<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T22:24:39.940389+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2025:8643</id>
    <title>ALSA-2025:8643 — Important: kernel security update</title>
    <updated>2026-10-03T22:24:40.351495+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: kernel, AlmaLinux:9: kernel-64k, AlmaLinux:9: kernel-64k-core, AlmaLinux:9: kernel-64k-debug, AlmaLinux:9: kernel-64k-debug-core, AlmaLinux:9: kernel-64k-debug-devel, AlmaLinux:9: kernel-64k-debug-devel-matched, AlmaLinux:9: kernel-64k-debug-modules, AlmaLinux:9: kernel-64k-debug-modules-core, AlmaLinux:9: kernel-64k-debug-modules-extra and 66 more</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: net: gso: fix ownership in __udp_gso_segment (CVE-2025-21926)
  * kernel: vlan: enforce underlying device type (CVE-2025-21920)
  * kernel: xsk: fix an integer overflow in xp_create_and_assign_umem() (CVE-2025-21997)
  * kernel: net: fix geneve_opt length integer overflow (CVE-2025-22055)
  * kernel: ext4: fix OOB read when checking dotdot dir (CVE-2025-37785)
  * kernel: wifi: ath12k: Fix invalid data access in ath12k_dp_rx_h_undecap_nwifi (CVE-2025-37943)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2025:8643"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-11777</id>
    <title>bdu:2025-11777</title>
    <updated>2026-10-03T22:24:40.351664+00:00</updated>
    <content>bdu:2025-11777</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-11777"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-21926</id>
    <title>BELL-CVE-2025-21926</title>
    <updated>2026-10-03T22:24:40.351685+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-21926"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0333</id>
    <title>certfr-2025-avi-0333 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian. Elles permettent à un attaquant de provo…</title>
    <updated>2026-10-03T22:24:40.351708+00:00</updated>
    <content>certfr-2025-avi-0333</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0333"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-364511</id>
    <title>EUVD-2026-364511</title>
    <updated>2026-10-03T22:24:40.351725+00:00</updated>
    <content>EUVD-2026-364511</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-364511"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-21926</id>
    <title>fkie_cve-2025-21926</title>
    <updated>2026-10-03T22:24:40.351737+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>net: gso: fix ownership in __udp_gso_segment</p>
<p>In __udp_gso_segment the skb destructor is removed before segmenting the
skb but the socket reference is kept as-is. This is an issue if the
original skb is later orphaned as we can hit the following bug:</p>
<p>kernel BUG at ./include/linux/skbuff.h:3312!  (skb_orphan)
  RIP: 0010:ip_rcv_core+0x8b2/0xca0
  Call Trace:
   ip_rcv+0xab/0x6e0
   __netif_receive_skb_one_core+0x168/0x1b0
   process_backlog+0x384/0x1100
   __napi_poll.constprop.0+0xa1/0x370
   net_rx_action+0x925/0xe50</p>
<p>The above can happen following a sequence of events when using
OpenVSwitch, when an OVS_ACTION_ATTR_USERSPACE action precedes an
OVS_ACTION_ATTR_OUTPUT action:</p>
<p>1. OVS_ACTION_ATTR_USERSPACE is handled (in do_execute_actions): the skb
   goes through queue_gso_packets and then __udp_gso_segment, where its
   destructor is removed.
2. The segments' data are copied and sent to userspace.
3. OVS_ACTION_ATTR_OUTPUT is handled (in do_execute_actions) and the
   same original skb is sent to its path.
4. If it later hits skb_orphan, we hit the bug.</p>
<p>Fix this by also removing the reference to the socket in
__udp_gso_segment.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-21926"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-jwp5-c35f-qv38</id>
    <title>GHSA-jwp5-c35f-qv38</title>
    <updated>2026-10-03T22:24:40.351772+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>net: gso: fix ownership in __udp_gso_segment</p>
<p>In __udp_gso_segment the skb destructor is removed before segmenting the
skb but the socket reference is kept as-is. This is an issue if the
original skb is later orphaned as we can hit the following bug:</p>
<p>kernel BUG at ./include/linux/skbuff.h:3312!  (skb_orphan)
  RIP: 0010:ip_rcv_core+0x8b2/0xca0
  Call Trace:
   ip_rcv+0xab/0x6e0
   __netif_receive_skb_one_core+0x168/0x1b0
   process_backlog+0x384/0x1100
   __napi_poll.constprop.0+0xa1/0x370
   net_rx_action+0x925/0xe50</p>
<p>The above can happen following a sequence of events when using
OpenVSwitch, when an OVS_ACTION_ATTR_USERSPACE action precedes an
OVS_ACTION_ATTR_OUTPUT action:</p>
<p>1. OVS_ACTION_ATTR_USERSPACE is handled (in do_execute_actions): the skb
   goes through queue_gso_packets and then __udp_gso_segment, where its
   destructor is removed.
2. The segments' data are copied and sent to userspace.
3. OVS_ACTION_ATTR_OUTPUT is handled (in do_execute_actions) and the
   same original skb is sent to its path.
4. If it later hits skb_orphan, we hit the bug.</p>
<p>Fix this by also removing the reference to the socket in
__udp_gso_segment.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-jwp5-c35f-qv38"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-26-209-04</id>
    <title>ICSA-26-209-04 — Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP</title>
    <updated>2026-10-03T22:24:40.351799+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).</p>
<p>Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-26-209-04"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-1874</id>
    <title>OESA-2025-1874 — kernel security update</title>
    <updated>2026-10-03T22:24:40.352025+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>pfifo_tail_enqueue: Drop new packet when sch-&amp;gt;limit == 0</p>
<p>Expected behaviour:
In case we reach scheduler&amp;apos;s limit, pfifo_tail_enqueue() will drop a
packet in scheduler&amp;apos;s queue and decrease scheduler&amp;apos;s qlen by one.
Then, pfifo_tail_enqueue() enqueue new packet and increase
scheduler&amp;apos;s qlen by one. Finally, pfifo_tail_enqueue() return
`NET_XMIT_CN` status code.</p>
<p>Weird behaviour:
In case we set `sch-&amp;gt;limit == 0` and trigger pfifo_tail_enqueue() on a
scheduler that has no packet, the &amp;apos;drop a packet&amp;apos; step will do nothing.
This means the scheduler&amp;apos;s qlen still has value equal 0.
Then, we continue to enqueue new packet and increase scheduler&amp;apos;s qlen by
one. In summary, we can leverage pfifo_tail_enqueue() to increase qlen by
one and return `NET_XMIT_CN` status code.</p>
<p>The problem is:
Let&amp;apos;s say we have two qdiscs: Qdisc_A and Qdisc_B.
 - Qdisc_A&amp;apos;s type must have &amp;apos;-&amp;gt;graft()&amp;apos; function to create parent/child relationship.
   Let&amp;apos;s say Qdisc_A&amp;apos;s type is `hfsc`. Enqueue packet to this qdisc will trigger `hfsc_enqueue`.
 - Qdisc_B&amp;apos;s type is pfifo_head_drop. Enqueue packet to this qdisc will trigger `pfifo_tail_enqueue`.
 - Qdisc_B is configured to have `sch-&amp;gt;limit == 0`.
 - Qdisc_A is configured to route the enqueued&amp;apos;s packet to Qdisc_B.</p>
<p>Enqueue packet through…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-1874"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:8643</id>
    <title>RHSA-2025:8643 — Red Hat Security Advisory: kernel security update</title>
    <updated>2026-10-03T22:24:40.352145+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: vlan: enforce underlying device type kernel: net: gso: fix ownership in __udp_gso_segment kernel: xsk: fix an integer overflow in xp_create_and_assign_umem() kernel: net: fix geneve_opt length integer overflow kernel: ext4: fix OOB read when checking dotdot dir kernel: wifi: ath12k: Fix invalid data access in ath12k_dp_rx_h_undecap_nwifi</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:8643"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:8669</id>
    <title>RHSA-2025:8669 — Red Hat Security Advisory: kernel security update</title>
    <updated>2026-10-03T22:24:40.352175+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: vsock/virtio: discard packets if the transport changes kernel: net: gso: fix ownership in __udp_gso_segment kernel: xsk: fix an integer overflow in xp_create_and_assign_umem() kernel: net: fix geneve_opt length integer overflow kernel: wifi: ath12k: Fix invalid data access in ath12k_dp_rx_h_undecap_nwifi</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:8669"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ssa-019113</id>
    <title>SSA-019113 — SSA-019113: Vulnerabilities in the additional GNU/Linux subsystem of the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1.6</title>
    <updated>2026-10-03T22:24:40.352198+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant).</p>
<p>Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends specific countermeasures for products where fixes are not, or not yet available.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ssa-019113"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:01600-1</id>
    <title>SUSE-SU-2025:01600-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-03T22:24:40.352446+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:01600-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-21926</id>
    <title>UBUNTU-CVE-2025-21926</title>
    <updated>2026-10-03T22:24:40.352521+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:Pro:18.04:LTS: linux-aws-5.4, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:Pro:18.04:LTS: linux-azure-5.4, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3 and 174 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: net: gso: fix ownership in __udp_gso_segment In __udp_gso_segment the skb destructor is removed before segmenting the skb but the socket reference is kept as-is. This is an issue if the original skb is later orphaned as we can hit the following bug:   kernel BUG at ./include/linux/skbuff.h:3312!  (skb_orphan)   RIP: 0010:ip_rcv_core+0x8b2/0xca0   Call Trace:    ip_rcv+0xab/0x6e0    __netif_receive_skb_one_core+0x168/0x1b0    process_backlog+0x384/0x1100    __napi_poll.constprop.0+0xa1/0x370    net_rx_action+0x925/0xe50 The above can happen following a sequence of events when using OpenVSwitch, when an OVS_ACTION_ATTR_USERSPACE action precedes an OVS_ACTION_ATTR_OUTPUT action: 1. OVS_ACTION_ATTR_USERSPACE is handled (in do_execute_actions): the skb    goes through queue_gso_packets and then __udp_gso_segment, where its    destructor is removed. 2. The segments' data are copied and sent to userspace. 3. OVS_ACTION_ATTR_OUTPUT is handled (in do_execute_actions) and the    same original skb is sent to its path. 4. If it later hits skb_orphan, we hit the bug. Fix this by also removing the reference to the socket in __udp_gso_segment.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-21926"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0683</id>
    <title>WID-SEC-W-2025-0683 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-03T22:24:40.352767+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial-of-Service auszulösen und um nicht näher spezifizierte Auswirkungen zu erzielen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0683"/>
  </entry>
</feed>
