<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T22:05:58.743972+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2025:12662</id>
    <title>ALSA-2025:12662 — Important: kernel security update</title>
    <updated>2026-10-03T22:05:59.369608+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:10: kernel-abi-stablelists, AlmaLinux:10: kernel-doc</p>
<p>The kernel packages contain the Linux kernel, the core of any Linux operating system.</p>
<p>Security Fix(es):</p>
<p>* kernel: padata: fix UAF in padata_reorder (CVE-2025-21727)
  * kernel: HID: intel-ish-hid: Fix use-after-free issue in ishtp_hid_remove() (CVE-2025-21928)
  * kernel: HID: intel-ish-hid: Fix use-after-free issue in hid_ishtp_cl_remove() (CVE-2025-21929)
  * kernel: memstick: rtsx_usb_ms: Fix slab-use-after-free in rtsx_usb_ms_drv_remove (CVE-2025-22020)
  * kernel: ext4: avoid journaling sb update on error if journal is destroying (CVE-2025-22113)
  * kernel: RDMA/core: Fix use-after-free when rename device name (CVE-2025-22085)
  * kernel: net_sched: hfsc: Fix a UAF vulnerability in class with netem as child qdisc (CVE-2025-37890)
  * kernel: net/tipc: fix slab-use-after-free Read in tipc_aead_encrypt_done (CVE-2025-38052)
  * kernel: net: ch9200: fix uninitialised access during mii_nway_restart (CVE-2025-38086)
  * kernel: net/sched: fix use-after-free in taprio_dev_notifier (CVE-2025-38087)
  * kernel: nvme-tcp: sanitize request list handling (CVE-2025-38264)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2025:12662"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-11776</id>
    <title>bdu:2025-11776</title>
    <updated>2026-10-03T22:05:59.369717+00:00</updated>
    <content>bdu:2025-11776</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-11776"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-21928</id>
    <title>BELL-CVE-2025-21928</title>
    <updated>2026-10-03T22:05:59.369736+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-21928"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0333</id>
    <title>certfr-2025-avi-0333 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian. Elles permettent à un attaquant de provo…</title>
    <updated>2026-10-03T22:05:59.369759+00:00</updated>
    <content>certfr-2025-avi-0333</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0333"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-314100</id>
    <title>EUVD-2026-314100</title>
    <updated>2026-10-03T22:05:59.369776+00:00</updated>
    <content>EUVD-2026-314100</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-314100"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-21928</id>
    <title>fkie_cve-2025-21928</title>
    <updated>2026-10-03T22:05:59.369788+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>HID: intel-ish-hid: Fix use-after-free issue in ishtp_hid_remove()</p>
<p>The system can experience a random crash a few minutes after the driver is
removed. This issue occurs due to improper handling of memory freeing in
the ishtp_hid_remove() function.</p>
<p>The function currently frees the `driver_data` directly within the loop
that destroys the HID devices, which can lead to accessing freed memory.
Specifically, `hid_destroy_device()` uses `driver_data` when it calls
`hid_ishtp_set_feature()` to power off the sensor, so freeing
`driver_data` beforehand can result in accessing invalid memory.</p>
<p>This patch resolves the issue by storing the `driver_data` in a temporary
variable before calling `hid_destroy_device()`, and then freeing the
`driver_data` after the device is destroyed.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-21928"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-v2qv-44ch-jx7v</id>
    <title>GHSA-v2qv-44ch-jx7v</title>
    <updated>2026-10-03T22:05:59.369817+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>HID: intel-ish-hid: Fix use-after-free issue in ishtp_hid_remove()</p>
<p>The system can experience a random crash a few minutes after the driver is
removed. This issue occurs due to improper handling of memory freeing in
the ishtp_hid_remove() function.</p>
<p>The function currently frees the `driver_data` directly within the loop
that destroys the HID devices, which can lead to accessing freed memory.
Specifically, `hid_destroy_device()` uses `driver_data` when it calls
`hid_ishtp_set_feature()` to power off the sensor, so freeing
`driver_data` beforehand can result in accessing invalid memory.</p>
<p>This patch resolves the issue by storing the `driver_data` in a temporary
variable before calling `hid_destroy_device()`, and then freeing the
`driver_data` after the device is destroyed.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-v2qv-44ch-jx7v"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-21928</id>
    <title>msrc_CVE-2025-21928 — HID: intel-ish-hid: Fix use-after-free issue in ishtp_hid_remove()</title>
    <updated>2026-10-03T22:05:59.369839+00:00</updated>
    <content>msrc_CVE-2025-21928</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-21928"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-1433</id>
    <title>OESA-2025-1433 — kernel security update</title>
    <updated>2026-10-03T22:05:59.369856+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP3: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>ASoC: atmel: Fix error handling in snd_proto_probe</p>
<p>The device_node pointer is returned by of_parse_phandle()  with refcount
incremented. We should use of_node_put() on it when done.</p>
<p>This function only calls of_node_put() in the regular path.
And it will cause refcount leak in error paths.
Fix this by calling of_node_put() in error handling too.(CVE-2022-49246)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>mt76: fix use-after-free by removing a non-RCU wcid pointer</p>
<p>Fixes an issue caught by KASAN about use-after-free in mt76_txq_schedule
by protecting mtxq-&amp;gt;wcid with rcu_lock between mt76_txq_schedule and
sta_info_[alloc, free].</p>
<p>[18853.876689] ==================================================================
[18853.876751] BUG: KASAN: use-after-free in mt76_txq_schedule+0x204/0xaf8 [mt76]
[18853.876773] Read of size 8 at addr ffffffaf989a2138 by task mt76-tx phy0/883
[18853.876786]
[18853.876810] CPU: 5 PID: 883 Comm: mt76-tx phy0 Not tainted 5.10.100-fix-510-56778d365941-kasan #5 0b01fbbcf41a530f52043508fec2e31a4215</p>
<p>[18853.876840] Call trace:
[18853.876861]  dump_backtrace+0x0/0x3ec
[18853.876878]  show_stack+0x20/0x2c
[18853.876899]  dump_stack+0x11c/0x1ac
[18853.876918]  print_address_description+0x74/0x514
[18853.876934]  kasan_report+0x134/0x174
[18853.876948]  __asan_report_load8_noabort+0x44/0x50…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-1433"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:12662</id>
    <title>RHSA-2025:12662 — Red Hat Security Advisory: kernel security update</title>
    <updated>2026-10-03T22:05:59.369925+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: padata: fix UAF in padata_reorder kernel: HID: intel-ish-hid: Fix use-after-free issue in ishtp_hid_remove() kernel: HID: intel-ish-hid: Fix use-after-free issue in hid_ishtp_cl_remove() kernel: memstick: rtsx_usb_ms: Fix slab-use-after-free in rtsx_usb_ms_drv_remove kernel: RDMA/core: Fix use-after-free when rename device name kernel: ext4: avoid journaling sb update on error if journal is destroying kernel: net_sched: hfsc: Fix a UAF vulnerability in class with netem as child qdisc kernel: net/tipc: fix slab-use-after-free Read in tipc_aead_encrypt_done kernel: net: ch9200: fix uninitialised access during mii_nway_restart kernel: net/sched: fix use-after-free in taprio_dev_notifier kernel: nvme-tcp: sanitize request list handling</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:12662"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:12746</id>
    <title>RHSA-2025:12746 — Red Hat Security Advisory: kernel security update</title>
    <updated>2026-10-03T22:05:59.369963+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: misc/vmw_vmci: fix an infoleak in vmci_host_do_receive_datagram() kernel: padata: avoid UAF for reorder_work kernel: padata: fix UAF in padata_reorder kernel: HID: intel-ish-hid: Fix use-after-free issue in ishtp_hid_remove() kernel: HID: intel-ish-hid: Fix use-after-free issue in hid_ishtp_cl_remove() kernel: cifs: Fix integer overflow while processing closetimeo mount option kernel: memstick: rtsx_usb_ms: Fix slab-use-after-free in rtsx_usb_ms_drv_remove kernel: net_sched: hfsc: Fix a UAF vulnerability in class with netem as child qdisc kernel: net/tipc: fix slab-use-after-free Read in tipc_aead_encrypt_done kernel: net/sched: fix use-after-free in taprio_dev_notifier</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:12746"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:01614-1</id>
    <title>SUSE-SU-2025:01614-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-03T22:05:59.369995+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:01614-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-21928</id>
    <title>UBUNTU-CVE-2025-21928</title>
    <updated>2026-10-03T22:05:59.370112+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:Pro:16.04:LTS: linux-oracle, Ubuntu:Pro:18.04:LTS: linux, Ubuntu:Pro:18.04:LTS: linux-aws, Ubuntu:18.04:LTS: linux-aws-5.0 and 194 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: HID: intel-ish-hid: Fix use-after-free issue in ishtp_hid_remove() The system can experience a random crash a few minutes after the driver is removed. This issue occurs due to improper handling of memory freeing in the ishtp_hid_remove() function. The function currently frees the `driver_data` directly within the loop that destroys the HID devices, which can lead to accessing freed memory. Specifically, `hid_destroy_device()` uses `driver_data` when it calls `hid_ishtp_set_feature()` to power off the sensor, so freeing `driver_data` beforehand can result in accessing invalid memory. This patch resolves the issue by storing the `driver_data` in a temporary variable before calling `hid_destroy_device()`, and then freeing the `driver_data` after the device is destroyed.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-21928"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0683</id>
    <title>WID-SEC-W-2025-0683 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-03T22:05:59.370369+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial-of-Service auszulösen und um nicht näher spezifizierte Auswirkungen zu erzielen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0683"/>
  </entry>
</feed>
