<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T17:49:22.079038+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-02204</id>
    <title>bdu:2025-02204</title>
    <updated>2026-10-02T17:49:22.723275+00:00</updated>
    <content>bdu:2025-02204</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-02204"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-21703</id>
    <title>BELL-CVE-2025-21703</title>
    <updated>2026-10-02T17:49:22.723347+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-21703"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0277</id>
    <title>certfr-2025-avi-0277 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian LTS. Elles permettent à un attaquant de p…</title>
    <updated>2026-10-02T17:49:22.723409+00:00</updated>
    <content>certfr-2025-avi-0277</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0277"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-346635</id>
    <title>EUVD-2026-346635</title>
    <updated>2026-10-02T17:49:22.723429+00:00</updated>
    <content>EUVD-2026-346635</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-346635"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-21703</id>
    <title>fkie_cve-2025-21703</title>
    <updated>2026-10-02T17:49:22.723441+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>netem: Update sch-&gt;q.qlen before qdisc_tree_reduce_backlog()</p>
<p>qdisc_tree_reduce_backlog() notifies parent qdisc only if child
qdisc becomes empty, therefore we need to reduce the backlog of the
child qdisc before calling it. Otherwise it would miss the opportunity
to call cops-&gt;qlen_notify(), in the case of DRR, it resulted in UAF
since DRR uses -&gt;qlen_notify() to maintain its active list.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-21703"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-cg86-m5xc-jqrm</id>
    <title>GHSA-cg86-m5xc-jqrm</title>
    <updated>2026-10-02T17:49:22.723472+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>netem: Update sch-&gt;q.qlen before qdisc_tree_reduce_backlog()</p>
<p>qdisc_tree_reduce_backlog() notifies parent qdisc only if child
qdisc becomes empty, therefore we need to reduce the backlog of the
child qdisc before calling it. Otherwise it would miss the opportunity
to call cops-&gt;qlen_notify(), in the case of DRR, it resulted in UAF
since DRR uses -&gt;qlen_notify() to maintain its active list.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-cg86-m5xc-jqrm"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-25-072-03</id>
    <title>ICSA-25-072-03 — Siemens SIMATIC S7-1500 TM MFP</title>
    <updated>2026-10-02T17:49:22.723491+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In the Linux kernel, the following vulnerability has been resolved:
Squashfs: check the inode number is not the invalid value of zero In the Linux kernel, the following vulnerability has been resolved: net: ethernet: lantiq_etop: fix double free in detach The number of the currently released descriptor is never incremented which results in the same skb being released multiple times. In the Linux kernel, the following vulnerability has been resolved: filelock: fix potential use-after-free in posix_lock_inode Light Hsieh reported a KASAN UAF warning in trace_posix_lock_inode(). The request pointer had been changed earlier to point to a lock entry that was added to the inode's list. However, before the tracepoint could fire, another task raced in and freed that lock. Fix this by moving the tracepoint inside the spinlock, which should ensure that this doesn't happen. In the Linux kernel, the following vulnerability has been resolved: mm: prevent derefencing NULL ptr in pfn_section_valid() Commit 5ec8e8ea8b77 ("mm/sparsemem: fix race in accessing memory_section-&gt;usage") changed pfn_section_valid() to add a READ_ONCE() call around "ms-&gt;usage" to fix a race with section_deactivate() where ms-&gt;usage can be cleared. The READ_ONCE() call, by itself, is not enough to prevent NULL pointer dereference. We need to check its value before dereferencing it. In the Linux kernel, the following vulnerability has been resolved: tcp_metrics: validate source addr length I don't see anything check…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-25-072-03"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-21703</id>
    <title>msrc_CVE-2025-21703 — netem: Update sch-&gt;q.qlen before qdisc_tree_reduce_backlog()</title>
    <updated>2026-10-02T17:49:22.723552+00:00</updated>
    <content>msrc_CVE-2025-21703</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-21703"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-1874</id>
    <title>OESA-2025-1874 — kernel security update</title>
    <updated>2026-10-02T17:49:22.723569+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>pfifo_tail_enqueue: Drop new packet when sch-&amp;gt;limit == 0</p>
<p>Expected behaviour:
In case we reach scheduler&amp;apos;s limit, pfifo_tail_enqueue() will drop a
packet in scheduler&amp;apos;s queue and decrease scheduler&amp;apos;s qlen by one.
Then, pfifo_tail_enqueue() enqueue new packet and increase
scheduler&amp;apos;s qlen by one. Finally, pfifo_tail_enqueue() return
`NET_XMIT_CN` status code.</p>
<p>Weird behaviour:
In case we set `sch-&amp;gt;limit == 0` and trigger pfifo_tail_enqueue() on a
scheduler that has no packet, the &amp;apos;drop a packet&amp;apos; step will do nothing.
This means the scheduler&amp;apos;s qlen still has value equal 0.
Then, we continue to enqueue new packet and increase scheduler&amp;apos;s qlen by
one. In summary, we can leverage pfifo_tail_enqueue() to increase qlen by
one and return `NET_XMIT_CN` status code.</p>
<p>The problem is:
Let&amp;apos;s say we have two qdiscs: Qdisc_A and Qdisc_B.
 - Qdisc_A&amp;apos;s type must have &amp;apos;-&amp;gt;graft()&amp;apos; function to create parent/child relationship.
   Let&amp;apos;s say Qdisc_A&amp;apos;s type is `hfsc`. Enqueue packet to this qdisc will trigger `hfsc_enqueue`.
 - Qdisc_B&amp;apos;s type is pfifo_head_drop. Enqueue packet to this qdisc will trigger `pfifo_tail_enqueue`.
 - Qdisc_B is configured to have `sch-&amp;gt;limit == 0`.
 - Qdisc_A is configured to route the enqueued&amp;apos;s packet to Qdisc_B.</p>
<p>Enqueue packet through…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-1874"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:01919-1</id>
    <title>SUSE-SU-2025:01919-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-02T17:49:22.723687+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:01919-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-21703</id>
    <title>UBUNTU-CVE-2025-21703</title>
    <updated>2026-10-02T17:49:22.723943+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:Pro:18.04:LTS: linux-aws-5.4, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:Pro:18.04:LTS: linux-azure-5.4, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3 and 123 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: netem: Update sch-&gt;q.qlen before qdisc_tree_reduce_backlog() qdisc_tree_reduce_backlog() notifies parent qdisc only if child qdisc becomes empty, therefore we need to reduce the backlog of the child qdisc before calling it. Otherwise it would miss the opportunity to call cops-&gt;qlen_notify(), in the case of DRR, it resulted in UAF since DRR uses -&gt;qlen_notify() to maintain its active list.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-21703"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0411</id>
    <title>WID-SEC-W-2025-0411 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-02T17:49:22.724105+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um Dateien zu manipulieren oder seine Rechte zu erweitern.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0411"/>
  </entry>
</feed>
