<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T04:05:33.759111+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-11853</id>
    <title>bdu:2025-11853</title>
    <updated>2026-10-03T04:05:34.091181+00:00</updated>
    <content>bdu:2025-11853</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-11853"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-21804</id>
    <title>BELL-CVE-2025-21804</title>
    <updated>2026-10-03T04:05:34.091252+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-21804"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0277</id>
    <title>certfr-2025-avi-0277 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian LTS. Elles permettent à un attaquant de p…</title>
    <updated>2026-10-03T04:05:34.091286+00:00</updated>
    <content>certfr-2025-avi-0277</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0277"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-346670</id>
    <title>EUVD-2026-346670</title>
    <updated>2026-10-03T04:05:34.091304+00:00</updated>
    <content>EUVD-2026-346670</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-346670"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-21804</id>
    <title>fkie_cve-2025-21804</title>
    <updated>2026-10-03T04:05:34.091316+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>PCI: rcar-ep: Fix incorrect variable used when calling devm_request_mem_region()</p>
<p>The rcar_pcie_parse_outbound_ranges() uses the devm_request_mem_region()
macro to request a needed resource. A string variable that lives on the
stack is then used to store a dynamically computed resource name, which
is then passed on as one of the macro arguments. This can lead to
undefined behavior.</p>
<p>Depending on the current contents of the memory, the manifestations of
errors may vary. One possible output may be as follows:</p>
<p>$ cat /proc/iomem
  30000000-37ffffff :
  38000000-3fffffff :</p>
<p>Sometimes, garbage may appear after the colon.</p>
<p>In very rare cases, if no NULL-terminator is found in memory, the system
might crash because the string iterator will overrun which can lead to
access of unmapped memory above the stack.</p>
<p>Thus, fix this by replacing outbound_name with the name of the previously
requested resource. With the changes applied, the output will be as
follows:</p>
<p>$ cat /proc/iomem
  30000000-37ffffff : memory2
  38000000-3fffffff : memory3</p>
<p>[kwilczynski: commit log]</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-21804"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-8w2r-337g-j83r</id>
    <title>GHSA-8w2r-337g-j83r</title>
    <updated>2026-10-03T04:05:34.091353+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>PCI: rcar-ep: Fix incorrect variable used when calling devm_request_mem_region()</p>
<p>The rcar_pcie_parse_outbound_ranges() uses the devm_request_mem_region()
macro to request a needed resource. A string variable that lives on the
stack is then used to store a dynamically computed resource name, which
is then passed on as one of the macro arguments. This can lead to
undefined behavior.</p>
<p>Depending on the current contents of the memory, the manifestations of
errors may vary. One possible output may be as follows:</p>
<p>$ cat /proc/iomem
  30000000-37ffffff :
  38000000-3fffffff :</p>
<p>Sometimes, garbage may appear after the colon.</p>
<p>In very rare cases, if no NULL-terminator is found in memory, the system
might crash because the string iterator will overrun which can lead to
access of unmapped memory above the stack.</p>
<p>Thus, fix this by replacing outbound_name with the name of the previously
requested resource. With the changes applied, the output will be as
follows:</p>
<p>$ cat /proc/iomem
  30000000-37ffffff : memory2
  38000000-3fffffff : memory3</p>
<p>[kwilczynski: commit log]</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-8w2r-337g-j83r"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-1339</id>
    <title>OESA-2025-1339 — kernel security update</title>
    <updated>2026-10-03T04:05:34.091380+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>dma-debug: fix a possible deadlock on radix_lock</p>
<p>radix_lock() shouldn&amp;apos;t be held while holding dma_hash_entry[idx].lock
otherwise, there&amp;apos;s a possible deadlock scenario when
dma debug API is called holding rq_lock():</p>
<p>CPU0                   CPU1                       CPU2
dma_free_attrs()
check_unmap()          add_dma_entry()            __schedule() //out
                                                  (A) rq_lock()
get_hash_bucket()
(A) dma_entry_hash
                                                  check_sync()
                       (A) radix_lock()           (W) dma_entry_hash
dma_entry_free()
(W) radix_lock()
                       // CPU2&amp;apos;s one
                       (W) rq_lock()</p>
<p>CPU1 situation can happen when it extending radix tree and
it tries to wake up kswapd via wake_all_kswapd().</p>
<p>CPU2 situation can happen while perf_event_task_sched_out()
(i.e. dma sync operation is called while deleting perf_event using
 etm and etr tmc which are Arm Coresight hwtracing driver backends).</p>
<p>To remove this possible situation, call dma_entry_free() after
put_hash_bucket() in check_unmap().(CVE-2024-47143)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>dlm: fix possible lkb_resource null dereference</p>
<p>This patch fixes a possible null pointer dereference when this function is
called from request_lock(…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-1339"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:01919-1</id>
    <title>SUSE-SU-2025:01919-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-03T04:05:34.091692+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:01919-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-21804</id>
    <title>UBUNTU-CVE-2025-21804</title>
    <updated>2026-10-03T04:05:34.091946+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 144 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: PCI: rcar-ep: Fix incorrect variable used when calling devm_request_mem_region() The rcar_pcie_parse_outbound_ranges() uses the devm_request_mem_region() macro to request a needed resource. A string variable that lives on the stack is then used to store a dynamically computed resource name, which is then passed on as one of the macro arguments. This can lead to undefined behavior. Depending on the current contents of the memory, the manifestations of errors may vary. One possible output may be as follows:   $ cat /proc/iomem   30000000-37ffffff :   38000000-3fffffff : Sometimes, garbage may appear after the colon. In very rare cases, if no NULL-terminator is found in memory, the system might crash because the string iterator will overrun which can lead to access of unmapped memory above the stack. Thus, fix this by replacing outbound_name with the name of the previously requested resource. With the changes applied, the output will be as follows:   $ cat /proc/iomem   30000000-37ffffff : memory2   38000000-3fffffff : memory3 [kwilczynski: commit log]</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-21804"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0461</id>
    <title>WID-SEC-W-2025-0461 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-03T04:05:34.092150+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen und um nicht näher spezifizierte Auswirkungen zu erzielen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0461"/>
  </entry>
</feed>
