<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T00:06:50.090404+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-12306</id>
    <title>bdu:2025-12306</title>
    <updated>2026-10-04T00:06:50.248719+00:00</updated>
    <content>bdu:2025-12306</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-12306"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-23158</id>
    <title>BELL-CVE-2025-23158</title>
    <updated>2026-10-04T00:06:50.248783+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-23158"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0463</id>
    <title>certfr-2025-avi-0463 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian LTS. Elles permettent à un attaquant de p…</title>
    <updated>2026-10-04T00:06:50.248819+00:00</updated>
    <content>certfr-2025-avi-0463</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0463"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-346797</id>
    <title>EUVD-2026-346797</title>
    <updated>2026-10-04T00:06:50.248843+00:00</updated>
    <content>EUVD-2026-346797</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-346797"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-23158</id>
    <title>fkie_cve-2025-23158</title>
    <updated>2026-10-04T00:06:50.248856+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>media: venus: hfi: add check to handle incorrect queue size</p>
<p>qsize represents size of shared queued between driver and video
firmware. Firmware can modify this value to an invalid large value. In
such situation, empty_space will be bigger than the space actually
available. Since new_wr_idx is not checked, so the following code will
result in an OOB write.
...
qsize = qhdr-&gt;q_size</p>
<p>if (wr_idx &gt;= rd_idx)
 empty_space = qsize - (wr_idx - rd_idx)
....
if (new_wr_idx &lt; qsize) {
 memcpy(wr_ptr, packet, dwords &lt;&lt; 2) --&gt; OOB write</p>
<p>Add check to ensure qsize is within the allocated size while
reading and writing packets into the queue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-23158"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-f6mg-77cc-c9pm</id>
    <title>GHSA-f6mg-77cc-c9pm</title>
    <updated>2026-10-04T00:06:50.248890+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>media: venus: hfi: add check to handle incorrect queue size</p>
<p>qsize represents size of shared queued between driver and video
firmware. Firmware can modify this value to an invalid large value. In
such situation, empty_space will be bigger than the space actually
available. Since new_wr_idx is not checked, so the following code will
result in an OOB write.
...
qsize = qhdr-&gt;q_size</p>
<p>if (wr_idx &gt;= rd_idx)
 empty_space = qsize - (wr_idx - rd_idx)
....
if (new_wr_idx &lt; qsize) {
 memcpy(wr_ptr, packet, dwords &lt;&lt; 2) --&gt; OOB write</p>
<p>Add check to ensure qsize is within the allocated size while
reading and writing packets into the queue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-f6mg-77cc-c9pm"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-23158</id>
    <title>msrc_CVE-2025-23158 — media: venus: hfi: add check to handle incorrect queue size</title>
    <updated>2026-10-04T00:06:50.248912+00:00</updated>
    <content>msrc_CVE-2025-23158</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-23158"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-2800</id>
    <title>OESA-2025-2800 — kernel security update</title>
    <updated>2026-10-04T00:06:50.248929+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP3: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>ext4: update s_journal_inum if it changes after journal replay</p>
<p>When mounting a crafted ext4 image, s_journal_inum may change after journal
replay, which is obviously unreasonable because we have successfully loaded
and replayed the journal through the old s_journal_inum. And the new
s_journal_inum bypasses some of the checks in ext4_get_journal(), which
may trigger a null pointer dereference problem. So if s_journal_inum
changes after the journal replay, we ignore the change, and rewrite the
current journal_inum to the superblock.(CVE-2023-53091)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>vxlan: Fix nexthop hash size</p>
<p>The nexthop code expects a 31 bit hash, such as what is returned by
fib_multipath_hash() and rt6_multipath_hash(). Passing the 32 bit hash
returned by skb_get_hash() can lead to problems related to the fact that
&amp;apos;int hash&amp;apos; is a negative number when the MSB is set.</p>
<p>In the case of hash threshold nexthop groups, nexthop_select_path_hthr()
will disproportionately select the first nexthop group entry. In the case
of resilient nexthop groups, nexthop_select_path_res() may do an out of
bounds access in nh_buckets[], for example:
    hash = -912054133
    num_nh_buckets = 2
    bucket_index = 65535</p>
<p>which leads to the following panic:</p>
<p>BUG: unable to handle page fault for address: ffffc9000…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-2800"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:01964-1</id>
    <title>SUSE-SU-2025:01964-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-04T00:06:50.249194+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:01964-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-23158</id>
    <title>UBUNTU-CVE-2025-23158</title>
    <updated>2026-10-04T00:06:50.249396+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:16.04:LTS: linux-hwe-edge, Ubuntu:Pro:16.04:LTS: linux-oracle, Ubuntu:Pro:18.04:LTS: linux, Ubuntu:Pro:18.04:LTS: linux-aws, Ubuntu:18.04:LTS: linux-aws-5.0 and 198 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: media: venus: hfi: add check to handle incorrect queue size qsize represents size of shared queued between driver and video firmware. Firmware can modify this value to an invalid large value. In such situation, empty_space will be bigger than the space actually available. Since new_wr_idx is not checked, so the following code will result in an OOB write. ... qsize = qhdr-&gt;q_size if (wr_idx &gt;= rd_idx)  empty_space = qsize - (wr_idx - rd_idx) .... if (new_wr_idx &lt; qsize) {  memcpy(wr_ptr, packet, dwords &lt;&lt; 2) --&gt; OOB write Add check to ensure qsize is within the allocated size while reading and writing packets into the queue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-23158"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0922</id>
    <title>WID-SEC-W-2025-0922 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-04T00:06:50.249659+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial of Service Angriff und nicht näher spezifizierte Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0922"/>
  </entry>
</feed>
