<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T10:20:41.468184+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-11783</id>
    <title>bdu:2025-11783</title>
    <updated>2026-10-03T10:20:41.653673+00:00</updated>
    <content>bdu:2025-11783</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-11783"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-22014</id>
    <title>BELL-CVE-2025-22014</title>
    <updated>2026-10-03T10:20:41.653745+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-22014"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0333</id>
    <title>certfr-2025-avi-0333 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian. Elles permettent à un attaquant de provo…</title>
    <updated>2026-10-03T10:20:41.653811+00:00</updated>
    <content>certfr-2025-avi-0333</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0333"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-314150</id>
    <title>EUVD-2026-314150</title>
    <updated>2026-10-03T10:20:41.653842+00:00</updated>
    <content>EUVD-2026-314150</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-314150"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-22014</id>
    <title>fkie_cve-2025-22014</title>
    <updated>2026-10-03T10:20:41.653900+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>soc: qcom: pdr: Fix the potential deadlock</p>
<p>When some client process A call pdr_add_lookup() to add the look up for
the service and does schedule locator work, later a process B got a new
server packet indicating locator is up and call pdr_locator_new_server()
which eventually sets pdr-&gt;locator_init_complete to true which process A
sees and takes list lock and queries domain list but it will timeout due
to deadlock as the response will queued to the same qmi-&gt;wq and it is
ordered workqueue and process B is not able to complete new server
request work due to deadlock on list lock.</p>
<p>Fix it by removing the unnecessary list iteration as the list iteration
is already being done inside locator work, so avoid it here and just
call schedule_work() here.</p>
<p>Process A                        Process B</p>
<p>process_scheduled_works()
pdr_add_lookup()                      qmi_data_ready_work()
 process_scheduled_works()             pdr_locator_new_server()
                                         pdr-&gt;locator_init_complete=true;
   pdr_locator_work()
    mutex_lock(&amp;pdr-&gt;list_lock);</p>
<p>pdr_locate_service()                  mutex_lock(&amp;pdr-&gt;list_lock);</p>
<p>pdr_get_domain_list()
       pr_err("PDR: %s get domain list
               txn wait failed: %d\n",
               req-&gt;service_name,
               ret);</p>
<p>Timeout error log due to deadlock:</p>
<p>"
 PDR: tms/servreg get domain lis…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-22014"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-93xm-x65x-hgxh</id>
    <title>GHSA-93xm-x65x-hgxh</title>
    <updated>2026-10-03T10:20:41.653994+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>soc: qcom: pdr: Fix the potential deadlock</p>
<p>When some client process A call pdr_add_lookup() to add the look up for
the service and does schedule locator work, later a process B got a new
server packet indicating locator is up and call pdr_locator_new_server()
which eventually sets pdr-&gt;locator_init_complete to true which process A
sees and takes list lock and queries domain list but it will timeout due
to deadlock as the response will queued to the same qmi-&gt;wq and it is
ordered workqueue and process B is not able to complete new server
request work due to deadlock on list lock.</p>
<p>Fix it by removing the unnecessary list iteration as the list iteration
is already being done inside locator work, so avoid it here and just
call schedule_work() here.</p>
<p>Process A                        Process B</p>
<p>process_scheduled_works()
pdr_add_lookup()                      qmi_data_ready_work()
 process_scheduled_works()             pdr_locator_new_server()
                                         pdr-&gt;locator_init_complete=true;
   pdr_locator_work()
    mutex_lock(&amp;pdr-&gt;list_lock);</p>
<p>pdr_locate_service()                  mutex_lock(&amp;pdr-&gt;list_lock);</p>
<p>pdr_get_domain_list()
       pr_err("PDR: %s get domain list
               txn wait failed: %d\n",
               req-&gt;service_name,
               ret);</p>
<p>Timeout error log due to deadlock:</p>
<p>"
 PDR: tms/servreg get domain lis…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-93xm-x65x-hgxh"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-22014</id>
    <title>msrc_CVE-2025-22014 — soc: qcom: pdr: Fix the potential deadlock</title>
    <updated>2026-10-03T10:20:41.654032+00:00</updated>
    <content>msrc_CVE-2025-22014</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-22014"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-1463</id>
    <title>OESA-2025-1463 — kernel security update</title>
    <updated>2026-10-03T10:20:41.654051+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>PCI/ASPM: Fix link state exit during switch upstream function removal</p>
<p>Before 456d8aa37d0f (&amp;quot;PCI/ASPM: Disable ASPM on MFD function removal to
avoid use-after-free&amp;quot;), we would free the ASPM link only after the last
function on the bus pertaining to the given link was removed.</p>
<p>That was too late. If function 0 is removed before sibling function,
link-&amp;gt;downstream would point to free&amp;apos;d memory after.</p>
<p>After above change, we freed the ASPM parent link state upon any function
removal on the bus pertaining to a given link.</p>
<p>That is too early. If the link is to a PCIe switch with MFD on the upstream
port, then removing functions other than 0 first would free a link which
still remains parent_link to the remaining downstream ports.</p>
<p>The resulting GPFs are especially frequent during hot-unplug, because
pciehp removes devices on the link bus in reverse order.</p>
<p>On that switch, function 0 is the virtual P2P bridge to the internal bus.
Free exactly when function 0 is removed -- before the parent link is
obsolete, but after all subordinate links are gone.</p>
<p>[kwilczynski: commit log](CVE-2024-58093)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>jfs: add check read-only before truncation in jfs_truncate_nolock()</p>
<p>Added a check for &amp;quot;read-only&amp;quot; mode in the `jfs_truncate_nolock`
function to avoid errors…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-1463"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:01614-1</id>
    <title>SUSE-SU-2025:01614-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-03T10:20:41.654179+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:01614-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-22014</id>
    <title>UBUNTU-CVE-2025-22014</title>
    <updated>2026-10-03T10:20:41.654318+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:18.04:LTS: linux-aws-5.0, Ubuntu:18.04:LTS: linux-aws-5.3, Ubuntu:18.04:LTS: linux-azure, Ubuntu:18.04:LTS: linux-azure-5.3, Ubuntu:18.04:LTS: linux-azure-edge, Ubuntu:18.04:LTS: linux-gcp, Ubuntu:18.04:LTS: linux-gcp-5.3, Ubuntu:18.04:LTS: linux-gke-4.15, Ubuntu:18.04:LTS: linux-gke-5.4 and 148 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: soc: qcom: pdr: Fix the potential deadlock When some client process A call pdr_add_lookup() to add the look up for the service and does schedule locator work, later a process B got a new server packet indicating locator is up and call pdr_locator_new_server() which eventually sets pdr-&gt;locator_init_complete to true which process A sees and takes list lock and queries domain list but it will timeout due to deadlock as the response will queued to the same qmi-&gt;wq and it is ordered workqueue and process B is not able to complete new server request work due to deadlock on list lock. Fix it by removing the unnecessary list iteration as the list iteration is already being done inside locator work, so avoid it here and just call schedule_work() here.        Process A                        Process B                                      process_scheduled_works() pdr_add_lookup()                      qmi_data_ready_work()  process_scheduled_works()             pdr_locator_new_server()                                          pdr-&gt;locator_init_complete=true;    pdr_locator_work()     mutex_lock(&amp;pdr-&gt;list_lock);      pdr_locate_service()                  mutex_lock(&amp;pdr-&gt;list_lock);       pdr_get_domain_list()        pr_err("PDR: %s get domain list                txn wait failed: %d\n",                req-&gt;service_name,                ret); Timeout error log due to deadlock: "  PDR: tms/servreg get domain list txn wai…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-22014"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0732</id>
    <title>WID-SEC-W-2025-0732 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-03T10:20:41.654545+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen im Linux-Kernel ausnutzen, um einen Denial-of-Service-Zustand zu erzeugen oder nicht spezifizierte Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0732"/>
  </entry>
</feed>
