trivial conflicts applying to stable kernels &amp;l…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-1371"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:34094</id>
    <title>RHSA-2026:34094 — Red Hat Security Advisory: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-02T15:52:17.256694+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: netfilter: conntrack: clamp maximum hashtable size to INT_MAX kernel: cachestat: fix page cache statistics permission checking kernel: ALSA: aloop: Fix racy access at PCM trigger kernel: mptcp: fix slab-use-after-free in __inet_lookup_established kernel: netfilter: nf_conntrack_helper: pass helper to expect cleanup kernel: dlm: validate length in dlm_search_rsb_tree kernel: RDMA/umem: Fix double dma_buf_unpin in failure path kernel: tcp: fix potential race in tcp_v6_syn_recv_sock() kernel: netfilter: flowtable: strictly check for maximum number of actions kernel: scsi: qla2xxx: Completely fix fcport double free kernel: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows kernel: RDMA/rxe: Fix double free in rxe_srq_from_init kernel: ALSA: aloop: Fix peer runtime UAF during format-change stop kernel: exit: prevent preemption of oopsing TASK_DEAD task kernel: RDMA/mlx5: Fix error path fall-through in mlx5_ib_dev_res_srq_init() kernel: RDMA/mlx4: Fix mis-use of RCU in mlx4_srq_event() kernel: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL kernel: netfilter: nft_inner: Fix IPv6 inner_thoff desync</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:34094"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-21691</id>
    <title>UBUNTU-CVE-2025-21691</title>
    <updated>2026-10-02T15:52:17.256758+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 106 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: cachestat: fix page cache statistics permission checking When the 'cachestat()' system call was added in commit cf264e1329fb ("cachestat: implement cachestat syscall"), it was meant to be a much more convenient (and performant) version of mincore() that didn't need mapping things into the user virtual address space in order to work. But it ended up missing the "check for writability or ownership" fix for mincore(), done in commit 134fca9063ad ("mm/mincore.c: make mincore() more conservative"). This just adds equivalent logic to 'cachestat()', modified for the file context (rather than vma).</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-21691"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0309</id>
    <title>WID-SEC-W-2025-0309 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-02T15:52:17.256997+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen und um seine Privilegien zu eskalieren.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0309"/>
  </entry>
</feed>
