<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T21:26:45.047372+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-12343</id>
    <title>bdu:2025-12343</title>
    <updated>2026-10-04T21:26:45.631586+00:00</updated>
    <content>bdu:2025-12343</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-12343"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-37741</id>
    <title>BELL-CVE-2025-37741</title>
    <updated>2026-10-04T21:26:45.631654+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-37741"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0463</id>
    <title>certfr-2025-avi-0463 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian LTS. Elles permettent à un attaquant de p…</title>
    <updated>2026-10-04T21:26:45.631703+00:00</updated>
    <content>certfr-2025-avi-0463</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0463"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-346800</id>
    <title>EUVD-2026-346800</title>
    <updated>2026-10-04T21:26:45.631735+00:00</updated>
    <content>EUVD-2026-346800</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-346800"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-37741</id>
    <title>fkie_cve-2025-37741</title>
    <updated>2026-10-04T21:26:45.631756+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>jfs: Prevent copying of nlink with value 0 from disk inode</p>
<p>syzbot report a deadlock in diFree. [1]</p>
<p>When calling "ioctl$LOOP_SET_STATUS64", the offset value passed in is 4,
which does not match the mounted loop device, causing the mapping of the
mounted loop device to be invalidated.</p>
<p>When creating the directory and creating the inode of iag in diReadSpecial(),
read the page of fixed disk inode (AIT) in raw mode in read_metapage(), the
metapage data it returns is corrupted, which causes the nlink value of 0 to be
assigned to the iag inode when executing copy_from_dinode(), which ultimately
causes a deadlock when entering diFree().</p>
<p>To avoid this, first check the nlink value of dinode before setting iag inode.</p>
<p>[1]
WARNING: possible recursive locking detected
6.12.0-rc7-syzkaller-00212-g4a5df3796467 #0 Not tainted
--------------------------------------------
syz-executor301/5309 is trying to acquire lock:
ffff888044548920 (&amp;(imap-&gt;im_aglock[index])){+.+.}-{3:3}, at: diFree+0x37c/0x2fb0 fs/jfs/jfs_imap.c:889</p>
<p>but task is already holding lock:
ffff888044548920 (&amp;(imap-&gt;im_aglock[index])){+.+.}-{3:3}, at: diAlloc+0x1b6/0x1630</p>
<p>other info that might help us debug this:
 Possible unsafe locking scenario:</p>
<p>CPU0
       ----
  lock(&amp;(imap-&gt;im_aglock[index]));
  lock(&amp;(imap-&gt;im_aglock[index]));</p>
<p>*** DEADLOCK ***</p>
<p>May be due to missing lock nesting notation</p>
<p>5 locks held by syz-executor301/5309:
 #0: ffff888…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-37741"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-q2h8-9338-55xq</id>
    <title>GHSA-q2h8-9338-55xq</title>
    <updated>2026-10-04T21:26:45.631856+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>jfs: Prevent copying of nlink with value 0 from disk inode</p>
<p>syzbot report a deadlock in diFree. [1]</p>
<p>When calling "ioctl$LOOP_SET_STATUS64", the offset value passed in is 4,
which does not match the mounted loop device, causing the mapping of the
mounted loop device to be invalidated.</p>
<p>When creating the directory and creating the inode of iag in diReadSpecial(),
read the page of fixed disk inode (AIT) in raw mode in read_metapage(), the
metapage data it returns is corrupted, which causes the nlink value of 0 to be
assigned to the iag inode when executing copy_from_dinode(), which ultimately
causes a deadlock when entering diFree().</p>
<p>To avoid this, first check the nlink value of dinode before setting iag inode.</p>
<p>[1]
WARNING: possible recursive locking detected
6.12.0-rc7-syzkaller-00212-g4a5df3796467 #0 Not tainted
--------------------------------------------
syz-executor301/5309 is trying to acquire lock:
ffff888044548920 (&amp;(imap-&gt;im_aglock[index])){+.+.}-{3:3}, at: diFree+0x37c/0x2fb0 fs/jfs/jfs_imap.c:889</p>
<p>but task is already holding lock:
ffff888044548920 (&amp;(imap-&gt;im_aglock[index])){+.+.}-{3:3}, at: diAlloc+0x1b6/0x1630</p>
<p>other info that might help us debug this:
 Possible unsafe locking scenario:</p>
<p>CPU0
       ----
  lock(&amp;(imap-&gt;im_aglock[index]));
  lock(&amp;(imap-&gt;im_aglock[index]));</p>
<p>*** DEADLOCK ***</p>
<p>May be due to missing lock nesting notation</p>
<p>5 locks held by syz-executor301/5309:
 #0: ffff888…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-q2h8-9338-55xq"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-37741</id>
    <title>msrc_CVE-2025-37741 — jfs: Prevent copying of nlink with value 0 from disk inode</title>
    <updated>2026-10-04T21:26:45.631940+00:00</updated>
    <content>msrc_CVE-2025-37741</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-37741"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-2465</id>
    <title>OESA-2025-2465 — kernel security update</title>
    <updated>2026-10-04T21:26:45.631971+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS: kernel</p>
<p>The Linux Kernel, the operating system core itself.

Security Fix(es):</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>Bluetooth: hci_conn: Use disable_delayed_work_sync</p>
<p>This makes use of disable_delayed_work_sync instead
cancel_delayed_work_sync as it not only cancel the ongoing work but also
disables new submit which is disarable since the object holding the work
is about to be freed.(CVE-2024-56591)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>ipv6: Fix memleak of nhc_pcpu_rth_output in fib_check_nh_v6_gw().</p>
<p>fib_check_nh_v6_gw() expects that fib6_nh_init() cleans up everything
when it fails.</p>
<p>Commit 7dd73168e273 (&amp;quot;ipv6: Always allocate pcpu memory in a fib6_nh&amp;quot;)
moved fib_nh_common_init() before alloc_percpu_gfp() within fib6_nh_init()
but forgot to add cleanup for fib6_nh-&amp;gt;nh_common.nhc_pcpu_rth_output in
case it fails to allocate fib6_nh-&amp;gt;rt6i_pcpu, resulting in memleak.</p>
<p>Let&amp;apos;s call fib_nh_common_release() and clear nhc_pcpu_rth_output in the
error path.</p>
<p>Note that we can remove the fib6_nh_release() call in nh_create_ipv6()
later in net-next.git.(CVE-2025-22005)</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>fs/ntfs3: Fix a couple integer overflows on 32bit systems</p>
<p>On 32bit systems the &amp;quot;off + sizeof(struct NTFS_DE)&amp;quot; addition can
have an integer wrapping issue.  Fix it by using size_add().(CVE-2025-22081)</p>
<p>In the Linux kernel, the following vulnerability has been re…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-2465"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:01964-1</id>
    <title>SUSE-SU-2025:01964-1 — Security update for the Linux Kernel</title>
    <updated>2026-10-04T21:26:45.632357+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for the Linux Kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:01964-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-37741</id>
    <title>UBUNTU-CVE-2025-37741</title>
    <updated>2026-10-04T21:26:45.632623+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: linux, Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe and 205 more</p>
<p>In the Linux kernel, the following vulnerability has been resolved: jfs: Prevent copying of nlink with value 0 from disk inode syzbot report a deadlock in diFree. [1] When calling "ioctl$LOOP_SET_STATUS64", the offset value passed in is 4, which does not match the mounted loop device, causing the mapping of the mounted loop device to be invalidated. When creating the directory and creating the inode of iag in diReadSpecial(), read the page of fixed disk inode (AIT) in raw mode in read_metapage(), the metapage data it returns is corrupted, which causes the nlink value of 0 to be assigned to the iag inode when executing copy_from_dinode(), which ultimately causes a deadlock when entering diFree(). To avoid this, first check the nlink value of dinode before setting iag inode. [1] WARNING: possible recursive locking detected 6.12.0-rc7-syzkaller-00212-g4a5df3796467 #0 Not tainted -------------------------------------------- syz-executor301/5309 is trying to acquire lock: ffff888044548920 (&amp;(imap-&gt;im_aglock[index])){+.+.}-{3:3}, at: diFree+0x37c/0x2fb0 fs/jfs/jfs_imap.c:889 but task is already holding lock: ffff888044548920 (&amp;(imap-&gt;im_aglock[index])){+.+.}-{3:3}, at: diAlloc+0x1b6/0x1630 other info that might help us debug this:  Possible unsafe locking scenario:        CPU0        ----   lock(&amp;(imap-&gt;im_aglock[index]));   lock(&amp;(imap-&gt;im_aglock[index]));  *** DEADLOCK ***  May be due to missing lock nesting notation 5 locks held by syz-executor301/5309:  #0: ffff8880422a4420 (s…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-37741"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0922</id>
    <title>WID-SEC-W-2025-0922 — Linux Kernel: Mehrere Schwachstellen</title>
    <updated>2026-10-04T21:26:45.633078+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um einen Denial of Service Angriff und nicht näher spezifizierte Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0922"/>
  </entry>
</feed>
