<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T12:15:12.624330+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-05643</id>
    <title>bdu:2025-05643</title>
    <updated>2026-10-04T12:15:12.782460+00:00</updated>
    <content>bdu:2025-05643</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-05643"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-21923</id>
    <title>BELL-CVE-2025-21923</title>
    <updated>2026-10-04T12:15:12.782547+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:25: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-21923"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0449</id>
    <title>certfr-2025-avi-0449 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un at…</title>
    <updated>2026-10-04T12:15:12.782589+00:00</updated>
    <content>certfr-2025-avi-0449</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0449"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-346710</id>
    <title>EUVD-2026-346710</title>
    <updated>2026-10-04T12:15:12.782616+00:00</updated>
    <content>EUVD-2026-346710</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-346710"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-21923</id>
    <title>fkie_cve-2025-21923</title>
    <updated>2026-10-04T12:15:12.782637+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>HID: hid-steam: Fix use-after-free when detaching device</p>
<p>When a hid-steam device is removed it must clean up the client_hdev used for
intercepting hidraw access. This can lead to scheduling deferred work to
reattach the input device. Though the cleanup cancels the deferred work, this
was done before the client_hdev itself is cleaned up, so it gets rescheduled.
This patch fixes the ordering to make sure the deferred work is properly
canceled.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-21923"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-5f2m-5gjf-8mqg</id>
    <title>GHSA-5f2m-5gjf-8mqg</title>
    <updated>2026-10-04T12:15:12.782686+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>HID: hid-steam: Fix use-after-free when detaching device</p>
<p>When a hid-steam device is removed it must clean up the client_hdev used for
intercepting hidraw access. This can lead to scheduling deferred work to
reattach the input device. Though the cleanup cancels the deferred work, this
was done before the client_hdev itself is cleaned up, so it gets rescheduled.
This patch fixes the ordering to make sure the deferred work is properly
canceled.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-5f2m-5gjf-8mqg"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-21923</id>
    <title>msrc_CVE-2025-21923 — HID: hid-steam: Fix use-after-free when detaching device</title>
    <updated>2026-10-04T12:15:12.782717+00:00</updated>
    <content>msrc_CVE-2025-21923</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-21923"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-1446</id>
    <title>OESA-2025-1446 — kernel security update</title>
    <updated>2026-10-04T12:15:12.782751+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP1: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>ntb_hw_switchtec: Fix shift-out-of-bounds in switchtec_ntb_mw_set_trans</p>
<p>There is a kernel API ntb_mw_clear_trans() would pass 0 to both addr and
size. This would make xlate_pos negative.</p>
<p>[   23.734156] switchtec switchtec0: MW 0: part 0 addr 0x0000000000000000 size 0x0000000000000000
[   23.734158] ================================================================================
[   23.734172] UBSAN: shift-out-of-bounds in drivers/ntb/hw/mscc/ntb_hw_switchtec.c:293:7
[   23.734418] shift exponent -1 is negative</p>
<p>Ensuring xlate_pos is a positive or zero before BIT.(CVE-2023-53034)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>drm/msm/gem: prevent integer overflow in msm_ioctl_gem_submit()</p>
<p>The &amp;quot;submit-&amp;gt;cmd[i].size&amp;quot; and &amp;quot;submit-&amp;gt;cmd[i].offset&amp;quot; variables are u32
values that come from the user via the submit_lookup_cmds() function.
This addition could lead to an integer wrapping bug so use size_add()
to prevent that.</p>
<p>Patchwork: https://patchwork.freedesktop.org/patch/624696/(CVE-2024-52559)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>fs/ntfs3: Mark inode as bad as soon as error detected in mi_enum_attr()</p>
<p>Extended the `mi_enum_attr()` function interface with an additional
parameter, `struct ntfs_inode *ni`, to allow marking the inode
as bad as soon as an error i…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-1446"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:01614-1</id>
    <title>SUSE-SU-2025:01614-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-04T12:15:12.783573+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:01614-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-21923</id>
    <title>UBUNTU-CVE-2025-21923</title>
    <updated>2026-10-04T12:15:12.783695+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 76 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: HID: hid-steam: Fix use-after-free when detaching device When a hid-steam device is removed it must clean up the client_hdev used for intercepting hidraw access. This can lead to scheduling deferred work to reattach the input device. Though the cleanup cancels the deferred work, this was done before the client_hdev itself is cleaned up, so it gets rescheduled. This patch fixes the ordering to make sure the deferred work is properly canceled.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-21923"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0683</id>
    <title>WID-SEC-W-2025-0683 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-04T12:15:12.783822+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial-of-Service auszulösen und um nicht näher spezifizierte Auswirkungen zu erzielen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0683"/>
  </entry>
</feed>
